Strange services.exe file
From: Dano (dan_at_thejamzone.com)
Date: 12/08/03
- Previous message: Ross Lettau: "RE: forcdos.exe = serv-u...."
- Next in thread: Harlan Carvey: "Re: Strange services.exe file"
- Reply: Harlan Carvey: "Re: Strange services.exe file"
- Maybe reply: Josh.Berry_at_compucom.com: "RE: Strange services.exe file"
- Reply: Nick FitzGerald: "Re: Strange services.exe file"
- Reply: Tom Wright: "Re: [mailinglists] Strange services.exe file"
- Maybe reply: jdavison3_at_cox.net: "Re: Strange services.exe file"
- Reply: Ansgar -59cobalt- Wiechers: "Re: Strange services.exe file"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 8 Dec 2003 14:40:10 -0800 (PST) To: incidents@securityfocus.com
Hello, I came across a strange services.exe file in WinXP and don't know
how it got there. This services.exe landed in the root
c:\windows\services.exe with a hidden attrib flag set. There was also a
registry key set at HKLM/software/microsoft/windows/currentversion/run
with the value "services C:\WINDOWS\services.exe -i". What it appeared to
do was send data back to hosts dhcp-ve3-101.cable.amis.net
(212.18.53.101) and um-sd04-907.uni-mb.si (164.8.15.109). I'm stil in
progress of disecting this to find out what exactly it does. Does anyone
know anything about this?
Thanks
Dan
---------------------------------------------------------------------------
----------------------------------------------------------------------------
- Previous message: Ross Lettau: "RE: forcdos.exe = serv-u...."
- Next in thread: Harlan Carvey: "Re: Strange services.exe file"
- Reply: Harlan Carvey: "Re: Strange services.exe file"
- Maybe reply: Josh.Berry_at_compucom.com: "RE: Strange services.exe file"
- Reply: Nick FitzGerald: "Re: Strange services.exe file"
- Reply: Tom Wright: "Re: [mailinglists] Strange services.exe file"
- Maybe reply: jdavison3_at_cox.net: "Re: Strange services.exe file"
- Reply: Ansgar -59cobalt- Wiechers: "Re: Strange services.exe file"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|