Noticed problem earlier this week while trying to install new software on the server. Upon installation everything is fine, but the moment a service associated with the new software is started the executable file deletes itself. Wasn't sure what to make of this at first random error or something wrong with the software but on further inspection this began to occur with multiple applications seemingly for no apparent reason. Currently running Kav for win2k3 server on the box, but it finds nothing. Tried rootkit detectors such as icesword, and Blacklight from f-secure... Still nothing, was about to give up and give it off to just me being over curious but ran an external scan of open ports on the pc. Port 7214 appears open and when queried is running a version of servu FTP server with implicit SSL enabled. Since no rootkit was detected I proceeded to believe a dll must be injected somewhere... Checked with tcpview to find what proc was listening on that port but no results. Used proc explorer to inspect various dlls loaded by system procs such as services.exe, winlogon.exe, etc still no luck. Anyone have some ideas? Possible solutions I can try?
Edit: Here's a HJT log... Don't think it'll help much tho :X
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:26:26, on 20-1-2008
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 SP2 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe
c:\ftpservs\Ftpserv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\rdpcli
p.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe
C:\WINDOWS\system32\wuaucl
t.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Loc
al Settings\Temporary Internet Files\Content.IE5\AEE3V7RB
\HiJackThi
s[1].exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = res://shdoclc.dll/softAdmi
n.htm
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page = res://shdoclc.dll/softAdmi
n.htm
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,First Home Page = res://shdoclc.dll/softAdmi
n.htm
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
pgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
pgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
pgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
pgrd.exe (User 'Default user')
O15 - ESC Trusted Zone:
http://runonce.msn.comO16 - DPF: {26700CD9-6157-4B72-B46F-E
C93C952F19
C} (SWToolSet.Engine) -
http://10.0.50.2/SWToolset.exeO23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe
O23 - Service: AutoFtp Service (TFtpserv) - PrimaSoft PC, Inc. - c:\ftpservs\Ftpserv.exe
Start Free Trial