µ±Ç°Î»Öà : 145zÓÎÏ·Õ¾¡¡|¡¡´«ÆæÊÀ½ç¡¡|¡¡¼¼Êõ½Ì³Ì¡¡|¡¡

ɾ³ý´«ÆæÊÀ½çĿ¼ÏµÄwsock32.dllÎļþ¼Ð

Èȶȣº
½üÆð·¢ÏÖ²»ÉÙ·¢²¼µÄ°æ±¾´øÓÐwsock32.dll´ó¼ÒÒÔºóÌṩ»òÕßÏÂÔØÇë×¢Ò⣬·¢ÏÖ´ËÎļþÁ¢¼´É¾³ý¾Í¿É
wsock32.dllÊÇWindows SocketsÓ¦ÓóÌÐò½Ó¿Ú£¬ÓÃÓÚÖ§³ÖºÜ¶àInternetºÍÍøÂçÓ¦ÓóÌÐò¡£
ºÜ²»ÐÒµÄÄã ÄãÖж¾ÁË

“cmcc.exe”¶ñÐÔµÁºÅľÂíÈí¼þ¡£

Çå³ý·½·¨

Ò»¡¢ÇëÏÈÈ¥°ÑϵͳÉèÖÃΪ“ÏÔʾÒþ²ØÎļþ”£¬ÒòΪ²¡¶¾ÒÔÒþ²ØÊôÐÔαװ£¬²»×ö´ËÉèÖý«ÎÞ·¨¿´µ½Ëü£¬ÉèÖõķ½·¨ÈçÏ£¨Èç¹ûϵͳÒѾ­×öÁË´ËÉèÖÿÉÒÔÌø¹ýÕâÒ»²½£©£º

´ò¿ª“ÎҵĵçÄÔ”£»
ÒÀ´Î´ò¿ª²Ëµ¥“¹¤¾ß/Îļþ¼ÐÑ¡Ï»
È»ºóÔÚµ¯³öµÄ“Îļþ¼ÐÑ¡Ïî”¶Ô»°¿òÖÐÇл»µ½“²é¿´”Ò³£»
È¥µô“Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ(ÍÆ¼ö)”Ç°ÃæµÄ¶Ô¹³£¬ÈÃËü±äΪ²»Ñ¡×´Ì¬£»
ÔÚÏÂÃæµÄ“¸ß¼¶ÉèÖÔÁбí¿òÖиı䓲»ÏÔʾÒþ²ØµÄÎļþºÍÎļþ¼Ð”Ñ¡ÏîΪ“ÏÔʾËùÓÐÎļþºÍÎļþ¼Ð”Ñ¡Ï
È¥µô“Òþ²ØÒÑÖªÎļþÀàÐ͵ÄÀ©Õ¹Ãû”Ç°ÃæµÄ¶Ô¹³£¬Ò²ÈÃËü±äΪ²»Ñ¡×´Ì¬£»
×îºóµã»÷“È·¶¨”¡£

¶þ¡¢°´“Ctrl+Alt+Del”¼üµ¯³öÈÎÎñ¹ÜÀíÆ÷£¬ÕÒµ½ctfmon.exeºÍsvchost64.exe½ø³Ì£¬ÕÒµ½ËüºóÑ¡ÖÐËü²¢µã»÷“½áÊø½ø³Ì”ÒÔ½áÊøµôľÂí½ø³Ì¡£È»ºóѸËÙ×öÏÂÃæÒ»²½£¬Ö»ËùÒÔҪѸËÙÊÇÒòΪÈç¹û¶¯×÷ÂýµÄ»°£¬Ä¾Âí¿ÉÄÜ»á×Ô¶¯»Ö¸´¶øÔÙ´ÎÔËÐÐÆðÀ´£¬ÕâÑù¾ÍÎÞ·¨É¾³ýµôÆäËûľÂíÎļþÁË£»

Èý¡¢
ɾ³ý×¢²á±íÖеÄ

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunctfmon.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsvchost64.exe

Èç¹ûûÓоÍÕÒÓÐÊ²Ã´ÌØ±ðµÄÏî,È»ºóɾ³ý£¬

ɾ³ýÎļþ (ÔÚDOSÏÂɾ³ý)
´ò¿ª“¿ªÊ¼/ÔËÐД£¬ÊäÈë“cmd”ºó“È·¶¨”ÒÔ´ò¿ªDOS´°¿Ú
C:WINNTsvchost64.exe
C:WINNTsystem32ctfmon.exe

²éÕÒËùÓÐµÄ wsock32.dll È»ºóÈ«²¿É¾³ý,
c:winntsystem32wsock32.dll
µÄɾ³ý²»ÁË£¬¿ÉÒÔ²»ÀíËü¡£

ÖØÐÂÆô¶¯¾ÍOKÁË¡£