锘??xml version="1.0" encoding="utf-8" standalone="yes"?> 鍚屾牱鏂規硶錛氫繚瀛樹笅闈俊鎭細
杈撳叆濡備笅淇℃伅錛?br />
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters]
"AutoShareServer"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters]
"AutoShareWks"=dword:00000001
淇濆瓨涓簅penshare.reg 錛屼繚瀛樼被鍨嬩竴瀹氳閫夋嫨鎵鏈夋枃浠訛紝鐒跺悗錛屾妸 姝ゆ枃浠舵墦寮錛屽鍏ュ埌娉ㄥ唽琛紝灝卞紑閫氫簡榛樿鍏變韓銆?/p>
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa]
"restrictanonymous"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"restrictanonymous"=dword:00000000
; 浠ヤ笂涓よ鍦ㄧ郴緇熶腑鐨勪綅緗槸錛氭湰鍦板畨鍏ㄧ瓥鐣?瀹夊叏閫夐」-緗戠粶璁塊棶錛氫笉鍏佽SAM甯愭埛鍜屽叡浜?br />; 鐨勫尶鍚嶆灇涓俱傜郴緇熼粯璁ゅ兼槸錛氬凡鍋滅敤銆?br />; 瑙h錛氭搷浣滅郴緇熼粯璁?鍒╃敤ipc$閫氶亾鍙互寤虹珛絀鴻繛鎺?鍖垮悕鏋氫婦鍑鴻鏈烘湁澶氬皯甯愭埛銆傛樉鐒?br />; 鏈変竴瀹氱殑瀹夊叏闅愭偅銆傛湰緋葷粺宸茶涓轟笉鍏佽絀鴻繛鎺ヤ簡銆備互姝ゆ彁楂樺崟鏈烘嫧鍙蜂笂緗戠殑瀹夊叏鎬с?br />; 璐熼潰褰卞搷鏄眬鍩熺綉涓嶈兘浜掕浜嗐傝鏇存敼涓涓嬫墠鍙互瑙e喅銆?br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"limitblankpassworduse"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa]
"limitblankpassworduse"=dword:00000000
; 浠ヤ笂涓よ鍦ㄧ郴緇熶腑鐨勪綅緗槸錛氭湰鍦板畨鍏ㄧ瓥鐣?-瀹夊叏閫夐」--甯愭埛錛氫嬌鐢ㄧ┖鐧藉瘑鐮佺殑鏈湴甯愭埛
; 鍙厑璁歌繘琛屾帶鍒跺彴鐧誨綍銆傜郴緇熼粯璁ゅ兼槸錛氬凡鍚敤銆?br />; 瑙h錛氬緢澶氫漢鐨勫笎鎴鋒槸涓嶅姞瀵嗙爜鐨勩傝繖鏍鳳紝褰撳眬鍩熺綉涓埆鐨勭數鑴戣闂湰鏈烘椂錛屼細寮瑰嚭閿欒鎻愮ず錛?br />; 鐧誨綍澶辮觸錛氱敤鎴峰笎鎴烽檺鍒?#8230;……銆傝繖鏄疿P緋葷粺鐨勪竴鏉″畨鍏ㄧ瓥鐣ラ犳垚鐨勶紝闃叉鍒漢瓚佷綘絀哄瘑鐮佹椂
; 榪涘叆浣犵殑鐢佃剳銆傚鏋滀綘瑙夊緱鏃犳墍璋擄紝涓嶅繀鍋氳繖浜涢檺鍒訛紝閭e氨鎶婂畠璁句負錛氬凡鍋滅敤銆?br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count]
"HRZR_EHAPCY"=hex:0C,00,00,00,26,00,00,00,F0,FB,E5,52,64,95,C6,01
"HRZR_EHAPCY:"P:\JVAQBJF\flfgrz32\sverjnyy.pcy",Jvaqbjf 闃茬伀澧?=hex:0C,00,00,00,08,00,00,00,F0,FB,E5,52,64,95,C6,01
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch]
"Epoch"=dword:000001ED
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Providers]
"LogonTime"=hex:E8,31,8E,4F,64,95,C6,01
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Epoch]
"Epoch"=dword:000001ED
; 浠ヤ笂鏁板煎搴旂郴緇熶腑鐨勪綅緗細鎺у埗闈㈡澘--闃茬伀澧?-渚嬪--鏂囦歡鍜屾墦鍗版満鍏變韓銆傜郴緇熼粯璁わ細涓嶉夈?br />; 瑙h錛氭墍鏈夌殑絳栫暐閮借緗ソ浜嗭紝灞鍩熺綉渚濈劧涓嶈兘璁塊棶錛屾彁紺猴細鎮ㄦ病鏈夋潈闄愪嬌鐢ㄧ綉緇滆祫婧愶紝鎵?br />; 涓嶅埌緗戠粶璺緞錛佸懙鍛碉紝鐪熸槸浠や漢鐏啋涓変笀錛佸叾瀹瀀P榪樻湁涓閬撳叧鍗★紝灝辨槸闃茬伀澧欙紝蹇呴』瑕佺粡榪?br />; 闃茬伀澧欑殑鍏佽鎵嶈銆?br />
灝卞紑閫氬嚑涔庢墍鏈夊叡浜傘?/p>
tasklist
2.鏌ョ湅绔彛鍙蜂笌PID鍏寵仈
netstat -ano
3.緇堟榪涚▼
鏂規硶涓錛氬埄鐢ㄨ繘紼嬬殑PID緇撴潫榪涚▼
taskkill /pid 1234 /f 錛?f鎸囩殑鏄己琛岀粨鏉燂級
鏂規硶浜岋細鍒╃敤榪涚▼鐨凱ID緇撴潫榪涚▼
鍛戒護鏍煎紡錛歯tsd -c q -p pid
鍛戒護鑼冧緥錛?ntsd -c q -p 1332 錛堢粨鏉焑xplorer.exe榪涚▼錛?br />鑼冧緥璇﹁В錛歟xplorer.exe鐨刾id涓?332錛屼絾鏄浣曡幏鍙栬繘紼嬬殑pid鍛紵鍦–MD涓嬭緭鍏ASKLIST灝卞彲浠ヨ幏鍙栧綋鍓嶄換鍔$鐞嗗櫒鎵鏈夎繘紼嬬殑PID
鏂規硶涓夛細鍒╃敤榪涚▼鍚嶇粨鏉熻繘紼?br />鍛戒護鏍煎紡錛歯tsd -c q -pn ***.exe 錛?**.exe 涓鴻繘紼嬪悕,exe涓嶈兘鐪侊級
鍛戒護鑼冧緥錛歯tsd -c q -pn explorer.exe