Over 1 million tech questions and answers.

Worm or Server Issue?

Q: Worm or Server Issue?

Hello All-Emails have been sent to numerous, if not all, of the addresses in my address book belonging to [email protected] to protect from spambots. Of course, they do not appear in my "sent" folder or elsewhere. I only know of this from the responses I get from recipients. This would have been a simple problem I thought, until I was unable to discover the cause.I am running Windows XP SP3, have two computers on the network typically, and have a number of email accounts. Four email accounts are sbcglobal.net accounts, and only one has been utilized to issue spam/viruses and so forth. This is done through a hypertext link with no message attached.On these two machines Norton 360 runs at start up. Scans reveal no malware. After these messages began being sent as if from [email protected] I did the following:Ran an additional Norton comprehensive scan. Nothing was found.Ran Malawarebytes' Anti-Malware full system scan on both machines. Nothing was found.Ran IObit Security 360 on both machines. Nothing was found.All secuirty programs were updated as of today's date. Then I ran the Microsoft Malicious Software Tool, and again nothing was found on either machine.I have run HiJack This and saved the results to Notepad. I am willing to share that information if would be of use to someone on this forum. Any further advice on steps I could take would be most appreciated.Thank you in advance for your assistance.Regards,-PaulEdit: Moved topic from Am I infected? What do I do? to the more appropriate forum. ~ Animal

RELEVANCY SCORE 200
Preferred Solution: Worm or Server Issue?

I recommend downloading and running DAP. It can help sort out any driver and firmware related issues on your system

It's worked out well for many of us in the past.

You can download it direct from this link http://downloaddap.org. (This link will open the download page of DAP so you can save a copy to your computer.)

A: Worm or Server Issue?

Here is my Hijack This logfile for review:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 2:28:05 PM, on 2/11/2010Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\IObit\IObit Security 360\IS360srv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\system32\LxrJD31s.exeC:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeC:\Program Files\MozyHome\mozybackup.exeC:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\BITWARE\NT\bwprnmon.exeC:\PROGRA~1\Virtual Account Numbers\CitiVAN.exeC:\WINDOWS\system32\ntvdm.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\WINDOWS\SOUNDMAN.EXEC:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exeC:\Program Files\Gbridge LLC\Gbridge\gbwinvnc.exeC:\WINDOWS\system32\OBroker.exeC:\Program Files\Common Files\Java\Java Update\jusched.exeC:\WINDOWS\system32\SearchIndexer.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\Program Files\IObit\IObit Security 360\IS360tray.exeC:\Documents and Settings\Paul Guttenberg\Local Settings\Application Data\Google\Update\GoogleUpdate.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Canon\CAL\CALMAIN.exeC:\Program Files\Gbridge LLC\Gbridge\gbwinvnc.exeC:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\Program Files\MozyHome\mozystat.exeC:\Program Files\Windows Desktop Search\WindowsSearch.exeC:\Program Files\Secunia\PSI\psi.exeC:\Program Files\OpenOffice.org 3\program\soffice.exeC:\Program Files\OpenOffice.org 3\program\soffice.binC:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exeC:\Program Files\HP\Digital Imaging\bin\hpqbam08.exeC:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exeC:\WINDOWS\System32\alg.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Documents and Settings\Paul Guttenberg\Local Settings\Application Data\Google\Chrome\Application\chrome.exeC:\Documents and Settings\Paul Guttenberg\Local Settings\Application Data\Google\Chrome\Application\chrome.exeC:\Documents and Settings\Paul Guttenberg\Desktop\HijackThis.exeC:\WINDOWS\system32\SearchProtocolHost.exeC:\WINDOWS\system32\SearchFilterHost.exeC:\WINDOWS\system32\wbem\wmiprvse.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.juno.com/s/search?r=minisearchR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.juno.com/s/search?r=minisearchR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.juno.com/s/search?r=minisearchR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.juno.com/s/search?r=minisearchR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.juno.com/s/search?r=minisearchR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearchR3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\JunoInternet\SearchEnh1.dllO2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\Program Files\Virtual Account Numbers\BhoCitUS.dllO2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\JunoInternet\qsacc\X1IEBHO.dllO2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dllO2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.8.0.41\IPSBHO.DLLO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dllO2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dllO3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dllO3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dllO4 - HKLM\..\Run: [bwprnmon.exe] C:\BITWARE\NT\bwprnmon.exeO4 - HKLM\..\Run: [Citi Virtual Account Numbers] C:\PROGRA~1\Virtual Account Numbers\CitiVAN.exe /lang=en_RG /dontopenmycardsO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kO4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXEO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorunO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exeO4 - HKLM\..\Run: [IObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostartO4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Paul Guttenberg\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /cO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXEO4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exeO4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exeO4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exeO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exeO4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exeO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200O8 - Extra context menu item: Display All Images with Full Quality - "res://C:\Program Files\JunoInternet\qsacc\appres.dll/228"O8 - Extra context menu item: Display Image with Full Quality - "res://C:\Program Files\JunoInternet\qsacc\appres.dll/227"O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.htmlO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\OFFICE11\REFIEBAR.DLLO9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dllO9 - Extra button: Virtual Account Numbers - {DE700910-58F7-4D2E-B7E6-3BA2DA1B6806} - C:\PROGRA~1\Virtual Account Numbers\CitiVAN.exeO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO15 - Trusted Zone: http://*.fpihpo.comO15 - Trusted Zone: http://*.profilesondemand.comO15 - Trusted Zone: http://apps.waddell.comO15 - Trusted Zone: http://centra.waddell.comO15 - Trusted Zone: http://mail.waddell.comO15 - Trusted Zone: http://owa.waddell.comO15 - Trusted Zone: http://wrsaepio.waddell.comO16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h20364.www2.hp.com/CSMWeb/Customer/...DataManager.CABO16 - DPF: {413D6754-BFD4-47FE-9346-319559290BFA} (HTECtrl Class) - https://www.webpcfos.com/webpcfos/websabre/HTEweb_new.cabO16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1159754930656O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cabO16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - https://wimpro.cce.hp.com/ChatEntry/downloads/msxml4.cabO16 - DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} (Siebel Desktop Integration) - https://core.waddell.com/fins/19241/applets...Integration.cabO16 - DPF: {8F623BE4-2C55-4095-B1E0-A41B631A49BD} (Siebel High Interactivity Framework) - https://core.waddell.com/fins/19241/applets...x_HI_Client.cabO16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dllO23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exeO23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exeO23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exeO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exeO23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exeO23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: uvnc_service_gs - UltraVNC - C:\Program Files\Gbridge LLC\Gbridge\gbwinvnc.exe--End of file - 12474 bytes

Read other 3 answers
RELEVANCY SCORE 51.6

Red Shield - IE Enhanced Security Configuration for Administrators
Amber Shield - IE Enhanced Security Configuration for Non-Administrators
Green Shield - IE Zones
When I click on the how to correct this it takes me to a Windows 2003 page not 2012 for the first issue

And page does not exist for the second issue ?
Any ideas ?

