| È«ÃæÁ˽âϵͳÖÐ svchost.exe Îļþ[µçÄÔ±¨] [message #124884] |
Mi, 30 November 2005 14:56 |
|
Ô´×Ô:µçÄÔ±¨
±ÊÕß¾³£ÔÚһЩ·´²¡¶¾ÂÛ̳ÉÏä¯ÀÀʱ£¬·¢ÏÖһЩÅóÓѶÔÈÎÎñ¹ÜÀíÆ÷ÖÐ µÄsvchost½ø³Ì²»ÉõÁË
½â£¬¿´¼û´æÔÚÐí¶àsvchost½ø³Ì¾ÍÒÔΪ×Ô¼ºÖÐÁ˲¡¶¾£¬Æäʵ²»È»¡£
svchost.exeÊÇNTºËÐÄϵͳ·Ç³£ÖØÒªµÄÎļþ£¬¶ÔÓÚWin2000/XPÀ´Ëµ£¬² »¿É»òȱ¡£ÕâЩsvcho
st½ø³ÌÌṩºÜ¶àϵͳ·þÎñ£¬È磺rpcss·þÎñ£¨remote procedure call£©¡¢dmserver·þÎñ£¨
logical disk manager£©¡¢dhcp·þÎñ£¨dhcp client£©µÈµÈ¡£
Èç¹ûÒªÁ˽âÿ¸ösvchost½ø³Ìµ½µ×ÌṩÁ˶àÉÙϵͳ·þÎñ£¬¿ÉÒÔÔÚWinXP µÄÃüÁîÌáʾ·û´°¿ÚÖÐ
ÊäÈë¡°tasklist /svc¡±ÃüÁîÀ´²é¿´¡£
¹¤×÷ÔÀí
Ò»°ãÀ´Ëµ£¬Windowsϵͳ½ø³Ì·ÖΪ¶ÀÁ¢½ø³ÌºÍ¹²Ïí½ø³ÌÁ½ÖÖ¡£svchost .exeÎļþ´æÔÚÓÚ%sys
temroot%\system32Ŀ¼Ï£¬ÊôÓÚ¹²Ïí½ø³Ì¡£
Ëæ×ÅWindowsϵͳ·þÎñ²»¶ÏÔö¶à£¬ÎªÁ˽Úʡϵͳ×ÊÔ´£¬Î¢Èí°ÑºÜ¶à·þÎ ñ¶¼×ö³É¹²Ïí·½Ê½£¬½»
ÓÉsvchost½ø³ÌÀ´Æô¶¯¡£µ«svchost½ø³ÌÖ»×÷Ϊ·þÎñËÞÖ÷£¬²¢²»ÄÜʵÏÖ ÈκηþÎñ¹¦ÄÜ£¬¼´Ëü
Ö»ÄÜÌṩÌõ¼þÈÃÆäËû·þÎñÔÚÕâÀï±»Æô¶¯£¬¶øËü×Ô¼ºÈ´²»ÄܸøÓû§Ìṩ ÈκηþÎñ¡£
ÕâЩ·þÎñÊÇÈçºÎʵÏÖµÄÄØ?ÔÀ´ÕâЩϵͳ·þÎñÊÇÒÔ¶¯Ì¬Á´½Ó¿â£¨dll£© ÐÎʽʵÏֵģ¬ËüÃǰÑ
¿ÉÖ´ÐгÌÐòÖ¸Ïòsvchost£¬ÓÉsvchostµ÷ÓÃÏàÓ¦·þÎñµÄ¶¯Ì¬Á´½Ó¿âÀ´Æô ¶¯·þÎñ¡£
ÄÇsvchostÓÖÔõô֪µÀij¸öϵͳ·þÎñ¸Ãµ÷ÓÃÄĸö¶¯Ì¬Á´½Ó¿âÄØ?ÕâÊÇͨ ¹ýϵͳ·þÎñÔÚ×¢²á±í
ÖÐÉèÖõIJÎÊýÀ´ÊµÏֵġ£
¾ßÌåʵÀý
ÏÂÃæÒÔRemote Registry·þÎñΪÀý£¬À´¿´¿´svchost½ø³ÌÊÇÈçºÎµ÷ÓÃDLLÎļþµÄ¡£ÔÚWi nXPÖÐ
£¬µã»÷¡°¿ªÊ¼¡úÔËÐС±£¬ÊäÈë¡°services.msc¡±ÃüÁ»áµ¯³ö·þÎñ¶Ô »°¿ò£¬È»ºó´ò¿ª¡°Re
