¡¶Ê·ÉÏ×îÈ«µÄµçÄÔ³£Ê¶ËѼ¯¡·

ÏÂÔر¾Êé

Ìí¼ÓÊéÇ©

Ê·ÉÏ×îÈ«µÄµçÄÔ³£Ê¶ËѼ¯- µÚ24²¿·Ö


°´¼üÅÌÉÏ·½Ïò¼ü ¡û »ò ¡ú ¿É¿ìËÙÉÏÏ·­Ò³£¬°´¼üÅÌÉ쵀 Enter ¼ü¿É»Øµ½±¾ÊéĿ¼ҳ£¬°´¼üÅÌÉÏ·½Ïò¼ü ¡ü ¿É»Øµ½±¾Ò³¶¥²¿£¡
»òÕßµ¥»÷ÈÎÎñÌõ×î×ó±ßµÄ¡°¿ªÊ¼¡±²Ëµ¥¡ú¡°ÔËÐС±£¬ÔÚµ¯³öµÄ¡°ÔËÐС±¶Ô»°¿òÀïÊäÈë¡¡gpedit¡£msc¡¡£¬»Ø³µ»òµã»÷¡°È·¶¨¡±°´Å¥£¬ÏµÍ³½«´ò¿ª¡°×é²ßÂÔ¡±´°¿Ú¡£×é²ßÂÔ¡úÓû§ÅäÖáú×ÀÃ棬ÔÚÓұߴ°¸ñÕÒµ½¡°´Ó×ÀÃæɾ³ý»ØÊÕÕ¾¡±ÏîÄ¿£¬Ë«»÷Ëü£¬ÔÚµ¯³öµÄ´°¿ÚµãÑ¡¡°Î´ÅäÖá±»ò¡°ÒѽûÓá±µ¥Ñ¡°´Å¥£¬È·¶¨£¬ÐèҪעÏú»òÖØÆô»úÆ÷£¬Ëù×öµÄÉèÖþÍÉúЧÁË¡£

ϵͳµÄ×î¶àÓÐ29¸ö

£¨1£©£§system¡¡Idle¡¡Process£§

½ø³ÌÎļþ£º¡¡£§system¡¡process£§¡¡or¡¡£§system¡¡process£§

½ø³ÌÃû³Æ£º¡¡WindowsÄÚ´æ´¦Àíϵͳ½ø³Ì

Ãè¡¡Êö£º¡¡WindowsÒ³ÃæÄÚ´æ¹ÜÀí½ø³Ì£¬ÓµÓÐ0¼¶ÓÅÏÈ¡£

½é¡¡ÉÜ£º¸Ã½ø³Ì×÷Ϊµ¥Ïß³ÌÔËÐÐÔÚÿ¸ö´¦ÀíÆ÷ÉÏ£¬²¢ÔÚϵͳ²»´¦ÀíÆäËûÏ̵߳Äʱºò·ÖÅÉ´¦ÀíÆ÷µÄʱ¼ä¡£ËüµÄcpuÕ¼ÓÃÂÊÔ½´ó±íʾ¿É¹©·ÖÅäµÄCPU×ÊÔ´Ô½¶à£¬Êý×ÖԽСÔò±íʾCPU×ÊÔ´½ôÕÅ¡£

£¨2£©£§alg¡£exe£§

½ø³ÌÎļþ£º¡¡alg¡¡or¡¡alg¡£exe

½ø³ÌÃû³Æ£º¡¡Ó¦ÓòãÍø¹Ø·þÎñ

Ãè¡¡Êö£º¡¡ÕâÊÇÒ»¸öÓ¦ÓòãÍø¹Ø·þÎñÓÃÓÚÍøÂç¹²Ïí¡£

½é¡¡ÉÜ£ºÒ»¸öÍø¹ØͨÐŲå¼þµÄ¹ÜÀíÆ÷£¬Îª¡¡¡°InternetÁ¬½Ó¹²Ïí·þÎñ¡±ºÍ¡¡¡°InternetÁ¬½Ó·À»ðǽ·þÎñ¡±ÌṩµÚÈý·½Ð­Òé²å¼þµÄÖ§³Ö¡£

