Re: Strange services.exe file

From: Ansgar -59cobalt- Wiechers (bugtraq_at_planetcobalt.net)
Date: 12/10/03

  • Next message: Nick FitzGerald: "Re: Strange services.exe file"
    Date: Wed, 10 Dec 2003 17:09:30 +0100
    To: incidents@securityfocus.com
    
    

    On 2003-12-08 Dano wrote:
    > Hello, I came across a strange services.exe file in WinXP and don't
    > know how it got there. This services.exe landed in the root
    > c:\windows\services.exe with a hidden attrib flag set. There was also
    > a registry key set at HKLM/software/microsoft/windows/currentversion/run
    > with the value "services C:\WINDOWS\services.exe -i". What it appeared
    > to do was send data back to hosts dhcp-ve3-101.cable.amis.net
    > (212.18.53.101) and um-sd04-907.uni-mb.si (164.8.15.109). I'm stil in
    > progress of disecting this to find out what exactly it does.

    Probably the XTC worm (or a mutation of it).

    http://vil.nai.com/vil/content/v_98913.htm

    Regards
    Ansgar Wiechers

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Nick FitzGerald: "Re: Strange services.exe file"

    Relevant Pages

    • Re: WMP Library acting funny
      ... > My Windows Media Player 10's, yes I have WinXP, Library is acting a little ... > strange. ... I can add files from My Music folder but a couple of files that ...
      (microsoft.public.windowsxp.music)
    • Re: are there some special about x1a symbol
      ... into a file a string with the '\x1a' symbol, and for FreeBSD system, it ... but for my WinXP box, it gives some strange: ...
      (comp.lang.python)
    • WMP Library acting funny
      ... My Windows Media Player 10's, yes I have WinXP, Library is acting a little ... strange. ... I can add files from My Music folder but a couple of files that ...
      (microsoft.public.windowsxp.music)
    • Runtime error 2046
      ... I am using Access 2000 on WinXP. ... Something strange on my database.... ... When I click debug, the code has stopped at this line: ... Prev by Date: ...
      (microsoft.public.access.formscoding)
    • Re: Shoe thrown at Bush
      ... Yeah, even for Dano, this is pretty strange. ... said - was what he found funny about this incident. ...
      (alt.sports.baseball.bos-redsox)