¤Þ¦Û
http://www.ck56.com/db/showthread.php?t=83702
svchost.exe¬ONT®Ö¤ß¨t²Î«D±`«nªºÀɮסA¹ï©óWin2000/XP¨Ó»¡¡A¤£¥i©Î¯Ê¡C³o¨Çsvchost¶i«×´£¨Ñ«Ü¦h¨t²ÎªA°È¡A¦p¡G rpcssªA°È¡]remote procedure call¡^¡BdmserverªA°È¡]logical disk manager¡^¡BdhcpªA°È¡]dhcp client¡^µ¥µ¥¡C
YªGnÁA¸Ñ¨CÓsvchost¶i«×¨ì©³´£¨Ñ¤F¦h¤Ö¨t²ÎªA°È¡A¥i¥H¦bWinXPªº«ü¥O´£¥Ü²Åµøµ¡¤¤¿é¤J¡utasklist /svc¡v«ü¥O¨ÓÀ˵ø¡C
¤u§@ì²z
¤@¯ë¨Ó»¡¡AWindows¨t²Î¶i«×¤À¬°¿W¥ß¶i«×©M¦@¨É¶i«×¨âºØ¡Csvchost.exeÀɮצs¦b©ó%systemroot%\system32¥Ø¿ý¤U¡AÄÝ©ó¦@¨É¶i«×¡C
ÀHµÛWindows¨t²ÎªA°È¤£Â_¼W¦h¡A¬°¤F¸`¬Ù¨t²Î¸ê·½¡A·L³n§â«Ü¦hªA°È³£°µ¦¨¦@¨É¼Ò¦¡¡A¥æ¥Ñsvchost¶i«×¨Ó±Ò°Ê¡C¦ýsvchost¶i«×¥u§@¬°ªA°È±J¥D¡A¨Ã¤£¯à¹ê²{¥ô¦óªA°È¥\¯à¡A§Y¥¦¥u¯à´£¨Ñ±ø¥óÅý¨ä¥LªA°È¦b³o¸Ì³Q±Ò°Ê¡A¦Ó¥¦¦Û¤v«o¤£¯àµ¹¨Ï¥ÎªÌ´£¨Ñ¥ô¦óªA°È¡C
³o¨ÇªA°È¬O¦p¦ó¹ê²{ªº©O?ì¨Ó³o¨Ç¨t²ÎªA°È¬O¥H°ÊºA³sµ²®w¡]dll¡^§Î¦¡¹ê²{ªº¡A¥¦Ì§â¥i°õ¦æµ{¦¡«ü¦Vsvchost¡A¥Ñsvchost©I¥s¬ÛÀ³ªA°Èªº°ÊºA³sµ²®w¨Ó±Ò°ÊªA°È¡C
¨ºsvchost¤S«ç»òª¾¹D¬YÓ¨t²ÎªA°È¸Ó©I¥sþӰʺA³sµ²®w©O?³o¬O³q¹L¨t²ÎªA°È¦bµù¥Uªí¤¤³]©wªº°Ñ¼Æ¨Ó¹ê²{ªº¡C
¨ãÅé¹ê¨Ò....
¤U±¥HRemote RegistryªA°È¬°¨Ò¡A¨Ó¬Ý¬Ýsvchost¶i«×¬O¦p¦ó©I¥sDLLÀɮתº¡C¦bWinXP¤¤¡AÂIÀ»¡u¶}©l¡÷°õ¦æ¡v¡A¿é¤J¡uservices.msc¡v«ü¥O¡A·|¸õ¥XªA°È¹ï¸Ü®Ø¡AµM«á¶}±Ò¡uRemote Registry¡vÄݩʹï¸Ü®Ø¡A¥i¥H¬Ý¨ìRemote RegistryªA°Èªº¥i°õ¦æÀɮתº¸ô®|¬°¡uC:\Windows\System32\svchost -k LocalService¡v¡A³o»¡©úRemote RegistryªA°È¬O¨Ì¾asvchost©I¥s¡uLocalService¡v°Ñ¼Æ¨Ó¹ê²{ªº¡A¦Ó°Ñ¼Æªº¤º®e«h¬O¦s©ñ¦b¨t²Îµù¥Uªí¤¤ªº¡C
