½üÆð·¢ÏÖ²»ÉÙ·¢²¼µÄ°æ±¾´øÓÐwsock32.dll´ó¼ÒÒÔºóÌṩ»òÕßÏÂÔØÇë×¢Ò⣬·¢ÏÖ´ËÎļþÁ¢¼´É¾³ý¾Í¿É
wsock32.dllÊÇWindows SocketsÓ¦ÓóÌÐò½Ó¿Ú£¬ÓÃÓÚÖ§³ÖºÜ¶àInternetºÍÍøÂçÓ¦ÓóÌÐò¡£
ºÜ²»ÐÒµÄÄã ÄãÖж¾ÁË
“cmcc.exe”¶ñÐÔµÁºÅľÂíÈí¼þ¡£
Çå³ý·½·¨
Ò»¡¢ÇëÏÈÈ¥°ÑϵͳÉèÖÃΪ“ÏÔʾÒþ²ØÎļþ”£¬ÒòΪ²¡¶¾ÒÔÒþ²ØÊôÐÔαװ£¬²»×ö´ËÉèÖý«ÎÞ·¨¿´µ½Ëü£¬ÉèÖõķ½·¨ÈçÏ£¨Èç¹ûϵͳÒѾ×öÁË´ËÉèÖÿÉÒÔÌø¹ýÕâÒ»²½£©£º
´ò¿ª“ÎҵĵçÄÔ”£»
ÒÀ´Î´ò¿ª²Ëµ¥“¹¤¾ß/Îļþ¼ÐÑ¡Ï»
È»ºóÔÚµ¯³öµÄ“Îļþ¼ÐÑ¡Ïî”¶Ô»°¿òÖÐÇл»µ½“²é¿´”Ò³£»
È¥µô“Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ(ÍÆ¼ö)”Ç°ÃæµÄ¶Ô¹³£¬ÈÃËü±äΪ²»Ñ¡×´Ì¬£»
ÔÚÏÂÃæµÄ“¸ß¼¶ÉèÖÔÁбí¿òÖиı䓲»ÏÔʾÒþ²ØµÄÎļþºÍÎļþ¼Ð”Ñ¡ÏîΪ“ÏÔʾËùÓÐÎļþºÍÎļþ¼Ð”Ñ¡Ï
È¥µô“Òþ²ØÒÑÖªÎļþÀàÐ͵ÄÀ©Õ¹Ãû”Ç°ÃæµÄ¶Ô¹³£¬Ò²ÈÃËü±äΪ²»Ñ¡×´Ì¬£»
×îºóµã»÷“È·¶¨”¡£
¶þ¡¢°´“Ctrl+Alt+Del”¼üµ¯³öÈÎÎñ¹ÜÀíÆ÷£¬ÕÒµ½ctfmon.exeºÍsvchost64.exe½ø³Ì£¬ÕÒµ½ËüºóÑ¡ÖÐËü²¢µã»÷“½áÊø½ø³Ì”ÒÔ½áÊøµôľÂí½ø³Ì¡£È»ºóѸËÙ×öÏÂÃæÒ»²½£¬Ö»ËùÒÔҪѸËÙÊÇÒòΪÈç¹û¶¯×÷ÂýµÄ»°£¬Ä¾Âí¿ÉÄÜ»á×Ô¶¯»Ö¸´¶øÔÙ´ÎÔËÐÐÆðÀ´£¬ÕâÑù¾ÍÎÞ·¨É¾³ýµôÆäËûľÂíÎļþÁË£»
Èý¡¢
ɾ³ý×¢²á±íÖеÄ
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunctfmon.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsvchost64.exe
Èç¹ûûÓоÍÕÒÓÐÊ²Ã´ÌØ±ðµÄÏî,È»ºóɾ³ý£¬
ɾ³ýÎļþ (ÔÚDOSÏÂɾ³ý)
´ò¿ª“¿ªÊ¼/ÔËÐД£¬ÊäÈë“cmd”ºó“È·¶¨”ÒÔ´ò¿ªDOS´°¿Ú
C:WINNTsvchost64.exe
C:WINNTsystem32ctfmon.exe
²éÕÒËùÓÐµÄ wsock32.dll È»ºóÈ«²¿É¾³ý,
c:winntsystem32wsock32.dll
