Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Bot Detected on Windows SBS 2003


  • This topic is locked This topic is locked
2 replies to this topic

#1 Unlock

Unlock

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:04:14 AM

Posted 09 March 2010 - 06:35 PM

Hi,

Im a server admin that manages 25 SBS2003 servers for various companies, Recently we have been having a problem permanantly removing a bot that is affecting one of these SBS 2003 servers, The bot was detected by Trend Micro RUBotted, The Servers primary role is a Domain controller and Exchange Server, The server is protected by Trend Micro Worry Free Business security and is up to date, It appears as though trend removes the bot but comes back after the server has been restarted.

Other than the bot being detected there does not appear to be any functional issues with the server other than the bot being detected on startup, I would like to remove this from appearing permanently.

Can you please take a look at the Hijack this log listed below and let me know if you can see anything that is suspicious.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:54:00 AM, on 10/03/2010
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP\Cissesrv\cissesrv.exe
C:\WINDOWS\system32\cpqrcmc.exe
C:\hp\hpsmh\data\cgi-bin\vcagent\vcagent.exe
C:\Program Files\RemoteSupportManager\DaMaint.exe
C:\WINDOWS\system32\dfssvc.exe
C:\WINDOWS\System32\dns.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\logmein.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SHAREPOINT\Binn\sqlservr.exe
C:\WINDOWS\system32\ntfrs.exe
C:\Program Files\Trend Micro\Security Server\PCCSRV\Web\Service\ofcaosmgr.exe
C:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exe
C:\Program Files\RemoteSupportManager\DesktopAuthority.exe
C:\Program Files\Trend Micro\RUBotted\tmrubotted.exe
C:\Program Files\Trend Micro\Messaging Security Agent\svcGenericHost.exe
C:\Program Files\Trend Micro\Messaging Security Agent\svcGenericHost.exe
C:\Program Files\Trend Micro\Messaging Security Agent\smex_systemwatcher.exe
C:\Program Files\Trend Micro\Messaging Security Agent\smex_master.exe
C:\Program Files\Kyocera\FileUtility\SFUSVC.exe
C:\Program Files\Kyocera\FileUtility\nsCatCom.exe
C:\Program Files\Trend Micro\Security Server\PCCSRV\Web\Service\DbServer.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\60\BIN\OWSTIMER.EXE
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\sysdown.exe
C:\hp\hpsmh\bin\smhstart.exe
C:\WINDOWS\System32\svchost.exe
C:\hp\hpsmh\bin\hpsmhd.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\hp\hpsmh\bin\hpsmhd.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\Program Files\Trend Micro\WFRMAgentForCSM\tmicagent.exe
C:\Program Files\Trend Micro\WFRMAgentForCSM\tmicAgentMonitor.exe
C:\WINDOWS\system32\CPQNiMgt\cpqnimgt.exe
C:\WINDOWS\system32\CpqMgmt\cqmgserv\cqmgserv.exe
C:\WINDOWS\system32\CpqMgmt\cqmgstor\cqmgstor.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\system32\vsnapvss.exe
C:\WINDOWS\system32\CpqMgmt\cqmghost\cqmghost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\LogMeIn\x86\logmeinsystray.exe
C:\Program Files\HP\NCU\cpqteam.exe
C:\Program Files\Windows Defender\msascui.exe
C:\Program Files\RemoteSupportManager\rmgui.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Trend Micro\WFRMAgentForCSM\tmicAgentSetting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtect.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\system32\mmc.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Exchsrvr\bin\store.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\N-able Technologies\Windows Software Probe\bin\WSPMaint.exe
C:\Program Files\N-able Technologies\Windows Software Probe\syslog\nsyslog.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\N-able Technologies\Windows Agent\bin\agent.exe
C:\Program Files\N-able Technologies\Windows Agent\bin\AgentMaint.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\WINDOWS\System32\logon.scr
