Mystery service

Discussion in 'other security issues & news' started by Tarnak, Jan 18, 2023.

  1. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
  2. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,642
    Location:
    USA
    My only suggestion would be the same as one of the comments from that site... look for it in the registry at:
    Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
    See if you can find what executable it starts and go from there.
     
  3. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    Here we go...

    Services_mystery service_03.JPG
     

    Attached Files:

  4. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,642
    Location:
    USA
    I'd make a registry backup and just delete the thing. If the path is invalid it probably doesn't do anything anyway.
     
  5. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    I couldn't open the file.

    Do you mean just delete the registry key?
     
  6. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,642
    Location:
    USA
    Yeah, delete the registry key under Services. You will have to reboot for it to disappear completely. Since it said it can't start it isn't likely to be missed.
     
  7. noway

    noway Registered Member

    Joined:
    Apr 24, 2005
    Posts:
    461
    First I'd try copying the Asian characters and paste into Google and see what comes up.
     
  8. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    I will give it whirl, and see if it disappears, or my laptop goes x@*&!!!!
     
  9. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    I tried that, and nothing definitive.
     
  10. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,642
    Location:
    USA
    I would guess this is probably related to a driver for something manufactured in an Asian country and was missed when they made the English version. As the path can't be found it probably does absolutely nothing though an export or registry backup as mentioned earlier wouldn't hurt. I'm curious as to whether it could even be exported (that key alone).
     
  11. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    Joined:
    Sep 19, 2012
    Posts:
    518
    Location:
    Bulgaria
    This one convert as -

    S2 iWesoBtosAistsnat; :CP\orrgmaF lise( 8x)6W\si\eiWesC ra e63\5oBtoiTeme.ex [X]

    Probably - WiseBootAssistant from WiseCare 365

    https://vms.drweb.com/virus/?i=21666476

    https://www.wisecleaner.com/wise-care-365.html

    So the entry should look like this:

    Code:
    S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe
     
  12. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    I deleted the key, and restarted the laptop, and it has gone. A relief. :thumb:

    Services_mystery service_04.JPG
     
  13. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296

    You may be right on this. I did purchase WiseCare 365, and it is installed on this laptop and another, which I will check later, today.

    Not sure how you mean on checking that entry. After all, I have deleted the key, and the laptop seems OK.
     
  14. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,642
    Location:
    USA
    It's probably fine. It wouldn't hurt to check for the existence of that BootTime.exe. But again, I assume this to be a leftover from a translation that didn't do anything.
     
  15. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    Joined:
    Sep 19, 2012
    Posts:
    518
    Location:
    Bulgaria
    Nice. I used this one to check the entry - https://2cyr.com/decode/

    And then it was easy to track it down since I am working with logs every day. (Mainly from FRST). :)

    So this is a leftover and not malware

    All the best! :)
     
  16. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    Like this, you mean? I suppose I could disable it, or maybe it is OK.

    Services_mystery service_05.JPG
     
  17. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    Thank you. At least, I am assured I don't have any malware on the laptop. It has been more than fifteen years since I have been infected. In my novice days venturing forth on the internet, I remember when I was a member of CastleCops, back in the day. How things change!!! :)
     
  18. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,642
    Location:
    USA
    It should be fine. Looks like what I suspected, the original item in question was just something left behind after a translation. Looks like you are good to go.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.