Posted: 2004/5¤ë/31 11:02¤W¤È | IP°O¿ý
|
|
|
Windows 2000/XP ªº¥ô°ÈºÞ²z¾¹¬O¤@Ó«D±`¦³¥Îªº¤u¨ã¡A¥¦¯à´£¨Ñ§Ú̫ܦh°T®§¡A¤ñ¦p²{¦b¨t²Î¤¤°õ¦æªºµ{¦¡¡]¶iµ{¡^¡A¦ý¬O±¹ï¨º¨Ç¤å¥ó¥i°õ¦æ¤å¥ó¦W§Ú Ì¥i¯à¦³ÂI¯íµM¡A¤£ª¾¹D¥¦Ì¬O°µ¤°»òªº¡A·|¤£·|¦³¥iºÃ¶iµ{¡]¯f¬r¡A¤ì°¨µ¥¡^¡C¥»¤åªº¥Øªº´N¬O´£¨Ñ¤@¨Ç±`¥ÎªºWindows 2000 ¤¤ªº¶iµ{¦W¡A¨Ã²³æ»¡©ú¥¦Ìªº¥Î³B¡C ’’¦b WINDOWS 2000 ¤¤,¨t²Î¥]§t¥H¤U¯Ê¬Ù¶iµ{¡G ’Â’ÂCsrss.exe ’Â’ÂExplorer.exe ’Â’ÂInternat.exe ’Â’ÂLsass.exe ’Â’ÂMstask.exe ’Â’ÂSmss.exe ’Â’ÂSpoolsv.exe ’Â’ÂSvchost.exe ’Â’ÂServices.exe ’Â’ÂSystem ’Â’ÂSystem Idle Process ’Â’ÂTaskmgr.exe ’Â’ÂWinlogon.exe ’Â’ÂWinmgmt.exe
’’¤U±¦C¥X§ó¦hªº¶iµ{©M¥¦ÌªºÂ²n»¡©ú
’’¶iµ{¦W’’’’’’´yz
’Â’Âsmss.exe’Â’Â’Â’Â’ÂSession’ÂManager ’Â’Âcsrss.exe ’’’’¤l¨t²ÎªA°È¾¹¶iµ{ ’Â’Âwinlogon.exe’’’º޲z¨Ï¥ÎªÌµn¿ý ’Â’Âservices.exe’Â’Â’Â¥]§t«Ü¦h¨t²ÎªA°È ’Â’Âlsass.exe ’’’’º޲z IP ¦w¥þµ¦²¤¥H¤Î±Ò°Ê ISAKMP/Oakley (IKE) ©M IP ¦w¥þÅX°Êµ{¦¡¡C ’Â’Âsvchost.exe’Â’Â’Â Windows 2000/XP ªº¤å¥ó«OÅ@¨t²Î ’Â’ÂSPOOLSV.EXE ’’’±N¤å¥ó¥[¸ü¨ì¤º¦s¤¤¥H«K¿ð«á¦C¦L¡C) ’Â’Âexplorer.exe’’’¸귽ºÞ²z¾¹ ’Â’Âinternat.exe’’’¦«½L°Ïªº«÷µ¹Ï¥Ü) ’Â’Âmstask.exe’’’’¤¹³\µ{¦¡¦b«ü©w®É¶¡°õ¦æ¡C ’Â’Âregsvc.exe’’’’¤¹³\»·µ{µù¥Uªí¾Þ§@¡C(¨t²ÎªA°È)->remoteregister ’Â’Âwinmgmt.exe ’’’´£¨Ñ¨t²ÎºÞ²z°T®§(¨t²ÎªA°È)¡C ’Â’Âinetinfo.exe’Â’Â’Âmsftpsvc,w3svc,iisadmn ’Â’Âtlntsvr.exe ’Â’Â’Âtlnrsvr ’Â’Âtftpd.exe ’’’’¹ê²{ TFTP Internet ¼Ð·Ç¡C¸Ó¼Ð·Ç¤£n¨D¨Ï¥ÎªÌ¦W©M±K½X¡C ’Â’Âtermsrv.exe ’Â’Â’Âtermservice ’Â’Âdns.exe ’Â’Â’Â’Â’ÂÀ³µª¹ï°ì¦W¨t²Î(DNS)¦WºÙªº¬d¸ß©M§ó·s½Ð¨D¡C ’Â’Âtcpsvcs.exe ’’’´£¨Ñ¦b PXE ¥i»·µ{±Ò°Ê«È¤á¹q¸£¤W»·µ{¦w¸Ë Windows 2000 Professional ªº¯à¤O¡C ’Â’Âismserv.exe ’’’¤¹³\¦b Windows Advanced Server ºô¯¸¶¡µo°e©M±µ¦¬®ø®§¡C ’Â’Âups.exe ’’’’’º޲z³s±µ¨ì¹q¸£ªº¤£¶¡Â_¹q·½(UPS)¡C ’Â’Âwins.exe’’’’’¬°µù¥U©M¸ÑªR NetBIOS «¬¦WºÙªº TCP/IP «È¤á´£¨Ñ NetBIOS ¦WºÙªA°È¡C ’Â’Âllssrv.exe’Â’Â’Â’ÂÃҮѰO¿ýªA°È ’Â’Ântfrs.exe ’’’’¦b¦hÓªA°È¾¹¶¡ºûÅ@¤å¥ó¥Ø¿ý¤º®eªº¤å¥ó¦P¨B¡C ’Â’ÂRsSub.exe ’’’’±±¨î¥Î¨Ó»·µ{Àx¦s¸ê®Æªº´CÅé¡C ’Â’Âlocator.exe ’’’º޲z RPC ¦WºÙªA°È¸ê®Æ®w¡C ’Â’Âlserver.exe ’’’µù¥U«È¤áºÝ³\¥iÃÒ¡C ’Â’Âdfssvc.exe’’’’º޲z¤À§G©ó§½°ìºô©Î¼s°ìºôªºÅÞ¿è¨÷¡C ’Â’Âclipsrv.exe ’’’¤ä«ù¡u°Å¶Kï¬d¬Ý¾¹¡v¡A¥H«K¥i¥H±q»·µ{°Å¶Kï¬d¾\°Å¶Kºô¶¡C ’Â’Âmsdtc.exe ’’’’¨æC¨Æ°È¡A¬O¤À§G©ó¨âÓ¥H¤Wªº¸ê®Æ®w¡A®ø®§¶¤¦C¡A¤å¥ó¨t²Î©Î¨ä¥¦¨Æ°È«OÅ@Å@¸ê·½ºÞ²z¾¹¡C ’Â’Âfaxsvc.exe’Â’Â’Â’ÂÀ°§U±zµo°e©M±µ¦¬¶Ç¯u¡C ’Â’Âcisvc.exe ’’’’¯Á¤ÞªA°È ’Â’Âdmadmin.exe ’’’ºϽLºÞ²z½Ð¨Dªº¨t²ÎºÞ²zªA°È¡C ’Â’Âmnmsrvc.exe ’’’¤¹³\¦³Åvªº¨Ï¥ÎªÌ¨Ï¥Î NetMeeting »·µ{³X°Ý Windows ®à±¡C ’Â’Ânetdde.exe’’’’´£¨Ñ°ÊºA¸ê®Æ¥æ´« (DDE) ªººôµ¸¶Ç¿é©M¦w¥þ¯S©Ê¡C ’Â’Âsmlogsvc.exe’’’°t¸m©Ê¯à¤é»x©Mĵ³ø¡C ’Â’Ârsvp.exe’’’’’¬°¨Ì¿à½è¶qªA°È(QoS)ªºµ{¦¡©M±±¨îÀ³¥Îµ{¦¡´£¨Ñºôµ¸«H¸¹©M¥»¦a³q«H±±¨î¦w¸Ë¥\¥\¯à¡C ’Â’ÂRsEng.exe ’’’’¨ó½Õ¥Î¨ÓÀx¦s¤£±`¥Î¸ê®ÆªºªA°È©MºÞ²z¤u¨ã¡C ’Â’ÂRsFsa.exe ’’’’º޲z»·µ{Àx¦sªº¤å¥óªº¾Þ§@¡C ’Â’Âgrovel.exe’’’’±½ºË¹s³Æ¥÷Àx¦s(SIS)±²¤Wªº«½Æ¤å¥ó¡A¨Ã¥B±N«½Æ¤å¥ó«ü¦V¤@Ó¸ê®ÆÀx¦sÂI¡A¥H¸`¬ÙºÏ½LªÅ¶¡ ¡]¥u¹ï NTFS ¤å¥ó¨t²Î¦³¥Î¡^¡C ’Â’ÂSCardSvr.ex ’’’¹ﴡ¤J¦b¹q¸£´¼¯à¥d¾\Ū¾¹¤¤ªº´¼¯à¥d¶i¦æºÞ²z©M³X°Ý±±¨î¡C ’Â’Âsnmp.exe’Â’Â’Â’Â’Â¥]§t¥N²zµ{¦¡¥i¥HºÊµøºôµ¸³]³Æªº¬¡°Ê¨Ã¥B¦Vºôµ¸±±¨î¥x¤u§@¯¸¶×³ø¡C ’Â’Âsnmptrap.exe’’’±µ¦¬¥Ñ¥»¦a©Î»·µ{ SNMP ¥N²zµ{¦¡²£¥Íªº³´¨À¡]trap¡^®ø®§¡AµM«á±N®ø®§¶Ç»¼¨ì°õ¦æ¦b³o¥x¹q¸£¤W SNMP ºÞ²zµ{¦¡¡C ’Â’ÂUtilMan.exe ’’’±q¤@Óµøµ¡¤¤±Ò°Ê©M°t¸m»²§U¤u¨ã¡C ’Â’Âmsiexec.exe’Â’Â’Â¨Ì¾Ú .MSI ¤å¥ó¤¤¥]§tªº©R¥O¨Ó¦w¸Ë¡B×´_¥H¤Î§R°£³nÅé¡C
’Â’ÂÁ`µ²¡G µo²{¥iºÃ¶iµ{ªº¯µ³Z´N¬On¦h¬Ý¥ô°ÈºÞ²z¾¹¤¤ªº¶iµ{¦Cªí¡A¬Ý¦h¤F¥H«á¡A¤@²´´N¥i¥Hµo²{¥i¥iºÃ¶iµ{¡A´N¹³§ä¤@¸s¼ô±x¤H¤¤ªº¯¥Í¤H¤@¼Ë ¡C
|