Re: Strange services.exe file

From: Ansgar -59cobalt- Wiechers (bugtraq_at_planetcobalt.net)
Date: 12/10/03

  • Next message: Nick FitzGerald: "Re: Strange services.exe file"
    Date: Wed, 10 Dec 2003 17:09:30 +0100
    To: incidents@securityfocus.com
    
    

    On 2003-12-08 Dano wrote:
    > Hello, I came across a strange services.exe file in WinXP and don't
    > know how it got there. This services.exe landed in the root
    > c:\windows\services.exe with a hidden attrib flag set. There was also
    > a registry key set at HKLM/software/microsoft/windows/currentversion/run
    > with the value "services C:\WINDOWS\services.exe -i". What it appeared
    > to do was send data back to hosts dhcp-ve3-101.cable.amis.net
    > (212.18.53.101) and um-sd04-907.uni-mb.si (164.8.15.109). I'm stil in
    > progress of disecting this to find out what exactly it does.

    Probably the XTC worm (or a mutation of it).

    http://vil.nai.com/vil/content/v_98913.htm

    Regards
    Ansgar Wiechers

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Nick FitzGerald: "Re: Strange services.exe file"

    Relevant Pages

    • Re: WMP Library acting funny
      ... > My Windows Media Player 10's, yes I have WinXP, Library is acting a little ... > strange. ... I can add files from My Music folder but a couple of files that ...
      (microsoft.public.windowsxp.music)
    • WMP Library acting funny
      ... My Windows Media Player 10's, yes I have WinXP, Library is acting a little ... strange. ... I can add files from My Music folder but a couple of files that ...
      (microsoft.public.windowsxp.music)
    • Runtime error 2046
      ... I am using Access 2000 on WinXP. ... Something strange on my database.... ... When I click debug, the code has stopped at this line: ... Prev by Date: ...
      (microsoft.public.access.formscoding)
    • Re: Xp firewall blocking web-desktop
      ... Thx for the solution. ... But strange that winxp didn't fix ...
      (microsoft.public.windowsxp.work_remotely)
    • Re: Kerio firewall - how do you get rid of it?
      ... >WinXP. ... Doh! ... Something very strange is going on here..... ... "Democracy is a form of religion, it is the worship of jackals by jackasses." ...
      (comp.security.firewalls)