ÈÎÎñ¹ÜÀíÆ÷ÀïÃæµÄ½ø³ÌÊÇʲô¶«Î÷,ÎÒÊDzËÄñ,˵µÄÔ½ÏêϸԽºÃ,лл,ÈçÓÐÂúÒâ´ð°¸ÎÒ³ö¸ß·Ö

January 6th, 2009
jsrk.com edit
ÈÎÎñ¹ÜÀíÆ÷ÀïÃæµÄ½ø³ÌÊÇʲô¶«Î÷,ÎÒÊDzËÄñ,˵µÄÔ½ÏêϸԽºÃ,лл,ÈçÓÐÂúÒâ´ð°¸ÎÒ³ö¸ß·Ö
ÔËÐеijÌÐò°¡!
¾ÍÊǵçÄÔÏÖÔÚÕýÔÚÆô¶¯×ŵijÌÐò,
ÓÐʱºòÒ»¸ö³ÌÐò²»Ò»¶¨ÊÇÒ»¸öÄã¿ÉÒÔ¿´µ½µÄ´°¿Ú»òÕßÓÒϽǵÄͼ±í,
ºÜ¶àÊÇ×Ô¶¯Æô¶¯×ŵÄ.µ«ÄãǧÍò²»ÄÜÂҹرÕ.ÓеÄÊǵçÄÔÀï×Ô¼ºµÄ³ÌÐò.ÓÐЩÊÇÄã¾³£Ó¦ÓõÄ.±ÈÈçÄãµÄÊäÈë·¨,ÏÔ¿¨¿ØÖƵÈ.ÁíÍâһЩÓпÉÄÜÊDz¡¶¾µÈ.
Èç¹ûÊÇÐÂÊֵϰ,¿ÉÒÔÀûÓÃһЩÈí¼þ¶Ô½ø³Ì½øÐзÖÎö.
±ÈÈçµ½www.3721.com yahooÖúÊÖÀïÓнø³Ì¹ÜÀí,»òÕßÏÂÔØwindows ÓÅ»¯´óʦµÈÈí¼þ.
×î¼Ñ´ð°¸ - ÓÉͶƱÕß2008-06-05 00:28:13Ñ¡³ö
ºÜ¶àÓû§¶¼¶ÔÓÚ×Ô¼º»úÆ÷µÄ½ø³Ì²»ÊǺÜÃ÷°×£¬ÓÐʱ×ÜÎóÈÏΪÊDz¡¶¾µÄ½ø³Ì£¬Ï£Íû½éÉÜһЩϵͳµÄС֪ʶ£¬±ãÓÚ´ó¼ÒʹÓüÆËã»ú¡£
×î»ù±¾µÄϵͳ½ø³Ì£¨Ò²¾ÍÊÇ˵£¬ÕâЩ½ø³ÌÊÇϵͳÔËÐеĻù±¾Ìõ¼þ£¬ÓÐÁËÕâЩ½ø³Ì£¬ÏµÍ³¾ÍÄÜÕý³£ÔËÐУ©:
smss.exe Session Manager
csrss.exe ×Óϵͳ·þÎñÆ÷½ø³Ì
winlogon.exe ¹ÜÀíÓû§µÇ¼
services.exe °üº¬ºÜ¶àϵͳ·þÎñ
lsass.exe ¹ÜÀí IP °²È«²ßÂÔÒÔ¼°Æô¶¯ ISAKMP/Oakley (IKE) ºÍ IP °²È«Çý¶¯³ÌÐò¡£(ϵͳ·þÎñ)
²úÉú»á»°ÃÜÔ¿ÒÔ¼°ÊÚÓèÓÃÓÚ½»»¥Ê½¿Í»§/·þÎñÆ÷ÑéÖ¤µÄ·þÎñƾ¾Ý(ticket)¡£(ϵͳ·þÎñ)
svchost.exe °üº¬ºÜ¶àϵͳ·þÎñ
SPOOLSV.EXE ½«Îļþ¼ÓÔØµ½ÄÚ´æÖÐÒÔ±ã³Ùºó´òÓ¡¡£(ϵͳ·þÎñ)
explorer.exe ×ÊÔ´¹ÜÀíÆ÷
internat.exe ÍÐÅÌÇøµÄÆ´Òôͼ±ê
¸½¼ÓµÄϵͳ½ø³Ì£¨ÕâЩ½ø³Ì²»ÊDZØÒªµÄ£¬Äã¿ÉÒÔ¸ù¾ÝÐèҪͨ¹ý·þÎñ¹ÜÀíÆ÷À´Ôö¼Ó»ò¼õÉÙ£©:
mstask.exe ÔÊÐí³ÌÐòÔÚÖ¸¶¨Ê±¼äÔËÐС£(ϵͳ·þÎñ)