¦b°õ¦æ¹ï¸Ü®Ø¤¤¿é¤J¡uregedit.exe¡v«áEnter¡A¶}±Òµù¥Uªí½s¿è¾¹¡A§ä¨ì¡uHKEY_LOCAL_MACHINE\System\currentcontrolset\services\Remote Registry¡v¶µ¡A¦A§ä¨ìÃþ«¬¬°¡ureg_expand_sz¡vªº¡uImagepath¡v¶µ¡A¨äÁäȬ°¡u%systemroot%\system32 \svchost -k LocalService¡v¡]³o´N¬O¦bªA°Èµøµ¡¤¤¬Ý¨ìªºªA°È±Ò°Ê«ü¥O¡^¡A¥t¥~¦b¡uparameters¡v¦¸¾÷½X¤¤¦³Ó¦W¬°¡uServiceDll¡vªºÁä¡A¨äȬ°¡u% systemroot%\system32\regsvc.dll¡v¡A¨ä¤¤¡uregsvc.dll¡v´N¬ORemote RegistryªA°Èn¨Ï¥Îªº°ÊºA³sµ²®wÀɮסC³o¼Ësvchost¶i«×³q¹LŪ¨ú¡uRemote Registry¡vªA°Èµù¥Uªí°T®§¡A´N¯à±Ò°Ê¸ÓªA°È¤F¡C
¤]¥¿¬O¦]¬°svchostªº«n©Ê¡A©Ò¥H¯f¬r¡B¤ì°¨¤]·QºÉ¿ìªk¨Ó§Q¥Î¥¦¡A¥ø¹Ï§Q¥Î¥¦ªº¯S©Ê¨Ó°g´b¨Ï¥ÎªÌ¡A¹F¨ì·P¬V¡B¤J«I¡B¯}Ãaªº¥Øªº¡C¨º»òÀ³¸Ó¦p¦ó§PÂ_¨ì©³þÓ¬O¯f¬r¶i«×©O?¼Ð·Çªºsvchost.exeÀÉ®×À³¸Ó¦s¦b©ó¡uC:\Windows\system32¡v¥Ø¿ý¤U¡AYªGµo²{¸ÓÀÉ®×¥X²{¦b¨ä¥L¥Ø¿ý¤U´Nn¤p¤ß¤F¡C
´£¥Ü¡Gsvchost.exeÀɮתº©I¥s¸ô®|¥i¥H³q¹L¡u¨t²Î°T®§¡÷³nÅéÀô¹Ò¡÷¥¿¦b°õ¦æ¥ô°È¡v¨ÓÀ˵ø
----------------------------------------------------------------------------------------------------
¤Þ¦Û
http://1984.9hy.com/contents/1156767750.phtml
* ¤¤¤F
SVOHOST.EXE¤ì°¨~·Ð¦º¤F~
µoªí©ó 2006-08-28 19:51:03µoªí©ó2006-08-2819:51:03
³o2¤ÑÁ`·|²ö¦W¨ä§®ªº³s¤W¤@Óºô¯¸~~¬Ý¤F±Ò°Ê¶µ~ùر¦h¤FÓSVOHOST~¤£¥J²Ó¬Ý·|¥H¬°¬OSVCHOST~`«á±¨ºÓ¬O¥¿±`ªº¨t²Î¶iµ{~`·íµM¥¦¥²¶·¬O¦bsystem32¥Ø¿ý¤Uªº~`¦pªG¥L¥X²{¦b¨ä¥L¥Ø¿ý~¨º100%¬O¯f¬r~`` ³o2¤ÑÁ`·|²ö¦W¨ä§®ªº³s¤W¤@Óºô¯¸~~¬Ý¤F±Ò°Ê¶µ~¸Ì±¦h¤FÓSVOHOST~¤£¥J²Ó¬Ý·|¥H¬°¬OSVCHOST~`«á±¨ºÓ¬O¥¿±`ªº¨t²Î¶iµ{~`·íµM¥¦¥²¶·¬O¦bsystem32¥Ø¿ý¤Uªº~`¦pªG¥L¥X²{¦b¨ä¥L¥Ø¿ý~¨º100%¬O¯f¬r~``
¥´¶}¶iµ{µo²{SVOHOST.exe¶iµ{~`«D±`¥iºÃ~´N§ä¨ì¤F¥Lªº©Ò¦b¥Ø¿ý~¦bSYSTEM32 ¤U~«Ü©_©Çªº¬O§Ú©~µM§ä¤£¨ì¥¦~³s·j¯Á³£·j¤£¨ì~`¬JµM¥¦¦b¶iµ{ùبº´N»¡©ú¥¦ªÖ©w¦b¨ºÓ¥Ø¿ýùØ~`¨S¿ìªk§Ú¥u¦nBAIDU¤@¤U¤F~ÁÙ§ä¨ì¤F¤£¤Ö¸ê®Æ~`¥´¶}¶iµ{µo²{SVOHOST.exe¶iµ{~`«D±`¥iºÃ~´N§ä¨ì¤F¥Lªº©Ò¦b¥Ø¿ý~¦bSYSTEM32 ¤U~«Ü©_©Çªº¬O§Ú©~µM§ä¤£¨ì¥¦~³s·j¯Á³£·j¤£¨ì~`¬JµM¥¦¦b¶iµ{¸Ì¨º´N»¡©ú¥¦ªÖ©w¦b¨ºÓ¥Ø¿ý¸Ì~`¨S¿ìªk§Ú¥u¦nBAIDU¤@¤U¤F~ÁÙ§ä¨ì¤F¤£¤Ö¸ê®Æ~`
