This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Suspect Malware is crashing my 'Server' Service

6 min read

This thread's last reply is from November 26, 2008, 9:21 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hello there,

I am experencing the following issue;

Randomly approximatly once per week my 'Server' Service either stops, or needs to be restarted manually.
Occassionaly (less frequently) another computer on the domain will have the same problem.

The computer runs MS Windows Server 2003 Standard Edition and is a terminal server.
The second computer that occissionally has the problem is a web server.



Here is my Hikack this log for the Terminal Server Computer;

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:40:59 AM, on 24/11/2008
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\Documents and Settings\administrator.NTD.000\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
c:\BMSLoggerStuff\XYNTService.exe
c:\bmslogger.exe
C:\Program Files\CA\SharedComponents\ARCserve Backup\CADS\casdscsvc.exe
C:\Program Files\HP\Cissesrv\Cissesrv.exe
C:\WINDOWS\system32\CpqRcmc.exe
C:\hp\hpsmh\data\cgi-bin\vcagent\vcagent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CA\SharedComponents\CA_LIC\lic98Service.exe
C:\Program Files\Microsoft SQL Server\MSSQL$WSUS\Binn\sqlservr.exe
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe
C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\Program Files\CA\ARCserve Backup Agent for Open Files\Ofant.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\sysdown.exe
C:\hp\hpsmh\bin\smhstart.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\lserver.exe
C:\hp\hpsmh\bin\hpsmhd.exe
C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\Program Files\TrustedNet Connect 2.1\tncservice.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\WINDOWS\system32\CPQNiMgt\cpqnimgt.exe
C:\WINDOWS\system32\CPQMgmt\CqMgServ\cqmgserv.exe
C:\WINDOWS\system32\CPQMgmt\CqMgStor\cqmgstor.exe
C:\hp\hpsmh\bin\hpsmhd.exe
C:\WINDOWS\system32\Dfsr.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\CPQMgmt\CqMgHost\cqmghost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\TEMP\XD2120.EXE
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\NETSUP~1\Client32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TrustedNet Connect 2.1\TNCTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\Program Files\Converged Voice\nxServer.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\NETSUP~1\Client32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TrustedNet Connect 2.1\TNCTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Microsoft Office\OFFICE11\MSACCESS.EXE
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\system32\mmc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://team.ntd.com.au
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://team.ntd.com.au
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://team.ntd.com.au
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://portal.tbs.telstra.com/sites/sme_solutions/TBS%20Pricing%20Tool%20Release%2081015/TBS%20Pricing%20Tool%20Client%20Version%20Release%208.10.1.5.zip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [NetSupportClient] "C:\PROGRA~1\NETSUP~1\termServCk.exe" %USERNAME%
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [gemstrmw] C:\WINDOWS\system32\gemstrmw.exe /r
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TrustedNet Connect 2.x] "C:\Program Files\TrustedNet Connect 2.1\TNCTray.exe"
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1122\..\Run: [] (User 'angela.fearn')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1122\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'angela.fearn')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1123\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'anne.beare')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1127\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'col.neyland')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1127\..\Run: [] (User 'col.neyland')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1127\..\Run: [TrustedNet Connect 2.x] "C:\Program Files\TrustedNet Connect 2.1\TNCTray.exe" (User 'col.neyland')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1133\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'greg.hardy')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1137\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'jenny.yang')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1142\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'mike.maunder')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1143\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'paul.mclean-williams')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1146\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'skye.rush')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-1167\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'kylee.davis')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-2105\..\Run: [TrustedNet Connect 2.x] "C:\Program Files\TrustedNet Connect 2.1\tnctray.exe" (User 'heidi.madsen')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-2122\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'ryan.knudsen')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-2153\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'caroline.o'brien')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-2177\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'lesley.collins')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-2185\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'diane.birzenieks')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-2187\..