regsvc.exe ÔÊÐíÔ¶³Ì×¢²á±í²Ù×÷¡£(ϵͳ·þÎñ)
winmgmt.exe Ìṩϵͳ¹ÜÀíÐÅÏ¢(ϵͳ·þÎñ)¡£
inetinfo.exe ͨ¹ý Internet ÐÅÏ¢·þÎñµÄ¹ÜÀíµ¥ÔªÌṩ FTP Á¬½ÓºÍ¹ÜÀí¡£(ϵͳ·þÎñ)
tlntsvr.exe ÔÊÐíÔ¶³ÌÓû§µÇ¼µ½ÏµÍ³²¢ÇÒʹÓÃÃüÁîÐÐÔËÐпØÖÆÌ¨³ÌÐò¡£(ϵͳ·þÎñ)
ÔÊÐíͨ¹ý Internet ÐÅÏ¢·þÎñµÄ¹ÜÀíµ¥Ôª¹ÜÀí Web ºÍ FTP ·þÎñ¡£(ϵͳ·þÎñ)
tftpd.exe ʵÏÖ TFTP Internet ±ê×¼¡£¸Ã±ê×¼²»ÒªÇóÓû§ÃûºÍÃÜÂë¡£Ô¶³Ì°²×°·þÎñµÄÒ»²¿·Ö¡£(ϵͳ·þÎñ)
termsrv.exe Ìṩ¶à»á»°»·¾³ÔÊÐí¿Í»§¶ËÉ豸·ÃÎÊÐéÄâµÄ Windows 2000 Professional ×ÀÃæ»á»°ÒÔ¼°ÔËÐÐÔÚ·þÎñÆ÷ÉϵĻù
ÓÚ Windows µÄ³ÌÐò¡£(ϵͳ·þÎñ)
dns.exe Ó¦´ð¶ÔÓòÃûϵͳ(DNS)Ãû³ÆµÄ²éѯºÍ¸üÐÂÇëÇó¡£(ϵͳ·þÎñ)
ÒÔÏ·þÎñºÜÉÙ»áÓõ½£¬ÉÏÃæµÄ·þÎñ¶¼¶Ô°²È«Óк¦£¬Èç¹û²»ÊDZØÒªµÄÓ¦¸Ã¹Øµô
tcpsvcs.exe ÌṩÔÚ PXE ¿ÉÔ¶³ÌÆô¶¯¿Í»§¼ÆËã»úÉÏÔ¶³Ì°²×° Windows 2000 Professional µÄÄÜÁ¦¡£(ϵͳ·þÎñ)
Ö§³ÖÒÔÏ TCP/IP ·þÎñ£ºCharacter Generator, Daytime, Discard, Echo, ÒÔ¼° Quote of the Day¡£(ϵͳ·þÎñ)
ismserv.exe ÔÊÐíÔÚ Windows Advanced Server Õ¾µã¼ä·¢ËͺͽÓÊÕÏûÏ¢¡£(ϵͳ·þÎñ)
ups.exe ¹ÜÀíÁ¬½Óµ½¼ÆËã»úµÄ²»¼ä¶ÏµçÔ´(UPS)¡£(ϵͳ·þÎñ)
wins.exe Ϊע²áºÍ½âÎö NetBIOS ÐÍÃû³ÆµÄ TCP/IP ¿Í»§Ìṩ NetBIOS Ãû³Æ·þÎñ¡£(ϵͳ·þÎñ)
llssrv.exe License Logging Service(system service)
ntfrs.exe ÔÚ¶à¸ö·þÎñÆ÷¼äά»¤ÎļþĿ¼ÄÚÈݵÄÎļþͬ²½¡£(ϵͳ·þÎñ)
RsSub.exe ¿ØÖÆÓÃÀ´Ô¶³Ì´¢´æÊý¾ÝµÄýÌå¡£(ϵͳ·þÎñ)
locator.exe ¹ÜÀí RPC Ãû³Æ·þÎñÊý¾Ý¿â¡£(ϵͳ·þÎñ)
lserver.exe ×¢²á¿Í»§¶ËÐí¿ÉÖ¤¡£(ϵͳ·þÎñ)
dfssvc.exe ¹ÜÀí·Ö²¼ÓÚ¾ÖÓòÍø»ò¹ãÓòÍøµÄÂß¼¾í¡£(ϵͳ·þÎñ)
clipsrv.exe Ö§³Ö¡°¼ôÌù²¾²é¿´Æ÷¡±£¬ÒÔ±ã¿ÉÒÔ´ÓÔ¶³Ì¼ôÌù²¾²éÔļôÌùÒ³Ãæ¡£(ϵͳ·þÎñ)
msdtc.exe ²¢ÁÐÊÂÎñ£¬ÊÇ·Ö²¼ÓÚÁ½¸öÒÔÉϵÄÊý¾Ý¿â£¬ÏûÏ¢¶ÓÁУ¬Îļþϵͳ£¬»òÆäËüÊÂÎñ±£»¤×ÊÔ´¹ÜÀíÆ÷¡£(ϵͳ·þÎñ)
faxsvc.exe °ïÖúÄú·¢ËͺͽÓÊÕ´«Õæ¡£(ϵͳ·þÎñ)
cisvc.exe Indexing Service(system service)
dmadmin.exe ´ÅÅ̹ÜÀíÇëÇóµÄϵͳ¹ÜÀí·þÎñ¡£(ϵͳ·þÎñ)
mnmsrvc.exe ÔÊÐíÓÐȨÏÞµÄÓû§Ê¹Óà NetMeeting Ô¶³Ì·ÃÎÊ Windows ×ÀÃæ¡£(ϵͳ·þÎñ)
netdde.exe Ìṩ¶¯Ì¬Êý¾Ý½»»» (DDE) µÄÍøÂç´«ÊäºÍ°²È«ÌØÐÔ¡£(ϵͳ·þÎñ)
smlogsvc.exe ÅäÖÃÐÔÄÜÈÕÖ¾ºÍ¾¯±¨¡£(ϵͳ·þÎñ)
rsvp.exe ΪÒÀÀµÖÊÁ¿·þÎñ(QoS)µÄ³ÌÐòºÍ¿ØÖÆÓ¦ÓóÌÐòÌá¹©ÍøÂçÐźźͱ¾µØÍ¨ÐÅ¿ØÖư²×°¹¦ÄÜ¡£(ϵͳ·þÎñ)
RsEng.exe е÷ÓÃÀ´´¢´æ²»³£ÓÃÊý¾ÝµÄ·þÎñºÍ¹ÜÀí¹¤¾ß¡£(ϵͳ·þÎñ)
RsFsa.exe ¹ÜÀíÔ¶³Ì´¢´æµÄÎļþµÄ²Ù×÷¡£(ϵͳ·þÎñ)
grovel.exe ɨÃèÁ㱸·Ý´æ´¢(SIS)¾íÉϵÄÖØ¸´Îļþ£¬²¢ÇÒ½«Öظ´ÎļþÖ¸ÏòÒ»¸öÊý¾Ý´æ´¢µã£¬ÒÔ½ÚÊ¡´ÅÅ̿ռ䡣(ϵͳ·þÎñ)
SCardSvr.exe ¶Ô²åÈëÔÚ¼ÆËã»úÖÇÄÜ¿¨ÔĶÁÆ÷ÖеÄÖÇÄÜ¿¨½øÐйÜÀíºÍ·ÃÎÊ¿ØÖÆ¡£(ϵͳ·þÎñ)
snmp.exe °üº¬´úÀí³ÌÐò¿ÉÒÔ¼àÊÓÍøÂçÉ豸µÄ»î¶¯²¢ÇÒÏòÍøÂç¿ØÖÆÌ¨¹¤×÷Õ¾»ã±¨¡£(ϵͳ·þÎñ)
snmptrap.exe ½ÓÊÕÓɱ¾µØ»òÔ¶³Ì SNMP ´úÀí³ÌÐò²úÉúµÄÏÝÚåÏûÏ¢£¬È»ºó½«ÏûÏ¢´«µÝµ½ÔËÐÐÔÚÕą̂¼ÆËã»úÉÏ SNMP ¹ÜÀí³ÌÐò
¡£(ϵͳ·þÎñ)
UtilMan.exe ´ÓÒ»¸ö´°¿ÚÖÐÆô¶¯ºÍÅäÖø¨Öú¹¤¾ß¡£(ϵͳ·þÎñ)
msiexec.exe ÒÀ¾Ý .MSI ÎļþÖаüº¬µÄÃüÁîÀ´°²×°¡¢ÐÞ¸´ÒÔ¼°É¾³ýÈí¼þ¡£(ϵͳ·þÎñ)
Ïêϸ˵Ã÷£º
win2kÔËÐнø³Ì
Svchost.exe
