
I have discovered file services.exe in C:\Windows folder and file mssyncr.exe in C:\Windows\System32 folder, both infected with TrojanDownloader.Win32.Small.qe as Kaspersky reports. They both have size arround 6K , packed with FSG packer. Unfortunately, Avast4 Home didn’t detected it, the same as NOD32. Norton AV detected it as Trojan.Download .

Shuold I post these files to Avast team, or it’s just false alarm ?

If you have XP, services.exe in \windows\system32 is normal. If it is in \windows\ it is not. They other definatly is not system (windows) file. What happens if you right click them and choose scan? If Avast doesn’t detect them, please put them in a password protected zip file and send them (along with the password ofcourse) to

I have sent mail with infected files. Hope Avast guys will find fix soon. Right click and scan says nothing, I’m using virus definitions downloaded yesterday (12-Aug-2004), currently I’m not home, so I can’t check if update from today will detect it.

I’m using VPS 0434-1 + Avast Home 4 ver. 4.1.418 , still no success :frowning:

Check the files with a online scanner. See if that tells something.


I'm using VPS 0434-1
I was infected with this months ago and NOTHING detected it or cleaned it at the time.

I figured out how to remove it myself.

here is how I did it


You mention a program called Security Task Manager and say you used it to trace and destroy the trojan but, you never mention where you got the program or how it’s used.
Referring someone to use other tools is fine. we do that all the time but, please be more specific. You also need to let people know that this is not a free program.

  • I am doing a Google search to see if anyone else has had a problem with services.exe and mssyncr.exe.

  • I see someone from this forum had problems and needed help.

  • I provide a link, that i previously posted on months ago, with information that can possibly help someone with their problem.

  1. Try typing Security Task Manager into Google, It will be listed in the first link.

  2. It is shareware, and works fine to look inside running processes.
    You don’t have to pay a dime if you don’t want to keep it on your PC, though it is a fine program.

  3. if you READ my posted link, I never said i used it to DESTROY it, only to look inside the executable.

Doesn’t this trojan require some user intervention to install itself?

Tried latest update 0438-1 and still nothing :frowning:

Good work Avast team!
It is now detected as Win32:Trojano-545 [Trj] , VPS version 0442-3.

I had this virus and my up-to-date Avast Home edition did NOT discover it. :-

Did you get rid of the virus now?