\Run: [] (User 'tamara.locke')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-2193\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'melissa.dearden')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-3608\..\Run: [] (User 'dianne.luthe')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-3609\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'chris.feeney')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-3626\..\Run: [] (User 'helen.bolton')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-3664\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'john.sheppard')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-3702\..\Run: [] (User 'Rebecca.Odwyer')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-4620\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'elizabeth.schremmer')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-4630\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'linda.rennie')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-4812\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'fiona.burns')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-4835\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'keira.brigham')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-4841\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'rhiannon.soar')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-4852\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'tui.emery')
O4 - HKUS\S-1-5-21-4288347563-2532583514-4128013705-4855\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'david.rowcliff')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O10 - Broken Internet access because of LSP provider 'c:\documents and settings\administrator.ntd.000\windows\system32\mswsock.dll' missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ntd.local
O17 - HKLM\Software\..\Telephony: DomainName = ntd.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{3BD99168-9C6A-4944-B695-A119BC2083AF}: Domain = ntd.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{3BD99168-9C6A-4944-B695-A119BC2083AF}: NameServer = 172.16.1.1,172.16.1.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{D39DD6CF-AA25-4FB5-8C4D-21BCA4A913F3}: NameServer = 172.16.1.1,172.16.1.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ntd.local
O18 - Protocol: hpapp - {24F45006-5BD9-41B7-9BD9-5F8921C8EBD1} - C:\Program Files\Compaq\Cpqacuxe\Bin\hpapp.dll
O20 - Winlogon Notify: sd4notify - sd4notify.dll (file missing)
O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: BMSLogger - Unknown owner - c:\BMSLoggerStuff\XYNTService.exe
O23 - Service: BMS Monitor (BMSMonitor) - Unknown owner - c:\bmsmonitor\bmsmonitor.exe
O23 - Service: CA ARCserve Discovery Service (CASDiscovery) - CA - C:\Program Files\CA\SharedComponents\ARCserve Backup\CADS\casdscsvc.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe
O23 - Service: HP Smart Array SAS/SATA Event Notification Service (Cissesrv) - Hewlett-Packard Company - C:\Program Files\HP\Cissesrv\Cissesrv.exe
O23 - Service: HP Insight NIC Agent (CpqNicMgmt) - Hewlett-Packard Company - C:\WINDOWS\system32\CPQNiMgt\cpqnimgt.exe
O23 - Service: HP ProLiant Remote Monitor Service (CpqRcmc) - Hewlett-Packard Company - C:\WINDOWS\system32\CpqRcmc.exe
O23 - Service: HP Version Control Agent (cpqvcagent) - Hewlett-Packard Company - C:\hp\hpsmh\data\cgi-bin\vcagent\vcagent.exe
O23 - Service: HP Insight Foundation Agents (CqMgHost) - Hewlett-Packard Company - C:\WINDOWS\system32\CPQMgmt\CqMgHost\cqmghost.exe
O23 - Service: HP Insight Server Agents (CqMgServ) - Hewlett-Packard Company - C:\WINDOWS\system32\CPQMgmt\CqMgServ\cqmgserv.exe
O23 - Service: HP Insight Storage Agents (CqMgStor) - Hewlett-Packard Company - C:\WINDOWS\system32\CPQMgmt\CqMgStor\cqmgstor.exe
O23 - Service: CyRecord Service (CyRecord) - CyTrack Technologies - C:\Program Files\CyTrack\CyPhone\CyRecordService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - CA - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Devices Manager Service (mscgcosd) - Unknown owner - C:\WINDOWS\system32\mscgco.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: NexusDB Server (nxDBServer) - Unknown owner - C:\Program Files\Converged Voice\nxServer.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
O23 - Service: CA Backup Agent for Open Files (OpenFileAgent) - CA - C:\Program Files\CA\ARCserve Backup Agent for Open Files\Ofant.exe
O23 - Service: HP ProLiant System Shutdown Service (sysdown) - Hewlett-Packard Company - C:\WINDOWS\system32\sysdown.exe
O23 - Service: HP System Management Homepage (SysMgmtHp) - Hewlett-Packard Company - C:\hp\hpsmh\bin\smhstart.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
O23 - Service: TrustedNet Connect 2 - SecureNet Limited - C:\Program Files\TrustedNet Connect 2.1\tncservice.exe

--
End of file - 16046 bytes



Thank you kindly for any help
Hi John Sheppard

As said in rules:

"Make sure you have one of the desktop versions of Windows, i.e. Win98, Win98SE, WinMe, Win2000, Windows XP, Windows Media, Vista.
We CANNOT HELP remove malware from any of the Windows Server editions, like Windows 2003."

This thread is now closed.