Wanted to start by stating that I have worked as a Windows system admin for the past 10 years and clean up viruses all the time, and this is one thing I have never seen before and cannot figure this out. I didn't notice any issues with my PC, I just happened to pull up services for one reason or another, think I was going to disable iTunes helper or something and I noticed an odd one called PennyBee Service and it showed running and claims to be running from c:\program files (x86)\PennyBee. The really odd thing about it is there is no such folder, and it's not simply hidden it's really not there, or for whatever reason I cannot see it even as a hidden folder. I can start and stop the service, and it shows running so it has to be somewhere, and even more strange it doesn't show up in Task Manager either. I ended up finding 3 other odd ones just like this, Util Deal Keeper and Update Deal Keeper showing running from c:\program files (x86)\Deal Keeper and Optimizer Pro Crash Monitor running from c:\program files (x86)\Optimizer Pro\ again which neither one of those folders exist, and you cannot see these tasks running except for under services.
I was able to simply switch all of them to disabled and reboot, but somhow the Update Deal Keeper service loads on startup still but the other 3 do not. I tried running sc delete "Update Deal Keeper" and same on the other services and it claims those services don't exist even though I plainly see them, and am using the correct service name to try deleting. I have used every tool I could find to search for/clean this stuff including MalwareBytes antimalware and anti root kit, SuperAntiSpyware, Windows Defender, Kaspersky, ESET, McAfee, TDSSKiller, Sophos, McAfee Rootkit Killer, and even if I run WindowexeAllKiller which basically gives you an absolute list of every exe, service,etc running on your system none of these things show up in this list. I have checked over the entire registry and lookd in scheduled tasks and nothing in there. Also none of these services show up under the services section in the registry, so whatever this stuff is somehow it's hidden more than anything I've ever seen and I just don't see how this is possible.
Again at this point the only thing actually running is Update Deal Killer service even though it's set to disabled it somehow starts up when I reboot, but the other 3 never start up, and I cannot delete them and the folders/files for these absolutely don't appear to exist. I'm running Windows 8.1 Pro 64bit. Any ideas? I mean I could wipe and start fresh but damn I really don't want to go through all that if I don't have to
Edited by darkonex, 05 August 2014 - 02:23 PM.