Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Win2K3 Server - Firefox opening new tabs


  • This topic is locked This topic is locked
2 replies to this topic

#1 Nodlew

Nodlew

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:07:43 AM

Posted 25 August 2010 - 07:26 PM

Mod EDIT: Moved to proper forum,Virus, Trojan, Spyware, and Malware Removal Logs ~~boopme
Hello all,

I have a 2K3 server that somebody recently logged onto and did some web browsing (I know, I deserve flames for even making this possible but the fact is I need to fix it).

I recently noticed when I tried to RDP to the box that it appears the explorer process would crash within 24 hrs of booting. A little digging in the event viewer also showed errors indicating that Windows Updates could not reach the microsoft site. I've done a bit of digging with AutoRuns and ProcessExplorer and nothing is standing out, but Firefox is opening new tabs, and going to any microsoft sites times out. Googling MS sites gives results, but when I try to visit them I just get returned to google. As the OS on this box is Win2K3, a number of tools that I've read about are not compatible with this machine.

I'm getting desperate, any assistance would be appreciated.

HJT log attached:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:24:44 PM, on 8/25/2010
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WIN2K3\System32\smss.exe
C:\WIN2K3\system32\winlogon.exe
C:\WIN2K3\system32\services.exe
C:\WIN2K3\system32\lsass.exe
C:\WIN2K3\system32\svchost.exe
C:\WIN2K3\System32\svchost.exe
C:\WIN2K3\System32\dns.exe
C:\WIN2K3\system32\spoolsv.exe
C:\WIN2K3\System32\svchost.exe
C:\WIN2K3\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WIN2K3\System32\svchost.exe
C:\WIN2K3\system32\ntfrs.exe
C:\WIN2K3\system32\nvsvc32.exe
C:\WIN2K3\System32\svchost.exe
C:\Program Files\SolarWinds\TFTPServer\SolarWinds TFTP Server.exe
C:\WIN2K3\System32\wins.exe
C:\WIN2K3\system32\Dfssvc.exe
C:\WIN2K3\System32\svchost.exe
C:\WIN2K3\System32\svchost.exe
C:\WIN2K3\System32\svchost.exe
C:\WIN2K3\Explorer.EXE
C:\WIN2K3\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\SolarWinds\TFTPServer\TFTPServer.exe
C:\WIN2K3\system32\rundll32.exe
C:\WIN2K3\system32\mmc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://iesetup.dll/hardAdmin.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ahsmail.capitalhealth.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WIN2K3\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WIN2K3\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WIN2K3\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: TFTP Server.lnk = C:\Program Files\SolarWinds\TFTPServer\TFTPServer.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O15 - ESC Trusted Zone: http://get.adobe.com
O15 - ESC Trusted Zone: http://www.adobe.com
O15 - ESC Trusted Zone: http://wwwimages.adobe.com
O15 - ESC Trusted Zone: http://www.cnn.com
O15 - ESC Trusted Zone: http://*.jade
O15 - ESC Trusted Zone: http://runonce.msn.com
O15 - ESC Trusted Zone: http://i.cdn.turner.com
O15 - ESC Trusted Zone: http://*.windowsupdate.com
O15 - ESC Trusted Zone: http://*.windowsupdate.com (HKLM)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = AD.local
O17 - HKLM\Software\..\Telephony: DomainName = AD.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{9FE3E5C5-A229-446C-B82B-DE0A7CDFEC60}: NameServer = 10.8.18.1,10.8.18.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{B5CCF4FE-4984-4A6B-BC5E-B60CCF572117}: NameServer = 10.8.18.110,10.8.18.10
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = AD.local
O17 - HKLM\System\CS1\Services\Tcpip\..\{9FE3E5C5-A229-446C-B82B-DE0A7CDFEC60}: NameServer = 10.8.18.1,10.8.18.110
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = AD.local
O17 - HKLM\System\CS2\Services\Tcpip\..\{9FE3E5C5-A229-446C-B82B-DE0A7CDFEC60}: NameServer = 10.8.18.1,10.8.18.110
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WIN2K3\system32\nvsvc32.exe
O23 - Service: PsExec (PSEXESVC) - Sysinternals - C:\WIN2K3\PSEXESVC.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SolarWinds TFTP Server - SolarWinds - C:\Program Files\SolarWinds\TFTPServer\SolarWinds TFTP Server.exe

--
End of file - 7225 bytes

Edited by boopme, 25 August 2010 - 08:59 PM.


BC AdBot (Login to Remove)

 


#2 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:01:43 PM

Posted 30 August 2010 - 07:07 PM

Hi,

Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.

  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.

  • Please reply to this post so I know you are there.
The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.

Once I receive a reply then I will return with your first instructions.

Thanks thumbup2.gif
Posted Image
m0le is a proud member of UNITE

#3 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:01:43 PM

Posted 04 September 2010 - 06:28 PM

This topic has been closed.

If you're the topic starter, and need this topic reopened, please contact me via pm with the address of the thread.

Everyone else please begin a New Topic.
Posted Image
m0le is a proud member of UNITE




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users