Forumleden,
ik kamp op dit moment met een probleem waar ik absoluut niet uitkom.
Mijn server is sinds begin april druk aan het downloaden geslagen. In een maand tijd al 115GB !!! Vreemde van dit alles is dat deze data nergens wordt opgeslagen en ook niet doorgestuurd wordt naar buiten.

Het downloaden gebeurt op poort 80 en van een serie IP adressen. Als ik er eentje afvang en blokkeer, dan wordt er wel weer een nieuwe gevonden.
IP adressen zitten oa in de range 213.200.x.y en bv 64.158.92.62 (= level3.net)
Virusscanner e.a. vinden niets vreemds en ik die ook geen vreemde processen draaien.
Op dit moment is de enige remedie het verbieden van mijn server om HTTP verkeer te gebruiken.
Het is een beetje een drukke server. Er draait oa Exchange, Winroute Pro, Bluetooth en wat andere tools op. In feite is het een communicatieserver.
Hieronder de HJT-log. Misschien ziet iemand logica hierin?
alvast bedankt.
Peter
-----------------------------
Logfile of HijackThis v1.99.1
Scan saved at 22:21:27, on 26-4-2005
Platform: Windows 2003 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\tcpsvcs.exe
D:\Bluetooth Adapter\bin\btwdins.exe
C:\WINDOWS\system32\certsrv.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\WINDOWS\System32\dns.exe
C:\WINDOWS\System32\svchost.exe
D:\GFI\MailEssentials\msecatt.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\ismserv.exe
D:\Network Associates\McAfee GroupShield\bin\SAFeService.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
D:\Network Associates\VirusScan\Mcshield.exe
D:\Network Associates\VirusScan\VsTskMgr.exe
D:\Network Associates\McAfee GroupShield\bin\RPCServ.EXE
C:\WINDOWS\system32\ntfrs.exe
C:\Program Files\Common Files\Network Associates\Outbreak Manager\Outbreak.exe
D:\POPcon\POPconSrv.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\tftpd.exe
G:\SUS\wusync\WUSyncSvc.exe
D:\GFI\MailEssentials\pop2exch.exe
D:\Exchsrvr\bin\exmgmt.exe
D:\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\System32\svchost.exe
D:\Exchsrvr\bin\store.exe
D:\Exchsrvr\bin\emsmta.exe
D:\Network Associates\McAfee GroupShield\bin\RPCServ.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\shmgrate.exe
C:\WINDOWS\system32\regsvr32.exe
c:\windows\system32\inetsrv\w3wp.exe
d:\Kerio\WinRoute Firewall\winroute.exe
C:\WINDOWS\Explorer.EXE
D:\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Kerio\WinRoute Firewall\wrctrl.exe
D:\Bluetooth Adapter\BTTray.exe
D:\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
D:\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Kerio\WinRoute Firewall\wrctrl.exe
D:\Bluetooth Adapter\BTTray.exe
D:\BLUETO~1\BTSTAC~1.EXE
D:\Kerio\Admin\KAdmin.exe
D:\Kerio\Admin\wradmin600.exe
C:\WINDOWS\system32\logon.scr
I:\temptools\hjt\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.nl
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [ShStatEXE] "D:\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WrCtrl] "D:\Kerio\WinRoute Firewall\wrctrl.exe"
O4 - Startup: Gbinfo Update.lnk = C:\Program Files\BGINFO\Bginfo.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: GFI Monitor.lnk = D:\GFI\MailEssentials\gfimntr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Send To &Bluetooth - D:\Bluetooth Adapter\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Bluetooth Adapter\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Bluetooth Adapter\btsendto_ie.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.google.nl
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = hosting.local
O17 - HKLM\Software\..\Telephony: DomainName = hosting.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{81B88D75-ECA2-4A77-BA51-C4E09AF0428D}: NameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8A454FE4-06EA-47A9-A551-17B016CD1E4C}: NameServer = 127.0.0.1,10.1.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{C08929D9-1688-4B08-A70E-DAE2E23B25B5}: NameServer = 127.0.0.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = hosting.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = hosting.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = hosting.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = hosting.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = hosting.local
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - D:\Bluetooth Adapter\bin\btwdins.exe
O23 - Service: GFI MailEssentials Attendant - GFI Software Ltd. - D:\GFI\MailEssentials\msecatt.exe
O23 - Service: GFI POP2Exchange - GFI Software Ltd. - D:\GFI\MailEssentials\pop2exch.exe
O23 - Service: GFI List Server (listserv) - GFI Software Ltd - D:\GFI\MailEssentials\ListServ.exe
O23 - Service: McAfee GroupShield - Unknown owner - D:\Network Associates\McAfee GroupShield\bin\SAFeService.exe" (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - D:\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - D:\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: McAfee Log Service (Network Associates Log Service) - Network Associates, Inc. - C:\Program Files\Common Files\McAfee\log and quarantine\bin\i386\NAIlgpip.exe
O23 - Service: McAfee Outbreak Manager (Outbreak Manager) - Network Associates, Inc. - C:\Program Files\Common Files\Network Associates\Outbreak Manager\Outbreak.exe
O23 - Service: POPcon: Exchange POP3 Connector (POPcon) - Christensen Software - D:\POPcon\POPconSrv.exe
O23 - Service: Microsoft Support (S-S_C0) - Unknown owner - C:\WINDOWS\system32\winhelp.exe (file missing)
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - c:\windows\system32\hoi.exe (file missing)
O23 - Service: Kerio WinRoute Firewall (WinRoute) - Kerio Technologies - d:\Kerio\WinRoute Firewall\winroute.exe
ik kamp op dit moment met een probleem waar ik absoluut niet uitkom.