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
C:\Program Files\Microsoft Windows Small Business Server\UpdateServices\Microsoft.SBS.UpdateServices.SBSUpdateServicesSecondDefaults.exe
C:\Program Files\Common Files\Microsoft Shared\DW\dw20.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cmd.exe
\spsrv\ofcscan\AutoPcc.exe
C:\Program Files\LogMeIn\x86\logmeinsystray.exe
C:\Program Files\HP\NCU\cpqteam.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\RemoteSupportManager\rmgui.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Trend Micro\WFRMAgentForCSM\tmicAgentSetting.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kyocera\FileUtility\NsCatCom.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Documents and Settings\utadmin\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\Client Server Security Agent\Misc\xpupg.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntupd.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [CPQTEAM] C:\Program Files\HP\NCU\cpqteam.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Remote Support Manager GUI] "C:\Program Files\RemoteSupportManager\rmgui.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [DWPersistentQueuedReporting] C:\PROGRA~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE -a
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKLM\..\Run: [TMIC Agent Setting Tool] "C:\Program Files\Trend Micro\WFRMAgentForCSM\tmicAgentSetting.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-550381277-1336893177-3339659235-1145\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SMX_SPSRV')
O4 - HKUS\S-1-5-21-550381277-1336893177-3339659235-1145\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SMX_SPSRV')
O4 - HKUS\S-1-5-21-550381277-1336893177-3339659235-1638\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'utservice')
O4 - HKUS\S-1-5-21-550381277-1336893177-3339659235-1638\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'utservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Scanner File Utility.lnk = ?
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O15 - ESC Trusted Zone: http://delphi.about.com
O15 - ESC Trusted Zone: http://z.about.com
O15 - ESC Trusted Zone: http://www.angryziber.com
O15 - ESC Trusted Zone: http://*.antispw.info
O15 - ESC Trusted Zone: http://view.atdmt.com
O15 - ESC Trusted Zone: http://www.bleepingcomputer.com
O15 - ESC Trusted Zone: http://www.codeode.com
O15 - ESC Trusted Zone: http://ninemsn.com.au
O15 - ESC Trusted Zone: http://searchsecurity.techtarget.com.au
O15 - ESC Trusted Zone: http://www.computerworld.com.au
O15 - ESC Trusted Zone: http://www.google.com.au
O15 - ESC Trusted Zone: http://www.idg.com.au
O15 - ESC Trusted Zone: http://www.dgmaustralia.com
O15 - ESC Trusted Zone: http://ad.doubleclick.net
O15 - ESC Trusted Zone: http://ad.au.doubleclick.net
O15 - ESC Trusted Zone: http://bwp.download.com
O15 - ESC Trusted Zone: http://software-files.download.com
O15 - ESC Trusted Zone: http://www.download.com
O15 - ESC Trusted Zone: http://www.dshield.org
O15 - ESC Trusted Zone: http://www.networking.eweek.com
O15 - ESC Trusted Zone: http://tags.expo9.exponential.com
O15 - ESC Trusted Zone: http://www.f-secure.com
O15 - ESC Trusted Zone: http://media.fastclick.net
O15 - ESC Trusted Zone: http://www.google-analytics.com
O15 - ESC Trusted Zone: http://groups.google.com.au
O15 - ESC Trusted Zone: http://pagead2.googlesyndication.com
O15 - ESC Trusted Zone: http://www.innofiles.com
O15 - ESC Trusted Zone: http://www.innovative-sol.com
O15 - ESC Trusted Zone: http://bleepingcomputer.us.intellitxt.com
O15 - ESC Trusted Zone: http://support.iress.com.au
O15 - ESC Trusted Zone: http://www.iress.com.au
O15 - ESC Trusted Zone: http://www.itsecurityportal.com
O15 - ESC Trusted Zone: http://blogs.ittoolbox.com
O15 - ESC Trusted Zone: http://www.jam-software.com
O15 - ESC Trusted Zone: http://www.kyoceramita.co.uk
O15 - ESC Trusted Zone: http://www.liutilities.com
O15 - ESC Trusted Zone: http://search.live.com
O15 - ESC Trusted Zone: http://ads1.msn.com
O15 - ESC Trusted Zone: http://rad.msn.com
O15 - ESC Trusted Zone: http://runonce.msn.com
O15 - ESC Trusted Zone: http://nepenthes.mwcollect.org
O15 - ESC Trusted Zone: http://www.networknotepad.com
O15 - ESC Trusted Zone: http://www.neuber.com
O15 - ESC Trusted Zone: http://www.petri.co.il
O15 - ESC Trusted Zone: http://winsite.planetmirror.com
O15 - ESC Trusted Zone: http://www.processlibrary.com
O15 - ESC Trusted Zone: http://www.protectorplus.com
O15 - ESC Trusted Zone: http://www.rarlab.com
O15 - ESC Trusted Zone: http://www.realtime-websecurity.com
O15 - ESC Trusted Zone: http://ask.slashdot.org
O15 - ESC Trusted Zone: http://www.smallbizserver.net
O15 - ESC Trusted Zone: http://webscripts.softpedia.com
O15 - ESC Trusted Zone: http://www.softwarepatch.com
O15 - ESC Trusted Zone: http://www.springerlink.com
O15 - ESC Trusted Zone: http://sony.storagesupport.com
O15 - ESC Trusted Zone: http://download.sysinternals.com
O15 - ESC Trusted Zone: http://an.tacoda.net
O15 - ESC Trusted Zone: http://go.trendmicro.com
O15 - ESC Trusted Zone: http://housecall65.trendmicro.com
O15 - ESC Trusted Zone: http://www.trendmicro.com
O15 - ESC Trusted Zone: http://a.tribalfusion.com
O15 - ESC Trusted Zone: http://noc.unlock.net.au
O15 - ESC Trusted Zone: http://www2.unlocktechnology.com.au
O15 - ESC Trusted Zone: http://ftp.snt.utwente.nl
O15 - ESC Trusted Zone: http://m.webtrends.com
O15 - ESC Trusted Zone: http://statse.webtrendslive.com
O15 - ESC Trusted Zone: http://*.windowsupdate.com
O15 - ESC Trusted Zone: http://dl.winsite.com
O15 - ESC Trusted Zone: http://www.winsite.com
O15 - ESC Trusted Zone: http://i.zdnet.com
O15 - ESC Trusted Zone: http://news.zdnet.com
O15 - ESC Trusted Zone: http://*.windowsupdate.com (HKLM)
O15 - ESC Trusted IP range: http://127.0.0.1
O15 - ESC Trusted IP range: http://192.168.15.254
O16 - DPF: {9BBB3919-F518-4D06-8209-299FC243FC2A} (Encrypt Class) - https://localhost:4343/SMB/console/html/root/AtxEnc.cab
O16 - DPF: {9DCD8EB7-E925-45C9-9321-8CA843FBED3C} (Security Server Management Console) - https://localhost:4343/SMB/console/html/root/AtxConsole.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sp.local
O17 - HKLM\Software\..\Telephony: DomainName = sp.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{C58E7960-E51F-482B-8480-5F5CB2BE5E1A}: NameServer = 192.168.19.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sp.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = sp.local
O18 - Protocol: hpapp - {24F45006-5BD9-41B7-9BD9-5F8921C8EBD1} - C:\Program Files\Compaq\hpadu\bin\hpapp.dll
O20 - AppInit_DLLs: DAinit.dll
O23 - Service: HP Smart Array SAS/SATA Event Notification Service (Cissesrv) - Hewlett-Packard Company - C:\Program Files\HP\Cissesrv\cissesrv.exe
O23 - Service: HP Insight NIC Agents (CpqNicMgmt) - Hewlett-Packard Company - C:\WINDOWS\system32\CPQNiMgt\cpqnimgt.exe
O23 - Service: HP ProLiant Remote Monitor Service (CpqRcmc) - Hewlett-Packard Company - C:\WINDOWS\system32\cpqrcmc.exe
O23 - Service: HP Version Control Agent (cpqvcagent) - Hewlett-Packard Company - C:\hp\hpsmh\data\cgi-bin\vcagent\vcagent.exe
O23 - Service: HP Insight Foundation Agents (CqMgHost) - Hewlett-Packard Company - C:\WINDOWS\system32\CpqMgmt\cqmghost\cqmghost.exe
O23 - Service: HP Insight Server Agents (CqMgServ) - Hewlett-Packard Company - C:\WINDOWS\system32\CpqMgmt\cqmgserv\cqmgserv.exe
O23 - Service: HP Insight Storage Agents (CqMgStor) - Hewlett-Packard Company - C:\WINDOWS\system32\CpqMgmt\cqmgstor\cqmgstor.exe
O23 - Service: Remote Support Manager Maintenance Service (DAMaint) - ScriptLogic Corporation - C:\Program Files\RemoteSupportManager\DaMaint.exe
O23 - Service: Trend Micro Messaging Security Agent EUQ Migrator (EUQ_Migrator) - Trend Micro Inc. - C:\Program Files\Trend Micro\Messaging Security Agent\EUQ\EUQMigrator.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: Trend Micro Plug-in Manager (OfcAoSMgr) - Trend Micro Inc. - C:\Program Files\Trend Micro\Security Server\PCCSRV\Web\Service\OfcAoSMgr.exe
O23 - Service: Trend Micro Security Server Master Service (ofcservice) - Trend Micro Inc. - C:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\ofcservice.exe
O23 - Service: Remote Support Manager Service (RemoteSupportManager) - ScriptLogic Corporation - C:\Program Files\RemoteSupportManager\DesktopAuthority.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: Trend Micro Messaging Security Agent Master Service (ScanMail_Master) - Trend Micro Inc. - C:\Program Files\Trend Micro\Messaging Security Agent\svcGenericHost.exe
O23 - Service: Trend Micro Messaging Security Agent Remote Configuration Server (ScanMail_RemoteConfig) - Trend Micro Inc. - C:\Program Files\Trend Micro\Messaging Security Agent\svcGenericHost.exe
O23 - Service: Trend Micro Messaging Security Agent System Watcher (ScanMail_SystemWatcher) - Trend Micro Inc. - C:\Program Files\Trend Micro\Messaging Security Agent\svcGenericHost.exe
O23 - Service: SFUSVC - KYOCERA MITA CORPORATION - C:\Program Files\Kyocera\FileUtility\SFUSVC.exe
O23 - Service: ShadowProtect Service (ShadowProtectSvc) - StorageCraft Technology Corporation - C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
O23 - Service: HP ProLiant System Shutdown Service (sysdown) - Hewlett-Packard Company - C:\WINDOWS\system32\sysdown.exe
O23 - Service: HP System Management Homepage (SysMgmtHp) - Hewlett-Packard Company - C:\hp\hpsmh\bin\smhstart.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe
O23 - Service: Trend Micro Client/Server Security Agent Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe
O23 - Service: Trend Micro Worry-Free Remote Manager Agent - Trend Micro Inc. - C:\Program Files\Trend Micro\WFRMAgentForCSM\TMICAgent.exe
O23 - Service: VisiScheduler(Network) - IWL Ltd. - E:\Applications\VisiPlan\DotNetApp\Local\\IWL.VisiPlan.Scheduler.Service.exe
O23 - Service: StorageCraft Shadow Copy Provider (VSNAPVSS) - StorageCraft Technology Corporation - C:\WINDOWS\system32\vsnapvss.exe
O23 - Service: Windows Agent Maintenance Service - N-able Technologies - C:\Program Files\N-able Technologies\Windows Agent\bin\AgentMaint.exe
O23 - Service: Windows Agent Service - N-able Technologies - C:\Program Files\N-able Technologies\Windows Agent\bin\agent.exe
O23 - Service: Windows Software Probe Maintenance Service - N-able Technologies - C:\Program Files\N-able Technologies\Windows Software Probe\bin\WSPMaint.exe
O23 - Service: Windows Software Probe Service - N-able Technologies - C:\Program Files\N-able Technologies\Windows Software Probe\bin\wsp.exe
O23 - Service: Windows Software Probe Syslog Service - Unknown owner - C:\Program Files\N-able Technologies\Windows Software Probe\syslog\nsyslog.exe
O23 - Service: XFBE - Unknown owner - C:\DOCUME~1\utadmin\LOCALS~1\Temp\XFBE.exe (file missing)

--
End of file - 20842 bytes

Edited by Orange Blossom, 09 March 2010 - 11:16 PM.
Move to log forum. ~ OB


BC AdBot (Login to Remove)

 


#2 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:05:14 PM

Posted 12 March 2010 - 07:42 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below I will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE


And

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.


Then

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.


  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.
Posted Image
m0le is a proud member of UNITE

#3 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:05:14 PM

Posted 18 March 2010 - 08:17 PM

This topic has been closed.

If you're the topic starter, and need this topic reopened, please contact me via pm with the address of the thread.

Everyone else please begin a New Topic.
Posted Image
m0le is a proud member of UNITE




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users