µÄɾ³ý²»ÁË£¬¿ÉÒÔ²»ÀíËü¡£
ÖØÐÂÆô¶¯¾ÍOKÁË¡£
wsock32.dllÊÇWindows SocketsÓ¦ÓóÌÐò½Ó¿Ú£¬ÓÃÓÚÖ§³ÖºÜ¶àInternetºÍÍøÂçÓ¦ÓóÌÐò¡£
ºÜ²»ÐÒµÄÄã ÄãÖж¾ÁË
“cmcc.exe”¶ñÐÔµÁºÅľÂíÈí¼þ¡£
Çå³ý·½·¨
Ò»¡¢ÇëÏÈÈ¥°ÑϵͳÉèÖÃΪ“ÏÔʾÒþ²ØÎļþ”£¬ÒòΪ²¡¶¾ÒÔÒþ²ØÊôÐÔαװ£¬²»×ö´ËÉèÖý«ÎÞ·¨¿´µ½Ëü£¬ÉèÖõķ½·¨ÈçÏ£¨Èç¹ûϵͳÒѾ×öÁË´ËÉèÖÿÉÒÔÌø¹ýÕâÒ»²½£©£º
´ò¿ª“ÎҵĵçÄÔ”£»
ÒÀ´Î´ò¿ª²Ëµ¥“¹¤¾ß/Îļþ¼ÐÑ¡Ï»
È»ºóÔÚµ¯³öµÄ“Îļþ¼ÐÑ¡Ïî”¶Ô»°¿òÖÐÇл»µ½“²é¿´”Ò³£»
È¥µô“Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ(ÍÆ¼ö)”Ç°ÃæµÄ¶Ô¹³£¬ÈÃËü±äΪ²»Ñ¡×´Ì¬£»
ÔÚÏÂÃæµÄ“¸ß¼¶ÉèÖÔÁбí¿òÖиı䓲»ÏÔʾÒþ²ØµÄÎļþºÍÎļþ¼Ð”Ñ¡ÏîΪ“ÏÔʾËùÓÐÎļþºÍÎļþ¼Ð”Ñ¡Ï
È¥µô“Òþ²ØÒÑÖªÎļþÀàÐ͵ÄÀ©Õ¹Ãû”Ç°ÃæµÄ¶Ô¹³£¬Ò²ÈÃËü±äΪ²»Ñ¡×´Ì¬£»
×îºóµã»÷“È·¶¨”¡£
¶þ¡¢°´“Ctrl+Alt+Del”¼üµ¯³öÈÎÎñ¹ÜÀíÆ÷£¬ÕÒµ½ctfmon.exeºÍsvchost64.exe½ø³Ì£¬ÕÒµ½ËüºóÑ¡ÖÐËü²¢µã»÷“½áÊø½ø³Ì”ÒÔ½áÊøµôľÂí½ø³Ì¡£È»ºóѸËÙ×öÏÂÃæÒ»²½£¬Ö»ËùÒÔҪѸËÙÊÇÒòΪÈç¹û¶¯×÷ÂýµÄ»°£¬Ä¾Âí¿ÉÄÜ»á×Ô¶¯»Ö¸´¶øÔÙ´ÎÔËÐÐÆðÀ´£¬ÕâÑù¾ÍÎÞ·¨É¾³ýµôÆäËûľÂíÎļþÁË£»
Èý¡¢
ɾ³ý×¢²á±íÖеÄ
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunctfmon.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsvchost64.exe
Èç¹ûûÓоÍÕÒÓÐÊ²Ã´ÌØ±ðµÄÏî,È»ºóɾ³ý£¬
ɾ³ýÎļþ (ÔÚDOSÏÂɾ³ý)
´ò¿ª“¿ªÊ¼/ÔËÐД£¬ÊäÈë“cmd”ºó“È·¶¨”ÒÔ´ò¿ªDOS´°¿Ú
C:WINNTsvchost64.exe
C:WINNTsystem32ctfmon.exe
²éÕÒËùÓÐµÄ wsock32.dll È»ºóÈ«²¿É¾³ý,
c:winntsystem32wsock32.dll
µÄɾ³ý²»ÁË£¬¿ÉÒÔ²»ÀíËü¡£
ÖØÐÂÆô¶¯¾ÍOKÁË¡£