£¨3£©£§csrss¡£exe£§

½ø³ÌÎļþ£º¡¡csrss¡¡or¡¡csrss¡£exe

½ø³ÌÃû³Æ£º¡¡Client/Server¡¡Runtime¡¡Server¡¡Subsystem

Ãè¡¡Êö£º¡¡¿Í»§¶Ë·þÎñ×Óϵͳ£¬ÓÃÒÔ¿ØÖÆWindowsͼÐÎÏà¹Ø×Óϵͳ¡£

½é¡¡ÉÜ£º¡¡Õâ¸öÊÇÓû§Ä£Ê½Win32×ÓϵͳµÄÒ»²¿·Ö¡£csrss´ú±í¿Í»§/·þÎñÆ÷ÔËÐÐ×Óϵͳ¶øÇÒÊÇÒ»¸ö»ù±¾µÄ×Óϵͳ±ØÐëÒ»Ö±ÔËÐС£csrssÓÃÓÚά³ÖWindows¡¡µÄ¿ØÖÆ£¬´´½¨»òÕßɾ³ýÏ̺߳ÍһЩ16λµÄÐéÄâMS¡­DOS»·¾³¡£

£¨4£©£§ddhelp¡£exe£§

½ø³ÌÎļþ£º¡¡ddhelp¡¡or¡¡ddhelp¡£exe

½ø³ÌÃû³Æ£º¡¡DirectDraw¡¡Helper

Ãè¡¡Êö£º¡¡DirectDraw¡¡HelperÊÇDirectXÕâ¸öÓÃÓÚͼÐηþÎñµÄÒ»¸ö×é³É²¿·Ö¡£

¼ò¡¡½é£ºDirectx¡¡°ïÖú³ÌÐò

£¨5£©£§dllhost¡£exe£§

½ø³ÌÎļþ£º¡¡dllhost¡¡or¡¡dllhost¡£exe

½ø³ÌÃû³Æ£º¡¡D¡¡DLL¡¡Host½ø³Ì

Ãè¡¡Êö£º¡¡D¡¡DLL¡¡Host½ø³ÌÖ§³Ö»ùÓÚ¶ÔÏóÖ§³ÖDLLÒÔÔËÐÐWindows³ÌÐò¡£

½é¡¡ÉÜ£º´úÀí£¬ÏµÍ³¸½¼ÓµÄdll×é¼þÔ½¶à£¬ÔòdllhostÕ¼ÓõÄcpu×ÊÔ´ºÍÄÚ´æ×ÊÔ´¾ÍÔ½¶à£¬¶ø8Ôµġ°³å»÷²¨É±ÊÖ¡±´ó¸ÅÈôó¼Ò¶ÔËü±È½ÏÊìϤ°É¡£

£¨6£©£§explorer¡£exe£§

½ø³ÌÎļþ£º¡¡explorer¡¡or¡¡explorer¡£exe

½ø³ÌÃû³Æ£º¡¡³ÌÐò¹ÜÀí

Ãè¡¡Êö£º¡¡Windows¡¡Program¡¡Manager»òÕßWindows¡¡ExplorerÓÃÓÚ¿ØÖÆWindowsͼÐÎShell£¬°üÀ¨¿ªÊ¼²Ëµ¥¡¢ÈÎÎñÀ¸£¬×ÀÃæºÍÎļþ¹ÜÀí¡£

½é¡¡ÉÜ£ºÕâÊÇÒ»¸öÓû§µÄshell£¬ÔÚÎÒÃÇ¿´ÆðÀ´¾ÍÏñÈÎÎñÌõ£¬×ÀÃæµÈµÈ¡£»òÕß˵Ëü¾ÍÊÇ×ÊÔ´¹ÜÀíÆ÷£¬²»ÏàÐÅÄãÔÚÔËÐÐÀïÖ´ÐÐËü¿´¿´¡£Ëü¶ÔwindowsϵͳµÄÎȶ¨ÐÔ»¹ÊDZȽÏÖØÒªµÄ£¬¶øºìÂëÒ²¾ÍÊÇÕÒËüµÄÂé·³£¬ÔÚcºÍd¸ùÏ´´½¨explorer¡£exe¡£