Svchost.exeÎļþ¶ÔÄÇЩ´Ó¶¯Ì¬Á¬½Ó¿âÖÐÔËÐеķþÎñÀ´ËµÊÇÒ»¸öÆÕͨµÄÖ÷»ú½ø³ÌÃû¡£Svhost.exeÎļþ¶¨Î»
ÔÚϵͳµÄ%systemroot%system32Îļþ¼ÐÏ¡£ÔÚÆô¶¯µÄʱºò£¬Svchost.exe¼ì²é×¢²á±íÖеÄλÖÃÀ´¹¹½¨ÐèÒª
¼ÓÔØµÄ·þÎñÁÐ±í¡£Õâ¾Í»áʹ¶à¸öSvchost.exeÔÚͬһʱ¼äÔËÐС£Ã¿¸öSvchost.exeµÄ»Ø»°ÆÚ¼ä¶¼°üº¬Ò»×é·þÎñ£¬
ÒÔÖÁÓÚµ¥¶ÀµÄ·þÎñ±ØÐëÒÀ¿¿Svchost.exeÔõÑùºÍÔÚÄÇÀïÆô¶¯¡£ÕâÑù¾Í¸ü¼ÓÈÝÒ׿ØÖƺͲéÕÒ´íÎó¡£
Svchost.exe ×éÊÇÓÃÏÂÃæµÄ×¢²á±íÖµÀ´Ê¶±ð¡£
HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionSvchost
ÿ¸öÔÚÕâ¸ö¼üϵÄÖµ´ú±íÒ»¸ö¶ÀÁ¢µÄSvchost×飬²¢ÇÒµ±ÄãÕýÔÚ¿´»î¶¯µÄ½ø³Ìʱ£¬ËüÏÔʾ×÷Ϊһ¸öµ¥¶ÀµÄ
Àý×Ó¡£Ã¿¸ö¼üÖµ¶¼ÊÇREG_MULTI_SZÀàÐ͵ÄÖµ¶øÇÒ°üÀ¨ÔËÐÐÔÚSvchost×éÄڵķþÎñ¡£Ã¿¸öSvchost×é¶¼°üº¬Ò»¸ö
»ò¶à¸ö´Ó×¢²á±íÖµÖÐѡȡµÄ·þÎñÃû£¬Õâ¸ö·þÎñµÄ²ÎÊýÖµ°üº¬ÁËÒ»¸öServiceDLLÖµ¡£
HKEY_LOCAL_MACHINESystemCurrentControlSetServicesService
explorer.exe
ÕâÊÇÒ»¸öÓû§µÄshell£¨ÎÒʵÔÚÊDz»ÖªµÀÔõô·Òëshell£©£¬ÔÚÎÒÃÇ¿´ÆðÀ´¾ÍÏñÈÎÎñÌõ£¬×ÀÃæµÈµÈ¡£Õâ¸ö
½ø³Ì²¢²»ÊÇÏñÄãÏëÏóµÄÄÇÑùÊÇ×÷Ϊһ¸öÖØÒªµÄ½ø³ÌÔËÐÐÔÚwindowsÖУ¬Äã¿ÉÒÔ´ÓÈÎÎñ¹ÜÀíÆ÷ÖÐÍ£µôËü£¬»òÕßÖØÐÂÆô¶¯¡£
ͨ³£²»»á¶Ôϵͳ²úÉúʲô¸ºÃæÓ°Ïì¡£
internat.exe
Õâ¸ö½ø³ÌÊÇ¿ÉÒÔ´ÓÈÎÎñ¹ÜÀíÆ÷ÖйصôµÄ¡£
internat.exeÔÚÆô¶¯µÄʱºò¿ªÊ¼ÔËÐС£Ëü¼ÓÔØÓÉÓû§Ö¸¶¨µÄ²»Í¬µÄÊäÈëµã¡£ÊäÈëµãÊÇ´Ó×¢²á±íµÄÕâ¸öλÖÃ
HKEY_USERS.DEFAULTKeyboard LayoutPreload ¼ÓÔØÄÚÈݵġ£
internat.exe ¼ÓÔØ¡°EN¡±Í¼±ê½øÈëϵͳµÄͼ±êÇø£¬ÔÊÐíʹÓÃÕß¿ÉÒÔºÜÈÝÒ×µÄת»»²»Í¬µÄÊäÈëµã¡£