Read other answers
RELEVANCY SCORE 50.4

Hello, I'm currently working with my girlfriend to resolve a computer issue. She recently had her e-mail account and photobucket account compromised, and as a result - I wanted to help her clean out her computer and make sure everything is clean. In doing so, I've run across a worm that I'm unable to guide her through removing myself. I'm not computer illiterate, but no genius either, which brings me here asking for your help.

I've had her run Spybot S&D, which turned no results other than cookies and such. I had her run Ad-Aware, which turned up Win32.P2P-Worm.Alcan.a. This is where I've began having issues. I've googled it, tried a few of the fixes that people have posted to no avail. I had her run hijack this and retrieve the logfile for me. I'll post it below.

If anyone could provide some help cleaning this worm out of her system, it would be much appreciated, as I'm clueless to what to do next.

Logfile of HijackThis v1.99.1
Scan saved at 9:39:52 PM, on 11/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\Ati2evxx.ex... Read more

A:Virus/Worm Issue - Win32.P2P-Worm.Alcan.a

Read other 7 answers
RELEVANCY SCORE 44.8

Hi,

I am having an issue with offline files created offline syncing back to the server. I have set up a network share to be available offline on a client computer. All files are available offline without issue. Here is the issue however. If I set the folder to work offline any file I create in the folder when it is offline just disappears when the folder comes back online, there are no conflicts or sync failures reported in sync center. If I create a new folder offline the folder does sync back to the server. Any changes made to an existing file are also replicated back to the server once the share is back online. So the issue is only with newly created files when the share is offline. I have not been able to replicate this error on any other file server in our environment, However I have recreated the issue with multiple shares with multiple Win 7 clients on this file server.

Steps taken so far.

Checked and reset permission levels on the share.
Recreated new shares from scratch for testing.
Disabled and enabled offline files on the client computer and cleared the offline cache.
Check various registry entry settings.
Disabled cashing on the File server.
Tested with XP the issue does not exist with XP.

I have spent hours researching this error online to no avail.

The clients are running Windows 7 Enterprise 64 bit
The File server is Server 2003 Standard 32 bit with SP2

Any help or ideas would be most welcome.

A:Offline Folder sync issue, Win 7 Client Server 2003 Flie Server.

I've seen the complaints about this problem but with no clear resolution. There are some hot fixes listed that may help, updating to Windows 7 SP1 is supposed to help in some cases but nothing seems for certain.

No way for me to recreate this problem but apparently others have the same problem.

Offline created files disappear after re-connect

Browse by Tags - The troubleshooters and problem solvers... - Site Home - TechNet Blogs

Administratively assigned offline files on Win7 client disappear from server (Network Steve Forum)

The Group Policy settings in the next link may have an effect on this problem.

http://mcpmag.com/articles/2003/11/0...ine-files.aspx

Read other 3 answers
RELEVANCY SCORE 44.8

The following Structure is a representation;
PC1 - IP 10.0.0.10 - FQDN PC1.DOM.LOCAL
PC2 - IP 10.0.0.20 - FQDN PC2.DOM.LOCAL
SRV1 - IP 10.0.0.5 - FQDN SRV1.DOM.LOCAL - File Share 'FLDR1' / USR1<ReadOnly>


SRV1 has a folder, FLDR1, being shared for read only access to user USR1.

PC1 and PC2 logged on as Domain User USR1.
PC1 is able to connect to SRV1 to see and look in FLDR1.
PC2 is unable to connect to SRV1 to see and look in FLDR1.
Now there are multiple means of connecting to SRV1 to see the share FLDR1.


The following connections were done in combination with the following methods;
Method 1 - via logged on Domain User CMD Prompt with 'NET VIEW'.
Method 2 - via logged on Domain Administrator CMD Prompt with 'NET VIEW'.
Method 3 - via logged on Domain User Explorer Window.
Method 4 - via logged on Domain Administrator Explorer Window.

Connection 1 - via Server Name.
Connection 2 - via Server IP Address.
Connection 3 - via Server Fully Qualified Domain Name.


Now that the stage is set, going to the fun part...

Testing from both PC1 and PC2...
-------------------------------------------
PC1 : Method 1 - Connection 1 - Success
PC1 : Method 1 - Connection 2 - Success
PC1 : Method 1 - Connection 3 - Success
PC1 : Method 2 - Connection 1 - Success
PC1 : Method 2 - Connection 2 - Success
PC1 : Method 2 - Connection 3 - Success
PC1 : Method 3 - Connection 1 - Success
PC1 : Method 3 - Connection 2 - Success
PC1 : Method 3 - Connection... Read more

Read other answers
RELEVANCY SCORE 44.8

We run a web proxy server on our network for internet access.
On client machines (running Windows 2012 R2) I have configured the proxy server setting in Internet Explorer "Tools\Internet Settings\Connections\LAN Settings" to point at the designated web proxy server.
When attempting to browse websites from IE I receive the "The proxy server isn't responding" error.
Conversely, browsing the same sites via Google Chrome and Firefox (installed on the same client server) return web pages without error.
In addition, if I run Internet Explorer as administrator (Right Click\Run as Administrator), I am able to browse web sites without receiving the error.
It would appear that the issue is isolated to browsing via IE when not run in elevated mode.
Has anyone come across this issue?

A:Server 2012 R2 - Internet Explorer Proxy Server Issue

Hi Dicki,
First, please try to reset the Internet Explorer. Some plug-ins may affect the proxy.
If it doesn't work, please try to perform a network capture on the client.
Please check if the client send the http traffic to the proxy server at the correct port.
If the client has sent the http traffic to the proxy server, please check if there is any warning or error in the proxy server.
To download Network Monitor, please refer to the link below:
http://www.microsoft.com/en-us/download/details.aspx?id=4865
Best Regards.Steven Lee Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

Read other 2 answers
RELEVANCY SCORE 44.4

I was infected(and still might be) with the storm worm about 2 weeks back. It wouldn't let me open my email, my ISP was calling telling me I had a virus(though they offer no assistance). After 2 days of running scan after scan & using various programs I thought it was all cleaned.