£¨7£©£§inetinfo¡£exe£§

½ø³ÌÎļþ£º¡¡inetinfo¡¡or¡¡inetinfo¡£exe

½ø³ÌÃû³Æ£º¡¡IIS¡¡Admin¡¡Service¡¡Helper

Ãè¡¡Êö£º¡¡InetInfoÊÇMicrosoft¡¡Internet¡¡Infomation¡¡Services¡¡£¨IIS£©µÄÒ»²¿·Ö£¬ÓÃÓÚDebugµ÷ÊÔ³ý´í¡£

½éÉÜ£ºIIS·þÎñ½ø³Ì£¬À¶ÂëÕýÊÇÀûÓõÄinetinfo¡£exeµÄ»º³åÇøÒç³ö©¶´¡£

£¨8£©£§internat¡£exe£§

½ø³ÌÎļþ£º¡¡internat¡¡or¡¡internat¡£exe

½ø³ÌÃû³Æ£º¡¡Input¡¡Locales

Ãè¡¡Êö£º¡¡Õâ¸öÊäÈë¿ØÖÆͼ±êÓÃÓÚ¸ü¸ÄÀàËƹú¼ÒÉèÖᢼüÅÌÀàÐͺÍÈÕÆÚ¸ñʽ¡£internat¡£exeÔÚÆô¶¯µÄʱºò¿ªÊ¼ÔËÐС£Ëü¼ÓÔØÓÉÓû§Ö¸¶¨µÄ²»Í¬µÄÊäÈëµã¡£ÊäÈëµãÊÇ´Ó×¢²á±íµÄÕâ¸öλÖÃHKEY_USERS¡£DEFAULTKeyboard¡¡LayoutPreload¡¡¼ÓÔØÄÚÈݵġ£internat¡£exe¡¡¼ÓÔØ¡°EN¡±Í¼±ê½øÈëϵͳµÄͼ±êÇø£¬ÔÊÐíʹÓÃÕß¿ÉÒÔºÜÈÝÒ×µÄת»»²»Í¬µÄÊäÈëµã¡£µ±½ø³ÌÍ£µôµÄʱºò£¬Í¼±ê¾Í»áÏûʧ£¬µ«ÊÇÊäÈëµãÈÔÈ»¿ÉÒÔͨ¹ý¿ØÖÆÃæ°åÀ´¸Ä±ä¡£

½é¡¡ÉÜ£ºËüÖ÷ÒªÊÇÓÃÀ´¿ØÖÆÊäÈë·¨µÄ£¬µ±ÄãµÄÈÎÎñÀ¸Ã»ÓС°EN¡±Í¼±ê£¬¶øϵͳÓÐinternat¡£exe½ø³Ì£¬²»·Á½áÊøµô¸Ã½ø³Ì£¬ÔÚÔËÐÐÀïÖ´ÐÐinternat¡¡ÃüÁî¼´¿É¡£

£¨9£©£§kernel32¡£dll£§

½ø³ÌÎļþ£º¡¡kernel32¡¡or¡¡kernel32¡£dll

½ø³ÌÃû³Æ£º¡¡Windows¿Ç½ø³Ì

Ãè¡¡Êö£º¡¡Windows¿Ç½ø³ÌÓÃÓÚ¹ÜÀí¶àÏ̡߳¢ÄÚ´æºÍ×ÊÔ´¡£

½é¡¡ÉÜ£º¸ü¶àÄÚÈÝä¯ÀÀ·Ç·¨²Ù×÷ÓëKernel32½â¶Á

£¨10£©£§lsass¡£exe£§

½ø³ÌÎļþ£º¡¡lsass¡¡or¡¡lsass¡£exe

½ø³ÌÃû³Æ£º¡¡±¾µØ°²È«È¨ÏÞ·þÎñ

Ãè¡¡Êö£º¡¡Õâ¸ö±¾µØ°²È«È¨ÏÞ·þÎñ¿ØÖÆWindows°²È«»úÖÆ¡£¹ÜÀí¡¡IP¡¡°²È«²ßÂÔÒÔ¼°Æô¶¯¡¡ISAKMP/Oakley¡¡£¨IKE£©¡¡ºÍ¡¡IP¡¡°²È«Çý¶¯³ÌÐòµÈ¡£

½é¡¡ÉÜ£ºÕâÊÇÒ»¸ö±¾µØµÄ°²È«ÊÚȨ·þÎñ£¬²¢ÇÒËü»áΪʹÓÃwinlogon·þÎñµÄÊÚȨÓû§Éú³ÉÒ»¸ö½ø³Ì¡£Õâ¸ö½ø³ÌÊÇͨ¹ýʹÓÃÊÚȨµÄ°ü£¬ÀýÈçĬÈϵġ¡msgina¡£dllÀ´Ö´Ðеġ£Èç¹ûÊÚȨÊdzɹ¦µÄ£¬lsass¾Í»á²úÉúÓû§µÄ½øÈëÁîÅÆ£¬ÁîÅƱðʹÓÃÆô¶¯³õʼµÄshell¡£ÆäËûµÄÓÉÓû§³õʼ»¯µÄ½ø³Ì»á¼Ì³ÐÕâ¸öÁîÅƵġ£¶øwindows»î¶¯Ä¿Â¼Ô¶³Ì¶ÑÕ»Òç³ö©¶´£¬ÕýÊÇÀûÓÃLDAP¡¡3ËÑË÷ÇëÇó¹¦ÄܶÔÓû§Ìá½»ÇëÇóȱÉÙÕýÈ·»º³åÇø±ß½ç¼ì²é£¬¹¹½¨³¬¹ý1000¸ö¡¨AND¡¨µÄÇëÇ󣬲¢·¢Ë͸ø·þÎñÆ÷£¬µ¼Ö´¥·¢¶ÑÕ»Òç³ö£¬Ê¹Lsass¡£exe·þÎñ±ÀÀ££¬ÏµÍ³ÔÚ30ÃëÄÚÖØÐÂÆô¶¯¡£

£¨11£©£§mdm¡£exe£§

½ø³ÌÎļþ£º¡¡mdm¡¡or¡¡mdm¡£exe

½ø³ÌÃû³Æ£º¡¡Machine¡¡Debug¡¡Manager

Ãè¡¡Êö£º¡¡Debug³ý´í¹ÜÀíÓÃÓÚµ÷ÊÔÓ¦ÓóÌÐòºÍMicrosoft¡¡OfficeÖеÄMicrosoft¡¡Script¡¡Editor½Å±¾±à¼­Æ÷¡£

½é¡¡ÉÜ£ºMdm¡£exeµÄÖ÷Òª¹¤×÷ÊÇÕë¶ÔÓ¦ÓÃÈí¼þ½øÐÐÅÅ´í£¨Debug£©£¬Ëµµ½ÕâÀ³¶µãÌâÍâ»°£¬Èç¹ûÄãÔÚϵͳ¼ûµ½fff¿ªÍ·µÄ0×Ö½ÚÎļþ£¬ËüÃǾÍÊÇ¡¡mdm¡£exeÔÚÅÅ´í¹ý³ÌÖвúÉúһЩÔÝ´æÎļþ£¬ÕâЩÎļþÔÚ²Ù×÷ϵͳ½øÐйػúʱûÓÐ×Ô¶¯±»Çå³ý£¬ËùÒÔÕâЩfff¿ªÍ·µÄ¹ÖÎļþÀïÊÇһЩºó׺ÃûΪCHKµÄÎļþ¶¼ÊÇûÓÐÓõÄÀ¬»øÎļþ£¬¿ÉÔÈÎÒâɾ³£¿£¿»»á¶Ôϵͳ²£¿£¿»Á¼Ó°Ïì¡6£¿Xϵͳ£¬Ö»ÒªÏµÍ³ÖÐÓÐMdm¡£exe´æÔÚ£¬¾ÍÓпÉÄܲúÉúÒÔfff¿ªÍ·µÄ¹ÖÎļþ¡£¿ÉÒÔ°´ÏÂÃæµÄ·½·¨ÈÃϵͳֹͣÔËÐÐMdm¡£exeÀ´³¹µ×ɾ³ýÒÔfff¿ªÍ·µÄ¹ÖÎļþ£ºÊ×ÏÈ°´¡°Ctrl£«Alt£«Del¡±×éºÏ¼ü£¬ÔÚµ¯³öµÄ¡°¹Ø±Õ³ÌÐò¡±´°¿ÚÖÐÑ¡ÖС¡¡°Mdm¡±£¬°´¡°½áÊøÈÎÎñ¡±°´Å¥À´Í£Ö¹Mdm¡£exeÔÚºǫ́µÄÔËÐУ¬½Ó×Å°ÑMdm¡£exe£¨ÔÚC£ºWindowsSystemĿ¼Ï£©¸ÄÃûΪ¡¡Mdm¡£bak¡£ÔËÐÐmsconfig³ÌÐò£¬ÔÚÆô¶¯Ò³ÖÐÈ¡Ïû¶Ô¡°Machine¡¡Debug¡¡Manager¡±µÄÑ¡Ôñ¡£ÕâÑù¿ÉÒÔ²»ÈÃMdm¡£exe×ÔÆô¶¯£¬È»ºóµã»÷¡°È·¶¨¡±°´Å¥£¬½áÊømsconfig³ÌÐò£¬²¢ÖØÐÂÆô¶¯µçÄÔ¡£ÁíÍ⣬Èç¹ûÄãʹÓÃIE¡¡5¡£XÒÔÉÏ°æ±¾ä¯ÀÀÆ÷£¬½¨Òé½ûÓýű¾µ÷Ó㨵ã»÷¡°¹¤¾ß¡úInternetÑ¡Ïî¡ú¸ß¼¶¡ú½ûÓýű¾µ÷Óá±£©£¬ÕâÑù¾Í¿ÉÒÔ±ÜÃâÒÔfff¿ªÍ·µÄ¹ÖÎļþÔٴβúÉú¡£

