serivces.exe - Dangerous
serivces.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
W32.Whybo.Z is a virus that infects executable files. It also opens a back door on the compromised computer.
Related files:
%System%\serivces.exe
%SystemDrive%\Program Files\Common Files\Microsoft Shared\[FIVE RANDOM LOWERCASE LETTERS].exe
%SystemDrive%\Program Files\Internet Explorer\Connection Wizard\[FIVE RANDOM LOWERCASE LETTERS].exe
%SystemDrive%\Program Files\Windows Media Player\[FIVE RANDOM LOWERCASE LETTERS].exe
%SystemDrive%\WINDOWS\addins\[FIVE RANDOM LOWERCASE LETTERS].exe
%SystemDrive%\WINDOWS\system\[FIVE RANDOM LOWERCASE LETTERS].exe
%SystemDrive%\WINDOWS\system32\[FIVE RANDOM LOWERCASE LETTERS].exe
%SystemDrive%\WINDOWS\system32\drivers\[FIVE RANDOM LOWERCASE LETTERS].exe
%SystemDrive%\WINDOWS\system32\dllcache\[FIVE RANDOM LOWERCASE LETTERS].exe
%SystemDrive%\WINDOWS\system32\IME\[FIVE RANDOM LOWERCASE LETTERS].exe
Kill the process serivces.exe and remove serivces.exe from Windows startup.