|
services.exe (5.1.2600.0)
Contenido en software |
Nombre: | Windows XP Home Edition, Deutsch |
Licencia: | comercial |
Acoplamiento de la información: | http://www.microsoft.com/windowsxp/ |
Detalles del archivo |
Trayectoria del archivo: | C:\WINDOWS\system32 \ services.exe |
Fecha del archivo: | 2002-08-29 14:00:00 |
Versión: | 5.1.2600.0 |
Tamaño del archivo: | 101.888 octetos |
La suma de comprobación y el archivo hashes |
CRC32: | 59F4EF56 |
MD5: | A87C 3A6B 407F B3B2 2C56 6315 607C E229 |
SHA1: | 9ECF 5BAC 16A2 F63E 0141 7565 E5CC D065 2845 4A2F |
Información del recurso de la versión |
Nombre de compañÃa: | Microsoft Corporation |
Descripción del archivo: | Anwendung für Dienste und Controller |
Sistema operativo del archivo: | Windows NT, Windows 2000, Windows XP, Windows 2003 |
Tipo del archivo: | Application |
Versión del archivo: | 5.1.2600.0 |
Nombre interno: | services.exe |
Copyright legal: | © Microsoft Corporation. Alle Rechte vorbehalten. |
Nombre de fichero original: | services.exe |
Nombre del producto: | Betriebssystem Microsoft® Windows® |
Versión del producto: | 5.1.2600.0 |
services.exe fue encontrado en los informes siguientes:
|
Adware.Replace |
Detalles técnicos ...1.01.00.dll Services.exe When Adware.Replace is executed,... ...Creates the following files: %System%ServicesServices.exe 1.01.00.dll... ..."xpsystem"="%system%ServicesServices.exe" in the registry key:... ...in the [windows] section: run=%system%ServicesServices.exe load=%system%ServicesServices.exe... ...[windows] run=%system%ServicesServices.exe load=%system%ServicesServices.exe... Instrucciones del retiro ..."xpsystem"="%system%ServicesServices.exe" Exit the Registry Editor.... ...look for a line similar to: run=%system%ServicesServices.exe load=%system%ServicesServices.exe... ...[windows] run=%system%ServicesServices.exe load=%system%ServicesServices.exe... Fuente: http://securityresponse.symantec.com/avcenter/venc/data/adware.replace.html |
Adware.Clickbank |
Detalles técnicos ...File names: Services.exe When Adware.Clickbank is run,... ...Copies itself as %Windir%system32inetsrvServices.exe. Note: %Windir% is a variable.... ..."SuperBar.Component" = %windir%system32inetsrvservices.exe "AdRotator.Application"... ..."{357AA41A-B7A8-4632-A27D-5B980B25CF43}" = %windir%system32inetsrvservices.exe to the registry key:... Instrucciones del retiro ..."SuperBar.Component" = %windir%system32inetsrvservices.exe "AdRotator.Application"... Fuente: http://securityresponse.symantec.com/avcenter/venc/data/adware.clickbank.html |
W32.HLLW.Kazping |
Detalles técnicos ...Copies itself as %Windir%Services.exe NOTE: %Windir% is a variable.... ...Adds the value: "Services.EXE"="%windir%services.exe"... ...HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion RunServices Copies itself to the following... Recomendaciones ...Turn off and remove unneeded services. By default, many operating... ...telnet, and a Web server. These services are avenues of attack. If they are removed, blended... ...If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.... ...Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.... Instrucciones del retiro ...the worm runs as>" "Services.EXE"="%windir%services.exe"... ...HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion RunServices In the right pane, delete... ...the value: "Services.EXE"="%windir%services.exe"... Fuente: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.kazping.html |
W32.Neveg.B@mm |
Detalles técnicos ...Copies itself as %Windir%systemservices.exe. Note: %Windir% is a variable... ...".Prog" = "%Windir%systemservices.exe" "BuildLab" = "%Windir%systemservices.exe"... ..."ccApps" = "%Windir%systemservices.exe" "FriendlyTypeName"... ..."Microsoft Visual SourceSafe" = "%Windir%systemservices.exe" "RegDone" = "%Windir%systemservices.exe"... ..."TEXTCONV" = "%Windir%systemservices.exe" "WMAudio" = "%Windir%systemservices.exe"... Recomendaciones ...Turn off and remove unneeded services. By default, many operating... ...telnet, and a Web server. These services are avenues of attack. If they are removed, blended... ...If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.... ...Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.... Instrucciones del retiro ...".Prog" = "%Windir%systemservices.exe" "BuildLab" = "%Windir%systemservices.exe"... ..."ccApps" = "%Windir%systemservices.exe" "FriendlyTypeName"... ..."Microsoft Visual SourceSafe" = "%Windir%systemservices.exe" "RegDone" = "%Windir%systemservices.exe"... ..."TEXTCONV" = "%Windir%systemservices.exe" "WMAudio" = "%Windir%systemservices.exe"... Fuente: http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.b@mm.html |
W32.Neveg.C@mm |
Detalles técnicos ...Copies itself as %WinDir%systemservices.exe. Note: %Windir% is a variable... ...".Prog"="%Windir%systemservices.exe" "BuildLab"= "%Windir%systemservices.exe"... ..."ccApps"="%Windir%systemservices.exe" "FriendlyTypeName"="%Windir%systemservices.exe"... ..."Microsoft Visual SourceSafe"="%Windir%systemservices.exe" "RegDone"="%Windir%systemservices.exe"... ..."TEXTCONV"="%Windir%systemservices.exe" "WMAudio"="%Windir%systemservices.exe"... Recomendaciones ...Turn off and remove unneeded services. By default, many operating... ...telnet, and a Web server. These services are avenues of attack. If they are removed, blended... ...If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.... ...Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.... Instrucciones del retiro ...".Prog"="%Windir%systemservices.exe" "BuildLab"= "%Windir%systemservices.exe"... ..."ccApps"="%Windir%systemservices.exe" "FriendlyTypeName"="%Windir%systemservices.exe"... ..."Microsoft Visual SourceSafe"="%Windir%systemservices.exe" "RegDone"="%Windir%systemservices.exe"... ..."TEXTCONV"="%Windir%systemservices.exe" "WMAudio"="%Windir%systemservices.exe"... Fuente: http://securityresponse.symantec.com/avcenter/venc/data/w32.neveg.c@mm.html |
W32.XTC.Worm |
Gravamen de la amenaza ...Name of attachment: Services.exe Size of attachment:... Recomendaciones ...Turn off and remove unneeded services. By default, many operating... ...telnet, and a Web server. These services are avenues of attack. If they are removed, blended... ...If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.... ...Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.... Instrucciones del retiro ... The Services.exe worm program runs as a service.... ...before you can delete it. To remove Services.exe from memory In the registry, search for... ...In the Windows (Windows 9x) or WINNT (Windows NT2000) directory, delete Services.exe. Note:... ...Be careful not to remove the file c:winntsystem32services.exe (a Windows NT system file.)... Fuente: http://securityresponse.symantec.com/avcenter/venc/data/w32.xtc.worm.html |
W32.Servese |
Detalles técnicos ...makes a copy of itself as: WindowsServices.exe It then adds the value... ...HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesOnce It then exits.... Instrucciones del retiro ...If the detected file is about 23 KB in size and the name is Services.exe, just you can delete this file.... ...... Fuente: http://securityresponse.symantec.com/avcenter/venc/data/w32.servese.html |
|
|