mhack
2006-10-20, 07:16
Hi, I am wondering if my system is infected with a rootkit. The reason is because I have downloaded Spybot-S&D 1.4, got the latest updates, did a scan and it found some spyware that it cleaned up (Pipas.A among others). Subsequent scans showed nothing. However, my initial problem remained (I do development work with mingw and it's not working properly). So I've been downloading other software, including some rootkit detectors. The Sophos Antirootkit did a scan and reported a number of hidden registry entries and files that I cannot view with Windows Explorer or a DOS box (using the 'show all' option). I believe that some of these hidden files are definitely spyware. The three in my \windows\system32 dir are pppcgm.exe, howiper.exe and kilacln.exe.
At this point, I'm not concerned with removing these spyware programs. What I want to understand is what is preventing me from viewing these files. I suspect that it is a rootkit that is trying to 'protect' various spyware files by hiding them.
I tried another rootkit detector, 'rootkit revealer' from Sysinternals, but it found nothing. So far, only the Sophos Antirootkit ver 1.1 has revealed them.
Below is my HijackThis log. Note: I know that my Windows system files are not up-to-date. I have specifically disabled all Windows updates and will keep it that way, because I would rather learn how to patch the system on my own instead of being helpless and depending on Microsoft.
--------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 10:13:58 PM, on 10/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\TpShocks.exe
C:\net\umt\vpnclient\cvpnd.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\os\sophos-antirootkit\sargui.exe
C:\net\firefox\firefox.exe
C:\install\virus\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O11 - Options group: [JAVA_IBM] Java (IBM)
O20 - AppInit_DLLs: C:\WINDOWS\system32\wmfhotfix.dll
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\net\umt\vpnclient\cvpnd.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
At this point, I'm not concerned with removing these spyware programs. What I want to understand is what is preventing me from viewing these files. I suspect that it is a rootkit that is trying to 'protect' various spyware files by hiding them.
I tried another rootkit detector, 'rootkit revealer' from Sysinternals, but it found nothing. So far, only the Sophos Antirootkit ver 1.1 has revealed them.
Below is my HijackThis log. Note: I know that my Windows system files are not up-to-date. I have specifically disabled all Windows updates and will keep it that way, because I would rather learn how to patch the system on my own instead of being helpless and depending on Microsoft.
--------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 10:13:58 PM, on 10/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\TpShocks.exe
C:\net\umt\vpnclient\cvpnd.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\os\sophos-antirootkit\sargui.exe
C:\net\firefox\firefox.exe
C:\install\virus\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O11 - Options group: [JAVA_IBM] Java (IBM)
O20 - AppInit_DLLs: C:\WINDOWS\system32\wmfhotfix.dll
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\net\umt\vpnclient\cvpnd.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe