瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » Backdoor.Gpigeon.5.an 怎么杀了重起机器还有?
PlayDice - 2005-7-11 9:21:00
在断开网络下也是这样?我用的是瑞星服务器最新版17.34
命运里の金色 - 2005-7-11 9:29:00
http://forum.ikaka.com/topic.asp?board=28&artid=6202404
PlayDice - 2005-7-11 10:04:00
【回复“命运里の金色”的帖子】

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: msconfig - Unknown owner - C:\WINDOWS\msconfig.exe
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - D:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe

那个是灰鸽子注册的系统服务名?
Mestoration - 2005-7-11 10:13:00
O23 - Service: msconfig - Unknown owner - C:\WINDOWS\msconfig.exe
这项就是灰鸽子。
===============================================
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
这2项很可疑!
1
查看完整版本: Backdoor.Gpigeon.5.an 怎么杀了重起机器还有?