£¨12£©£§mmtask¡£tsk£§

½ø³ÌÎļþ£º¡¡mmtask¡¡or¡¡mmtask¡£tsk

½ø³ÌÃû³Æ£º¡¡¶àýÌåÖ§³Ö½ø³Ì

Ãè¡¡Êö£º¡¡Õâ¸öWindows¶àýÌåºǫ́³ÌÐò¿ØÖƶàýÌå·þÎñ£¬ÀýÈçMIDI¡£

½é¡¡ÉÜ£ºÕâÊÇÒ»¸öÈÎÎñµ÷¶È·þÎñ£¬¸ºÔðÓû§ÊÂÏȾö¶¨ÔÚijһʱ¼äÔËÐеÄÈÎÎñµÄÔËÐС£

13£©£§mprexe¡£exe£§

½ø³ÌÎļþ£º¡¡mprexe¡¡or¡¡mprexe¡£exe

½ø³ÌÃû³Æ£º¡¡Windows·Óɽø³Ì

Ãè¡¡Êö£º¡¡Windows·Óɽø³Ì°üÀ¨ÏòÊʵ±µÄÍøÂ粿·Ö·¢³öÍøÂçÇëÇó¡£

½é¡¡ÉÜ£ºÕâÊÇWindowsµÄ32λÍøÂç½çÃæ·þÎñ½ø³ÌÎļþ£¬ÍøÂç¿Í»§¶Ë²¿¼þÆô¶¯µÄºËÐÄ¡£Ó¡ÏóÖС°A¡­311ľÂí£¨Trojan¡£A¡­311¡£104£©¡±Ò²»áÔÚÄÚ´æÖн¨Á¢mprexe¡£exe½ø³Ì£¬¿ÉÒÔͨ¹ý×ÊÔ´¹ÜÀí½áÊø½ø³Ì¡£

£¨14£©£§msgsrv32¡£exe£§

½ø³ÌÎļþ£º¡¡msgsrv32¡¡or¡¡msgsrv32¡£exe

½ø³ÌÃû³Æ£º¡¡WindowsÐÅʹ·þÎñ

Ãè¡¡Êö£º¡¡WindowsÐÅʹ·þÎñµ÷ÓÃWindowsÇý¶¯ºÍ³ÌÐò¹ÜÀíÔÚÆô¶¯¡£

½é¡¡ÉÜ£ºmsgsrv32¡£exe¡¡Ò»¸ö¹ÜÀíÐÅÏ¢´°¿ÚµÄÓ¦ÓóÌÐò£¬win9xÏÂÈç¹ûÉù¿¨»òÕßÏÔ¿¨Çý¶¯³ÌÐòÅäÖò»ÕýÈ·£¬»áµ¼ÖÂËÀ»ú»òÕßÌáʾmsgsrv32¡£exe¡¡³ö´í¡£