µ±½ø³ÌÍ£µôµÄʱºò£¬Í¼±ê¾Í»áÏûʧ£¬µ«ÊÇÊäÈëµãÈÔÈ»¿ÉÒÔͨ¹ý¿ØÖÆÃæ°åÀ´¸Ä±ä¡£
lsass.exe
Õâ¸ö½ø³ÌÊDz»¿ÉÒÔ´ÓÈÎÎñ¹ÜÀíÆ÷ÖйصôµÄ¡£
ÕâÊÇÒ»¸ö±¾µØµÄ°²È«ÊÚȨ·þÎñ£¬²¢ÇÒËü»áΪʹÓÃwinlogon·þÎñµÄÊÚȨÓû§Éú³ÉÒ»¸ö½ø³Ì¡£Õâ¸ö½ø³ÌÊÇ
ͨ¹ýʹÓÃÊÚȨµÄ°ü£¬ÀýÈçĬÈϵÄmsgina.dllÀ´Ö´Ðеġ£Èç¹ûÊÚȨÊdzɹ¦µÄ£¬lsass¾Í»á²úÉúÓû§µÄ½øÈë
ÁîÅÆ£¬ÁîÅÆ±ðʹÓÃÆô¶¯³õʼµÄshell¡£ÆäËûµÄÓÉÓû§³õʼ»¯µÄ½ø³Ì»á¼Ì³ÐÕâ¸öÁîÅÆµÄ¡£
mstask.exe
Õâ¸ö½ø³ÌÊDz»¿ÉÒÔ´ÓÈÎÎñ¹ÜÀíÆ÷ÖйصôµÄ¡£
ÕâÊÇÒ»¸öÈÎÎñµ÷¶È·þÎñ£¬¸ºÔðÓû§ÊÂÏȾö¶¨ÔÚijһʱ¼äÔËÐеÄÈÎÎñµÄÔËÐС£
smss.exe
Õâ¸ö½ø³ÌÊDz»¿ÉÒÔ´ÓÈÎÎñ¹ÜÀíÆ÷ÖйصôµÄ¡£
ÕâÊÇÒ»¸ö»á»°¹ÜÀí×Óϵͳ£¬¸ºÔðÆô¶¯Óû§»á»°¡£Õâ¸ö½ø³ÌÊÇͨ¹ýϵͳ½ø³Ì³õʼ»¯µÄ²¢ÇÒ¶ÔÐí¶à»î¶¯µÄ£¬
°üÀ¨ÒѾÕýÔÚÔËÐеÄWinlogon£¬Win32£¨Csrss.exe£©Ï̺߳ÍÉ趨µÄϵͳ±äÁ¿×÷³ö·´Ó³¡£ÔÚËüÆô¶¯ÕâЩ
½ø³Ìºó£¬ËüµÈ´ýWinlogon»òÕßCsrss½áÊø¡£Èç¹ûÕâЩ¹ý³ÌʱÕý³£µÄ£¬ÏµÍ³¾Í¹ØµôÁË¡£Èç¹û·¢ÉúÁËʲô
²»¿ÉÔ¤ÁϵÄÊÂÇ飬smss.exe¾Í»áÈÃϵͳֹͣÏìÓ¦£¨¾ÍÊÇ¹ÒÆð£©¡£
spoolsv.exe
Õâ¸ö½ø³ÌÊDz»¿ÉÒÔ´ÓÈÎÎñ¹ÜÀíÆ÷ÖйصôµÄ¡£
»º³å£¨spooler£©·þÎñÊǹÜÀí»º³å³ØÖеĴòÓ¡ºÍ´«Õæ×÷Òµ¡£
service.exe
Õâ¸ö½ø³ÌÊDz»¿ÉÒÔ´ÓÈÎÎñ¹ÜÀíÆ÷ÖйصôµÄ¡£
´ó¶àÊýµÄϵͳºËÐÄģʽ½ø³ÌÊÇ×÷Ϊϵͳ½ø³ÌÔÚÔËÐС£
System Idle Process
Õâ¸ö½ø³ÌÊDz»¿ÉÒÔ´ÓÈÎÎñ¹ÜÀíÆ÷ÖйصôµÄ¡£
Õâ¸ö½ø³ÌÊÇ×÷Ϊµ¥Ïß³ÌÔËÐÐÔÚÿ¸ö´¦ÀíÆ÷ÉÏ£¬²¢ÔÚϵͳ²»´¦ÀíÆäËûÏ̵߳Äʱºò·ÖÅÉ´¦ÀíÆ÷µÄʱ¼ä¡£
winlogon.exe
Õâ¸ö½ø³ÌÊǹÜÀíÓû§µÇ¼ºÍÍÆ³öµÄ¡£¶øÇÒwinlogonÔÚÓû§°´ÏÂCTRL+ALT+DELʱ¾Í¼¤»îÁË£¬ÏÔʾ°²È«¶Ô»°¿ò¡£
winmgmt.exe
