Seneste forumindlæg
Køb / Salg
 * Uofficiel Black/White liste V3
Login / opret bruger

Forum \ Internet \ Netværk
Denne tråd er over 6 måneder gammel

Er du sikker på, at du har noget relevant at tilføje?

Hvordan finder jeg spambitten?

Af Elite Supporter Neerup | 27-07-2009 15:57 | 1884 visninger | 3 svar, hop til seneste
Hejsa Hejsa Jeg har læst mig frem til, at der ligger én spam bot på min server og sender spam. Hvordan finder jeg den spam bot?? Jeg har prøvet med lidt antivirus programmer, men de siger at min server er clean. I message tracking kan ejg se, at [email protected] sender en del spam, og jeg sender også spam til mig selv:/ Hvordan finder jeg den spambot/med hvilket program? På forhånd tak Hilsen neerup
--
Css klan: UOR= Union of retards
#1
DwArK
Junior Nørd
27-07-2009 15:59

Rapporter til Admin
tjaah sådan er det vel med windows server og dårlig sikkerhed... hvad med en Hijackthis Log?
--
Amd 3800+ 64 2x512 Geil dual 2x512 hyperx dual, 512mb Ati Radeon X1950 Pro, Creative Audigy 2 ZS, Microsoft Explorer Intelli 3.0, Steelpad
#2
Neerup
Elite Supporter
27-07-2009 16:01

Rapporter til Admin
Her er den: Logfile of HijackThis v1.99.1 Scan saved at 4:00:00 PM, on 7/27/2009 Platform: Windows 2003 SP2 (WinNT 5.02.3790) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\Program Files (x86)\Java\jre6\bin\jqs.exe C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\WINDOWS\SysWOW64\ctfmon.exe C:\Program Files (x86)\Genie-Soft\GBMServer8\GBMAgent.exe C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE C:\Program Files (x86)\Java\jre6\bin\jusched.exe C:\Program Files (x86)\Microsoft Forefront Security\Exchange Server\FSCMonitor.exe C:\Program Files (x86)\Microsoft Forefront Security\Exchange Server\FSCController.exe C:\Program Files (x86)\Microsoft Forefront Security\Exchange Server\FSCStatsServ.exe C:\Program Files (x86)\Microsoft Forefront Security\Exchange Server\FSSAClient.exe C:\WINDOWS\SysWOW64\ctfmon.exe C:\Program Files (x86)\Genie-Soft\GBMServer8\GBMAgent.exe C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE C:\Program Files (x86)\Java\jre6\bin\jusched.exe C:\Documents and Settings\Administrator.SCSERVER\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com[...] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/hardAdmin.htm R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com[...] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com[...] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com[...] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com[...] R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com[...] F2 - REG:system.ini: UserInit=userinit O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files (x86)\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [GBMServer8Agent] "C:\Program Files (x86)\Genie-Soft\GBMServer8\GBMAgent.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [GBMServer8Agent] C:\Program Files (x86)\Genie-Soft\GBMServer8\GBMAgent.exe O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe O11 - Options group: [INTERNATIONAL] International O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com[...] O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com[...] O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = reklame.local O17 - HKLM\System\CCS\Services\Tcpip\..\{191CAB01-081E-48BD-8E48-CB3C6B2372C5}: NameServer = 10.0.0.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{F2AFC711-77E3-461F-B910-0E437143A0F5}: NameServer = 10.0.0.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = reklame.local O17 - HKLM\System\CS1\Services\Tcpip\..\{191CAB01-081E-48BD-8E48-CB3C6B2372C5}: NameServer = 10.0.0.1 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = reklame.local O17 - HKLM\System\CS2\Services\Tcpip\..\{191CAB01-081E-48BD-8E48-CB3C6B2372C5}: NameServer = 10.0.0.1,208.67.222.222 O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsntfy.dll O20 - Winlogon Notify: EFS - C:\WINDOWS\SYSTEM32\sclgntfy.dll O23 - Service: Adaptec Storage Manager Agent (AdaptecStorageManagerAgent) - Adaptec Incorporated - C:\Program Files\Adaptec\Adaptec Storage Manager\StorServ.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe (file missing) O23 - Service: DNS Server (DNS) - Unknown owner - C:\WINDOWS\System32\dns.exe (file missing) O23 - Service: Event Log (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe (file missing) O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: IIS Admin Service (IISADMIN) - Unknown owner - C:\WINDOWS\system32\inetsrv\inetinfo.exe (file missing) O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files (x86)\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files (x86)\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: Kerberos Key Distribution Center (kdc) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: McAfee Engine Service (McAfeeEngineService) - McAfee, Inc. - C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\EngineServer.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing) O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\McShield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\WINDOWS\system32\mfevtps.exe (file missing) O23 - Service: Distributed Transaction Coordinator (MSDTC) - Unknown owner - C:\WINDOWS\system32\msdtc.exe (file missing) O23 - Service: Microsoft Search (Exchange) (msftesql-Exchange) - Unknown owner - C:\Program Files\Microsoft\Exchange Server\bin\msftesql.exe" -Exchange -s:Exchange -f:Exchange (file missing) O23 - Service: FTP Publishing Service (MSFtpsvc) - Unknown owner - C:\WINDOWS\system32\inetsrv\inetinfo.exe (file missing) O23 - Service: Net Logon (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: NT LM Security Support Provider (NtLmSsp) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe (file missing) O23 - Service: IPSEC Services (PolicyAgent) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Protected Storage (ProtectedStorage) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Remote Desktop Help Session Manager (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe (file missing) O23 - Service: Security Accounts Manager (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: SPAMfighter - SPAMfighter ApS - C:\Program Files\SPAMfighter\bin\SPAMfighter.exe O23 - Service: File Server Storage Reports Manager (SrmReports) - Unknown owner - C:\WINDOWS\system32\srmhost.exe (file missing) O23 - Service: Telnet (TlntSvr) - Unknown owner - C:\WINDOWS\system32\tlntsvr.exe (file missing) O23 - Service: Virtual Disk Service (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: Volume Shadow Copy (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe (file missing) O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing) O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing) O23 - Service: Windows Search (WSearch) - Unknown owner - C:\WINDOWS\system32\SearchIndexer.exe (file missing) Takker
--
Css klan: UOR= Union of retards
#3
Neerup
Elite Supporter
27-07-2009 21:02

Rapporter til Admin
..::--::..
--
Css klan: UOR= Union of retards

Opret svar til indlægget: Hvordan finder jeg spambitten?

Grundet øget spam aktivitet fra gæstebrugere, er det desværre ikke længere muligt, at oprette svar som gæst.

Hvis du ønsker at deltage i debatten, skal du oprette en brugerprofil.

Opret bruger | Login
NYHEDSBREV
Afstemning