Hi Experts,
I am recently facing a issue with one of my Windows 2003 Server (File Server), Whenever I and trying to update/save any file in any of the share folder it always FREEZES (Not Responding), I have checked the HDD, Network Connection, Switch Port, Speed Settings and everything seems to be ok.
Server Details
OS: Windows Server 2003 STD R2
File System: NTFS
AV: Symantec Endpoint Protection 11.0.5002.333 (Only Antivirus & Antispyware)
I restarted the server and found that there is a continuous network activity on my server, so I used
netstat –a –b –o command and found that there are multiple outgoing connection on 25 Port (SMTP) on different server on internet using
services.exe.
List of the Active Connections
Proto Local Address Foreign Address State PID
TCP MYSERVER:epmap MYSERVER.MISLP.COM:0 LISTENING 672
RpcSs
[svchost.exe]
TCP MYSERVER:microsoft-ds MYSERVER.MISLP.COM:0 LISTENING 4
[System]
TCP MYSERVER:1040 MYSERVER.MISLP.COM:0 LISTENING 420
[lsass.exe]
TCP MYSERVER:3389 MYSERVER.MISLP.COM:0 LISTENING 2156
TermService
[svchost.exe]
TCP MYSERVER:5800 MYSERVER.MISLP.COM:0 LISTENING 1988
[WinVNC.exe]
TCP MYSERVER:5900 MYSERVER.MISLP.COM:0 LISTENING 1988
[WinVNC.exe]
TCP MYSERVER:1055 MYSERVER.MISLP.COM:0 LISTENING 2364
[alg.exe]
TCP MYSERVER:netbios-ssn MYSERVER.MISLP.COM:0 LISTENING 4
[System]
TCP MYSERVER:1087 mislpsec01.mislp.com:http ESTABLISHED 780
[Smc.exe]
TCP MYSERVER:1234 mx1.prserv.net:smtp ESTABLISHED 408
[services.exe]
TCP MYSERVER:1132 mail.aarkel.com:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1138 72.14.213.27:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1140 s201a2.psmtp.com:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1148 smtp3.180com.net:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1160 61.151.251.2:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1163 uplk01-napbr.abranet.net.br:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1167 smtp.aliceposta.it:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1183 pmxapp1.american.edu:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1190 vidar2.svf.au.dk:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1260 newman.behr.com:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1275 f2.63.85ae.static.theplanet.com:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1276 f2.63.85ae.static.theplanet.com:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1285 smtpgw2-na-chq.bs-fs.com:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1286 mail.global.frontbridge.com:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1287 turna.bcc.bilkent.edu.tr:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1288 mail.global.frontbridge.com:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1289 u23.altospam.com:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1290 deframx20.softcom.dk:smtp FIN_WAIT_1 408
[services.exe]
TCP MYSERVER:1279 barracuda.com:smtp CLOSING 408
[services.exe]
TCP MYSERVER:1280 mx01.perfora.net:smtp CLOSING 408
[services.exe]
TCP MYSERVER:1281 azshara.cbox.biz:smtp CLOSING 408
[services.exe]
TCP MYSERVER:1185 was1-mh202.smtproutes.com:smtp LAST_ACK 408
[services.exe]
TCP MYSERVER:1259 mtain-me.r1000.mx.aol.com:smtp LAST_ACK 408
[services.exe]
UDP MYSERVER:isakmp *:* 420
[lsass.exe]
UDP MYSERVER:microsoft-ds *:* 4
[System]
UDP MYSERVER:4500 *:* 420
[lsass.exe]
UDP MYSERVER:1060 *:* 780
[Smc.exe]
UDP MYSERVER:1048 *:* 360
[winlogon.exe]
UDP MYSERVER:ntp *:* 864
W32Time
[svchost.exe]
UDP MYSERVER:1026 *:* 420
[lsass.exe]
UDP MYSERVER:netbios-ns *:* 4
[System]
UDP MYSERVER:ntp *:* 864
W32Time
[svchost.exe]
UDP MYSERVER:netbios-dgm *:* 4
[System]
Troubleshooting Done
I removed the default gateway of the server and than checked the netstat –a –b –o and found that it was not connecting to any of the external SMTP.
I did a full scan of the server is SAFEMODE and it found a file named “bmosd.sys” which it detects as “HACKTOOL.ROOTKIT” and“ACTION-Cleaned”.
As soon as I configure the GATEWAY, It again generates the SMTP traffic and than slows down my server.
I have scanned the server using “McAfee Rootkit” which showed nothing releated to Rootkits.
I scanned the server using “MS-ROOTKITREVELAR” following are the logs.
I am unable to do online “ACTIVESCAN 2.0” from PANDA as it does not support Windows 2003.
Please help as I am totally stuck and I need this server to be up and running as soon as possible.