Mijn server is sinds begin april druk aan het downloaden geslagen. In een maand tijd al 115GB !!! Vreemde van dit alles is dat deze data nergens wordt opgeslagen en ook niet doorgestuurd wordt naar buiten.

Het downloaden gebeurt op poort 80 en van een serie IP adressen. Als ik er eentje afvang en blokkeer, dan wordt er wel weer een nieuwe gevonden.
IP adressen zitten oa in de range 213.200.x.y en bv 64.158.92.62 (= level3.net)
Virusscanner e.a. vinden niets vreemds en ik die ook geen vreemde processen draaien.
Op dit moment is de enige remedie het verbieden van mijn server om HTTP verkeer te gebruiken.
Het is een beetje een drukke server. Er draait oa Exchange, Winroute Pro, Bluetooth en wat andere tools op. In feite is het een communicatieserver.
Hieronder de HJT-log. Misschien ziet iemand logica hierin?
alvast bedankt.
Peter
-----------------------------
Logfile of HijackThis v1.99.1
Scan saved at 22:21:27, on 26-4-2005
Platform: Windows 2003 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\tcpsvcs.exe
D:\Bluetooth Adapter\bin\btwdins.exe
C:\WINDOWS\system32\certsrv.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\WINDOWS\System32\dns.exe
C:\WINDOWS\System32\svchost.exe
D:\GFI\MailEssentials\msecatt.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\ismserv.exe
D:\Network Associates\McAfee GroupShield\bin\SAFeService.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
D:\Network Associates\VirusScan\Mcshield.exe
D:\Network Associates\VirusScan\VsTskMgr.exe
D:\Network Associates\McAfee GroupShield\bin\RPCServ.EXE
C:\WINDOWS\system32\ntfrs.exe
C:\Program Files\Common Files\Network Associates\Outbreak Manager\Outbreak.exe
D:\POPcon\POPconSrv.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\tftpd.exe
G:\SUS\wusync\WUSyncSvc.exe
D:\GFI\MailEssentials\pop2exch.exe
D:\Exchsrvr\bin\exmgmt.exe
D:\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\System32\svchost.exe
D:\Exchsrvr\bin\store.exe
D:\Exchsrvr\bin\emsmta.exe
D:\Network Associates\McAfee GroupShield\bin\RPCServ.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\shmgrate.exe
C:\WINDOWS\system32\regsvr32.exe
c:\windows\system32\inetsrv\w3wp.exe
d:\Kerio\WinRoute Firewall\winroute.exe
C:\WINDOWS\Explorer.EXE
D:\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Kerio\WinRoute Firewall\wrctrl.exe
D:\Bluetooth Adapter\BTTray.exe
D:\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
D:\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Kerio\WinRoute Firewall\wrctrl.exe
D:\Bluetooth Adapter\BTTray.exe
D:\BLUETO~1\BTSTAC~1.EXE
D:\Kerio\Admin\KAdmin.exe
D:\Kerio\Admin\wradmin600.exe
C:\WINDOWS\system32\logon.scr
I:\temptools\hjt\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.nl
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [ShStatEXE] "D:\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WrCtrl] "D:\Kerio\WinRoute Firewall\wrctrl.exe"
O4 - Startup: Gbinfo Update.lnk = C:\Program Files\BGINFO\Bginfo.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: GFI Monitor.lnk = D:\GFI\MailEssentials\gfimntr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Send To &Bluetooth - D:\Bluetooth Adapter\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Bluetooth Adapter\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Bluetooth Adapter\btsendto_ie.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.google.nl
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = hosting.local
O17 - HKLM\Software\..\Telephony: DomainName = hosting.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{81B88D75-ECA2-4A77-BA51-C4E09AF0428D}: NameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8A454FE4-06EA-47A9-A551-17B016CD1E4C}: NameServer = 127.0.0.1,10.1.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{C08929D9-1688-4B08-A70E-DAE2E23B25B5}: NameServer = 127.0.0.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = hosting.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = hosting.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = hosting.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = hosting.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = hosting.local
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - D:\Bluetooth Adapter\bin\btwdins.exe
O23 - Service: GFI MailEssentials Attendant - GFI Software Ltd. - D:\GFI\MailEssentials\msecatt.exe
O23 - Service: GFI POP2Exchange - GFI Software Ltd. - D:\GFI\MailEssentials\pop2exch.exe
O23 - Service: GFI List Server (listserv) - GFI Software Ltd - D:\GFI\MailEssentials\ListServ.exe
O23 - Service: McAfee GroupShield - Unknown owner - D:\Network Associates\McAfee GroupShield\bin\SAFeService.exe" (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - D:\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - D:\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: McAfee Log Service (Network Associates Log Service) - Network Associates, Inc. - C:\Program Files\Common Files\McAfee\log and quarantine\bin\i386\NAIlgpip.exe
O23 - Service: McAfee Outbreak Manager (Outbreak Manager) - Network Associates, Inc. - C:\Program Files\Common Files\Network Associates\Outbreak Manager\Outbreak.exe
O23 - Service: POPcon: Exchange POP3 Connector (POPcon) - Christensen Software - D:\POPcon\POPconSrv.exe
O23 - Service: Microsoft Support (S-S_C0) - Unknown owner - C:\WINDOWS\system32\winhelp.exe (file missing)
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - c:\windows\system32\hoi.exe (file missing)
O23 - Service: Kerio WinRoute Firewall (WinRoute) - Kerio Technologies - d:\Kerio\WinRoute Firewall\winroute.exe