|
services.exe (5.1.2600.0)
소프트웨어안에 포함하는 |
이름: | Windows XP Home Edition, Deutsch |
면허: | 상업 |
정보 연결: | http://www.microsoft.com/windowsxp/ |
파일 세부사항 |
파일 경로: | C:\WINDOWS\system32 \ services.exe |
파일 날짜: | 2002-08-29 14:00:00 |
버전: | 5.1.2600.0 |
파일 사이즈: | 101.888 바이트 |
검사함과 파일은 잘게 썬다 |
CRC32: | 59F4EF56 |
MD5: | A87C 3A6B 407F B3B2 2C56 6315 607C E229 |
SHA1: | 9ECF 5BAC 16A2 F63E 0141 7565 E5CC D065 2845 4A2F |
버전 자원 정보 |
회사명: | Microsoft Corporation |
파일 설명: | Anwendung fr Dienste und Controller |
파일 운영 체계: | Windows NT, Windows 2000, Windows XP, Windows 2003 |
파일 유형: | Application |
파일 버전: | 5.1.2600.0 |
내부 이름: | services.exe |
법적인 저작권: | Microsoft Corporation. Alle Rechte vorbehalten. |
원래 파일 이름: | services.exe |
제품 이름: | Betriebssystem Microsoft Windows |
제품 버전: | 5.1.2600.0 |
services.exe은 뒤에 오는 보고안에 발견되었다:
|
Adware.Replace |
기술적 세부사항 ...1.01.00.dll Services.exe When Adware.Replace is executed,... ...Creates the following files: %System%ServicesServices.exe 1.01.00.dll... ..."xpsystem"="%system%ServicesServices.exe" in the registry key:... ...in the [windows] section: run=%system%ServicesServices.exe load=%system%ServicesServices.exe... ...[windows] run=%system%ServicesServices.exe load=%system%ServicesServices.exe... 제거 지시 ..."xpsystem"="%system%ServicesServices.exe" Exit the Registry Editor.... ...look for a line similar to: run=%system%ServicesServices.exe load=%system%ServicesServices.exe... ...[windows] run=%system%ServicesServices.exe load=%system%ServicesServices.exe... 근원: http://securityresponse.symantec.com/avcenter/venc/data/adware.replace.html |
Adware.Clickbank |
기술적 세부사항 ...File names: Services.exe When Adware.Clickbank is run,... ...Copies itself as %Windir%system32inetsrvServices.exe. Note: %Windir% is a variable.... ..."SuperBar.Component" = %windir%system32inetsrvservices.exe "AdRotator.Application"... ..."{357AA41A-B7A8-4632-A27D-5B980B25CF43}" = %windir%system32inetsrvservices.exe to the registry key:... 제거 지시 ..."SuperBar.Component" = %windir%system32inetsrvservices.exe "AdRotator.Application"... 근원: http://securityresponse.symantec.com/avcenter/venc/data/adware.clickbank.html |
W32.HLLW.Kazping |
기술적 세부사항 ...Copies itself as %Windir%Services.exe NOTE: %Windir% is a variable.... ...Adds the value: "Services.EXE"="%windir%services.exe"... ...HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion RunServices Copies itself to the following... 권고 ...Turn off and remove unneeded services. By default, many operating... ...telnet, and a Web server. These services are avenues of attack. If they are removed, blended... ...If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.... ...Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.... 제거 지시 ...the worm runs as>" "Services.EXE"="%windir%services.exe"... ...HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion RunServices In the right pane, delete... ...the value: "Services.EXE"="%windir%services.exe"... 근원: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.kazping.html |
W32.Neveg.B@mm |
기술적 세부사항 ...Copies itself as %Windir%systemservices.exe. Note: %Windir% is a variable... ...".Prog" = "%Windir%systemservices.exe" "BuildLab" = "%Windir%systemservices.exe"... ..."ccApps" = "%Windir%systemservices.exe" "FriendlyTypeName"... ..."Microsoft Visual SourceSafe" = "%Windir%systemservices.exe" "RegDone" = "%Windir%systemservices.exe"... ..."TEXTCONV" = "%Windir%systemservices.exe" "WMAudio" = "%Windir%systemservices.exe"... 권고 ...Turn off and remove unneeded services. By default, many operating... ...telnet, and a Web server. These services are avenues of attack. If they are removed, blended... ...If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.... ...Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.... 제거 지시 ...".Prog" = "%Windir%systemservices.exe" "BuildLab" = "%Windir%systemservices.exe"... ..."ccApps" = "%Windir%systemservices.exe" "FriendlyTypeName"... ..."Microsoft Visual SourceSafe" = "%Windir%systemservices.exe" "RegDone" = "%Windir%systemservices.exe"... ..."TEXTCONV" = "%Windir%systemservices.exe" "WMAudio" = "%Windir%systemservices.exe"... 근원: http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.b@mm.html |
W32.Neveg.C@mm |
기술적 세부사항 ...Copies itself as %WinDir%systemservices.exe. Note: %Windir% is a variable... ...".Prog"="%Windir%systemservices.exe" "BuildLab"= "%Windir%systemservices.exe"... ..."ccApps"="%Windir%systemservices.exe" "FriendlyTypeName"="%Windir%systemservices.exe"... ..."Microsoft Visual SourceSafe"="%Windir%systemservices.exe" "RegDone"="%Windir%systemservices.exe"... ..."TEXTCONV"="%Windir%systemservices.exe" "WMAudio"="%Windir%systemservices.exe"... 권고 ...Turn off and remove unneeded services. By default, many operating... ...telnet, and a Web server. These services are avenues of attack. If they are removed, blended... ...If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.... ...Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.... 제거 지시 ...".Prog"="%Windir%systemservices.exe" "BuildLab"= "%Windir%systemservices.exe"... ..."ccApps"="%Windir%systemservices.exe" "FriendlyTypeName"="%Windir%systemservices.exe"... ..."Microsoft Visual SourceSafe"="%Windir%systemservices.exe" "RegDone"="%Windir%systemservices.exe"... ..."TEXTCONV"="%Windir%systemservices.exe" "WMAudio"="%Windir%systemservices.exe"... 근원: http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.c@mm.html |
W32.XTC.Worm |
위협 평가 ...Name of attachment: Services.exe Size of attachment:... 권고 ...Turn off and remove unneeded services. By default, many operating... ...telnet, and a Web server. These services are avenues of attack. If they are removed, blended... ...If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.... ...Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.... 제거 지시 ... The Services.exe worm program runs as a service.... ...before you can delete it. To remove Services.exe from memory In the registry, search for... ...In the Windows (Windows 9x) or WINNT (Windows NT2000) directory, delete Services.exe. Note:... ...Be careful not to remove the file c:winntsystem32services.exe (a Windows NT system file.)... 근원: http://securityresponse.symantec.com/avcenter/venc/data/w32.xtc.worm.html |
W32.Servese |
기술적 세부사항 ...makes a copy of itself as: WindowsServices.exe It then adds the value... ...HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesOnce It then exits.... 제거 지시 ...If the detected file is about 23 KB in size and the name is Services.exe, just you can delete this file.... ...... 근원: http://securityresponse.symantec.com/avcenter/venc/data/w32.servese.html |
|
|