Re: Strange services.exe file

From: Harlan Carvey (keydet89_at_yahoo.com)
Date: 12/10/03

  • Next message: Josh.Berry_at_compucom.com: "RE: Strange services.exe file"
    Date: Wed, 10 Dec 2003 04:33:23 -0800 (PST)
    To: incidents@securityfocus.com
    
    

    > Hello, I came across a strange services.exe file in
    > WinXP and don't know
    > how it got there. This services.exe landed in the
    > root
    > c:\windows\services.exe with a hidden attrib flag
    > set. There was also a
    > registry key set at
    > HKLM/software/microsoft/windows/currentversion/run
    > with the value "services C:\WINDOWS\services.exe
    > -i". What it appeared to
    > do was send data back to hosts
    > dhcp-ve3-101.cable.amis.net
    > (212.18.53.101) and um-sd04-907.uni-mb.si
    > (164.8.15.109).

    Did a Google search, or search of A/V sites turn up
    anything?

    > I'm stil in
    > progress of disecting this to find out what exactly
    > it does.

    Well, a couple of ways to do that would be to run
    openports.exe, dump the process memory and run
    strings, and use Dependancy Walker on the executable.

    > Does anyone know anything about this?

    Can you provide a copy of it, zipped up?

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Josh.Berry_at_compucom.com: "RE: Strange services.exe file"

    Relevant Pages

    • Strange services.exe file
      ... I came across a strange services.exe file in WinXP and don't know ... This services.exe landed in the root ... c:\windows\services.exe with a hidden attrib flag set. ...
      (Incidents)
    • [SLE] KDE 3.4 Arts FIX (Solved)
      ... I found this from a Google search: ... edit (as root) the file: ... For additional commands send e-mail to suse-linux-e-help@suse.com ...
      (SuSE)
    • Disable macros
      ... Excel 2002, WinXP ... I am opening a file with VBA and I want to open it with macros disabled. ... Google search of this subject gave me the following statement: ...
      (microsoft.public.excel.programming)
    • Re: Writing data to DVDRW using Windowx XP SP3
      ... and burns Dvd's. ... Do a google search and download. ... WinXP by itself does not ...
      (microsoft.public.windowsxp.general)
    • Re: How do you view all files in finder?
      ... Robert Peirce wrote: ... need to set it up for root whose home is in a hidden folder. ... after doing a google search for "finder view all files" ...
      (comp.sys.mac.misc)