Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > HijackThis Log Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

HijackThis Log Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Reply
 
Thread Tools
Old 10-20-2004, 10:26 AM   #1 (permalink)
M23
Registered User
 
M23's Avatar
 
Join Date: Oct 2004
Posts: 4
OS: XP


Wierd messages coming from our Symantec server.

We are running Symantec corporate 8

This appeared on all the clients this morning.

Read Carefully



Could someone have haxored my AV server?
M23 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 10-20-2004, 10:42 AM   #2 (permalink)
Fox
Moderator, Microsoft Support
 
Fox's Avatar
 
Join Date: Sep 2002
Location: NJ
Posts: 7,752
OS: XP Pro, CentOS

My System

Send a message via ICQ to Fox Send a message via AIM to Fox Send a message via MSN to Fox Send a message via Yahoo to Fox Send a message via Skype™ to Fox
apparently
Fox is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 10-20-2004, 10:53 AM   #3 (permalink)
Knower of all that is MS
 
CTSNKY's Avatar
 
Join Date: Aug 2004
Posts: 10,755
OS: (multiple machines) 95, 98, 2K & XP Home & Pro


LOL......have to give the originator points for creativity anyway!

:4-type:
__________________


GO BIG BLUE!!
CTSNKY is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 10-21-2004, 08:17 AM   #4 (permalink)
M23
Registered User
 
M23's Avatar
 
Join Date: Oct 2004
Posts: 4
OS: XP


Quote:
Originally Posted by CTSNKY
LOL......have to give the originator points for creativity anyway!

:4-type:
I'm dead serious, wtf could have caused this? Is there a way to modify the out of date AV notifications with Symantec corporate?
M23 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 10-21-2004, 03:59 PM   #5 (permalink)
Old Timer
 
jgvernonco's Avatar
 
Join Date: Sep 2003
Location: Northern Arizona
Posts: 7,957
OS: Vista Home Premium, SP 27


I doubt that there is anyone on this forum who is conversant with Symantec Corp , so we are pretty useless to you.

As an aside, I was pretty up on Symantec solutions until I turned my back and walked away. The whole thing is too integrated into the OS to be really secure, and demands unreasnable amounts of resources. I am aware that this does not resolve your problem right now, but I am still going to recommend that you look carefully at the Trend Micro Enterprise solutions at your first opportunity. Not only does it perform better, but you wouldn't be talking to us right now, as they have decent support.

I believe that your server has been compromised. You can run HJT scans on servers. If you would like us to take a look, we would be happy to.
jgvernonco is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 10-22-2004, 09:24 AM   #6 (permalink)
M23
Registered User
 
M23's Avatar
 
Join Date: Oct 2004
Posts: 4
OS: XP


Quote:
Originally Posted by jgvernonco
I doubt that there is anyone on this forum who is conversant with Symantec Corp , so we are pretty useless to you.

As an aside, I was pretty up on Symantec solutions until I turned my back and walked away. The whole thing is too integrated into the OS to be really secure, and demands unreasnable amounts of resources. I am aware that this does not resolve your problem right now, but I am still going to recommend that you look carefully at the Trend Micro Enterprise solutions at your first opportunity. Not only does it perform better, but you wouldn't be talking to us right now, as they have decent support.

I believe that your server has been compromised. You can run HJT scans on servers. If you would like us to take a look, we would be happy to.
What are HJT scans?
M23 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 10-22-2004, 09:29 AM   #7 (permalink)
Manager, The Relaxation Room/Analyst, Security Team
 
mimo2005's Avatar
 
Join Date: Oct 2004
Posts: 10,735
OS: xp


Quote:
Originally Posted by M23
What are HJT scans?

create a permanent folder ,name it hijackthis

then download and install inside that folder ,this program:


http://www.softpedia.com/public/cat/...10-17-69.shtml

scan with it ,save the log ,and post it in this thread .
mimo2005 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 10-29-2004, 08:29 AM   #8 (permalink)
M23
Registered User
 
M23's Avatar
 
Join Date: Oct 2004
Posts: 4
OS: XP


Quote:
Originally Posted by mimo2005
create a permanent folder ,name it hijackthis

then download and install inside that folder ,this program:


http://www.softpedia.com/public/cat/...10-17-69.shtml

scan with it ,save the log ,and post it in this thread .
Dude, was in an IE tool have to do with My Symantec AV server problem?
M23 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 10-29-2004, 08:58 AM   #9 (permalink)
Analyst, Security Team
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,327
OS: Windows 98 & Windows XP Home/Pro

My System

What? Your question is not making sense. Could you clarify?

Post your HijackThis log file in this thread (just reply to it) and we will take a look at it.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.

greyknight17 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 10-29-2004, 10:00 AM   #10 (permalink)
Fox
Moderator, Microsoft Support
 
Fox's Avatar
 
Join Date: Sep 2002
Location: NJ
Posts: 7,752
OS: XP Pro, CentOS

My System

Send a message via ICQ to Fox Send a message via AIM to Fox Send a message via MSN to Fox Send a message via Yahoo to Fox Send a message via Skype™ to Fox
Quote:
Dude, was in an IE tool have to do with My Symantec AV server problem?
HijackThis is not an Internet Explorer tool. It is a way to show everything that is active in memory and everything that has altered the way your computer communicates with the network.
Fox is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 05:31 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82