Fast forward to today...I had uploaded some new files last night to my web server. I visit the site today that I had uploaded the files to and low and behold it tells me it has a virus!

I looked at the FTP dates & the last I had uploaded files was yesterday(10/10) yet it was showing a few files as being modified today(10/11). I downloaded the files & saw that attached to the bottom was a line of code, an iframe to be exact, with a URL to a site that was trying to download the infected files.

This URL as far as I know is part of the storm virus (do not try to go there) y x b e g a n d o t c o m

I talked with my web host & they said that it had to be on my end since the server can't get infected...because its a Linux server.

So my question then is how did the file get modified? Since I'm 99% sure the file was modified AFTER I uploaded it then how can that happen? I doubt the server was hacked in order to add it to a few random files.

The files on my end did not have the code before I uploaded them...the only 'new' thing I uploaded besides PHP files was wordpress...is that known to have any holes when it comes to the storm worm?

I'm just conf... Read more

A:Confused As To Storm Worm On Web Server...

Shamelss bump...it happened again today...

I'm going to go ahead and guess that possibly passwords were stolen & now being used to hack into the website & modify the files - its a stretch but seems like the most realistic answer right now.

Any better suggestions let me know, I'm just going to go ahead and update all passwords see if that doesn't fix it.

Read other 4 answers
RELEVANCY SCORE 44.4

Our Server is a Dell PowerEdge running Windows Server 2003 SP2. I have tried many, many different scans to remove what we think is a worm or bot of some kind. RegRun will see the file (usually named A345A.EXE or something else really random like that), but when I KILL it, it just comes back a few minutes later. Its always named something random and its always located in C:\TEMP\. I know that some utilities used to exist that would allow you to boot from CD and scan BEFORE windows starts. This also should scan ROM and much more than windows apps can't once it's booted.

Thanks in advance for any suggestions!
 

Read other answers
RELEVANCY SCORE 44

Hi,

What you guys will do to stop a worm propagation on your critical server?
We know that unplug the server is an impossible option...
Thanks!

Read other answers
RELEVANCY SCORE 44

Windows 2000 Server is on a network with 3 other PC's. One PC has had Windows Xp for some time, I believe the machine came with it as a matter of fact, the other two PC's were upgraded from Win98 to XP Pro recently.

The issue with the Windows 2000 Server machine is that it seems to issue a system message indicating that lsass.exe has terminated unexpectedly with code 128 and needs to close. System starts a timer to shutdown which then shuts down and restarts the system after 60 seconds. Being a Win2K box, the shutdown command is not recognized like in XP.

This machine had no antivirus or firewall applications loaded when I got to it. It was also in limbo for a year since someone came out and looked at it, as it was still on SP3.

Here's what I did:

-Ran the Sasser removal tool from Symantec, nothing found.

-Applied the patch from MS04-11 security bulletin for LSASS vulnerability, everything OK

-Followed instructions on creating a read-only log file in the %systemroo%\debug folder called dcpromo.log. This read only log file was supposed to stop the machine from rebooting, similar to the shutdown -a command on XP boxes, but which Win2K does not have

-Unplugged the network cable, this seemed to stop the LSASS service from rebooting the machine for now.

-Applied SP4, everything OK

-Loaded up and ran AVG Antivirus with latest defs, no viruses detected.

-Downloaded all the latest updates beyond SP4. About 32-33 updates were downloaded from the Windows Upda... Read more

Read other answers
RELEVANCY SCORE 43.2

I hope that someone here can point me in the right direction. I've inherited the responsibility of caring for a Windows 2003 Standard Server that appears to be infected by the Worm.Conficker (According to my Malwarebytes scan). I initially realized there was something wrong with the server when I couldnt get to the Windows Update website, then I realized it was much worse when I could not access any antivirus or anti-malware websites... all were blocked and not resolving with DNS....

I used a thumbdrive to put the latest and greatest Malwarebytes on the system to scan it... and it found the following:
__________________________________________________
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (PUM.Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\iztbv.dll (Worm.Conficker) -> Delete on reboot.
___________________________________________________

The worm deletes on reboot, and everything appears to work (I can access Windows Update and all antivirus and anti-malware websites)... but within 24 hours the same worm, with the same name, in the same file location reappears.....

I've just done the below HIJACKTHIS scan and was hoping someone could help me translate... any insig... Read more

A:Worm.Conficker returnes daily on my Win2k3 server

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything. We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here. To help Bleeping Computer better assist you please perform the following steps:*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/420716 <<< CLICK THIS LINK If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.*************************************************** If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lo... Read more

Read other 2 answers
RELEVANCY SCORE 42

Hello,

McAfee has continued to pop up a bos that states possible worm activity, multiple emails are attempting to be sent. It give me the option to stop it but doesnt locate it when I scan for it. Spybot has also not found anything. Emails appear to be sent to random people and contain various subject lines like:

"Software at Low Prices"
"0EM Software"
"Need S0ftware"

I've not been able to remove it. Here is my HijackThis Log. Please help. Thanks.

Logfile of HijackThis v1.99.1
Scan saved at 6:53:39 PM, on 12/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\Progra... Read more

A:Worm Issue/Help Please

Help Please

MCafee is giving me a notice of potential worm activity detected as last few emails sent with similar subject lines. Spawning about 5 a second. here is my HJ log. Any help would be appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 11:15:17 AM, on 12/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
c:\p... Read more

Read other 2 answers
RELEVANCY SCORE 41.6

About a week ago, I got a dialogue box on my Dell desktop which said lsass.exe and had only “ok” or “x”, both of which take me to a black screen afterwards. No warning, other than my desktop had been commandeered saying I had spyware. My Norton is as current as possible (no notices to update it). No noise prior, nothing.
I spoke to a tech support guy at work and he suggested changing my boot sequence to the cd drive so that I could reinstall Windows to attempt to retrieve some stuff which had not been backed up. Let me also say, I tried my last good boot and it wouldn’t do anything. After I changed the boot sequence to the CD drive, I got a message saying “press F1 to reboot or F2 to ? (I can’t remember what it was)”. When I hit F1, it beeps and says the same message (over and over again). F2 takes me back to the set up. I tried to boot in safe mode and I still get the lsass.exe box in safe mode.
At this point, I’d just be happy to be able to wipe and reinstall Windows, though my plan A would be to retrieve some pics and Word docs.
I am a single parent and I don’t have a lot of financial resources. I am reasonably tech savvy as it pertains to directions, but not when it comes to knowing the guts of the PC. I’d appreciate any help anyone can offer.
Thanks!
 

