servicepack2.exe - trojan?

From: Carol Chisholm (carol.lists_at_smalldomain.ch)
Date: 08/27/04


Date: Fri, 27 Aug 2004 20:46:07 +0200

I've a laptop with a mysterious servicepack2.exe service which I
cannot get rid of.
It's not signed by anyone, and sits in the system32 directory.
It re-installs on every reboot, when the computer is connected to the
internet.
It may be associated with an unwanted autostarting Internet Explorer
trying to install a Hot-SeXXX toolbar.

I've tried Ad-aware, updated McAfee, run stinger, turned off System
Restore, deleted everything from the run, run once and services keys
in the registry. I've deleted the executable after terminating the
service and still it comes back.
The machine is running XP SP2, and this has survived the SP2 install.
It seems to be able to disables Windows firewall, or install itself as
an exception in Windows Firewall. Zone Alarm seems to get bypassed
somehow.
Any ideas?



Relevant Pages

  • Re: servicepack2.exe - trojan?
    ... | It may be associated with an unwanted autostarting Internet Explorer ... | The machine is running XP SP2, and this has survived the SP2 install. ... | It seems to be able to disables Windows firewall, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: installing MFC71.dll, msvcr71.dll, and msvcp71.dll in system32
    ... It is not recommended and it is not supported to install 7.1 redistributable ... Dlls to System32. ... redistributing these libraries. ... > If MFC42.dll and friends are installed in the system32 directory, ...
    (microsoft.public.vc.mfc)
  • Re: System shuts down while loading.
    ... Use the Windows Recovery Console if you have no other ... from the CD to the system32 directory. ... > PLEASE ANYONE WHO HAS THE SAME PROBLEM, TRY TO REVERT YOUR COMPUTER ... > DO NOT INSTALL THE SECURITY UPDATES. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Shell Functions and DOS executables
    ... System32 directory. ... exactly which package is used to install this, but I'll look around and see ... to post a new topic asking what you need to install to get that file. ... Hi Lance, ...
    (microsoft.public.vb.general.discussion)
  • Re: How do I re-install COMM.DRV
    ... >system32 directory: COMM.DRV ... install those by recovering them from the ... C:/Windows/system folder, but COMM.DRV is not in that ...
    (microsoft.public.windowsxp.perform_maintain)

Quantcast