Security Incidents mailing list archives
Re: Strange services.exe file
From: Harlan Carvey <keydet89 () yahoo com>
Date: Thu, 11 Dec 2003 05:46:29 -0800 (PST)
Ansgar, Unfortunately, there seem to be responses to this post for every bit of malware that uses the name service.exe or services.exe. A couple of things come to mind...the first of which is, what about the '-i' switch. Second, I'm going to assume that the original poster (OP) corresponded the executable to the destination IP addresses using fport.exe...but it would be nice to see more info, like the actual output of fport, as well as tlist/pslist/listdlls/handle, etc. Also, maybe a copy of the executable (zipped up, of course). --- Ansgar -59cobalt- Wiechers <bugtraq () planetcobalt net> wrote:
On 2003-12-08 Dano wrote:Hello, I came across a strange services.exe filein WinXP and don'tknow how it got there. This services.exe landed inthe rootc:\windows\services.exe with a hidden attrib flagset. There was alsoa registry key set atHKLM/software/microsoft/windows/currentversion/runwith the value "services C:\WINDOWS\services.exe-i". What it appearedto do was send data back to hostsdhcp-ve3-101.cable.amis.net(212.18.53.101) and um-sd04-907.uni-mb.si(164.8.15.109). I'm stil inprogress of disecting this to find out whatexactly it does. Probably the XTC worm (or a mutation of it). http://vil.nai.com/vil/content/v_98913.htm Regards Ansgar Wiechers
---------------------------------------------------------------------------
----------------------------------------------------------------------------
--------------------------------------------------------------------------- ----------------------------------------------------------------------------
Current thread:
- Strange services.exe file Dano (Dec 09)
- Re: Strange services.exe file Harlan Carvey (Dec 10)
- Re: Strange services.exe file Nick FitzGerald (Dec 10)
- Re: Strange services.exe file Tomasz Papszun (Dec 11)
- Re: [mailinglists] Strange services.exe file Tom Wright (Dec 10)
- Re: Strange services.exe file Ansgar -59cobalt- Wiechers (Dec 10)
- Re: Strange services.exe file Nick FitzGerald (Dec 11)
- Re: Strange services.exe file Harlan Carvey (Dec 11)
- Re: Strange services.exe file Harlan Carvey (Dec 11)
- Re: Strange services.exe file Nick FitzGerald (Dec 11)
- <Possible follow-ups>
- RE: Strange services.exe file Josh.Berry (Dec 10)
- RE: Strange services.exe file Harlan Carvey (Dec 11)
- Re: Strange services.exe file jdavison3 (Dec 10)
- Re: Strange services.exe file Nick FitzGerald (Dec 11)
- Re: Strange services.exe file Harlan Carvey (Dec 11)