bsvchostM(jn)̲ üðSvchost.exeQ(chng)IJ@Nʽ\еIJ](mi)ֱSvchost.exeM(jn)dž(dng)һ(g)Q(chng)ͬSvchost.exeIJM(jn)@(g)ðIJM(jn)̲](mi)мdϵy(w)Svchost.exeM(jn)Dzֻͬд\һ¡Tasklist /svcĂ(g)Svchost.exeM(jn)̺ʾķ(w)Ϣǡȱһ(g)wķ(w)ôDzM(jn)ӛ@(g)M(jn)̌PIDֵ(M(jn)̘R)΄(w)M(jn)бҵYM(jn)̺CP(pn)Svchost.exeļҲõM(jn)ֱ̹Ӳ鿴ԓM(jn)̵·Svchost.exeļλ%systemroot%\System32ĿеðSvchost.exeľRļt(hu )Ŀ硰w32.welchina.wormðSvchost.exe[Windows\System32\WinsĿhص
һЩt(li)ϵy(w)(dng)ķʽͨ^(gu)Svchost.exeM(jn)̼dSvchost.exeͨ^(gu)עԱ픵(li)QҪbdķ(w)бԲͨ(hu )עԱв·M(jn)мdһ(g)µķ(w)MڽMӲ(w)ڬFеķ(w)MֱӲ(w)ĬFз(w)MĬFз(w)䡰ServiceDllIֵָД:Ҫͨ^(gu)Svchost.exeM(jn)̼dͱҪP(gun)עԱ픵Դ_(ki)[HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\
CurrentVersion\Svchost]^(gun)Л](mi)µķ(w)Mͬr(sh)Ҫ(w)Mеķ(w)б^(gun)Л](mi)пɵķ(w)Q(chng)ͨ(li)f(shu)(hu )ֻһ(g)(w)Q(chng)ĽM(hu )xLocalServicenetsvcs@ɂ(g)d(w)^ĽMԸɔ_߀ͨ^(gu)ķ(w)ָͨ^(gu)עԱД(li)^y@r(sh)ǰBķ(w)팣(zhun)քe_(ki)LocalServicenetsvcs֧(g)z߅(w)беķ(w)Ҫע(w)ϢȫӢĵܿǵbķ(w)ͬr(sh)ҪYļ汾˾P(gun)ϢM(jn)оCД@(g)PortLess BackDoorľRڷ(w)бпԿķ(w)顰Intranet Servicesļ汾˾Ϣȫܛϵy(w)ǽ^ܳF@NFĆ(dng)ϢC:\WINDOWS\System32\svchost.exe -k netsvcsпԿ@һ͵Svchost.exeM(jn)̼d\еľR֪ԭҲܺ(jin)ˣ÷(w)팣(zhun)ֹͣԓ(w)\Ȼ\regedit.exe_(ki)עԱh[HKEY_LOCAL_MACHINE\System\CurrentControlSet\
Services\IPRIP]I(dng)ӋCلh%systemroot%\System32ĿеľRԴsvchostdll.dllͨ^(gu)r(sh)gְl(f)F˕r(sh)gȫͬľRbPortlessInst.exeһh svchost.exentϵyķdzҪM(jn)2000xp(li)f(shu)ɻȱܶಡľRҲ(hu ){˽@(g)Xın֮һҌwindowsϵyһİǷעϵyСsvchost.exe@(g)ļĵѕ(hu )l(f)Fwindowsдڶ(g) svchostM(jn)̣ͨ^(gu)ctrl+alt+delI_(ki)΄(w)@ġM(jn)̡˺оͿɿˣʲô(hu )@́(li)_(ki)ص漆l(f)FڻntȺ˵windowsϵyͬ汾windowsϵyڲͬġsvchostM(jn)Ñ(h)ʹá΄(w)ɲ鿴M(jn)̔Ŀһ(li)f(shu)win2000Ѓɂ(g)svchostM(jn)winxpЄtĂ(g)Ă(g)ϵsvchostM(jn)̣Ժϵyж(g)@NM(jn)ǧf(wn)eжϵyвˆѣwin2003 serverЄt@ЩsvchostM(jn)ṩܶϵy(w)磺rpcss(w)remote