winmgmtÊÇwin2000¿Í»§¶Ë¹ÜÀíµÄºËÐÄ×é¼þ¡£µ±¿Í»§¶ËÓ¦ÓóÌÐòÁ¬½Ó»òµ±¹ÜÀí³ÌÐòÐèÒªËû±¾ÉíµÄ·þÎñʱÕâ¸ö½ø³Ì³õʼ»¯
taskmagr.exe
Õâ¸ö½ø³Ì¾ÍÊÇÈÎÎñ¹ÜÀíÆ÷¡£
ÔÚÖªµÀÀïÕÒµ½²»ÉÙÖÆ×÷QQ¿Õ¼äµÄ´úÂë¡£µ«Ã¿´ÎÎÒÔÚн¨Ä£¿éÎÞÂÛÔÚÍøÖ·ÀﻹÊÇÆÀÂÛÀïÊäÈë´úÂë×îºó±£´æ¶¼Ã»ÓÐÏÔʾÏàÓ¦µÄЧ¹û£¬ÇëÎʾßÌåÖÆ×÷²½ÖèÊÇÔõÑù£¿
winXP½ø³ÌÈ«½Ó´¥
Windows 2000/XP µÄÈÎÎñ¹ÜÀíÆ÷ÊÇÒ»¸ö·Ç³£ÓÐÓõŤ¾ß£¬ËüÄÜÌṩÎÒÃǺܶàÐÅÏ¢£¬±ÈÈç
ÏÖÔÚϵͳÖÐÔËÐеijÌÐò£¨½ø³Ì£©£¬µ«ÊÇÃæ¶ÔÄÇЩÎļþ¿ÉÖ´ÐÐÎļþÃûÎÒÃÇ¿ÉÄÜÓеããȻ£¬
²»ÖªµÀËüÃÇÊÇ×öʲôµÄ£¬»á²»»áÓпÉÒɽø³Ì£¨²¡¶¾£¬Ä¾ÂíµÈ£©¡£±¾ÎĵÄÄ¿µÄ¾ÍÊÇÌṩһ
Щ³£ÓõÄWindows 2000 ÖеĽø³ÌÃû£¬²¢¼òµ¥ËµÃ÷ËüÃǵÄÓô¦¡£
ÔÚ WINDOWS 2000 ÖÐ,ϵͳ°üº¬ÒÔÏÂȱʡ½ø³Ì£º
Csrss.exe
Explorer.exe
Internat.exe
Lsass.exe
Mstask.exe
Smss.exe
Spoolsv.exe
Svchost.exe
Services.exe
System
System Idle Process
Taskmgr.exe
Winlogon.exe
Winmgmt.exe
ÏÂÃæÁгö¸ü¶àµÄ½ø³ÌºÍËüÃǵļòҪ˵Ã÷
½ø³ÌÃû ÃèÊö
smss.exe Session Manager
csrss.exe ×Óϵͳ·þÎñÆ÷½ø³Ì
winlogon.exe ¹ÜÀíÓû§µÇ¼
services.exe °üº¬ºÜ¶àϵͳ·þÎñ
lsass.exe ¹ÜÀí IP °²È«²ßÂÔÒÔ¼°Æô¶¯ ISAKMP/Oakley (IKE) ºÍ IP °²
È«Çý¶¯³ÌÐò¡£
svchost.exe Windows 2000/XP µÄÎļþ±£»¤ÏµÍ³
SPOOLSV.EXE ½«Îļþ¼Ó
ÔØµ½ÄÚ´æÖÐÒÔ±ã³Ùºó´òÓ¡¡£)
explorer.exe ×ÊÔ´¹ÜÀíÆ÷
internat.exe ÍÐÅÌÇøµÄÆ´Òôͼ±ê)
mstask.exe ÔÊÐí³ÌÐòÔÚÖ¸¶¨Ê±¼äÔËÐС£
regsvc.exe ÔÊÐíÔ¶³Ì×¢²á±í²Ù×÷¡£(ϵͳ·þÎñ)->remoteregister
winmgmt.exe Ìṩϵͳ¹ÜÀíÐÅÏ¢(ϵͳ·þÎñ)¡£
