Last night I notice a file on my desktop called Oblt-log.log then I look in my ftp folder and saw two folders k 50091 an t 64044 I try to delete them an says cannot read from source disk right click on the folders / properties and have no security tab The log file on the desk top has this to say
Created domain group: _Web Anonymous Users Added user 'IUSR_SERVER-001' to domain group '_Web Anonymous Users'. Created domain group: _Web Applications Added user 'IWAM_SERVER-001' to domain group '_Web Applications'. IUSER=501,5000000,15,4c022957,5274c742,3f32a78a,453, IWAM=501,5000000,15,4c022957,5274c742,3f32a78a,454, Service smtpsvc, Automatic to Disabled Service msftpsvc, Automatic to Disabled Backed up metabase DenyACE<0(0 20),,>C:\WINNT\system32\inetsrv\httpext.dll ACE C:\WINNT\system32\inetsrv\httpext.dll DenyACE<0(0 20),,>C:\WINNT\system32\idq.dll ACE C:\WINNT\system32\idq.dll Disabled Internet Printing Installed URLScan
and the rest of the file has DenyACE in front following lines of services that are running
PLEASE ADVISE
This conversation is currently closed to new comments.
to find out if you are hacked please download and run in this order: adaware6.0 from lavasoft, spybot search and destroy from www.security.kolla.de and hijackthis from www.tomcoyote.org/hjt . careful on running hijackthis for this list everything running on your computer.
If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.
Am I hack
Created domain group: _Web Anonymous Users
Added user 'IUSR_SERVER-001' to domain group '_Web Anonymous Users'.
Created domain group: _Web Applications
Added user 'IWAM_SERVER-001' to domain group '_Web Applications'.
IUSER=501,5000000,15,4c022957,5274c742,3f32a78a,453, IWAM=501,5000000,15,4c022957,5274c742,3f32a78a,454,
Service smtpsvc, Automatic to Disabled
Service msftpsvc, Automatic to Disabled
Backed up metabase
DenyACE<0(0 20),,>C:\WINNT\system32\inetsrv\httpext.dll
ACE C:\WINNT\system32\inetsrv\httpext.dll
DenyACE<0(0 20),,>C:\WINNT\system32\idq.dll
ACE C:\WINNT\system32\idq.dll
Disabled Internet Printing
Installed URLScan
and the rest of the file has DenyACE in front following lines of services that are running
PLEASE ADVISE