hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Dedicated Server : How to remove "hscan.exe"
Reply

Dedicated Server Current and past experiences with dedicated server providers, bandwidth, and server performance. Review managed and unmanaged dedicated web servers, discuss both Windows and Unix dedicated server solutions, and discuss dedicated hosting providers. If your service is unavailable, please click here.
Forum Jump

How to remove "hscan.exe"

Reply Post New Thread In Dedicated Server Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 07-05-2005, 12:00 PM
anilktm anilktm is offline
Newbie
 
Join Date: Jun 2005
Posts: 8

How to remove "hscan.exe"


Hello,

I have a Server with EV1 and yesterday I got one Abuse mail from them that my Server is Compromised.

I have checked the current running programs through Taskmanager and I can find that "Hscan.exe" is running on my Server.

I have stopped it and again it will come. After that EV1 support people remove it from registery.

But now today that hscan.exe is running.

So Please tell me how to remove this "hscan.exe" from my Server??

Expecting everybodys reply.

Anilktm

Reply With Quote


Sponsored Links
  #2  
Old 07-05-2005, 12:17 PM
Steven Steven is online now
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,625
Sounds like you are running windows and you are hacked. Most likely though an unpatched exploit. My suggestion is getting a reload and securing the server properly the first time.

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
  #3  
Old 07-05-2005, 12:28 PM
anilktm anilktm is offline
Newbie
 
Join Date: Jun 2005
Posts: 8
Can anybody help me how to remove this hscan.exe from my Win Server.

Aniktms

Reply With Quote
Sponsored Links
  #4  
Old 07-05-2005, 12:34 PM
sirius sirius is offline
Community Liaison 2.0
 
Join Date: Nov 2002
Location: WebHostingTalk
Posts: 8,674
Quote:
Originally posted by anilktm
Can anybody help me how to remove this hscan.exe from my Win Server.

Aniktms
You got the best answer you're going to get from thelinuxguy... he knows his stuff.

Sirius

__________________
I support the Human Rights Campaign!
New Port Richey Chiropractor
Trinity Chiropractor

Reply With Quote
  #5  
Old 07-05-2005, 12:45 PM
dollar dollar is offline
Retired Moderator
 
Join Date: Sep 2004
Location: Flint, Michigan
Posts: 5,768
Quote:
Originally posted by anilktm
Can anybody help me how to remove this hscan.exe from my Win Server.

Aniktms
Right click on the file and delete it

In all seriousness, your server has been compromised, the only way to fix your problem is to have a fresh OS image put on the machine, otherwise you will be back here in another two weeks asking the same question again.

__________________
Mike from Zoodia.com
Professional web design and development services.
In need of a fresh hosting design? See what premade designs we have in stock!
Web design tips, tricks, and more at MichaelPruitt.com

Reply With Quote
  #6  
Old 07-05-2005, 12:54 PM
anilktm anilktm is offline
Newbie
 
Join Date: Jun 2005
Posts: 8
Thanks everybodys reply.

I think this is the fault of EV1 right?

If so, then why they are not suggest me to reload with new OS. They asked me to hire a Good Server Admin for trouble shooting this. They are providing only UNmanaged Servers. I think this is some business relation between EV1 & Server Admins...

Reply With Quote
  #7  
Old 07-05-2005, 12:56 PM
dollar dollar is offline
Retired Moderator
 
Join Date: Sep 2004
Location: Flint, Michigan
Posts: 5,768
This is your fault for not securing your server.

If you don't lock the door to your house at night and a person breaks in, you don't blame the people that built your door do you?

This is no business between EV1 and server admins.

EV1 offers unmanaged servers, meaning security and updates are supposed to be taken care of by you in some way or another. Either you need to be on top of it, or you need to hire somebody else to take care of it. If you want the company you purchase your machine from to do this for you, you should be purchasing a "managed" server which will cost more.

You really should have done more reasearch before purchasing a machine =/

__________________
Mike from Zoodia.com
Professional web design and development services.
In need of a fresh hosting design? See what premade designs we have in stock!
Web design tips, tricks, and more at MichaelPruitt.com

Reply With Quote
  #8  
Old 07-05-2005, 01:11 PM
sirius sirius is offline
Community Liaison 2.0
 
Join Date: Nov 2002
Location: WebHostingTalk
Posts: 8,674
Quote:
Originally posted by anilktm
Thanks everybodys reply.

I think this is the fault of EV1 right?

If so, then why they are not suggest me to reload with new OS. They asked me to hire a Good Server Admin for trouble shooting this. They are providing only UNmanaged Servers. I think this is some business relation between EV1 & Server Admins...
Nada. You're playing with big boy toys now... and with that, comes responsibility.

You are responsible for your data and keeping it secure. EV1 is there to ensure that you server hardware is available and that the network is available. You are responsible for everything else.

Like has been said, get an OS reload and have a professional secure your server.

Sirius

__________________
I support the Human Rights Campaign!
New Port Richey Chiropractor
Trinity Chiropractor

Reply With Quote
  #9  
Old 07-05-2005, 01:21 PM
sprintserve sprintserve is offline
Retired Moderator
 
Join Date: Jan 2003
Posts: 9,000
For Windows, it's actually easier to clean out of trojans than Linux. I have done both and windows is no doubt easier. The fact that Windows is closed sourced is a blessing. It is actually possible to clean out a Windows system from most common trojans.

If you want, i can see if I can remove the backdoor for you. My 4th July good deed : )

__________________
••• 100% Customer Satisfaction!!! •••
••• http://www.sprintserve.net •••
••• Offering: | Internap FCP Bandwidth! | Rebootless Kernel Updates! | Magento Optimized Hosting | •••
••• Services: | Managed Multiple Cores 64bit Servers | Server Management | •••

Reply With Quote
  #10  
Old 07-05-2005, 02:06 PM
sirius sirius is offline
Community Liaison 2.0
 
Join Date: Nov 2002
Location: WebHostingTalk
Posts: 8,674
Quote:
Originally posted by sprintserve
If you want, i can see if I can remove the backdoor for you. My 4th July good deed : )
Although a good deed, you are leaving the thread starter open to further attacks. By providing a band aid (removing the trojan) the thread starter is likely going to do nothing else and will just be compromised again.

My .02

Sirius

P.S. Never let a good deed go unpunished.

__________________
I support the Human Rights Campaign!
New Port Richey Chiropractor
Trinity Chiropractor

Reply With Quote
  #11  
Old 07-05-2005, 02:46 PM
Stacie Stacie is offline
Aspiring Evangelist
 
Join Date: Jun 2004
Posts: 372

__________________
All My Data » From small shared web hosting accounts to powerful dedicated servers.
Now offering Affordable UNIX shells and IRCd hosting!

Reply With Quote
  #12  
Old 07-05-2005, 02:52 PM
dkitchen dkitchen is offline
Managed Hosting Expert
 
Join Date: Jan 2004
Location: North Yorkshire, UK
Posts: 4,163
Either get the box completely reloaded, or hire a professional Windows admin to fix the box for you.

I have to second what sprintserve said, it is pretty easy to clear a Windows exploit if you know what you're doing, as there is really nowhere for it to hide...

You should remember though that server security is an ongoing thing, and if you don't know what you're doing yourself, hire someone professional to do it for you - or this will happen again and again...

__________________
█ Dan Kitchen | Technical Director | Razorblue
█ ddi: (+44) (0)1748 900 680 | e: dkitchen@razorblue.com
█ UK Intensive Managed Hosting, Clusters and Colocation.
█ HP Servers, Cisco/Juniper Powered BGP Network (AS15692).


Reply With Quote
  #13  
Old 07-05-2005, 02:55 PM
Steven Steven is online now
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,625
there are rootkits for windows to hide things.

http://www.securityfocus.com/news/2879

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
  #14  
Old 07-06-2005, 04:14 AM
nadtz nadtz is offline
Web Hosting Guru
 
Join Date: Feb 2005
Posts: 334
depends on the exploit. I've seen some that were a right pain to remove.

Reply With Quote
  #15  
Old 07-06-2005, 04:36 AM
TDMWeb TDMWeb is offline
Web Hosting Evangelist
 
Join Date: Mar 2002
Location: UK
Posts: 458
Whether it is cheaper for you to have an OS reinstall and re-add all of your data, or to hire a professional experienced in removing Windows "malware", depends on how easy it will be to re-add all your data and how much this costs you in revenue etc.

This chap knows a lot about Win malware removal: www.blong.com (but he operates commercially).

__________________
Chris at TDMWeb.com
Windows & Linux hosting and fully managed dedicated servers with great customer service!
UK-based but serving the world...

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Important changes to WHIR Networking Events Europe schedule Blog 2013-04-15 16:00:16
International Skype Traffic Grew 44 Percent in 2012: TeleGeography Report Web Hosting News 2013-02-13 14:27:20
White House Opposes SOPA and PIPA, SOPA Vote Delayed Web Hosting News 2012-01-16 14:10:31
Bit lockers and the DMCA Blog 2011-12-15 17:14:36
Web Host Rackspace Launches Private Beta for MySQL Cloud Database Web Hosting News 2011-12-01 21:09:51


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?