Read other answers
RELEVANCY SCORE 41.6

I'm new to the forum but have a problem that I want make the right decision on. I play Aces High II which is a flight simulation game. It may not be as hard core as Battlefield 3 but they do keep upgrading to high res graphics. My computer is a prebuilt Dell Studio XPS 8000. Intel i7 core 860 processor @ 2.8GHz. Graphics card a Nvidia geforce GTS 240. 8 Mb memory, Windows 7 home premium os. Now that said I am experiencing stutter sometimes while i'm playing. My fps go from 60 which is where it should be to 10 or less. I,m not sure if this is the game card or a lousy connection to the game server as we do get discoed sometimes. The computer is a year and a half old and don't remember experiencing this before that much. Any advice would be greatly appreciated. I'm not against getting a new card and probably need new power supply.
 

A:GeForce GTS 240 issue or gaming server issue?

What resolution are you playing at? What is your budget for your upgrade?

Its your gpu more than likely
 

Read other 8 answers
RELEVANCY SCORE 41.2

Hello,

Thanks in advance for looking into this problem that just started last weekend.

I have Norton Anti-Virus 2007 and it detected that I had W32.Spybot.Worm. I checked Symantec's removal procedures, but I'm honestly not very good with the registry and I don't even know what to look for.

I ran Microsoft's Malicious Software Removal Tool and then I ran a full Norton scan and it did not find anything. I somehow don't trust that I've magically removed this thing.

Can someone please advise?

Here is my HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:28:48 PM, on 12/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
c:\toshiba\ivp\swupdate\swupdtmr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySwe... Read more

A:Solved: W32.Spybot.Worm issue

Read other 14 answers
RELEVANCY SCORE 41.2

Hi

Not sure if this is the right room but...

Ran a A/V and A/S scan yesterday with Zone alarm and it turned up 2 issues

one being win32.worm.Sock

So i put them in Quarantine.

And now i seem to have lost my XP welcome screen and it all looks a little Win 2000 with a login box.

I have since realised that ZA was on version 8 and updated to the latest.

How do i get my welcome screen back however?

Any help would be great.

A:win32.worm.sock issue

Hello and Welcome to TSF.

We want all our members to perform the steps outlined in the link I'll give you below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

---------------------------------------------------------------------------------------------

Please follow our pre-posting process outlined here:

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Please note that the Virus/Trojan/Spyware Help forum is extremely busy, and it may take a while to receive a reply.

Read other 1 answers
RELEVANCY SCORE 41.2

i have this on a server and wondering how to remove it. it looks like it is the same as net-worm.win32.dipnet.d . thanks for the help
 

Read other answers
RELEVANCY SCORE 41.2

The computer keeps coming up with the messages regarding the computer having a worm.win32.netsky infection, please update your antivirus sort of pop-ups.

I have had a look around on forums etc and we downloaded smitfraudfix.exe to help solve the problem.

Smitfraudfix would not load in safe mode so we tried it in normal mode. Once it was finally up and running, it just kept repeating "access is denied" over dozen times. Then it said "killing process" then "access is denied" again.

We have tried a few other things, but I have been noticing people posting their HijackThis logs so I thought I would try that and see if anyone has any suggestions. I hope that you can help me!

This is not my computer, but I am trying to fix it!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:34:09, on 29/12/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.e... Read more

A:Please help, worm.win32.netsky issue

Hello and welcome to TSF.

HijackThis is no longer the preferred initial analysis tool in this forum.

We want all our members to perform the steps outlined in the link given below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

Please follow our pre-posting process outlined here:

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Read other 1 answers
RELEVANCY SCORE 41.2

Hello,
My pc is infected by this worm. I have installed Spyware Doctor on my PC. It detects it removes it. But again creates the same virus after restarting the PC.

I found some files in the HijackThis reoprt and i deleted them but those are creating again again after restarting the Pc.
What should i do next to reomve it completely. Please help me

Hijack Report
-----------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 1:11:35 PM, on 9/20/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\xampp\apache\bin\apache.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\xampp\mysql\bin\mysqld-nt.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Fi... Read more

A:Email-Worm.Brontok.Q issue

You may want to print this or save it to notepad as we will go to safe mode.

Fix these with HiJackThis – mark them, close IE, click fix checked

F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"

O4 - HKCU\..\Run: [Tok-Cirrhatus-2586] "C:\Documents and Settings\Narendra\Local Settings\Application Data\br6195on.exe"

O4 - Startup: Empty.pif = ?

O17 - HKLM\System\CCS\Services\Tcpip\..\{45C88CAD-F277-4E97-BB0B-9A099A8E9045}: NameServer = 208.67.222.222,208.67.220.220

O17 - HKLM\System\CS1\Services\Tcpip\..\{45C88CAD-F277-4E97-BB0B-9A099A8E9045}: NameServer = 208.67.222.222,208.67.220.220

O17 - HKLM\System\CS2\Services\Tcpip\..\{45C88CAD-F277-4E97-BB0B-9A099A8E9045}: NameServer = 208.67.222.222,208.67.220.220

DownLoad http://www.downloads.subratam.org/KillBox.zip or
http://www.thespykiller.co.uk/files/killbox.exe

Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following line(s) one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.
Be sure to note... Read more

Read other 1 answers
RELEVANCY SCORE 41.2

Prior to finding this site i was reading and following detailed instructions regarding HJT. I downloaded HJT to jump drive and installed on infected PC. Ran HJT and followed directions to remove F2 REG:system.ini:UserInit=C:\WINDOWS\system32\winlogon32.exe and several other files on the log file to no avail. When I run the scan again the files still come up. The computer comes up with worm.win32.netsky detected on your machine error message when rebooted and still has the dark green screen showing the computer is infected recommending a full system scan. Additionally there is a icon in the system tray that looks like a red stop sign with a white X that pops up with an error message stating Click Here to protect your computer from spyware! Your Computer is infected! Windows has detected an infection of spyware! It is recommended to use special atispyware tools to prevent data loss. Windows will now download and install the most up-to-date antispyware for you. When i try to access the internet it states cannot connect to internet. Below is my Logfile of HJT. I am running Windows XP SP3. Any help you can give for this issue is appreciated. I do have access to a working computer and jump drive.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:11:57 PM, on 1/31/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32... Read more

Read other answers
RELEVANCY SCORE 40.8

Hello everyone.
Once again I search for someone with whom I have the utmost faith in their ability and skill.
I have been having a problem getting rid of W32/Generic.worm!p2p. I am working on my nieces computer and have exhausted all my ideas. Every time I would download hijack this McAfee would delete the file due to this worm.

