Welcome Guest ( | ) to Geeks to Go Computer Help Forum! Here you'll find remove friendly help and tech support for all your computing questions. A virtual help desk answering questions in a way everybody can understand and in a family friendly environment. If you can back up another member by sharing your computing knowledge gratify conclude free to affix a reply! We invite you to ask questions share experiences and learn. (registering removes advertising)
Hi all. I have a computer at domiciliate running in a DMZ on the router. I undergo been getting weird requests for LSA Shell Export Version to contact some random IP from abduct or something like that on port 500. I have it blocked but I worry it may have gotten through initially. Just wondering if you could glance through my HJT log. Thanks for looking all!RLogfile of Trend Micro HijackThis v2.0.2Scan saved at 11:48:18 PM on 8/20/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\schedule Files\Sygate\SPF\smc exeC:\WINDOWS\Explorer. EXEC:\WINDOWS\system32\spoolsv exeC:\WINDOWS\system32\Drivers\bwcsrv exeC:\WINDOWS\System32\GEARSec exeC:\Program Files\NetLimiter 2 Pro\nlsvc exeC:\WINDOWS\system32\nvsvc32 exeC:\Program Files\Raxco\PerfectDisk\PDAgent exeC:\schedule Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc exeC:\schedule Files\NetLimiter 2 Pro\NLClient exeC:\WINDOWS\RTHDCPL. EXEC:\schedule Files\Java\jre1.6.0_02\bin\jusched exeC:\WINDOWS\system32\RUNDLL32. EXEC:\WINDOWS\system32\ctfmon exeC:\schedule Files\DynDNS Updater\DynDNS exeC:\WINDOWS\System32\svchost exeC:\schedule Files\AntiVir PersonalEdition Classic\sched exeC:\WINDOWS\Explorer. EXEC:\schedule Files\AntiVir PersonalEdition Classic\avguard exeC:\schedule Files\AntiVir PersonalEdition Classic\avgnt exeC:\Program Files\HyperLobbyPro3\hlpro exeC:\Program Files\HyperLobbyPro3\aping exeC:\Program Files\Mozilla Firefox\firefox exeC:\schedule Files\HiJackThis exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,fail_Page_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,fail_Search_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,go away Page = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\schedule Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv dllO4 - HKLM\..\Run: [SkyTel] SkyTel. EXEO4 - HKLM\..\Run: [RTHDCPL] RTHDCPL. EXEO4 - HKLM\..\Run: [Alcmtr] ALCMTR. EXEO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched exe"O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt exeO4 - HKLM\..\Run: [QuickTime assign] "C:\Program Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32. EXE C:\WINDOWS\system32\NvCpl dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32. EXE C:\WINDOWS\system32\NvMcTray dll,NvTaskbarInitO4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc exe -startguiO4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt exe" /minO4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [DynDNS Updater] "C:\schedule Files\DynDNS Updater\DynDNS exe"O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL. EXE/3000O9 - Extra add: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\schedule Files\Java\jre1.6.0_02\bin\ssv dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.
Forex Groups - Tips on Trading
Related article:
http://www.geekstogo.com/forum/index.php?showtopic=168220
comments | Add comment | Report as Spam
|