Re: Anyone know what "piiserviceO" is?
From: H C (keydet89@yahoo.com)Date: 09/03/02
- Previous message: Kyle Davis: "RE: IUSR_machinename"
- In reply to: Amer Karim: "Anyone know what "piiserviceO" is?"
- Next in thread: Amer Karim: "RE: Anyone know what "piiserviceO" is?"
- Reply: Amer Karim: "RE: Anyone know what "piiserviceO" is?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 3 Sep 2002 10:56:47 -0700 (PDT) From: H C <keydet89@yahoo.com> To: Amer Karim <amerk@telus.net>, Focus on Microsoft Mailing List <FOCUS-MS@SECURITYFOCUS.COM>
Amer,
> I was just doing some cleaning up on my home system
> (W2K Pro SP3) and I
> noticed this ?piiserviceO? in the processes list. I
> found it in the
> registry under
>
?HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run?,
> but I
> can?t find any info on it either at MSKB or via
> google searches. I?ve
> deleted the key and haven?t noticed any change in
> the systems behaviour, but
> I?d like to know what it is (or was)?
As with other cases like this..."I got rid of it but
now I want to know what it was"...there are a lot more
questions than answers:
1. What was the full entry to the Registry key? Was
there a path to the process image (ie, executable
file)?
2. Did you happen to run pslist.exe, handle.exe,
listdlls.exe (from SysInternals), and fport.exe (from
FoundStone) to gather any information about the
process? Handle.exe and listdlls.exe provide such
information as the process owner, full image path,
command line, and which modules (DLLs) are in use.
3. You mentioned that you searched for a file by that
name, but didn't find anything...how did you conduct
your search? By hand, or by using the Find
capability? Or did you search by the path that you
found in the Registry?
I've recommended the steps in #2 above to the list
before, in order for folks to gather more information
regarding the incident.
If you do end up finding a copy of the file on your
system, I'd greatly appreciate a zipped up copy of it
for review.
HTH,
Carv
__________________________________________________
Do You Yahoo!?
Yahoo! Finance - Get real-time stock quotes
http://finance.yahoo.com
- Previous message: Kyle Davis: "RE: IUSR_machinename"
- In reply to: Amer Karim: "Anyone know what "piiserviceO" is?"
- Next in thread: Amer Karim: "RE: Anyone know what "piiserviceO" is?"
- Reply: Amer Karim: "RE: Anyone know what "piiserviceO" is?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|