I'm ivestigating on a problem.
I've found a running exe on my pc, located in C:\WINDOWS\Temp\ylpf1.exe
I removed it, but after a day it was there.
So I removed it one more time and raplaced it with a ylpf1.exe of 0kb (read-only). After another day I found a ylpf2.exe. Trying to understand the problem I've discovered a new user on my pc with name RHM and I removed it.
I'm not able to understand what is the vulnerability exploited.
By now I'm looking at C:\WINDOWS\TEMP with FileMon.exe (FileSystem access monitor) and on the LAN with Ethereal trying to figure out what happens.
With Ethereal I've noticed a strange behaviour that could be related to the problem, when I open the browser (MS Explorer), periodically it seraches to download WinHound.exe. I've attached the capture log.
I have XP SP2 and firewall on the lan that stops netbios, rpc and ports under 1024. I use Emule leatest version, I have Google toolbar installed, and Microsoft Messenger.
I've checked the system with Hijack (see the logfile attached) and Spyboat and it is clean.
Please, help me to understand!
Thanks,
Mattia
---- Ethereal Capture --------------------------------------------
(ip.addr eq 192.168.1.33 and ip.addr eq 207.226.160.3)
and (tcp.port eq 4030 and tcp.port eq 80)
GET /WinHoundInstaller.exe HTTP/1.1
User-Agent: Mozilla/4.0
Host: download.winhound.com
HTTP/1.1 500 Internal Error
Server: thttpd/2.21b-p36c 15jul2005
Content-Type: text/html
Date: Sat, 19 Aug 2006 20:48:45 GMT
Last-Modified: Sat, 19 Aug 2006 20:48:45 GMT
Accept-Ranges: bytes
Connection: close
<HTML>
<HEAD><TITLE>500 Internal Error</TITLE></HEAD>
<BODY BGCOLOR="#cc9999" TEXT="#000000" LINK="#2020ff" VLINK="#4040cc">
<H2>500 Internal Error</H2>
There was an unusual problem serving the requested URL '/WinHoundInstaller.exe'.
<HR>
<ADDRESS>thttpd/2.21b-p36c 15jul2005</ADDRESS>
</BODY>
</HTML>
---- Hijack Log --------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 23.09.02, on 19/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\lexpps.exe
C:\Programmi\eMule\emule.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program_Installer\Filemon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Programmi\Ethereal\ethereal.exe
C:\Programmi\Ethereal\ethereal.exe
C:\Programmi\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programmi\eMule\emule.exe -AutoStart
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programmi\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Unknown owner - C:\Programmi\iPod\bin\iPodService.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)