mystery services found on my xp pro machine


Go Back   Computer Help Articles > Windows XP Security Admin
User Name
Password
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-05-2006, 05:43 AM
d. bennett
 
Posts: n/a
Default mystery services found on my xp pro machine

I found the following services in my Services.msc snap-in:

NJND
PEFEJJ
JIEHGOWNLWY
EGW
NOVAVFKT

I have disabled all of them and deleted the files (all the files where
located in my user temp directory)...

Does anyone know what these are? I have searched all the sites I know for
info to see if they are viruses but I haven't found anything... My virus
scan doesn't report anything (I've made sure I'm updated) and I can't find
them listed as viruses on any sites (MS or Norton).

-d
Reply With Quote
  #2  
Old 01-05-2006, 05:43 AM
Wesley Vogel
 
Posts: n/a
Default Re: mystery services found on my xp pro machine

If you have used RootkitRevealer, it adds a random named *.exe file and a
random named service and runs as that service. The random named *.exe file
will show up in %homepath%\Local Settings\Temp folder. Every time you run
RootkitRevealer it adds another random service to services.msc. The
randomly named *.exe file will be deleted, but the registry settings are
left behind.

[[The reason that there is no longer a command-line version is that malware
authors have started targeting RootkitRevealer's scan by using its
executable name. We've therefore updated RootkitRevealer to execute its scan
from a randomly named copy of itself that runs as a Windows service.]]
http://www.sysinternals.com/Utilitie...tRevealer.html

RootkitRevealer leaves references to these random named *.exe files behind
so that you see strange service names in services.msc.

You'll find the left behind services here...

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es

Locate the service(s) in the list. ImagePath should point to
Local Settings\Temp folder, as a double check.

Delete them and reboot.

[[Important This article contains information about modifying the registry.
Before you modify the registry, make sure to back it up and make sure that
you understand how to restore the registry if a problem occurs. For
information about how to back up, restore, and edit the registry, click the
following article number to view the article in the Microsoft Knowledge
Base: 256986 Description of the Microsoft Windows Registry]]
http://support.microsoft.com/default.aspx?kbid=256986

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In news:B2BF3D67-D751-4537-B0E7-B2D158152F41@microsoft.com,
d. bennett <d. bennett@discussions.microsoft.com> hunted and pecked:
> I found the following services in my Services.msc snap-in:
>
> NJND
> PEFEJJ
> JIEHGOWNLWY
> EGW
> NOVAVFKT
>
> I have disabled all of them and deleted the files (all the files where
> located in my user temp directory)...
>
> Does anyone know what these are? I have searched all the sites I know for
> info to see if they are viruses but I haven't found anything... My virus
> scan doesn't report anything (I've made sure I'm updated) and I can't find
> them listed as viruses on any sites (MS or Norton).
>
> -d


Reply With Quote
  #3  
Old 01-05-2006, 05:43 AM
Mike Fields
 
Posts: n/a
Default Re: mystery services found on my xp pro machine


"d. bennett" <d. bennett@discussions.microsoft.com> wrote in message
news:B2BF3D67-D751-4537-B0E7-B2D158152F41@microsoft.com...
> I found the following services in my Services.msc snap-in:
>
> NJND
> PEFEJJ
> JIEHGOWNLWY
> EGW
> NOVAVFKT
>
> I have disabled all of them and deleted the files (all the files where
> located in my user temp directory)...
>
> Does anyone know what these are? I have searched all the sites I know

for
> info to see if they are viruses but I haven't found anything... My

virus
> scan doesn't report anything (I've made sure I'm updated) and I can't

find
> them listed as viruses on any sites (MS or Norton).
>
> -d


Generally when you find something like that that has either none
or a couple of hits on google, you have one of my favorites that
start a clone of themselves at start time with a random combination
of letters/numbers etc so if you find it, all you did was get the
current copy not the real one that is lurking. Try snooping with
Hijackthis and see what you find that is getting started. Be
vewy vewy vewy suspicious of things that get started from the
temp folders. Also, try doing this in safe mode - there are a
number of "thingies" out there that can mask themselves when
running normally. Also run Adaware and Spybot to see what
they pick up.

mikey

Reply With Quote
  #4  
Old 01-05-2006, 05:43 AM
David H. Lipman
 
Posts: n/a
Default Re: mystery services found on my xp pro machine

From: "d. bennett" <d. bennett@discussions.microsoft.com>

| I found the following services in my Services.msc snap-in:
|
| NJND
| PEFEJJ
| JIEHGOWNLWY
| EGW
| NOVAVFKT
|
| I have disabled all of them and deleted the files (all the files where
| located in my user temp directory)...
|
| Does anyone know what these are? I have searched all the sites I know for
| info to see if they are viruses but I haven't found anything... My virus
| scan doesn't report anything (I've made sure I'm updated) and I can't find
| them listed as viruses on any sites (MS or Norton).
|
| -d


I hope you ran the following commands...

sc delete NJND
sc delete PEFEJJ
sc delete JIEHGOWNLWY
sc delete EGW
sc delete NOVAVFKT

I suggest you perform the following ASAP !

Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Reply With Quote
  #5  
Old 01-05-2006, 05:43 AM
d. bennett
 
Posts: n/a
Default Re: mystery services found on my xp pro machine

Thanks Wesley... Yes I had run RootkitRevealer but had failed to fully read
the docs...

thanks for the links and info.