mote Registry¡±ÊôÐÔ¶Ô»°¿ò£¬¿ÉÒÔ¿´µ½Remote Registry·þÎñµÄ¿ÉÖ´ÐÐÎļþµÄ·¾¶Îª¡°C:
\Windows\System32\svchost -k LocalService¡±£¬Õâ˵Ã÷Remote Registry·þÎñÊÇÒÀ¿¿sv
chostµ÷Óá°LocalService¡±²ÎÊýÀ´ÊµÏֵ쬶ø²ÎÊýµÄÄÚÈÝÔòÊÇ´æ·ÅÔ Úϵͳע²á±íÖеġ£
ÔÚÔËÐжԻ°¿òÖÐÊäÈë¡°regedit.exe¡±ºó»Ø³µ£¬´ò¿ª×¢²á±í±à¼Æ÷£¬Õ Òµ½¡°HKEY_LOCAL_MA
CHINE\System\currentcontrolset\services\Remote Registry¡±ÏÔÙÕÒµ½ÀàÐÍΪ¡°reg
_expand_sz¡±µÄ¡°Imagepath¡±ÏÆä¼üֵΪ¡°%systemroot%\system 32\svchost -k Loca
lService¡±£¨Õâ¾ÍÊÇÔÚ·þÎñ´°¿ÚÖп´µ½µÄ·þÎñÆô¶¯ÃüÁ£¬ÁíÍâÔÚ¡° parameters¡±×ÓÏîÖÐ
ÓиöÃûΪ¡°ServiceDll¡±µÄ¼ü£¬ÆäֵΪ¡°% systemroot%\system32\regsvc.dll¡±£¬ÆäÖС°
regsvc.dll¡±¾ÍÊÇRemote Registry·þÎñҪʹÓõĶ¯Ì¬Á´½Ó¿âÎļþ¡£ÕâÑùsvchost½ø³Ìͨ¹ý
¶ÁÈ¡¡°Remote Registry¡±·þÎñ×¢²á±íÐÅÏ¢£¬¾ÍÄÜÆô¶¯¸Ã·þÎñÁË¡£
Ò²ÕýÊÇÒòΪsvchostµÄÖØÒªÐÔ£¬ËùÒÔ²¡¶¾¡¢Ä¾ÂíÒ²Ï뾡°ì·¨À´ÀûÓÃËü£ ¬ÆóͼÀûÓÃËüµÄÌØÐÔÀ´
ÃÔ»óÓû§£¬´ïµ½¸ÐȾ¡¢ÈëÇÖ¡¢ÆÆ»µµÄÄ¿µÄ¡£ÄÇôӦ¸ÃÈçºÎÅжϵ½µ×ÄÄ ¸öÊDz¡¶¾½ø³ÌÄØ?Õý³£
µÄsvchost.exeÎļþÓ¦¸Ã´æÔÚÓÚ¡°C:\Windows\system32¡±Ä¿Â¼Ï£¬Èç ¹û·¢ÏÖ¸ÃÎļþ³öÏÖÔÚ
ÆäËûĿ¼Ï¾ÍҪСÐÄÁË¡£
Ìáʾ£ºsvchost.exeÎļþµÄµ÷Ó÷¾¶¿ÉÒÔͨ¹ý¡°ÏµÍ³ÐÅÏ¢¡úÈí¼þ»·¾³¡ úÕýÔÚÔËÐÐÈÎÎñ¡±À´²é
¿´
--
[m[34m¡ù À´Ô´:¡¤°×ɽºÚˮվ http://bbs.neu.edu.cn¡¤[FROM: 219.216.117.159][m
|
|
|
| Re: È«ÃæÁ˽âϵͳÖÐ svchost.exe Îļþ[µçÄÔ±¨] [message #124890 ] |