I don't care for McAfee anyway so I removed it and downloaded Avg and I am also going to get Zone Alarm for her.

She has a
Dell dimension 4700
windows xp
it is entirely update through microsoft.

Before I got started I removed Limewire and and few other programs. Downloaded all the above...updated them ....Turned off system restore....went to work in safe mode.

I have done.....
Smitrem
Restored Original Hosters
Stinger.exe
CW Shredder
Cleanup
Ewido
Trend On-line
Panda On-line
Ad-aware
Spy-bot
Hijack This
Spy ware Blaster

I would appreciate your help with this log. I am terrible about deleting more than I should and giving myself something else to fix. So I thought I would leave it up to someone that truly knows what they are doing.
Thank You so very much for your time and saving me from even more gray hair.

Logfile of HijackThis v1.99.1
Scan saved at 3:13:59 PM, on 9/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.e... Read more

A:Solved: HJL...could i borrow your expertise? Worm issue

Read other 8 answers
RELEVANCY SCORE 40.4

Hello, my computer has been infected with some type of virus. I had to use system restore to even be able to install Hijackthis. I was having problems using any programs due to the virus not allowing me to do so. I kept getting fake messages popped up trying to get me to purchase antispyware. At one point I was able to open my Antispyware and remove everything, and also run Avira after that. Everything would look fine, but then I noticed google would redirect me to fake sites. Eventually, I was back to not being able to run any programs, and that's when I tried the system restore in order to install Hijackthis. While doing that, a message popped up saying something about being denied access to Hosts file, and telling me to run HijackThis as administrator. Any help would be greatly appreciated, here is my hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:19:35 PM, on 5/24/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19048)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Avira... Read more

A:Win32 Blaster Worm/Google Redirect Issue

Hello and welcome to the forums!My secret agent name on the forums is SweetTech (you can call me ST for short), it's a pleasure to meet you. I am very sorry for the delay in responding, but as you can see we are at the moment being flooded with logs which, when paired with the never-ending shortage of helpers, resulted in the delayed responding to your thread.I would be glad to take a look at your log and help you with solving any malware problems.If you have since resolved the issues you were originally experiencing, or have received help elsewhere, please inform me so that this topic can be closed. If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forums.
Please make sure to carefully read any instruction that I give you. Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.
If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator&#... Read more

Read other 16 answers
RELEVANCY SCORE 39.6

Hi! Had my previous post transferred a couple of weeks ago, haven't had a reply, however, have an update,,,, ran Malware, quarantined the 405 issues ... below is the Malware log and Hijack This log.
Thanks in advance for your time and help,,, it's much appreciated!

Still same issues exist,,,, Major freezing at random,,, Powers off at random, video resolution changes at random, really high memory usage on IE, then very slow, several apps show Bad Image error on startup. Regedit still will not run,,,

Also found in System.ini - "NotBoosted" Dummy.Dummy=1
Also found in Win.ini - annie - CaptureFile= VideoDevice=0 Audio Device=0 FrameRate=667111 UserFrameRate=1 CaptureAudio=1 WantPreview=1 MasterStream=-1
Are these supposed to be there? I unchecked them, restarted and didn't notice anything.

Here is the Malware log,,, Have highlighted the trojans, worm and rogues in red

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/30/2010 9:49:56 PM
mbam-log-2010-07-30 (21-49-56).txt
Scan type: Quick scan
Objects scanned: 173370
Time elapsed: 54 minute(s), 1 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 201
Registry Values Infected: 16
Registry Data Items Infected: 1
Folders Infected: 31
Files Infected: 156
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Regist... Read more

Read other answers
RELEVANCY SCORE 38

Morning everyone,

I just inherited this machine at work but it has a few startup issues that I need your help on. Upon initial startup (before completely loading the desktop) an error popup saying "Your SQL Server insdtallation is either corrupt or has been tampered with (could not open SQLEVN70.RLL). Please uninstall then re-run setup to correct this problem."

I've never done this before, could someone help with a step-by-step? I would really appreciate the help

thanks!

A:SQL Server Issue

You might have a look here.About a third of the way down the page is a "possible solution" by an "andydc3".It will start with: "I had the same problem, and I didn't have the duplicate/empty folders that the previous reply mentioned. Here's how I solved it:I went to C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\Resources\1033 and found that there resided a good...."Hope this helps,

Read other 3 answers
RELEVANCY SCORE 38

Below is the log.

Symptoms: No icons or Start Menu after logging into the computer. Start menu shows up and disappears after a split second. Please help if you can. I appreciate it.
Logfile of HijackThis v1.99.1
Scan saved at 9:34:50 AM, on 5/27/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\msdtc.exe
C:\Program Files\Common Files\CA\Alert\ALERT.EXE
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\ComputerAssociates\ARCserve\DBENG.exe
C:\Program Files\CA\SharedComponents\BrightStor\CADS\casdscsvc.exe
C:\Program Files\ComputerAssociates\ARCserve\jobeng.exe
C:\Program Files\ComputerAssociates\ARCserve\msgeng.exe
C:\Program Files\ComputerAssociates\ARCserve\caserved.exe
C:\Program Files\ComputerAssociates\ARCserve\casmrtbk.exe
C:\Program Files\ComputerAssociates\ARCserve\tapeeng.exe
C:\Program Files\ComputerAssociates\ARCserve\cadisc... Read more

A:Server Issue

Hi Coop-Show. The only thing I see in the log that is questionable is:E:\hi.exeDo you know what this is? if not then terminate the process and delete the file.If you are unsure then do the following:Go to the Jotti's malware scan page and use the buttons at the top of the page to browse to this file(s) on your hard drive to submit for a scan:E:\hi.exeSeveral scanning engines will be used to check the file for any threats. Please post the results of the scans back here.Cheers.OT

