ramon82 Posted September 2, 2008 Report Share Posted September 2, 2008 I have been having a strange problem. My Windows 2000 server is sometimes rebooting after giving a quick BSOD....The last line in the SYSTEM event log following the reboot was this:01-09-2008 11:59:17 AM Save Dump Information None 1001 N/A SERVER-A The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xe4ff3428, 0x00000000, 0xf74f4c9e, 0x00000001). Microsoft Windows 2000 [v15.2195]. A dump was saved in: C:\WINNT\MEMORY.DMP. The hijackthis log is this:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 6:04:54 AM, on 02-09-2008Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Boot mode: NormalRunning processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\FUJITS~1\SERVER~2\SERVER~1\WEBSER~1\bin\Apache.exeC:\WINNT\system32\Dfssvc.exeC:\WINNT\System32\svchost.exec:\teamware\server\i500\i500stack\RFC1006D.EXEC:\WINNT\System32\llssrv.exeC:\Program Files\McAfee\Common Framework\FrameworkService.exeC:\PROGRA~1\FUJITS~1\SERVER~2\SERVER~1\WEBSER~1\bin\Apache.exeC:\Program Files\Network Associates\VirusScan\Mcshield.exeC:\Program Files\Network Associates\VirusScan\VsTskMgr.exeC:\Program Files\Network Associates\ePO\MSSQL\Binn\sqlservr.exeC:\WINNT\system32\ntfrs.exeC:\WINNT\system32\regsvc.exeC:\WINNT\System32\locator.exeC:\WINNT\system32\MSTask.exeC:\WINNT\System32\snmp.exeC:\WINNT\System32\snmptrap.exeC:\Program Files\Fujitsu Siemens\ServerView Agents\Server Control\SrvCtrl.exec:\teamware\server\tosvc.exec:\teamware\server\tostart.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\Program Files\RealVNC\VNC4\WinVNC4.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\tcpsvcs.exeC:\WINNT\System32\dns.exeC:\WINNT\System32\inetsrv\inetinfo.exeC:\WINNT\System32\ismserv.exec:\teamware\server\toentdir.exec:\teamware\server\i500\bin\odssched.exec:\teamware\server\i500\bin\odscomms.exec:\teamware\server\i500\bin\odsmdsa.exec:\teamware\server\i500\bin\odssdsa.exec:\teamware\server\i500\bin\odssdsa.exec:\teamware\server\i500\bin\odssdsa.exec:\teamware\server\i500\bin\odsshad.exec:\teamware\server\i500\i500ldap\mtldapd.exec:\teamware\server\i500\i500ldap\odsldapv3.exec:\teamware\server\toserver.exec:\teamware\server\tombdisp.exec:\teamware\server\tomime.exec:\teamware\server\tomprep.exec:\teamware\server\toemsend.exec:\teamware\server\to3xbox.exec:\teamware\server\tohttp.exec:\teamware\server\tohttp.exec:\teamware\server\toalarm.exec:\teamware\server\toimap4.exec:\teamware\server\toalert.exec:\teamware\server\toaluser.exeC:\WINNT\System32\svchost.exeC:\WINNT\Explorer.EXEC:\Program Files\McAfee\Common Framework\UpdaterUI.exeC:\Program Files\Network Associates\VirusScan\SHSTAT.EXEC:\WINNT\system32\Atiptaxx.exeC:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exeC:\WINNT\system32\cmd.exeC:\WINNT\system32\robocopy.exeC:\Documents and Settings\Administrator\Desktop\HiJackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nai.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 142.191.42.98:3128R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 142.191.3.20O1 - Hosts: 142.191.3.20 mail.techlab.com.mtO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocxO4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UpdaterUI.exe" /StartedFromRunKeyO4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONEO4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exeO4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exeO9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htmO9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htmO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: {00A7BD45-3D5C-11D4-BDA7-00C0F02C56AB} (DMSrvPushX Control) - http://142.191.31.10/webpages/DMWebX.ocxO16 - DPF: {4EABBB94-847F-45CB-8C70-99AE8E88635A} (WebClient Control) - http://142.191.25.25/WebCamX.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1126528307562O16 - DPF: {E8775171-BF76-42EC-A093-55E16A45C375} (prjTWAttachmentListG.TWAttachmentList) - https://www.snt.com.mt/prjTWAttachmentListG.CABO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = techlab.comO17 - HKLM\System\CCS\Services\Tcpip\..\{30EE7ADA-AD51-481C-A3D3-5E414189010E}: NameServer = 142.191.3.20,194.159.36.19O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = techlab.comO17 - HKLM\System\CS1\Services\Tcpip\..\{30EE7ADA-AD51-481C-A3D3-5E414189010E}: NameServer = 142.191.3.20,194.159.36.19O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = techlab.comO17 - HKLM\System\CS2\Services\Tcpip\..\{30EE7ADA-AD51-481C-A3D3-5E414189010E}: NameServer = 142.191.3.20,194.159.36.19O23 - Service: Apache2 - Apache Software Foundation - C:\PROGRA~1\FUJITS~1\SERVER~2\SERVER~1\WEBSER~1\bin\Apache.exeO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exeO23 - Service: McAfee ePolicy Orchestrator 3.0.1 Event Parser (EVENTPARSER301) - Network Associates, Inc. - C:\Program Files\Network Associates\ePO\3.0.1\EVENTPARSER.EXEO23 - Service: FSC ServerView Services - Fujitsu Siemens Computers - C:\PROGRA~1\FUJITS~1\SERVER~2\SERVER~1\scripts\SERVER~1\SnmpTrap\AlarmService.exeO23 - Service: RFC1006 Transport Service (ISOSTACK.RFC1006) - ISOCOR - c:\teamware\server\i500\i500stack\RFC1006D.EXEO23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exeO23 - Service: Network Associates McShield (McShield) - McAfee, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exeO23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exeO23 - Service: McAfee ePolicy Orchestrator 3.0.1 Server (NAIMSERV301) - Network Associates, Inc. - C:\Program Files\Network Associates\ePO\3.0.1\NAIMSERV.EXEO23 - Service: Server Control Service (SrvCtrl) - Fujitsu Siemens Computers GmbH - C:\Program Files\Fujitsu Siemens\ServerView Agents\Server Control\SrvCtrl.exeO23 - Service: Teamware Server v7.1 (TeamWAREOffice5) - Unknown owner - c:\teamware\server\tosvc.exeO23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe--End of file - 7247 bytesCAN YOU KINDLY HELP ME PLS Quote Link to comment Share on other sites More sharing options...
andsome Posted September 2, 2008 Report Share Posted September 2, 2008 No one on here is qualified at present to read Hijack thie log files.Post it on here.Let us know how you get on. All the best. :D Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.