£¨15£©£§mstask¡£exe£§

½ø³ÌÎļþ£º¡¡mstask¡¡or¡¡mstask¡£exe

½ø³ÌÃû³Æ£º¡¡Windows¼Æ»®ÈÎÎñ

Ãè¡¡Êö£º¡¡Windows¼Æ»®ÈÎÎñÓÃÓÚÉ趨¼Ì³ÐÔÚʲôʱ¼ä»òÕßʲôÈÕÆÚ±¸·Ý»òÕßÔËÐС£

½é¡¡ÉÜ£º¼Æ»®ÈÎÎñ£¬Ëüͨ¹ý×¢²á±í×ÔÆô¶¯¡£Òò´Ë£¬Í¨¹ý¼Æ»®ÈÎÎñ³ÌÐòʵÏÖ×ÔÆô¶¯µÄ³ÌÐòÔÚϵͳÐÅÏ¢Öп´²»µ½ËüµÄÎļþÃû£¬Ò»µ©°ÑËü´Ó×¢²á±íÖÐɾ³ý»ò½ûÓã¬ÄÇôͨ¹ý¼Æ»®ÈÎÎñÆô¶¯µÄ³ÌÐòÈ«²¿²»ÄÜ×Ô¶¯ÔËÐС£win9XÏÂϵͳÆô¶¯¾Í»á¿ªÆô¼Æ»®ÈÎÎñ£¬¿ÉÒÔͨ¹ýË«»÷¼Æ»®ÈÎÎñͼ±ê£­¸ß¼¶£­ÖÕÖ¹¼Æ»®ÈÎÎñÀ´Í£Ö¹Ëü×ÔÆô¶¯¡£ÁíÍ⣬¹¥»÷ÕßÔÚ¹¥»÷¹ý³ÌÖУ¬Ò²¾­³£Óõ½¼Æ»®ÈÎÎñ£¬°üÀ¨ÉÏ´«Îļþ¡¢ÌáÉýȨÏÞ¡¢ÖÖÖ²ºóÃÅ¡¢Çåɨ½ÅÓ¡µÈ¡£

£¨16£©£§regsvc¡£exe£§

½ø³ÌÎļþ£º¡¡regsvc¡¡or¡¡regsvc¡£exe

½ø³ÌÃû³Æ£º¡¡Ô¶³Ì×¢²á±í·þÎñ

Ãè¡¡Êö£º¡¡Ô¶³Ì×¢²á±í·þÎñÓÃÓÚ·ÃÎÊÔÚÔ¶³Ì¼ÆËã»úµÄ×¢²á±í¡£

£¨17£©£§rpcss¡£exe£§

½ø³ÌÎļþ£º¡¡rpcss¡¡or¡¡rpcss¡£exe

½ø³ÌÃû³Æ£º¡¡RPC¡¡Portmapper

Ãè¡¡Êö£º¡¡Windows¡¡µÄRPC¶Ë¿ÚÓ³Éä½ø³Ì´¦ÀíRPCµ÷Óã¨Ô¶³ÌÄ£¿éµ÷Óã©È»ºó°ÑËüÃÇÓ³Éä¸øÖ¸¶¨µÄ·þÎñÌṩÕß¡£

½é¡¡ÉÜ£º98Ëü²»ÊÇÔÚ×°ÔؽâÊÍÆ÷ʱ»òÒýµ¼Ê±Æô¶¯£¬Èç¹ûʹÓÃÖÐÓÐÎÊÌ⣬¿ÉÒÔÖ±½ÓÔÚÔÚ×¢²á±íHKEY_LOCAL_MACHINESOFTWARE¡¡MicrosoftWindowsCurrentVersionRun

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices¡¡Ìí¼Ó¡¨×Ö·û´®Öµ¡¨£¬¶¨Ïòµ½¡¨C£ºWINDOWSSYSTEMRPCSS¡¨¼´¿É¡£