-d

"Wesley Vogel" wrote:

> If you have used RootkitRevealer, it adds a random named *.exe file and a
> random named service and runs as that service. The random named *.exe file
> will show up in %homepath%\Local Settings\Temp folder. Every time you run
> RootkitRevealer it adds another random service to services.msc. The
> randomly named *.exe file will be deleted, but the registry settings are
> left behind.
>
> [[The reason that there is no longer a command-line version is that malware
> authors have started targeting RootkitRevealer's scan by using its
> executable name. We've therefore updated RootkitRevealer to execute its scan
> from a randomly named copy of itself that runs as a Windows service.]]
> http://www.sysinternals.com/Utilitie...tRevealer.html
>
> RootkitRevealer leaves references to these random named *.exe files behind
> so that you see strange service names in services.msc.
>
> You'll find the left behind services here...
>
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es
>
> Locate the service(s) in the list. ImagePath should point to
> Local Settings\Temp folder, as a double check.
>
> Delete them and reboot.
>
> [[Important This article contains information about modifying the registry.
> Before you modify the registry, make sure to back it up and make sure that
> you understand how to restore the registry if a problem occurs. For
> information about how to back up, restore, and edit the registry, click the
> following article number to view the article in the Microsoft Knowledge
> Base: 256986 Description of the Microsoft Windows Registry]]
> http://support.microsoft.com/default.aspx?kbid=256986
>
> --
> Hope this helps. Let us know.
>
> Wes
> MS-MVP Windows Shell/User
>
> In news:B2BF3D67-D751-4537-B0E7-B2D158152F41@microsoft.com,
> d. bennett <d. bennett@discussions.microsoft.com> hunted and pecked:
> > I found the following services in my Services.msc snap-in:
> >
> > NJND
> > PEFEJJ
> > JIEHGOWNLWY
> > EGW
> > NOVAVFKT
> >
> > I have disabled all of them and deleted the files (all the files where
> > located in my user temp directory)...
> >
> > Does anyone know what these are? I have searched all the sites I know for
> > info to see if they are viruses but I haven't found anything... My virus
> > scan doesn't report anything (I've made sure I'm updated) and I can't find
> > them listed as viruses on any sites (MS or Norton).
> >
> > -d

>
>

Reply With Quote
  #6  
Old 01-05-2006, 05:44 AM
Wesley Vogel
 
Posts: n/a
Default Re: mystery services found on my xp pro machine

Keep having fun. :-)

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In news:7C8F6600-CCAF-4E28-939E-4A1BF9F1990A@microsoft.com,
d. bennett <dbennett@discussions.microsoft.com> hunted and pecked:
> Thanks Wesley... Yes I had run RootkitRevealer but had failed to fully
> read the docs...
>
> thanks for the links and info.
>
> -d
>
> "Wesley Vogel" wrote:
>
>> If you have used RootkitRevealer, it adds a random named *.exe file and a
>> random named service and runs as that service. The random named *.exe
>> file will show up in %homepath%\Local Settings\Temp folder. Every time
>> you run RootkitRevealer it adds another random service to services.msc.
>> The randomly named *.exe file will be deleted, but the registry settings
>> are left behind.
>>
>> [[The reason that there is no longer a command-line version is that
>> malware authors have started targeting RootkitRevealer's scan by using
>> its executable name. We've therefore updated RootkitRevealer to execute
>> its scan from a randomly named copy of itself that runs as a Windows
>> service.]] http://www.sysinternals.com/Utilitie...tRevealer.html
>>
>> RootkitRevealer leaves references to these random named *.exe files
>> behind so that you see strange service names in services.msc.
>>
>> You'll find the left behind services here...
>>
>> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es
>>
>> Locate the service(s) in the list. ImagePath should point to
>> Local Settings\Temp folder, as a double check.
>>
>> Delete them and reboot.
>>
>> [[Important This article contains information about modifying the
>> registry. Before you modify the registry, make sure to back it up and
>> make sure that you understand how to restore the registry if a problem
>> occurs. For information about how to back up, restore, and edit the
>> registry, click the following article number to view the article in the
>> Microsoft Knowledge Base: 256986 Description of the Microsoft Windows
>> Registry]] http://support.microsoft.com/default.aspx?kbid=256986
>>
>> --
>> Hope this helps. Let us know.
>>
>> Wes
>> MS-MVP Windows Shell/User
>>
>> In news:B2BF3D67-D751-4537-B0E7-B2D158152F41@microsoft.com,
>> d. bennett <d. bennett@discussions.microsoft.com> hunted and pecked:
>>> I found the following services in my Services.msc snap-in:
>>>
>>> NJND
>>> PEFEJJ
>>> JIEHGOWNLWY
>>> EGW
>>> NOVAVFKT
>>>
>>> I have disabled all of them and deleted the files (all the files where
>>> located in my user temp directory)...
>>>
>>> Does anyone know what these are? I have searched all the sites I know
>>> for info to see if they are viruses but I haven't found anything... My
>>> virus scan doesn't report anything (I've made sure I'm updated) and I
>>> can't find them listed as viruses on any sites (MS or Norton).
>>>
>>> -d


Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Hijack problem Tom B. Windows XP Security Admin 7 01-05-2006 05:44 AM
winfixer infection Robert Windows XP Security Admin 7 01-05-2006 05:07 AM
Long delay before Drives & Files appear in My Computer & Address Bar shizzlenizzlator@gmail.com Windows XP Help and Support 3 01-05-2006 02:44 AM
EGroup.IEAccess.C (dialer) dtcar Windows XP Help and Support 22 01-05-2006 02:41 AM
On startup, displays Microsoft folder which contains Synctoy Dave Williams Windows XP General 9 01-05-2006 02:36 AM


All times are GMT. The time now is 08:09 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd. SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.

mystery services found on my xp pro machine