Read other 7 answers
RELEVANCY SCORE 38

I have a demo web server, which is where all of our test changes are made to our real web site. Our programmers and other various web folk ftp the changes to the site (which is just an IP address we don't have a DNS record associated with it). Our web people are in the US, India and Korea and are all having the following problem. They cannot FTP or HTTP to the ip address of the web site, unless they ping it first, if they ping it then they can suddenly get a response from the site and can access it for a period of time. The Demo machine is not behind a firewall of any kind, its just sitting out there. It has no problem seeing the rest of the world. Its running win2k, I might add. This problem just started happening a few weeks ago... I have reinstalled tcp-ip, made sure that the card is not going to sleep, which wasn't the case anyhow.. its like each individual machine has to handshake with it before it will respond to http and ftp, and then after a period of inactivity from that machine it can't access it again without resending the icmp.. oh traceroute also seems to work to wake it up. I can attempt to access the web site, have it not work, ping it, have it work and the guy on the same hub/switch two feet from me has to go through the same process, as do the people in india and korea as well as other varios friends I've had try it. I'm sorry if I'm repeating or over simplyfing my explanation but I want to give full details on the problem... any... Read more

A:Web Server Issue

So I say so I go *bump*

I needs da helpin!
 

Read other 1 answers
RELEVANCY SCORE 37.6

I have a thread over the imaging section,

http://forums.techguy.org/digital-p...on-mf3240-scanner-axis-print.html#post8698740
But the problem may be a network issue? Perhaps some of the network gurus here might have some ideas?
 

A:USB scanner server issue

Please do not start more than one thread for the same issue.

I've moved the other one to the Hardware forum and am closing this one.
 

Read other 1 answers
RELEVANCY SCORE 37.6

Having a weird DNS issue. I have my TCP/IP properties set for DHCP with DHCP disabled in the router, but alternate configuration is configured. For some reason I keep getting DNS servers assigned to me that I've never used.

It keeps setting the DNS to staticly uses these addresses

85.255.115.75
85.255.112.109

I've flushed the DNS rebooted I've checked the Advanced DNS tab in the TCP/IP Properties and it also lists those DNS Server addresses there as well, I remove them and they just keep comming back. This is happening on 1 of 2 machines on the same network. Any idea what would cause this?

XP Pro SP2

Windows IP Configuration

Host Name . . . . . . . . . . . . : antec
Primary Dns Suffix . . . . . . . : xtech.n64
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . :No
WINS Proxy Enabled. . . . . . . No
DNS Suffix Search List. . . . . . xtech.n64

Ethernet adapter Wireless Network Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Linksys Wireless-G PCI Network Adapt
er with SpeedBooster
Physical Address. . . . . . . . . : 00-12-17-69-AF-C4
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Autoconfiguration IP Address. . . : 10.0.1.20
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.0.1.1
DNS Servers . . . . . . . . . . . : 85.255.115.75
85.255.112.109
 

A:Solved: DNS server issue

Read other 16 answers
RELEVANCY SCORE 37.6

unable to browse to any server/workstation using UNC names after virus

removed all infected files, virusues dlls exes ect....

check the gpo and reg there is no disabled rights

sfc finished>reboot

even ran a script to edit the regitstry to clean up rights ( as per microsoft )

cd /d "%ProgramFiles%\Windows Resource Kits\Tools"
subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=administrators=f /grant=system=f
subinacl /subkeyreg HKEY_CURRENT_USER /grant=administrators=f /grant=system=f
subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=administrators=f /grant=system=f
subinacl /subdirectories %SystemDrive% /grant=administrators=f /grant=system=f
subinacl /subdirectories %windir%\*.* /grant=administrators=f /grant=system=f
secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose

reboot

from there checked all services, everything is running
masterbrowser, everything

however getting GPO errors

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1030
Date: 9/3/2008
Time: 3:48:32 PM
User: *******
Computer: *********
Description:
Windows cannot query for the list of Group Policy objects. A message that describes the reason for this was previously logged by the policy engine.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1030
Date: 9/3/2008
Time: 3:46:38 PM
User:... Read more

A:issue with UNC \\server\share

To get Expert Help with malware removal:

I recommend that you read this article… ( Simply, click on the links to be re-directed.)

"Having problems with spyware and pop-ups? First steps;

IMPORTANT - Read This Before Posting For Malware Removal Help

Please follow the instructions very carefully; then, post all the requested logs and information; as instructed, in the HiJackThis Log Help Forum.

http://www.techsupportforum.com/secu...this-log-help/

Please ensure that you create a new thread in the HiJackThis Log Help Forum; not back here in this one.

IMPORTANT - Read This Before Posting For Malware Removal Help

When carrying out The 5 Steps,

If you cannot complete any of them for whatever reason, just continue on with the next one until they are all completed.

However, it is extremely important to make mention of the fact that you could not complete any of the steps in your post to HiJackThis Log Help Forum.

http://www.techsupportforum.com/secu...this-log-help/

Where an Analyst will assist you with other workarounds.

Once done, please be patient, as the Security Team Analysts are usually very busy; one of them will answer your request as soon as they can.

Read other 7 answers
RELEVANCY SCORE 37.6

Hi,
I was created a DHCP server in Server-2008 r2 but it didn't provide IP automatically to client and on the other way in the roles sections when I click on DHCP, it didn't expand as other roles expand.
Please provide the solution.
Thanks,
Shashank Saxena

Read other answers
RELEVANCY SCORE 37.6

So, tonight all of a sudden my internet crashed. I waited a couple hours and it didn't come up so I googled the issue on my phone and was trying to fix it. Anyway, after running a diagnosis it said my DNS server might be unavailable. So, following some tips on a website I went to Wireless Network Connection properties and switched the option from "Use the following DNS server addresses" to "Obtain DNS server address automatically" and suddenly the internet came back up just like that. I'm confused, I didn't change any settings so what would have happened to cause this and how would the option get changed like that? I mean I never messed with any settings, I was playing WoW when the internet went down. Thanks for any help.

Edit: Actually I did turn on/off and reset my router/modem during the couple hours when it was down. However, it didn't fix the issue.
 

A:DNS server issue tonight

which were the ip of the old DNS, there are some cases that a router can be compromised if you use generic password. Just in case check with your ISP if the problem is within the modem/router
 

Read other 3 answers
RELEVANCY SCORE 37.6

Hi, I am running win 2000 Server as a print and licence machine, when accessing a domain through network places the error "Insufficient system resources exist to complete the requested service". This has me baffled - when viewing task mgr system idle is 99%. all patches/service packs up to date, it's running on a 100MB link, no errors are showing in the logs. all drivers also up to date.
Any Ideas??
 

