Unsolved
This post is more than 5 years old
7 Posts
0
550
October 2nd, 2008 18:00
Suspicious Service "ACKCZR"
Hi,
I would be very appreciative if someone could please take a look at this HiJackThis Log. A service called "ackczr" was running in the services console. You could not stop the service this service. I have run Symantec AV, Malwarebytes, Process Explorer, Blacklight and haven't found anything suspicious. I have tried googling this service and nothing comes up. I unchecked the service in msconfig under the services tab. TIA for the help.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:03:33 PM, on 10/2/2008
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\SysMgt\dataeng\bin\dsm_sa_eventmgr32.exe
C:\Program Files\Dell\SysMgt\dataeng\bin\dsm_sa_datamgr32.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\WINDOWS\System32\dns.exe
D:\NovaRIS\Server\HL7BrokerService.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\ismserv.exe
C:\Program Files\Dell\SysMgt\sm\mr2kserv.exe
D:\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
D:\NovaPACS\Server\NRArchiveService.exe
D:\NovaPACS\Server\NRArchiveMaintenanceService.exe
D:\NovaPACS\Server\NRDICOMService.exe
D:\NovaPACS\Server\NRImageProcessor.exe
D:\NovaPACS\Server\NRRemoteDataService.exe
D:\NovaPACS\Server\NRRouter.exe
C:\Program Files\Novarad\Site Management\InstallationManager\Novarad.InstallationManager.exe
C:\Program Files\Novarad\Site Management\Server\Novarad.SiteServer.exe
C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
C:\WINDOWS\system32\ntfrs.exe
C:\Program Files\Dell\SysMgt\oma\bin\dsm_om_shrsvc32.exe
D:\Microsoft SQL Server\MSSQL.2\Reporting Services\ReportServer\bin\ReportingServicesService.exe
D:\NovaRIS\Server\RISDicomService.exe
D:\NovaRIS\Server\RISProcessorService.exe
D:\NovaRIS\Server\RISRemoteDataService.exe
C:\Program Files\Dell\SysMgt\iws\bin\win32\dsm_om_connsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orl\VNC\WinVNC.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\Novarad\Site Management\Data Replication\Novarad.DataReplicationService.exe
D:\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
D:\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\WINDOWS\Explorer.EXE
c:\windows\system32\inetsrv\w3wp.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CBA\pds.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\system32\wuauclt.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\WINDOWS\system32\mmc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://192.168.2.128/novaris
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\Orl\VNC\winvnc.exe" -servicehelper
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [MSConfig] "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
O4 - HKLM\..\Policies\Explorer\Run: [1] C:\Program Files\NovaPACS\Viewer\PacsViewer.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O15 - ESC Trusted Zone: http://runonce.msn.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1204580192681
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = NR-DYMC.local
O17 - HKLM\Software\..\Telephony: DomainName = NR-DYMC.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4574B51-D105-40A7-BEEC-B34C781BB7A3}: NameServer = 192.168.2.150,166.102.165.11,166.102.165.13
O17 - HKLM\System\CCS\Services\Tcpip\..\{A7B1AB2B-5EB1-49F6-A987-B73AEEA08521}: NameServer = 192.168.1.88,166.102.165.11
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = NR-DYMC.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = NR-DYMC.local
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: NovaRad Data Replication Service (DataReplicationService) - NovaRad Corporation - C:\Program Files\Novarad\Site Management\Data Replication\Novarad.DataReplicationService.exe
O23 - Service: DSM SA Event Manager (dcevt32) - Dell Inc. - C:\Program Files\Dell\SysMgt\dataeng\bin\dsm_sa_eventmgr32.exe
O23 - Service: DSM SA Data Manager (dcstor32) - Dell Inc. - C:\Program Files\Dell\SysMgt\dataeng\bin\dsm_sa_datamgr32.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: NovaRIS HL7 Broker (HL7BrokerService) - NovaRad Corporation - D:\NovaRIS\Server\HL7BrokerService.exe
O23 - Service: Intel Alert Handler - Intel® Corporation - C:\WINDOWS\system32\ams_ii\hndlrsvc.exe
O23 - Service: Intel Alert Originator - Intel® Corporation - C:\WINDOWS\system32\ams_ii\iao.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\system32\CBA\pds.exe
O23 - Service: mr2kserv - LSI Logic Corporation - C:\Program Files\Dell\SysMgt\sm\mr2kserv.exe
O23 - Service: NovaPACS Archive Backup - NovaRad Corporation - D:\NovaPACS\Server\NRArchiveService.exe
O23 - Service: NovaPACS Archive Maintenance - NovaRad Corporation - D:\NovaPACS\Server\NRArchiveMaintenanceService.exe
O23 - Service: NovaPACS Dicom Server - NovaRad Corporation - D:\NovaPACS\Server\NRDICOMService.exe
O23 - Service: NovaPACS Image Processor - NovaRad Corporation - D:\NovaPACS\Server\NRImageProcessor.exe
O23 - Service: NovaPACS Remote Data Access - NovaRad Corporation - D:\NovaPACS\Server\NRRemoteDataService.exe
O23 - Service: NovaPACS Router - NovaRad Corporation - D:\NovaPACS\Server\NRRouter.exe
O23 - Service: Novarad Installation Manager - NovaRad Corporation - C:\Program Files\Novarad\Site Management\InstallationManager\Novarad.InstallationManager.exe
O23 - Service: Novarad Site Management Server - NovaRad Corporation - C:\Program Files\Novarad\Site Management\Server\Novarad.SiteServer.exe
O23 - Service: Symantec System Center Discovery Service (NSCTOP) - Symantec Corporation - C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - Service: DSM SA Shared Services (omsad) - Dell Inc. - C:\Program Files\Dell\SysMgt\oma\bin\dsm_om_shrsvc32.exe
O23 - Service: NovaRIS DICOM Service (RISDicomService) - NovaRad Corporation - D:\NovaRIS\Server\RISDicomService.exe
O23 - Service: NovaRIS Processor Service (RISProcessorService) - NovaRad Corporation - D:\NovaRIS\Server\RISProcessorService.exe
O23 - Service: NovaRIS Remote Data Service (RISRemoteDataService) - NovaRad Corporation - D:\NovaRIS\Server\RISRemoteDataService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: DSM SA Connection Service (Server Administrator) - Unknown owner - C:\Program Files\Dell\SysMgt\iws\bin\win32\dsm_om_connsvc32.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WinVNC - UltraVNC - C:\Program Files\Orl\VNC\WinVNC.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
--
End of file - 8858 bytes


Bugbatter
4 Apprentice
•
20.5K Posts
0
October 4th, 2008 12:00
We are short of help for a few days.
I suggest posting your log at SpywareHammer. The site has many Microsoft MVP's on staff and helpers there may be able to help you:
http://spywarehammer.com/