£¨18£©£§services¡£exe£§

½ø³ÌÎļþ£º¡¡services¡¡or¡¡services¡£exe

½ø³ÌÃû³Æ£º¡¡Windows¡¡Service¡¡Controller

Ãè¡¡Êö£º¡¡¹ÜÀíWindows·þÎñ¡£

½é¡¡ÉÜ£º´ó¶àÊýµÄϵͳºËÐÄģʽ½ø³ÌÊÇ×÷Ϊϵͳ½ø³ÌÔÚÔËÐС£´ò¿ª¹ÜÀí¹¤¾ßÖеķþÎñ£¬¿ÉÒÔ¿´µ½Óкܶà·þÎñ¶¼ÊÇÔÚµ÷Óã¥systemroot£¥system32¡¡service¡£exe

£¨19£©£§smss¡£exe£§

½ø³ÌÎļþ£º¡¡smss¡¡or¡¡smss¡£exe

½ø³ÌÃû³Æ£º¡¡Session¡¡Manager¡¡Subsystem

Ãè¡¡Êö£º¡¡¸Ã½ø³ÌΪ»á»°¹ÜÀí×ÓϵͳÓÃÒÔ³õʼ»¯ÏµÍ³±äÁ¿£¬MS¡­DOSÇý¶¯Ãû³ÆÀàËÆLPT1ÒÔ¼°£¬µ÷ÓÃWin32¿Ç×ÓϵͳºÍÔËÐÐÔÚWindowsµÇ½¹ý³Ì¡£

¼ò¡¡½é£ºÕâÊÇÒ»¸ö»á»°¹ÜÀí×Óϵͳ£¬¸ºÔðÆô¶¯Óû§»á»°¡£Õâ¸ö½ø³ÌÊÇͨ¹ýϵͳ½ø³Ì³õʼ»¯µÄ²¢ÇÒ¶ÔÐí¶à»î¶¯µÄ£¬°üÀ¨ÒѾ­ÕýÔÚÔËÐеġ¡Winlogon£¬Win32£¨Csrss¡£exe£©Ï̺߳ÍÉ趨µÄϵͳ±äÁ¿×÷³ö·´Ó³¡£ÔÚËüÆô¶¯ÕâЩ½ø³Ìºó£¬ËüµÈ´ýWinlogon»òÕßCsrss½áÊø¡£Èç¹ûÕâЩ¹ý³ÌʱÕý³£µÄ£¬ÏµÍ³¾Í¹ØµôÁË¡£Èç¹û·¢ÉúÁËʲô²»¿ÉÔ¤ÁϵÄÊÂÇ飬smss¡£exe¾Í»áÈÃϵͳֹͣÏìÓ¦£¨¾ÍÊǹÒÆ𣩡£

