File: C:\Documents and Settings\Administrator\桌面\server\server.exe
Size: 132303 bytes
Modified: 2007年5月20日, 12:01:34
MD5: 583F86D285D644AD34727456297A32BD
SHA1: 857F638BAA9CB1C97984C2DC88C168E4A06E0842
CRC32: 55907570
建立服务
netctrl
HKLM\SYSTEM\ControlSet001\Services\netctrl\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKLM\SYSTEM\ControlSet001\Services\netctrl\Parameters\ServiceDll: "C:\WINDOWS\system32\syst.dll"
HKLM\SYSTEM\ControlSet001\Services\netctrl\Enum\0: "Root\LEGACY_NETCTRL\0000"
HKLM\SYSTEM\ControlSet001\Services\netctrl\Enum\Count: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\netctrl\Enum\NextInstance: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\netctrl\Type: 0x00000110
HKLM\SYSTEM\ControlSet001\Services\netctrl\Start: 0x00000002
HKLM\SYSTEM\ControlSet001\Services\netctrl\ErrorControl: 0x00000000
HKLM\SYSTEM\ControlSet001\Services\netctrl\ImagePath: "C:\WINDOWS\system32\svchost.exe -k remoteservice"
HKLM\SYSTEM\ControlSet001\Services\netctrl\DisplayName: "Remote Help & Control Service"
HKLM\SYSTEM\ControlSet001\Services\netctrl\
ObjectName: "LocalSystem"
HKLM\SYSTEM\ControlSet001\Services\netctrl\Description: "Remote Help & Control Service"
HKLM\SYSTEM\ControlSet001\Services\netctrl\Info: "0;1*40?&9/07=?>789?:22751;7?<
用sreng 删除相关服务后
重启删除那个syst.dll即可