Read other answers
RELEVANCY SCORE 37.6

Hi, I am running win 2000 Server as a print and licence machine, when accessing a domain through network places the error "Insufficient system resources exist to complete the requested service". This has me baffled - when viewing task mgr system idle is 99%. all patches/service packs up to date, it's running on a 100MB link, no errors are showing in the logs. all drivers also up to date.
Any Ideas??
 

Read other answers
RELEVANCY SCORE 37.6

Im not sure if I started this thread in the correct location so if it needs to be moved please do so.

My server at the house has Windows 2003 server, I have IIS installed and have one of my web pages hosted behind my Linksys wireless router/firewall. My server has a fixed IP address and the router has the IP address open with port 80. I do not have a static IP address. However, Dynsite and Zone Edit take care of that and the web site works fine. Now the issue, I have a total of four web sites to host, IIS gives me an IP address error when I try to start one of the other web sites.
It has to be something silly im missing.
 

Read other answers
RELEVANCY SCORE 37.6

Linux running Fedora 14 is the NFS server and License server for my Toon Boom Animation software. Mac Pro running Mountain Lion is the client.

This set up previously worked but after a power outage the software will not open on the Mac since it cannot verify the license with the linux license server.

Network setup:

Motorola Uverse Wireless Router/Modem ---> TrendNet Switch ---> Server and Client

Manual IP addresses set for the server and client

I have to use NFS Manager on the Mac to be able to view and edit the NFS mounting, but upon starting it, I recieve an error message saying that the Mac has reverted back to Bonjour only operation and that there is a possible problem with the forward and backward name resolutions.

I think the router is handling the DNS, and I don't know how to resolve the issue... I'm not all that knowledgeable about advanced networking and have been barely getting by until now.

Both computers are talking to each other since I can access files that are on the Mac from the Linux machine via SMB. Haven't figured out how to access linux files from the Mac though.
 

Read other answers
RELEVANCY SCORE 37.6

Hey Guys,

We have a terminal server which we currently use and it seems to be bluescreening quite frequent. I know it's a issue related to the Plug and Play driver (PNP_DETECTED_FATAL_ERROR) but I haven't found any clear indication online on how to fix it.

I've attached the BSOD data. If anybody could have a look and advise would be greatly appreciated. Just stumped on how to fix the issue.

Cheers,

Read other answers
RELEVANCY SCORE 37.6

I recently registered mydomain with Yahoo. I created a little web site. I decided to buy MDaemon Mail Server and host and look after my own mail. So I added my MX record to my Yahoo services so that Yhoo no longer look after any mail for me.

I opened the appropriate ports in my router and firewall to allow for this. I also got a static IP address from my ISP. But everytime I try to send a mail to a user @mydomain I get the following failed mail delivery message.

Message from yahoo.com.
Unable to deliver message to the following address(es).

<@yahoo.com>:
4.79.181.12 does not like recipient.
Remote host said: 501 Syntax error in parameters or arguments
Giving up.

--- Original message follows.

Return-Path: <[email protected]>
Message-ID: <[email protected]>
X-Yahoo-Forwarded: from [email protected] to @yahoo.com
X-Rocket-Track: 1: 100 ; IPCR=n-w0,n99,g1 ; IP=159.134.118.21 ; SERVER=216.155.197.136 # cat=UK; info=ip:NN<ip=159.134.118.21,policy=n-w0,n99,g1>;sv:UK<ip=216.155.197.136>;sg:UK<size=23,cnt=1>
X-Originating-IP: [159.134.118.21]
Authentication-Results: mta105.biz.mail.re2.yahoo.com
from=eircom.net; domainkeys=neutral (no sig)
Received: from 159.134.118.21 (HELO mail05.svc.cra.dublin.eircom.net) (159.134.118.21)
by mta105.biz.mail.re2.yahoo.com with SMTP; Tue, 12 Jul 2005 02:24:02 -0700
Received: (qmail 58042 messnum 3326923 invoked from network[159.134.237.83/webmail02.eircom.net]); 12 Jul 2005 09:24:01 -0000
Receiv... Read more

Read other answers
RELEVANCY SCORE 37.6

I have had blackops for my computer since its release and i recently come into a serious issue regarding the server list.

When i played about 2 weeks ago i would be able to go into the server browser and see a list of servers, Under servers then it showed A number like 284(950) meaning certain servers are being blocked by my Filters

But now I have all filters set to allow everything and i get 0(2521)
Meaning no servers can be seen, I cant figure out why,

Im running a store bought windows 7, Due to the fact my Graphics card cant handle the game, I run it in the games lowered settings which i have done since i bought the game without problems I added this to help figured out if its the issue, as far as i know its irrelevant

When i was playing inside of servers i had a consistent ping Or Latency take your pick there the same depending on your game of 60-75 (90 when i first load in)

Ive done a factory Restart and completely wiped it from my computer and that did not help I checked my router settings and all Ports used by this game a currently allowed

Im stumped, Any ideas?
 

A:Black ops server Issue

Maybe there is a new patch avalible, get it with Game Spy Comrade
 

Read other 2 answers
RELEVANCY SCORE 37.6

Can anyone help me?

We have an NT server, and currently having Major problems with people who don't know what they are doing deleting folders!!!

Is there any way of allowing users (W98) to access and save documents to the folders without them being about to delete them?
 

A:NT Server Security Issue

If the file system is NTFS, then you can set permissions to write and modify but not delete if you want. If the users are connecting through a share, you should set share permissions that way also. I would set both if able. Don't worry about w98 machines seeing a NTFS share, it uses the server to translate and looks like a FAT folder to the network users. To set share permissions, right-click on the folder and select sharing and then the permissions button set only admins and system as having full control, and everyone (or domain users) to read write and change. That is for win2k, options for NT may read modify instead of change. For folder permissions, right-click on the folder and select properties and the security tab, click permissions and set accordingly. Hope this helps.
 

Read other 1 answers
RELEVANCY SCORE 37.6

I downloaded the 1.6 and 1.7 patches to my Call of Duty 4: Modern Warfare.

For the past month I have been playing CoD4 with no problems. But after I installed the patch, non of the servers on the server list show up. I click refresh, and it connects to the master server, but then nothing appears.

