U
User
This morning I noticed some unusual network activity on my win2kpro system
and tracked it down.
An application that is spawned from explorer.exe is making repeated network
connections to IP 82.192.80.97:2918 which lists in my computer as
hosted-by.12servers.nl
The application name is c:/winnt/system32/systemcfg, witch was created at
10:19:52am today
Also listed in my even log are two entries from that time like this below
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 7/8/2004
Time: 10:19:52 AM
User: N/A
Computer: T1001885
Description:
The rxpdn service failed to start due to the following error:
The executable program that this service is configured to run in does not implement the service.
There are other entries claiming my officescan terminated unexpectedly - though it appears to
be running now. My event logger appears to have started and stopped a few times too.
-----------
So the question is, what do I do next. I have suspended the task, but don't know where to
disable it from autostarting. Does anyone want a copy. How did I get broken into, I am
totally up to date as far as I know in all respects. I was browsing the web at the time of
"infection".
Thanks
and tracked it down.
An application that is spawned from explorer.exe is making repeated network
connections to IP 82.192.80.97:2918 which lists in my computer as
hosted-by.12servers.nl
The application name is c:/winnt/system32/systemcfg, witch was created at
10:19:52am today
Also listed in my even log are two entries from that time like this below
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 7/8/2004
Time: 10:19:52 AM
User: N/A
Computer: T1001885
Description:
The rxpdn service failed to start due to the following error:
The executable program that this service is configured to run in does not implement the service.
There are other entries claiming my officescan terminated unexpectedly - though it appears to
be running now. My event logger appears to have started and stopped a few times too.
-----------
So the question is, what do I do next. I have suspended the task, but don't know where to
disable it from autostarting. Does anyone want a copy. How did I get broken into, I am
totally up to date as far as I know in all respects. I was browsing the web at the time of
"infection".
Thanks