Do, 01 Dezember 2005 02:09 |
|
ÔÎÁË
ǰ¼¸Ìì¸øÉ¾ÁË
¡¾ ÔÚ yuransky (Óðȼ) µÄ´ó×÷ÖÐÌáµ½: ¡¿
: Ô´×Ô:µçÄÔ±¨
: ±ÊÕß¾³£ÔÚһЩ·´²¡¶¾ÂÛ̳ÉÏä¯ÀÀʱ£¬·¢ÏÖһЩÅóÓѶÔÈÎÎñ¹ÜÀíÆ÷ÖÐ µÄsvchost½ø³Ì²»ÉõÁË
: ½â£¬¿´¼û´æÔÚÐí¶àsvchost½ø³Ì¾ÍÒÔΪ×Ô¼ºÖÐÁ˲¡¶¾£¬Æäʵ²»È»¡£
: svchost.exeÊÇNTºËÐÄϵͳ·Ç³£ÖØÒªµÄÎļþ£¬¶ÔÓÚWin2000/XPÀ´Ëµ£¬² »¿É»òȱ¡£ÕâЩsvcho
: st½ø³ÌÌṩºÜ¶àϵͳ·þÎñ£¬È磺rpcss·þÎñ£¨remote procedure call£©¡¢dmserver·þÎñ£¨
: logical disk manager£©¡¢dhcp·þÎñ£¨dhcp client£©µÈµÈ¡£
: Èç¹ûÒªÁ˽âÿ¸ösvchost½ø³Ìµ½µ×ÌṩÁ˶àÉÙϵͳ·þÎñ£¬¿ÉÒÔÔÚWinXP µÄÃüÁîÌáʾ·û´°¿ÚÖÐ
: ÊäÈë¡°tasklist /svc¡±ÃüÁîÀ´²é¿´¡£
: ¹¤×÷ÔÀí
: Ò»°ãÀ´Ëµ£¬Windowsϵͳ½ø³Ì·ÖΪ¶ÀÁ¢½ø³ÌºÍ¹²Ïí½ø³ÌÁ½ÖÖ¡£svchost .exeÎļþ´æÔÚÓÚ%sys
: ...................
--
[0m£¯ £¯¨M [5m¡¤ ¨M[0m¨•¨M ©c ¨M ©a ¨M [5m©a¨• ¨M [0;34m©g[37m¨M ¨M ¨•
[33m£¯ [37m¨M £¯ £¯ [5m¨M [0m¨M ¡¤ [1;36m©a[0m¨M ¨M ¨M ¨M [1;32mÊ® [0m¨•
£¯[33m©d [1;5;35m¨M [0m£¯[31mäÀ [1;5;36m©d [0;32mÁ¤[37m¨• ¨M[34mÓÚ [37m¡¨E[36mÓê [37m¨M [5m£¯ [0m¨•ÖÐ [1;36m©f [0;5m¨M [0m¨M [1;36mÒ» [0m©e©c
[5m£¯ [0m¡¤ £¯ ¨• ¨M [35m©e [37m¨M [5m¡¤¨M [0m¨M [5m©d [0m¨ [at] ¨M ¨M ¨M [1;33mÔÂ
[0m£¯ [1;36m£¯ [0m£¯ ¨M [5m¡¨ [0m¨M £¯ ¨M ¨M ¨M [1;31mµÄ
[0;32m©d©Î ©Ç [37m¨M ¨• [32m©• ©Ä [37m¨M¨•[32m©e ©À ©È [1;5;35mÓê
[m[1;32m¡ù À´Ô´:¡¤°×ɽºÚˮվ bbs.neu.edu.cn¡¤[FROM: 202.199.0.182][m
|
|
|