inetinfo.exe msftpsvc,w3svc,iisadmn
tlntsvr.exe tlnrsvr
tftpd.exe ʵÏÖ TFTP Internet ±ê×¼¡£¸Ã±ê×¼²»ÒªÇóÓû§ÃûºÍÃÜÂë¡£
termsrv.exe termservice
dns.exe Ó¦´ð¶ÔÓòÃûϵͳ(DNS)Ãû³ÆµÄ²éѯºÍ¸üÐÂÇëÇó¡£
tcpsvcs.exe ÌṩÔÚ PXE ¿ÉÔ¶³ÌÆô¶¯¿Í»§¼ÆËã»úÉÏÔ¶³Ì°²×° Windows
2000 Professional µÄÄÜÁ¦¡£
ismserv.exe ÔÊÐíÔÚ Windows Advanced Server Õ¾µã¼ä·¢ËͺͽÓÊÕÏûÏ¢¡£
ups.exe ¹ÜÀíÁ¬½Óµ½¼ÆËã»úµÄ²»¼ä¶ÏµçÔ´(UPS)¡£
wins.exe Ϊע²áºÍ½âÎö NetBIOS ÐÍÃû³ÆµÄ TCP/IP ¿Í»§Ìṩ NetBIOS
Ãû³Æ·þÎñ¡£
llssrv.exe Ö¤Êé¼Ç¼·þÎñ
ntfrs.exe ÔÚ¶à¸ö·þÎñÆ÷¼äά»¤ÎļþĿ¼ÄÚÈݵÄÎļþͬ²½¡£
RsSub.exe ¿ØÖÆÓÃÀ´Ô¶³Ì´¢´æÊý¾ÝµÄýÌå¡£
locator.exe ¹ÜÀí RPC Ãû³Æ·þÎñÊý¾Ý¿â¡£
lserver.exe ×¢²á¿Í»§¶ËÐí¿ÉÖ¤¡£
dfssvc.exe ¹ÜÀí·Ö²¼ÓÚ¾ÖÓòÍø»ò¹ãÓòÍøµÄÂß¼¾í¡£
clipsrv.exe Ö§³Ö¡°¼ôÌù²¾²é¿´Æ÷¡±£¬ÒÔ±ã¿ÉÒÔ´ÓÔ¶³Ì¼ôÌù²¾²éÔļôÌùÒ³
Ãæ¡£
msdtc.exe ²¢ÁÐÊÂÎñ£¬ÊÇ·Ö²¼ÓÚÁ½¸öÒÔÉϵÄÊý¾Ý¿â£¬ÏûÏ¢¶ÓÁУ¬Îļþϵͳ
»òÆäËüÊÂÎñ±£»¤»¤×ÊÔ´¹ÜÀíÆ÷¡£
faxsvc.exe °ïÖúÄú·¢ËͺͽÓÊÕ´«Õæ¡£
cisvc.exe Ë÷Òý·þÎñ
dmadmin.exe ´ÅÅ̹ÜÀíÇëÇóµÄϵͳ¹ÜÀí·þÎñ¡£
mnmsrvc.exe ÔÊÐíÓÐȨÏÞµÄÓû§Ê¹Óà NetMeeting Ô¶³Ì·ÃÎÊ Windows ×À
Ãæ¡£
netdde.exe Ìṩ¶¯Ì¬Êý¾Ý½»»» (DDE) µÄÍøÂç´«ÊäºÍ°²È«ÌØÐÔ¡£
smlogsvc.exe ÅäÖÃÐÔÄÜÈÕÖ¾ºÍ¾¯±¨¡£
rsvp.exe ΪÒÀÀµÖÊÁ¿·þÎñ(QoS)µÄ³ÌÐòºÍ¿ØÖÆÓ¦ÓóÌÐòÌá¹©ÍøÂçÐźźÍ
±¾µØÍ¨ÐÅ¿ØÖư²×°¹¦¹¦ÄÜ¡£
RsEng.exe е÷ÓÃÀ´´¢´æ²»³£ÓÃÊý¾ÝµÄ·þÎñºÍ¹ÜÀí¹¤¾ß¡£
RsFsa.exe ¹ÜÀíÔ¶³Ì´¢´æµÄÎļþµÄ²Ù×÷¡£
