TechSpot

HiJackThis experts, please help me

By TechInNeedmm
Jul 14, 2005
  1. Hi all,

    I am having a problem with my server here and am unable to figure out the root of it. Please take a look at the attached to help me determine if my system is clean or not.

    Thanks in advance.
     

    Attached Files:

  2. RealBlackStuff

    RealBlackStuff TS Rookie Posts: 6,503

    You should install SP4, then do the online Windows update.

    You have no infections. The suggestions below are mainly cosmetic.

    Run a HJT scan and place a tick-mark in the little square before:
    ...................................................................................................
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O4 - Startup: map.bat <<== is this yours (click Start/Programs/Startup)? If not 'fix' it
    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    Unless mosey.on.ca is yours, fix these 3 'mosey' entries
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mosey.on.ca
    Unless these IPs are from your ISP, fix it
    O17 - HKLM\System\CCS\Services\Tcpip\..\{51CA0EEF-FDA9-4492-9682-40DC50E3B93F}: NameServer = 216.254.141.3,209.90.160.221
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mosey.on.ca
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mosey.on.ca
    O23 - Service: Microsoft Connector for POP3 Mailboxes (MSPOP3Connector) - Unknown owner - C:\Program Files\Microsoft BackOffice\Connectivity\POP3 Connector\vmimb.exe" /SERVICE (file missing)
    ...................................................................................................
    Now click on the Fix Checked button in HJT.

    Delete all files and directories from: C:\Documents and Settings\[username]\Local Settings\Temp
    Repeat this for ALL [usernames].
    Delete all files and directories from: C:\WINDOWS\Temp (except files dated from TODAY).

    Your server-problems do not manifest themselves in HJT!
     
  3. jim_novice

    jim_novice TS Rookie

    Jaili

    Haha, I just checked... I know what jaili is. Its hijackthis renamed! Silly me.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...