Hjælp - min server sender SYN_SENT hele tiden
Hjælp - min server sender SYN_SENT hele tiden.Når jeg kører en 'netstat -an' kan jeg se at den sender konstant og hele tiden et ip-nummer højere.
Jeg har kørt en HiJackThis og vedlægger log.
Mit problem er at jeg ikke er sikker på hvad der skal væk og nogle af tingene ved jeg ikke hvad er.
log:
Logfile of HijackThis v1.99.1
Scan saved at 14:02:06, on 23-05-2005
Platform: Windows 2003 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\WINDOWS\System32\dns.exe
C:\WINDOWS\System32\svchost.exe
C:\winnt\system32\evttrp.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\JRun4\bin\jrunsvc.exe
C:\JRun4\bin\jrunsvc.exe
C:\JRun4\bin\jrun.exe
C:\JRun4\bin\jrun.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\dllcache\netservices.dll
C:\WINDOWS\system32\ntfrs.exe
C:\WINDOWS\system32\Service.exe
C:\WINDOWS\System32\wins.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Exchsrvr\bin\store.exe
C:\Program Files\Exchsrvr\bin\emsmta.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\MySQL\bin\winmysqladmin.exe
C:\Program Files\MySQL\bin\mysqld.exe
C:\Documents and Settings\Administrator\Desktop\hijackthis\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
O4 - HKLM\..\Run: [DWPersistentQueuedReporting] C:\PROGRA~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE -a
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: SQL Server.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\scm.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ScanSoftApS.local
O17 - HKLM\Software\..\Telephony: DomainName = ScanSoftApS.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ScanSoftApS.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ScanSoftApS.local
O23 - Service: System Event Trap (evttrp) - Cat Soft - C:\winnt\system32\evttrp.exe
O23 - Service: Macromedia JRun Admin Server (JRun Admin) - Macromedia Inc. - C:\JRun4\bin\jrunsvc.exe
O23 - Service: Macromedia JRun Default Server (JRun Default) - Macromedia Inc. - C:\JRun4\bin\jrunsvc.exe
O23 - Service: MySql - Unknown owner - c:/Program Files/MySQL/bin/mysqld-nt.exe
O23 - Service: Kernel32 Gateways (netrun) - Unknown owner - C:\WINDOWS\system32\dllcache\netservices.dll
O23 - Service: ProService for 9.1D (ProService9.1D) - Progress Software - C:\Program Files\PROGRESS\bin\ProSrvc.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\Service.exe" /service (file missing)
O23 - Service: TCP/IP Controller (tcp-ip) - Windows - C:\WINDOWS\system32\dllcache\tcpsysrv.exe
O23 - Service: Telephony Motion (TeleMotion) - Unknown owner - C:\WINDOWS\system32\dfrgfat32.exe
O23 - Service: MS Windows Server (window) - Unknown owner - c:\windows\system32\regsvr.exe