Re: Anyone know what "piiserviceO" is?

From: Frank Knobbe (fknobbe@knobbeits.com)
Date: 09/03/02


From: Frank Knobbe <fknobbe@knobbeits.com>
To: Amer Karim <amerk@telus.net>
Date: 03 Sep 2002 12:21:11 -0500

Smells like a trojan/backdoor. Have you run STRINGS over the binary to
see what it contains? Also, use FPORT to find out what port(s) it is
listening on and connect to it to see what kind of header you get (if
one at all).

Regards,
Frank

On Mon, 2002-09-02 at 13:11, Amer Karim wrote:
> Hi All,
>
> I was just doing some cleaning up on my home system (W2K Pro SP3) and I
> noticed this “piiserviceO” in the processes list. I found it in the
> registry under “HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run”, but I
> can’t find any info on it either at MSKB or via google searches. I’ve
> deleted the key and haven’t noticed any change in the systems behaviour, but
> I’d like to know what it is (or was)…
>
> I can’t find any files on the system named ‘piiserviceO’, or any variation
> thereof, and google gave me zero returns (a first) except for something
> called ‘psiservice’.
>
> TIA.
>
> Regards,
> Amer Karim
> Nautilis Information Systems
> e-mail: amerk@telus.net, mamerk@hotmail.com
>
>
>



Relevant Pages

  • Re: locale errors
    ... With regards to it being asked previously; ... I understand that the "noise" and/or extra bandwidth that I used in ... and more presice to my dilemma, then if I had gone through google. ... I apologize now for being a giant, swarthy, uncouth, american. ...
    (Debian-User)
  • To Shenan,
    ... to be put into check in regards to your comment about using Google. ... Google for information. ... > Geddy Lee wrote: ... > How much RAM does your BIOS/post screen tell you that you have? ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Idiot spam attack on sci.lang
    ... Since when has Google, or anyone, a right to censor anything? ... I'll quite happily set up a new instant Yahoo group to replace this ... one, but I won't be moderator, or accept any responsibility if it's ...
    (sci.lang)
  • Re: Idiot spam attack on sci.lang
    ... Since when has Google, or anyone, a right to censor anything? ... one, but I won't be moderator, or accept any responsibility if it's ... Sorry to add to my own reply, but Yahoo Groups allow you to ...
    (sci.lang)
  • Anyone know what "piiserviceO" is?
    ... I was just doing some cleaning up on my home system (W2K Pro SP3) and I ... can’t find any info on it either at MSKB or via google searches. ... I can’t find any files on the system named ‘piiserviceO’, ...
    (Focus-Microsoft)