wmiaqsrv.exe

来源:互联网 发布:mac系统怎么编辑pdf 编辑:程序博客网 时间:2024/04/30 09:40

今天发现服务器进程中有个wmiaqsrv.exe,感觉有问题,于是百度没有发现资料,看来还得google了,发现一下介绍:

Name: WMI-Service
Filename: wmiaqsrv.exe
Command: C:/Windows/System32/wmiaqsrv.exe
Description: Added by the Troj/Mdrop-AIA multi-dropper backdoor Trojan.
File Location: %System%
Startup Type: This startup entry is installed as a Windows NT, 2000, 2003, or XP service.
Service Name: WmiAqSrv
Service Display Name: WMI-Service
HijackThis Category: O23 Entry 
Note: %System% is a variable that refers to the Windows System folder. By default this is C:/Windows/System for Windows 95/98/ME, C:/Winnt/System32 for Windows NT/2000, or C:/Windows/System32 for Windows XP.

按照介绍中的说明看来是一个木马,于是禁用该服务。

原创粉丝点击