I know for certain that my firewall isn't blocking anything.

IS there a way to fix this so the servers come up? Or even a way to remove the patch so I can go back to the older version that actually worked?
 

A:COD4 Server Issue

Help.
 

Read other 1 answers
RELEVANCY SCORE 37.6

I went out and bought a Linksys WRT160N V2 to replace my old wired router (which I had NO problems with, btw) and started having this problem on the XP computer that was hardwired to the router. My main computer (Vista) that was using the wireless adapter had ZERO problems.

The other day, I decided to switch the location of the router and modem to be closer to my PS3, so now my main computer is hardwired while my XP computer is using the wireless adapter. Now my main computer is having this DNS problem. It literally took me about half an hour to be able to reply to this thread because all I kept getting was "Internet Explore cannot display the webpage" and a "diagnose connection" button.

I noticed the pattern to this problem was right after I fired up my computer. What boggles me, is that it's NOT an internet connection problem. I say this, because my MSN Messenger will sometimes connect right off the bat, being able to chat with friends and whatnot, but when I try to check my email or go to any other page for that matter, "Internet Explorer cannot display the webpage." And if it's not not being able to display the webpage, I get a Google page saying "Oops! This link appears to be broken" and a thing in the upper right hand corner saying "DNS error - cannot find server.

Now, my PS3 and my XP computer are both having the problem loading webpages within 30 minutes of connecting to the internet. There's gotta be a... Read more

A:New Router, DNS Server issue

Even though it appears you're having the same problem, please start a new thread when you have a new issue. It's very difficult to keep two problems straight and who's working on what in a single thread.

I've created a new thread for your issue here.

Note: You will need to post complete details of your configuration and your specific issue in this new thread for us to help you.

Thanks for your cooperation.
 

Read other 2 answers
RELEVANCY SCORE 37.6

I just have a quick question, I have setup a VPN using RRAS and L2TP shared secret, etc. From the client computer it connects no problem, and I can access shared resources on the LAN like it's supposed to work. The only problem is when I connect to the VPN, my browser doesn't work, can't get external internet to work and copying files from outlook 2007 to a shared resource seems to lock outlook up.

I'm not sure if this has something to do with sending all traffic over vpn or not. Is there any steps I can take to quickly resolve this issue? This seems to be the only thing affecting the users at the office.

Thanks,
 

A:Server 2003 VPN Issue

Is the VPN setup as a separate subnet example: if host 192.168.1.100 client 192.168.0.100.

Also depending on ISP and other possible settings you may need to use other DNS servers .

If so on the client try OpenDNS https://www.opendns.com/homenetwork/start/

Do this on the Client not on Server. Reboot let us know!

Mike
 

Read other 5 answers
RELEVANCY SCORE 37.6

Yesterday at 3:05 PM we had a momentary power sag in the office, a couple of the office computers turned off, but after that everything seemed to be okay. Both of the users were able to restart their machines and continue working. This morning when I got to work I went to check the server which is working fine, but the tape drive seems like it has no power. when I try to eject the tape in the drive nothing happens. I also tried to format the disk by using the server software and it tells me that the "cartridge is not in place" It is connected to a UPS so I don't see why this would quit working due to a power sag. What can I do?
 

A:Server Backup Issue

Read other 11 answers
RELEVANCY SCORE 37.6

Dear All,

It is my first Forums.

I am having problems with my laptop I am using Windows XP with SP2 and using DHCP client.In my office i am not access any external ( http://www.google.com). At the time I checked in my network connection In TCP/IP protocol Preferred DNS server takes some IP 84.xx.xx.xx.

After windows XP system restore It is fixed. Can I expect the permanent solution.

Advanced Thanks,
Ayyappan.H
 

A:Reg : Prefered DNS server Issue

Windows solution permanent? You must be new to computers. A system restore was was a bit drastic for a DNS problem. Next time post the problem first.
 

Read other 1 answers
RELEVANCY SCORE 37.6

I am running Windows 8.1 RTM (with all updates as of 10/3/13). I have an unRAID server in my local workgroup at home, which was connectable fine when my machine was Windows 7. Now it appears to have some issues.

If I browse to \\HADES (the machine name) it fails saying it "Windows could not find \\Hades"
If I browse to \\10.x.x.x (the machine IP) it works fine
The first week I was still able to get to Microsoft Internet Information Services 8 to access to UI to unRAID, now that is failing unless I use Microsoft Internet Information Services 8.

My unRAID server is a static IP
My Windows 8.1 server is a static IP
My router is Actiontec MI424WR-GEN3I

I tried modifying my host file just adding a "10.x.x.x HADES" line but that didn't work.

Any thoughts or ideas would be appreciated, I am totally lost.

A:Connecting to server issue

Originally Posted by wickedathletes


I am running Windows 8.1 RTM (with all updates as of 10/3/13). I have an unRAID server in my local workgroup at home, which was connectable fine when my machine was Windows 7. Now it appears to have some issues.

If I browse to \\HADES (the machine name) it fails saying it "Windows could not find \\Hades"
If I browse to \\10.x.x.x (the machine IP) it works fine
The first week I was still able to get to Microsoft Internet Information Services 8 to access to UI to unRAID, now that is failing unless I use Microsoft Internet Information Services 8.

My unRAID server is a static IP
My Windows 8.1 server is a static IP
My router is Actiontec MI424WR-GEN3I

I tried modifying my host file just adding a "10.x.x.x HADES" line but that didn't work.

Any thoughts or ideas would be appreciated, I am totally lost.



Is there a DNS server at all on the network? using the HOSTS file isn't always reliable.

Josh

Read other 3 answers
RELEVANCY SCORE 37.6

Not too sure if I should be posting a server issue but any advice is good so here is my issue. I have a 2K server and it seems to start up slow. Takes about 5 minutes. Where before t was like 2 minutes.

- WIN2K Server
- Always do Windows updates ( the important ones )
- It's an Intel P4 | 1 gig of ram | 2.4 Ghz
- Sometimes it take long to install a 2 megs update. I always run registry fixers and it works.
- Mcafee scan every Saturday
- Used HJT posted here http://forums.techguy.org/t390197.html
- Use adaware | spybot |crapcleaner | MS Anti spyware | CW Sheedder

I'm going to do more during the week but anyone have more advice they can give
 

A:Win2k Server Issue

BUMP
Anyone ?
 

Read other 2 answers