windows 2003 med malware / virus (hijack)
Logfile of Trend Micro HijackThis v2.0.4Scan saved at 4:40:26 AM, on 5/7/2010
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Parallels\Plesk\kav\kavsvc.exe
C:\Program Files\SmarterTools\SmarterMail\Service\MailService.exe
C:\Program Files\Parallels\Plesk\Mail Servers\Mail
Enable\Bin\MELSC.EXE
C:\Program Files\Parallels\Plesk\Mail Servers\Mail
Enable\Bin\MEMTA.EXE
C:\Program Files\Parallels\Plesk\Mail Servers\Mail
Enable\Bin\MEPOC.EXE
C:\Program Files\Parallels\Plesk\Mail Servers\Mail
Enable\Bin\MEPOPS.EXE
C:\Program Files\Parallels\Plesk\Mail Servers\Mail
Enable\Bin\MESMTPC.EXE
C:\Program Files\Parallels\Plesk\Databases\MySQL\bin\mysqld-nt.exe
C:\Program Files\Parallels\Plesk\dns\bin\named.exe
C:\Program Files\Parallels\Plesk\admin\bin\plesksrv.exe
C:\Program Files\Red5\wrapper\wrapper.exe
C:\Program
Files\Parallels\Plesk\SiteBuilder\HostingService\Bin\HostingServic
e.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\SmarterTools\SmarterMail\Web Server\SMWebSvr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Parallels\Plesk\stunnel\stunnel.exe
C:\Program Files\Parallels\Plesk\Additional\Tomcat\bin\tomcat5.exe
C:\Program Files\Parallels\Plesk\admin\bin\PopPassD.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Parallels\Plesk\admin\bin\PleskControlPanel.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program
Files\Parallels\Plesk\Acronis\TrueImageEnterprise\TrueImageMonitor
.exe
C:\Program
Files\Parallels\Plesk\Acronis\TrueImageEnterprise\TimounterMonitor
.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Parallels\Plesk\admin\bin\traymonitor.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\igfxsrvc.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Parallels\Plesk\Additional\PleskPHP5\php-cgi.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Parallels\Plesk\Additional\PleskPHP5\php-cgi.exe
C:\Program Files\Parallels\Plesk\Additional\PleskPHP5\php-cgi.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
about:blank
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext
= http://update.microsoft.com/
O2 - BHO: BitComet ClickCapture -
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program
Files\BitComet\tools\BitCometBHO_1.4.1.10.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} -
C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper -
{DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program
Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl -
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program
Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program
Files\Parallels\Plesk\Acronis\TrueImageEnterprise\TrueImageMonitor
.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program
Files\Parallels\Plesk\Acronis\TrueImageEnterprise\TimounterMonitor
.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program
Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [ClamWin] "C:\Program
Files\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0
-u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program
Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [BitTorrent] "C:\Program
Files\BitTorrent\bittorrent.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program
Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 -
HKUS\S-1-5-21-3939834843-3727261901-931908913-1013\..\RunOnce:
[tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Plesk
Administrator')
O4 - HKUS\S-1-5-21-3939834843-3727261901-931908913-1035\..\Run:
[IDMan] C:\Program Files\Internet Download Manager\IDMan.exe
/onboot (User 'MJ-Team')
O4 - HKUS\S-1-5-21-3939834843-3727261901-931908913-1035\..\Run:
[Skype] "C:\Documents and Settings\MJ-Team\Local
Settings\Application Data\Skype\Phone\Skype.exe" /nosplash
/minimized (User 'MJ-Team')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Plesk Services Monitor.lnk = C:\Program
Files\Parallels\Plesk\admin\bin\traymonitor.exe
O8 - Extra context menu item: &D&ownload &with BitComet -
res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet -
res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet -
res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Google Sidewiki... -
res://C:\Program Files\Google\Google
Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll
/cmsidewiki.html
O9 - Extra button: BitComet -
{D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program
Files\BitComet\tools\BitCometBHO_1.4.1.10.dll/206 (file missing)
O15 - ESC Trusted Zone: http://runonce.msn.com
O15 - ESC Trusted Zone: http://*.windowsupdate.com
O15 - ESC Trusted Zone: http://*.windowsupdate.com (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl
Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cli
ent/wuweb_site.cab?1262723386531
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash
.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{4F7F2267-1246-4CB1-B083-C71E70B
870CC}: NameServer = 76.73.0.2,76.73.0.3
O22 - SharedTaskScheduler: Browseui preloader -
{438755C2-A8BA-11D1-B96B-00A0C90312E1} -
C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon -
{8C7461EF-2B13-11d2-BE35-3078302C2030} -
C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis -
C:\Program Files\Common Files\Acronis\Agent\agent.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis -
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: DrWebCom - Doctor Web Ltd. - C:\Program
Files\Parallels\Plesk\DrWeb\drwebcom.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun
Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kaspersky Antivirus TM (kavsvc) - Parallels, Inc -
C:\Program Files\Parallels\Plesk\kav\kavsvc.exe
O23 - Service: SmarterMail Service (MailService) - Unknown owner -
C:\Program Files\SmarterTools\SmarterMail\Service\MailService.exe
O23 - Service: MailEnable List Connector (MELCS) - Unknown owner -
C:\Program Files\Parallels\Plesk\Mail Servers\Mail
Enable\Bin\MELSC.EXE
O23 - Service: MailEnable Mail Transfer Agent (MEMTAS) - Unknown
owner - C:\Program Files\Parallels\Plesk\Mail Servers\Mail
Enable\Bin\MEMTA.EXE
O23 - Service: MailEnable Postoffice Connector (MEPOCS) - Unknown
owner - C:\Program Files\Parallels\Plesk\Mail Servers\Mail
Enable\Bin\MEPOC.EXE
O23 - Service: MailEnable POP Service (MEPOPS) - Unknown owner -
C:\Program Files\Parallels\Plesk\Mail Servers\Mail
Enable\Bin\MEPOPS.EXE
O23 - Service: MailEnable SMTP Connector (MESMTPCS) - Unknown
owner - C:\Program Files\Parallels\Plesk\Mail Servers\Mail
Enable\Bin\MESMTPC.EXE
O23 - Service: Network Windows Service (MSWindows) - Unknown owner
- C:\WINDOWS\system32\urdvxc.exe (file missing)
O23 - Service: MySQL Server (MySQL) - Unknown owner - C:\Program
Files\Parallels\Plesk\Databases\MySQL\bin\mysqld-nt.exe
O23 - Service: Plesk Name Server (named) - Unknown owner -
C:\Program Files\Parallels\Plesk\dns\bin\named.exe
O23 - Service: Parallels Plesk Panel service (PleskControlPanel) -
Parallels, Inc - C:\Program
Files\Parallels\Plesk\admin\bin\PleskControlPanel.exe
O23 - Service: Plesk Management Service (plesksrv) - Parallels,
Inc - C:\Program Files\Parallels\Plesk\admin\bin\plesksrv.exe
O23 - Service: Plesk PopPass Service (PopPassD) - Parallels, Inc -
C:\Program Files\Parallels\Plesk\admin\bin\PopPassD.exe
O23 - Service: Red5 - Unknown owner - C:\Program
Files\Red5\wrapper\wrapper.exe
O23 - Service: Sitebuilder for Windows Hosting Service
(SBPreviewHost) - Parallels - C:\Program
Files\Parallels\Plesk\SiteBuilder\HostingService\Bin\HostingServic
e.exe
O23 - Service: Sitebuilder for Windows Updater Service (SBUpdater)
- Parallels - C:\Program
Files\Parallels\Plesk\SiteBuilder\HostingService\Bin\HostingServic
e.exe
O23 - Service: SmarterMail Web Server (SMWebSvr) - SmarterTools
Inc - C:\Program Files\SmarterTools\SmarterMail\Web
Server\SMWebSvr.exe
O23 - Service: Plesk SSL Wrapper Service (stunnel) - Unknown owner
- C:\Program Files\Parallels\Plesk\stunnel\stunnel.exe
O23 - Service: Apache Tomcat (Tomcat5) - Apache Software
Foundation - C:\Program
Files\Parallels\Plesk\Additional\Tomcat\bin\tomcat5.exe
O23 - Service: XBT Tracker - Unknown owner - C:\Program
Files\XBT\Tracker\XBT Tracker.exe
--
End of file - 11135 bytes