PC attempts connnection to malware site - Can't find the culprit app
My supervisor's PC is repeatedly trying to connect to:
http://203. 121. 69. 232 /theif2 /parse.php?op=log &fn=07_06_2007.html &user=SYSTEM_PC67&str= [spaces added to keep the URL from being clickable]
The only references I found for this IP are ramazun.com and registration from Australia.
I have scanned with Ad-aware SE, Spybot S&D v1.4, Ewido v3.5, Housecall from Trend Micro and TrojanScan.com. Nothing major was found by ANY of these scanners.
I looked at the processes with Sysinternals Process Explorer -- nothing odd looking there.
The PC seems to try on a random time basis -- even if the web browser is closed. It will try more frequently when the browser is open, though. The same results seem to occur whether Firefox or IE6 are used.
PC is a Gateway E-series workstation w/ Win XP Pro SP2 / Office 2003 SP? and a few other apps.
I am attaching the HJT log for your review. Certain items are redacted so as not to expose personal information. I would appreciate ANY help you folks can offer.
My supervisor's PC is repeatedly trying to connect to:
http://203. 121. 69. 232 /theif2 /parse.php?op=log &fn=07_06_2007.html &user=SYSTEM_PC67&str= [spaces added to keep the URL from being clickable]
The only references I found for this IP are ramazun.com and registration from Australia.
I have scanned with Ad-aware SE, Spybot S&D v1.4, Ewido v3.5, Housecall from Trend Micro and TrojanScan.com. Nothing major was found by ANY of these scanners.
I looked at the processes with Sysinternals Process Explorer -- nothing odd looking there.
The PC seems to try on a random time basis -- even if the web browser is closed. It will try more frequently when the browser is open, though. The same results seem to occur whether Firefox or IE6 are used.
PC is a Gateway E-series workstation w/ Win XP Pro SP2 / Office 2003 SP? and a few other apps.
I am attaching the HJT log for your review. Certain items are redacted so as not to expose personal information. I would appreciate ANY help you folks can offer.