ì¨Ó³oºØ¤ì°¨³Ìªñ«Ü¬y¦æ~¥Dn¬OµsQQ¸¹ªº~¯gª¬´N¸ò§Ú¹q¸£¤@¼Ë~¤ì°¨Àɧ䤣¨ì~¦Ó¥B´Nºâ¦b±Ò°Ê¶µ¥h±¼¥L«±Ò¥H«á¥¦¤S·|¦A¶ñ¤W~¨ä¹ê¥¦§Q¥Î¤@Ó¤ñ¸û²³æªºì²z~´N¬O×§ïµù¥UªíÅý¹q¸£µLªkÅã¥ÜÁôÂÃÀÉ~©Ò¥H¦pªG§A¦b·j¯Áùر¤£§âÁôÂÃÀɳoÓ¿ï¶µ¤Ä¤Wªº¸Ü~`·j¯Á¤]§ä¤£¨ì~``ì¨Ó³oºØ¤ì°¨³Ìªñ«Ü¬y¦æ~¥Dn¬OµsQQ¸¹ªº~¯gª¬´N¸ò§Ú¹q¸£¤@¼Ë~¤ì°¨Àɧ䤣¨ì~¦Ó¥B´Nºâ¦b±Ò°Ê¶µ¥h±¼¥L«±Ò¥H«á¥¦¤S·|¦A¶ñ¤W~¨ä¹ê¥¦§Q¥Î¤@Ó¤ñ¸û²³æªºì²z~´N¬O×§ïµù¥UªíÅý¹q¸£µLªkÅã¥ÜÁôÂäå¥ó~©Ò¥H¦pªG§A¦b·j¯Áùر¤£§âÁôÂäå¥ó³oÓ¿ï¶µ¤Ä¤Wªº¸Ü~`·j¯Á¤]§ä¤£¨ì~``
¸Ñ¨M¤èªk«Ü²³æ~¥un×§ïµù¥UªíÅýÁôÂÃÀÉÅã¥Ü´N§R±¼´N¥i¥H¤F~`¥´¶}µù¥UªíHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft \Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\¸Ñ¨M¤èªk«Ü²³æ~¥un×§ïµù¥UªíÅýÁôÂäå¥óÅã¥Ü´N§R±¼´N¥i¥H¤F~`¥´¶}µù¥UªíHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft \Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\
SHOWALL³oÓÁä.¬Ý¥kÃä.§ä¨ì¤@ÓCheckedValueªºÈ.³oÓäú¤ßªº¯f¬r©~µM§â¥L§ï¦¨¤F¦r¦êÈ.§A§ï¤F¤]¨S¥Î.§â³oÓȧR°£.««Ø¤@ÓDWORDªºÈ¬°CheckedValue.§â¥LªºÈ³]¬°1.´N¦æ¤F~SHOWALL³oÓÁä.¬Ý¥kÃä.§ä¨ì¤@ÓCheckedValueªºÈ.³oÓäú¤ßªº¯f¬r©~µM§â¥L§ï¦¨¤F¦r¦êÈ.§A§ï¤F¤]¨S¥Î.§â³oÓȧR°£.««Ø¤@ÓDWORDªºÈ¬°CheckedValue.§â¥LªºÈ³]¬°1.´N¦æ¤F~
«OÀI°_¨£¡G³Ì¦n¥h¦¿¥Áºô¯¸¤UÓÅ]ªi±M±þ
http://www.jiangmin.com/download/mo...ocbotkiller.exe
¤£ª¾¹D¬O¤£¬O³oӤ차·dªº¥¦¦b¨CÓ½L¤U±³£·s«Ø¤FÓ¦Û¹B¦æÀÉ~¨ãÅ餺®e¨S¬Ý¨ì~`§Ú¤]¬OµL·N¤§¶¡¤U¤FÓ³oÓ±þ¤Fªº~ ¤£ª¾¹D¬O¤£¬O³oӤ차·dªº¥¦¦b¨CÓ½L¤UÄѳ£·s«Ø¤FÓ¦Û¹B¦æ¤å¥ó~¨ãÅ餺®e¨S¬Ý¨ì~`§Ú¤]¬OµL·N¤§¶¡¤U¤FÓ³oÓ±þ¤Fªº~