Scan your PC for Errors

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Virus infection on server

[Fixed] Hijackthis! Logs - [Fixed] Virus infection on server posted in the Security & Safety forums; Hmm... ok, I'll take a look at the free software....

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 03-14-2006
Bronze Member
 
Join Date: Mar 2006
Posts: 70
adigiorgio - See this Members User comments on their Profile page
Default

Hmm... ok, I'll take a look at the free software.


  #9  
Old 03-14-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Boot youre pc in safemode (hit f8 when booting up).


Click Start>Run and type in: services.msc
Click OK
In the Services window find: BusinessC
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK

Open HJT and click config > misc tools > ?delete an NT service?
Copy and past:BusinessContinuity
Click OK.

Then remove this entry with hjt:

O23 - Service: BusinessC (BusinessContinuity) - Unknown owner - C:\WINNT\msstl.exe (file missing)


And do you know what this is from?

O23 - Service: 83022 - Unknown owner - \\64.166.34.170\Admin$\eraseme_70210.exe

If not , please upload the file in bold to this site:

http://www.virustotal.com/flash/index_en.html


And can you also do an Panda AV scan online and post the resulting log file:

http://www.pandasoftware.com/products/activescan.htm


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 03-14-2006 at 10:49 PM.
  #10  
Old 03-14-2006
Friend of PCHF
 
Join Date: Sep 2004
Location: Right here !
Posts: 2,149
Zimbo - See this Members User comments on their Profile page
Default

dvprpt is part of command AV itself.
:laughing4


  #11  
Old 03-23-2006
Bronze Member
 
Join Date: Mar 2006
Posts: 70
adigiorgio - See this Members User comments on their Profile page
Default

OK, now that you're done laughing at the n00b, here's what I've done...

I ran the free clam virus scanner (which, by the way, took 5 days to fully scan the server). Attached is the report. I also followed the instructions posted by joe5. However, I was unable to locate the file in question. From what I saw of the clam scan, the virus is only located in the old backups.
Attached Files
File Type: txt clamav_report_220306_160312.txt (2.9 KB, 1 views)


  #12  
Old 03-23-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by adigiorgio
OK, now that you're done laughing at the n00b, here's what I've done...
Nah , i wasn't laughing at you , but the Command AV app.

Originally Posted by adigiorgio
I ran the free clam virus scanner (which, by the way, took 5 days to fully scan the server)
:o 5 days?!? How much storage space is on there? And what is the system resources usage of the server?

Originally Posted by adigiorgio
I also followed the instructions posted by joe5. However, I was unable to locate the file in question.
Do you regocnize this IP?

64.166.34.170 (SBC Internet Services )

Why is there a service with an file on that IP running on there?
Is it a pc related to youre company or anything?

I dont have a clue as to what that service/file is , but it looks highly suspisious to me..

Originally Posted by adigiorgio
From what I saw of the clam scan, the virus is only located in the old backups.
It is probebly imbedded in old emails , any objections in deleting those backup files? (i dont know what else is in there)

If you dont want to delete them then try the Stinger tool (see link below in my sig) or one of the special bagle-h removal tools here:

http://secunia.com/virus_information/599/bagle-h/



Or you can delete the files with Killbox:

Download Pocket Killbox:
http://www.atribune.org/downloads/KillBox.exe

Start Killbox and place a tick next to [x]delete on reboot.
And press the "all files" button. (just above the yellow triangle)

Copy this list into the windows clipboard:


C:\Backups\B2D000005.bkf
C:\Backups\B2D000007.bkf
C:\Backups\B2D000013.bkf
C:\Backups\B2D000026.bkf
C:\Backups\B2D000027.bkf
C:\Backups\B2D000030.bkf
C:\Backups\B2D000036.bkf
C:\Backups\B2D000040.bkf
C:\Backups\B2D000041.bkf
C:\Backups\B2D000046.bkf
C:\Backups\B2D000053.bkf
C:\Backups\B2D000054.bkf
C:\Backups\B2D000056.bkf
C:\Backups\B2D000057.bkf
C:\Backups\B2D000059.bkf
C:\Backups\B2D000064.bkf
C:\Backups\B2D000069.bkf
C:\Backups\B2D000076.bkf
C:\Backups\B2D000079.bkf
C:\Backups\B2D000081.bkf
C:\Backups\B2D000086.bkf
C:\Backups\B2D000094.bkf
C:\Backups\B2D000096.bkf
C:\Backups\B2D000098.bkf
C:\Backups\B2D000099.bkf


Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 03-23-2006 at 03:28 AM.
  #13  
Old 03-24-2006
Bronze Member
 
Join Date: Mar 2006
Posts: 70
adigiorgio - See this Members User comments on their Profile page
Default

64.166.34.170 is our IP address. We have a VPN running with remote users logging on and off.

I deleted those backups and found that to be the reason the virus scan took so long. Those backups took up over 80% of the space on our server! I don't even know where they came from because we use Acronis True Image and it backs up to an external HD.

Anyways, thanks for your help. I'm going to run another Clam scan and see what it finds this time (and see if it is quicker)


  #14  
Old 03-24-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looks like it are files from Windows backup utility set , and there is a change that they are automaticly scheduled and will keep filling the HD up again.

Have a look here for more info and instructions:

http://www.microsoft.com/windowsxp/u..._03july14.mspx


And do you still get the virus warning?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 04:04 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top