grovel.exe ɨÃèÁ㱸·Ý´æ´¢(SIS)¾íÉϵÄÖØ¸´Îļþ£¬²¢ÇÒ½«Öظ´ÎļþÖ¸Ïò
Ò»¸öÊý¾Ý´æ´¢µã£¬ÒÔ½ÚÊ¡´ÅÅ̿ռ䣨ֻ¶Ô NTFS ÎļþϵͳÓÐÓã©¡£
SCardSvr.ex ¶Ô²åÈëÔÚ¼ÆËã»úÖÇÄÜ¿¨ÔĶÁÆ÷ÖеÄÖÇÄÜ¿¨½øÐйÜÀíºÍ·ÃÎÊ¿Ø
ÖÆ¡£
snmp.exe °üº¬´úÀí³ÌÐò¿ÉÒÔ¼àÊÓÍøÂçÉ豸µÄ»î¶¯²¢ÇÒÏòÍøÂç¿ØÖÆÌ¨¹¤×÷
Õ¾»ã±¨¡£
snmptrap.exe ½ÓÊÕÓɱ¾µØ»òÔ¶³Ì SNMP ´úÀí³ÌÐò²úÉúµÄÏÝÚ壨trap£©ÏûÏ¢£¬
È»ºó½«ÏûÏ¢´«µÝµ½ÔËÐÐÔÚÕą̂¼ÆËã»úÉÏ SNMP ¹ÜÀí³ÌÐò¡£
UtilMan.exe ´ÓÒ»¸ö´°¿ÚÖÐÆô¶¯ºÍÅäÖø¨Öú¹¤¾ß¡£
msiexec.exe ÒÀ¾Ý .MSI ÎļþÖаüº¬µÄÃüÁîÀ´°²×°¡¢ÐÞ¸´ÒÔ¼°É¾³ýÈí¼þ¡£
ÁíÍâ,ÓкܶàÅóÓѶ¼ÓÐÕâÑùµÄÒÉÎÊ:ÎҵĿª»ú½ø³ÌÀïÓÐsmss.exeºÍcsrss.exeÁ½¸öÎļþ£¬
ÓÐʲô×÷Óã¿
½ø³ÌÎļþ: smss or smss.exe
½ø³ÌÃû³Æ: Session Manager Subsystem
ÃèÊö: ¸Ã½ø³ÌΪ»á»°¹ÜÀí×ÓϵͳÓÃÒÔ³õʼ»¯ÏµÍ³±äÁ¿£¬MS-DOSÇý¶¯Ãû³ÆÀàËÆLPT1ÒÔ¼°
COM£¬µ÷ÓÃWin32¿Ç×ÓϵͳºÍÔËÐÐÔÚWindowsµÇ½¹ý³Ì¡£
³£¼û´íÎó: N/A
ÊÇ·ñΪϵͳ½ø³Ì: ÊÇ
½ø³ÌÎļþ: csrss or csrss.exe
½ø³ÌÃû³Æ: Client/Server Runtime Server Subsystem
ÃèÊö: ¿Í»§¶Ë·þÎñ×Óϵͳ£¬ÓÃÒÔ¿ØÖÆWindowsͼÐÎÏà¹Ø×Óϵͳ¡£
³£¼û´íÎó: N/A
ÊÇ·ñΪϵͳ½ø³Ì: ÊÇ
ËùÒÔ,¶Ô×Ô¼º²»ÊìϤ ûÓаÑÎյĽø³Ì, ²»ÒªËæ±ã½áÊøËü.½¨Òé:°ÑÄãÈÏΪÓÐÎÊÌâµÄ½ø³Ì±È
Èç"csrss.exe",ÔÚgoogleÀïËÑË÷"csrss.exe",¾Í»á»ñµÃÏà¹ØµÄ֪ʶ.
»¹Óв»ÖªµÀµÄ¾Í¿´Õâ¸öÍøÕ¾£ºhttp://www.dofile.com ½ø³Ì֪ʶ¿â
ÔÚwww.3721.comÀïÃæ¿ÉÒԲ鿴ÏêϸµÄ½ø³Ì˵Ã÷¡£
http://www.dofile.com/glworld/default.htm
Äã×Ô¼º¿´°É
#If you have any other info about this subject , Please add it free.# |