services.exe - Dangerous

%program files%\common files\services.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

%program files%\common files\services.exe
Mass mailing worm W32.Crowt.
Adds the values:
"Services Logon" = "%Templates%\services.exe"
"Services Startup" = "%CommonProgramFiles%\services.exe"
to Windows startup registry keys.
%Templates% is a variable that refers to the Templates folder. By default this is C:\Documents and Settings\[user name]\Templates.
Opens a browser window displaying a Web page on the www.cnn.com domain.
Steals passwords to %Windir%\temp\keys.tmp.
Opens a backdoor by connecting to the host cocoazul.ath.cx on TCP port 80.
Allows teh remote control.
Kill it using RegRun Startup Optimizer,

Remove services.exe now!