£¨20£©£§snmp¡£exe£§

½ø³ÌÎļþ£º¡¡snmp¡¡or¡¡snmp¡£exe

½ø³ÌÃû³Æ£º¡¡Microsoft¡¡SNMP¡¡Agent

Ãè¡¡Êö£º¡¡Windows¼òµ¥µÄÍøÂçЭÒé´úÀí£¨SNMP£©ÓÃÓÚ¼àÌýºÍ·¢ËÍÇëÇóµ½Êʵ±µÄÍøÂ粿·Ö¡£

¼ò¡¡½é£º¸ºÔð½ÓÊÕSNMPÇëÇó±¨ÎÄ£¬¸ù¾ÝÒªÇó·¢ËÍÏìÓ¦±¨ÎIJ¢´¦ÀíÓëWinsockAPIµÄ½Ó¿Ú¡£

£¨21£©£§spool32¡£exe£§

½ø³ÌÎļþ£º¡¡spool32¡¡or¡¡spool32¡£exe

½ø³ÌÃû³Æ£º¡¡Printer¡¡Spooler

Ãè¡¡Êö£º¡¡Windows´òÓ¡ÈÎÎñ¿ØÖƳÌÐò£¬ÓÃÒÔ´òÓ¡»ú¾ÍÐ÷¡£

£¨22£©£§spoolsv¡£exe£§

½ø³ÌÎļþ£º¡¡spoolsv¡¡or¡¡spoolsv¡£exe

½ø³ÌÃû³Æ£º¡¡Printer¡¡Spooler¡¡Service

Ãè¡¡Êö£º¡¡Windows´òÓ¡ÈÎÎñ¿ØÖƳÌÐò£¬ÓÃÒÔ´òÓ¡»ú¾ÍÐ÷¡£

½é¡¡ÉÜ£º»º³å£¨spooler£©·þÎñÊǹÜÀí»º³å³ØÖеĴòÓ¡ºÍ´«Õæ×÷Òµ¡£

£¨23£©£§stisvc¡£exe£§

½ø³ÌÎļþ£º¡¡stisvc¡¡or¡¡stisvc¡£exe

½ø³ÌÃû³Æ£º¡¡Still¡¡Image¡¡Service

Ãè¡¡Êö£º¡¡Still¡¡Image¡¡ServiceÓÃÓÚ¿ØÖÆɨÃèÒǺÍÊýÂëÏà»úÁ¬½ÓÔÚWindows¡£

£¨24£©£§svchost¡£exe£§

½ø³ÌÎļþ£º¡¡svchost¡¡or¡¡svchost¡£exe

½ø³ÌÃû³Æ£º¡¡Service¡¡Host¡¡Process

Ãè¡¡Êö£º¡¡Service¡¡Host¡¡ProcessÊÇÒ»¸ö±ê×¼µÄ¶¯Ì¬Á¬½Ó¿âÖ÷»ú´¦Àí·þÎñ¡£

½é¡¡ÉÜ£ºSvchost¡£exeÎļþ¶ÔÄÇЩ´Ó¶¯Ì¬Á¬½Ó¿âÖÐÔËÐеķþÎñÀ´ËµÊÇÒ»¸öÆÕͨµÄÖ÷»ú½ø³ÌÃû¡£Svhost¡£exeÎļþ¶¨Î»ÔÚϵͳµÄ£¥systemroot£¥system32Îļþ¼ÐÏ¡£ÔÚÆô¶¯µÄʱºò£¬Svchost¡£exe¼ì²é×¢²á±íÖеÄλÖÃÀ´¹¹½¨ÐèÒª¼ÓÔصķþÎñÁÐ±í¡£Õâ¾Í»áʹ¶à¸öSvchost¡£exeÔÚͬһʱ¼äÔËÐС£Ã¿¸öSvchost¡£exeµÄ»Ø»°Æڼ䶼°üº¬Ò»×é·þÎñ£¬ÒÔÖÁÓÚµ¥¶ÀµÄ·þÎñ±ØÐëÒÀ¿¿Svchost¡£exeÔõÑùºÍÔÚÄÇÀïÆô¶¯¡£ÕâÑù¾Í¸ü¼ÓÈÝÒ׿ØÖƺͲéÕÒ´íÎó¡£windows¡¡2kÒ»°ãÓÐ2¸ösvchost½ø³Ì£¬Ò»¸öÊÇRPCSS£¨Remote¡¡Procedure¡¡Call£©·þÎñ½ø³Ì£¬ÁíÍâÒ»¸öÔòÊÇÓɺܶà·þÎñ¹²ÏíµÄÒ»¸ösvchost¡£exe¡£¶øÔÚwindows¡¡XPÖУ¬ÔòÒ»°ãÓÐ4¸öÒÔÉϵÄsvchost¡£exe·þÎñ½ø³Ì£¬windows¡¡2003¡¡serverÖÐÔò¸ü¶à¡£

£¨25£©£§taskmon¡£exe£§

½ø³ÌÎļþ£º¡¡taskmon¡¡or¡¡taskmon¡£exe

½ø³ÌÃû³Æ£º¡¡Windows¡¡Task¡¡Optimizer

Ãè¡¡Êö£º¡¡windowsÈÎÎñÓÅ»¯Æ÷¼àÊÓÄãʹÓÃij¸ö³ÌÐòµÄƵÂÊ£¬²¢ÇÒͨ¹ý¼ÓÔ
СÌáʾ£º°´ »Ø³µ [Enter] ¼ü ·µ»ØÊéÄ¿£¬°´ ¡û ¼ü ·µ»ØÉÏÒ»Ò³£¬ °´ ¡ú ¼ü ½øÈëÏÂÒ»Ò³¡£ ÔÞһϠÌí¼ÓÊéÇ©¼ÓÈëÊé¼Ü