瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 请高手帮我分析一下灰鸽子的服务名!

12   2  /  2  页   跳转

请高手帮我分析一下灰鸽子的服务名!

现在是这样了
O20 - Winlogon Notify: reset5 - C:\WINDOWS\SYSTEM32\reset5.dll
O23 - Service: Remtoe Access Client - Unknown owner - C:\WINDOWS\Explorers.exe
O23 - Service: Reset 5 - Unknown owner - C:\WINDOWS\system32\srvany.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe

gototop
 

引用:
【蓝田雨的贴子】现在是这样了
O20 - Winlogon Notify: reset5 - C:\WINDOWS\SYSTEM32\reset5.dll
O23 - Service: Remtoe Access Client - Unknown owner - C:\WINDOWS\Explorers.exe
O23 - Service: Reset 5 - Unknown owner - C:\WINDOWS\system32\srvany.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe


...........................

弄死了一只,又来了一只新的:
O23 - Service: Remtoe Access Client - Unknown owner - C:\WINDOWS\Explorers.exe
gototop
 

【回复“蓝田雨”的帖子】
O23 - Service: Reset 5 - Unknown owner - C:\WINDOWS\system32\srvany.exe
这项也有问题。如果能找到C:\WINDOWS\system32\srvany.exe,请打包传上来。
gototop
 

找到了,可我不会传上去
gototop
 

O23 - Service: Remtoe Access Client - Unknown owner - C:\WINDOWS\Explorers.exe
注册表已修改,但找不到文件.
O23 - Service: Reset 5 - Unknown owner - C:\WINDOWS\system32\srvany.exe
这项也有问题。如果能找到C:\WINDOWS\system32\srvany.exe,请打包传上来。
文件已找到,也压缩了.但弄不上来.不好意思!我太板了
您告诉我怎么搞,我自己动手吧.
gototop
 

点最上面的回复 里面有个文件浏览,你点后面那个 然后选你要上传的文件就行了,不要大于1m
gototop
 

谢谢!找到了

附件附件:

下载次数:0
文件类型:application/octet-stream
文件大小:
上传时间:2005-7-28 11:14:25
描述:

gototop
 

谢谢,斑竹!帮我再看看
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT