ÎÒ¿ª»úÌáʾc:\windows\svchost.exeÕÒ²»µ½ÁË ¸ß·Ö¶í

January 8th, 2009
jsrk.com edit
ÎÒ¿ª»úÌáʾc:windowssvchost.exeÕÒ²»µ½ÁË ¸ß·Ö¶í
×î¼Ñ´ð°¸ - ÓÉͶƱÕß2008-06-05 06:05:17Ñ¡³ö
Ê×ÏÈ£¬²»±ØÔÙÈ¥ÕÒsvchost.exe
ÏµÍ³ÕæÕý×Ô´øµÄsvchost.exeµÄĿ¼Ӧ¸ÃÊÇc:windowssystem32svchost.exe £¨XP£©£¬
c:windowssvchost.exeϵÄÒ»¶¨ÊDz¡¶¾£¬ÄãÇå³ýÁ˲¡¶¾£¬µ«¿ÉÄÜÆô¶¯ÏîÀﻹûÓÐÇåÀí
°´ÕÕÏÂÃæ·½·¨×ö¼´¿É
¿ªÊ¼--ÔËÐÐ--ÊäÈëMSCONFIG--´ò¿ªºóÑ¡Ôñ¡®Æô¶¯¡¯--ÔÚÁбíÖÐÕÒµ½c:windowssvchost.exeÏà¹ØµÄ£¬È¥µôÇ°ÃæµÄ¹´
È»ºó¿ªÊ¼--ÔËÐÐ--ÊäÈëREGEDIT--´ò¿ª×¢²á±í--·Ö±ðÕ¹¿ªÒÔÏÂÁ½Ïî 01:HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun 02:HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunOnce
ÕÒµ½c:windowssvchost.exeÏà¹ØµÄɾ³ý¼´¿É
Çмǣ¬Ò»¶¨Òª¿´Çå³þÔÙɾ³ý£¬Èç¹ûÔÚÉÏÃæ½éÉܵÄÀïÃæÕÒµ½ÓкÍsvchost.exeÏà¹ØµÄ£¬¿´Çå³þ£¬Èç¹ûÖ¸Ïòc:windowssystem32svchost.exe¾ÍǧÍò²»ÒªÉ¾³ý
Ö»ÓÐÖ¸Ïòc:windowssvchost.exeµÄ²Åɾ³ý
Svchost.exeÎļþ¶ÔÄÇЩ´Ó¶¯Ì¬Á¬½Ó¿âÖÐÔËÐеķþÎñÀ´ËµÊÇÒ»¸öÆÕͨµÄÖ÷»ú½ø³ÌÃû¡£Svhost.exeÎļþ¶¨Î»ÔÚϵͳµÄ%systemroot%system32Îļþ¼ÐÏ¡£ÔÚÆô¶¯µÄʱºò£¬Svchost.exe¼ì²é×¢²á±íÖеÄλÖÃÀ´¹¹½¨ÐèÒª¼ÓÔØµÄ·þÎñÁÐ±í¡£Õâ¾Í»áʹ¶à¸öSvchost.exeÔÚͬһʱ¼äÔËÐС£Ã¿¸öSvchost.exeµÄ»Ø»°ÆÚ¼ä¶¼°üº¬Ò»×é·þÎñ£¬ÒÔÖÁÓÚµ¥¶ÀµÄ·þÎñ±ØÐëÒÀ¿¿Svchost.exeÔõÑùºÍÔÚÄÇÀïÆô¶¯¡£
windows ϵͳ·þÎñ·ÖΪ¶ÀÁ¢½ø³ÌºÍ¹²Ïí½ø³ÌÁ½ÖÖ£¬ÔÚwindows NTʱֻÓзþÎñÆ÷¹ÜÀíÆ÷SCM£¨Services.exe£©Óжà¸ö¹²Ïí·þÎñ£¬Ëæ×ÅϵͳÄÚÖ÷þÎñµÄÔö¼Ó£¬ÔÚwindows 2000ÖÐmsÓְѺܶà·þÎñ×ö³É¹²Ïí·½Ê½£¬ÓÉsvchost.exeÆô¶¯¡£windows 2000Ò»°ãÓÐ2¸ösvchost½ø³Ì£¬Ò»¸öÊÇRPCSS£¨Remote Procedure Call£©·þÎñ½ø³Ì£¬ÁíÍâÒ»¸öÔòÊÇÓɺܶà·þÎñ¹²ÏíµÄÒ»¸ösvchost.exe¡£¶øÔÚwindows XPÖУ¬ÔòÒ»°ãÓÐ4¸öÒÔÉϵÄsvchost.exe·þÎñ½ø³Ì£¬windows 2003 serverÖÐÔò¸ü¶à£¬¿ÉÒÔ¿´³ö°Ñ¸ü¶àµÄϵͳÄÚÖ÷þÎñÒÔ¹²Ïí½ø³Ì·½Ê½ÓÉsvchostÆô¶¯ÊÇmsµÄÒ»¸öÇ÷ÊÆ¡£ÕâÑù×öÔÚÒ»¶¨³Ì¶ÈÉϼõÉÙÁËϵͳ×ÊÔ´µÄÏûºÄ£¬²»¹ýÒ²´øÀ´Ò»¶¨µÄ²»Îȶ¨ÒòËØ£¬ÒòΪÈκÎÒ»¸ö¹²Ïí½ø³ÌµÄ·þÎñÒòΪ´íÎóÍ˳ö½ø³Ì¾Í»áµ¼ÖÂÕû¸ö½ø³ÌÖеÄËùÓзþÎñ¶¼Í˳ö¡£ÁíÍâËü»¹°üº¬ºÜ¶àϵͳ·þÎñ .µ«ÊÇÓÐÒ»µã°²È«Òþ»¼,³å»÷²¨£¬Ò²»á¸ÐȾËü.
¿ÉÄÜÊÇÄ㽫ϵͳÖеÄSvchost.exeÎļþɾÁË£¬»òÕßÊÇSvchost.exeÎļþ¸ÐȾÁ˲¡¶¾£¬É±¶¾Èí¼þ½«ËüɾÁË¡£Äã¿ÉÒÔ´ÓÁíÍâһ̨ͬϵͳµÄµçÄÔÉÏ¿½Ò»Svchost.exeÎļþ½øÈ¥ÊÔÊÔ
svchostÊǹؼü½ø³Ì£¬¶øÇÒϵͳÀïÖ»ÓÐÒ»¸ö£¬²»¿ÉÄÜÕÒ²»µ½£¬ËùÒÔÏÈɱ¶¾¡£
svchost.exe³ö´í³å»÷²¨²¡¶¾ÊÇÀûÓÃÁË΢ÈíϵͳµÄRPC©¶´½øÐеĹ¥»÷£¬Éæ¼°µÄ²Ù×÷ϵͳÓУºwinnt¡¢win2k¡¢winxp¡¢windows server 2003£»µçÄÔ±»¹¥»÷ºóµÄ±íÏÖ£ºÏµÍ³×ÊÔ´Õ¼Óýϴó£¬ÓÐʱµ¯³öRPC·þÎñÖÕÖ¹µÄ¶Ô»°¿ò£¬ÏµÍ³·´¸´ÖØÆô¡£Ò²ÓÐÓû§¿ÉÄܲ»ÄÜÔÚIEÖдò¿ªÐ´°¿Ú£¬IEÉÏÍø²»Õý³££¬windows²»Äܸ´ÖÆÕ³ÌùµÈÆæ¹ÖÏÖÏó¡£
´Óϵͳ½Ç¶È˵£¬Èç¹û¼ì²éwindowsϵͳĿ¼ÏµÄÁ½¸ö²¡¶¾Îļþ£º%systemroot%system32winssvchost.exe£»
%systemroot%system32winsdllhost.exe£»
%systemroot%ÊÇÖ¸µÄÄãµÄwindows2000»òXPµÄ°²×°Ä¿Â¼,Ò»°ãÊÇ c:WINDOWS»òc:WINNT£¬Èç¹û´æÔÚÕâÁ½¸öÎļþ,Ôò»úÆ÷ÒѾȾÉϲ¡¶¾¡£
´¦Àí·½·¨Ò»£º
×ÜÌå˼·£ºÏÈ´ò²¹¶¡£¬ºóɱ¶¾¡£
1¡¢´ò²¹¶¡£º Win2000 :Ö´ÐÐWindows2000-KB823980-x86-CHS[url=http://www.hengshui.com/temp/lyz/3/Windows2000-KB823980-x86-CHS.exe][/url]
Win XP: Ö´ÐÐWindowsXP-KB823980-x86-CHShttp://www.hengshui.com/temp/lyz/3/WindowsXP-KB823980-x86-CHS.exe
´¦Àí·½·¨¶þ£º£¨ÊÖ¹¤Çå³ýµÄ·½·¨£©
Ò»¡¢Ê¹ÓÃÆô¶¯ÅÌ£¬ÔÚDOS»·¾³ÏÂÇå³ý²¡¶¾¡£1.µ±Óû§ÖÐÕгöÏÖÒÔÉÏÏÖÏóºó£¬ÓÃDOSϵͳÆô¶¯ÅÌÆô¶¯½øÈëDOS»·¾³Ï£¬½øÈëCÅ̵IJÙ×÷ϵͳĿ¼.²Ù×÷ÃüÁ£ºC:CD C:windows (»òCD c:winnt) 2.²éÕÒĿ¼Öеġ°msblast.exe¡±²¡¶¾Îļþ¡£ÃüÁî²Ù×÷¼¯£ºdir msblast.exe /s/p
3.ÕÒµ½ºó½øÈ벡¶¾ËùÔÚµÄ×ÓĿ¼£¬È»ºóÖ±½Ó½«¸Ã²¡¶¾Îļþɾ³ý¡£Del msblast.exe
¶þ¡¢½øÈ밲ȫģʽ£¬ÊÖ¹¤Çå³ý²¡¶¾Èç¹ûÓû§ÊÖͷûÓÐDOSÆô¶¯ÅÌ£¬»¹ÓÐÒ»¸ö·½·¨£¬¾ÍÊÇÆô¶¯ÏµÍ³ºó½øÈ밲ȫģʽ£¬È»ºóËÑË÷CÅÌ£¬²éÕÒmsblast.exeÎļþ£¬ÕÒµ½ºóÖ±½Ó½«¸ÃÎļþɾ³ý£¬È»ºóÔÙ´ÎÕý³£Æô¶¯¼ÆËã»ú¼´¿É¡£µ±Óû§ÊÖ¹¤Çå³ýÁ˲¡¶¾Ìåºó£¬Ó¦ÉÏÍøÏȽøÈë΢ÈíÍøÕ¾£¬ÏÂÔØÏàÓ¦µÄϵͳ²¹¶¡£¬¸øÏµÍ³´òÉϲ¹¶¡¡£²¹¶¡ÏÂÔØ
֨װ»ò»¹Ô£¬ÊǺõĽâ¾ö·½·¨
windows XP ÖÐÓиötasklist.exe³ÌÐò
ÔÚCMDÏÂÔËÐÐtasklist /svc¾Í¿ÉÒÔ¿´µ½Ã¿¸ö½ø³ÌÖеķþÎñ,Èç
System Idle Process 0 ÔÝȱ
System 4 ÔÝȱ
smss.exe 444 ÔÝȱ
csrss.exe 508 ÔÝȱ
winlogon.exe 532 ÔÝȱ
services.exe 576 Eventlog, PlugPlay
lsass.exe 588 PolicyAgent, ProtectedStorage, SamSs
svchost.exe 748 DcomLaunch, TermService
svchost.exe 788 RpcSs
svchost.exe 1140 AudioSrv, Browser, CryptSvc, Dhcp, dmserver,
EventSystem, FastUserSwitchingCompatibility,
helpsvc, LanmanServer, lanmanworkstation,
Netman, Nla, RasMan, Schedule, seclogon,
SENS, SharedAccess, ShellHWDetection,
TapiSrv, Themes, TrkWks, W32Time, winmgmt,
wscsvc, wuauserv, WZCSVC
svchost.exe 1652 Dnscache
svchost.exe 1688 Alerter, LmHosts, WebClient
explorer.exe 316 ÔÝȱ
RavMon.exe 472 ÔÝȱ
ThunderMini.exe 476 ÔÝȱ
ctfmon.exe 488 ÔÝȱ
nvsvc32.exe 1396 NVSvc
RavMonD.exe 1452 RsRavMon
wdfmgr.exe 1716 UMWdf
alg.exe 1236 ALG
PortalClient.exe 1648 ÔÝȱ
cmd.exe 1928 ÔÝȱ
conime.exe 1840 ÔÝȱ
wmiprvse.exe 1384 ÔÝȱ
tasklist.exe 1264 ÔÝȱ
Ò»°ãsvchost½ø³Ì¶¼ÊÇ·þÎñ½ø³Ì£¬Èç¹ûÓиösvchost²»´ø·þÎñÃû£¬ÄÇôËü¾Í¿ÉÒÉÁË£¬Ó¦¸Ã²é¶¾¡£
ÄãÏÈ»¹Ôµ½×òÌìÄǸöϵͳ,ÔÙÓÃÉÏÃæµÄ·½·¨¿´ÊDz»ÊÇÕâ¸öSVCHOSTÓÐÎÊÌâ
http://www.itcnw.com/Article/zl/system/Windowsxp/200603/167154.htmlÕâÀïÓÐһƪÎÄÕÂ,Ò²Ðí¿ÉÒÔ°ïÄã½â¾öÎÊÌâ,È¥¿´¿´Ò»ÏÂ
#If you have any other info about this subject , Please add it free.# |