procedure calldmserver(w)logical disk managerdhcp(w)dhcp clientҪ˽ÿ(g)svchostM(jn)̵ṩ˶ϵy(w)win2000ʾݔ롰tlist -s(li)鿴ԓwin2000 support toolsṩwinxptʹátasklist /svc svchostп(g)(w)롡windowsϵyM(jn)̷֞骚M(jn)̺M(jn)̃ɷNsvchost.exeļڡ%systemroot% system 32ĿڹM(jn)S(zh)windowsϵy(w)˹ʡϵyYԴܛѺܶ(w)ɹʽ svchost.exeM(jn)́(li)(dng)svchostM(jn)ֻ(w)܌(sh)Fκη(w)ֻṩl(w)@ﱻ(dng)ԼsܽoÑ(h)ṩκη(w)@Щ(w)Ό(sh)Fԭ(li)@Щϵy(w)Ԅ(dng)B(ti)朽ӎ죨dllʽ(sh)FѿɈгָ svchostsvchost{(w)Ą(dng)B(ti)朽ӎ(li)(dng)(w)svchostô֪ij(g)ϵy(w)ԓ{Ă(g)(dng)B(ti)朽ӎ@ͨ^(gu)ϵy(w)עԱOõą(li)(sh)Frpcssremote procedure call(w)M(jn)vĆ(dng)пҊ(jin)(w)ǿsvchost(li)(dng)(sh)windows xpc(din)_(ki)ʼ/\Сݔ롰services.msc(w)Ԓ(hu)Ȼ_(ki)remote procedure callԌԒ(hu)Կrpcss(w)ĿɈļ·顰c:\windows\system32\svchost -k rpcss@f(shu)rpcss(w)svchost{árpcss(li)(sh)Fă݄tǴϵyעԱе\ЌԒ(hu)ݔ롰regedit.exe܇(ch)_(ki)עԱҵ[hkey_local_machine systemcurrentcontrolsetservicesrpcss]ҵ(li)͞顰reg_expand_szImagepathIֵ顰%systemroot%system32svchost -k rpcss@ڷ(w)пķ(w)(dng)ڡparametersЂ(g)顰servicedllIֵ顰% systemroot%system32rpcss.dllСrpcss.dllrpcss(w)ҪʹõĄ(dng)B(ti)朽ӎļ@ svchostM(jn)ͨ^(gu)xȡrpcss(w)עԱϢ܆(dng)ԓ(w)svchostM(jn)̆(dng)N(w)ԲľRҲMk(li)Dԁ(li)ԻÑ(h)_ȾƉĵĿģ_׃Nw32.welchia.wormwindowsϵyڶ(g)svchostM(jn)ǺܸȾęCеĂ(g)DzM(jn)@Heһ(li)f(shu)Owindows xpϵyw32.welchia.wormȾsvchostļڡc:\windows\system32Ŀl(f)FԓļFĿ¾ҪСw32.welchia.wormڡc:\windows\system32winsĿʹM(jn)̹鿴svchostM(jn)̵Ĉļ·ͺװl(f)FϵyǷȾ˲windowsϵyԎ΄(w)܉鿴M(jn)̵·ʹõM(jn)̹ܛ硰windows(yu)M(jn)̹ͨ^(gu)@Щ߾Ϳɺز鿴еsvchostM(jn)̵Ĉļ·һl(f)F·鲻ƽλþ͑ԓRM(jn)Йzy̎ƪP(gun)ϵ܌svchostȫM(jn)ԔB@һ(g)windowsеһ(g)M(jn)dȤĿɅP(gun)g(sh)YM(jn)һȥ˽ҶҪ֪Svchost.exe,ϵyزٵһ(g)M(jn),ܶ(w)(hu )õ, Ҳ֪,,"ڿ͂"϶Dz(hu )^(gu),ǰΕr(sh)gSvchost.exeľRL(fng),ґԓӛq°,ҬF߀кܶCﶼдľR,bϵyM(jn)Svchost.exeһ,Ժܶ˷ֲ,ǂ(g)M(jn),ǂ(g)ľR.... õ,߀҂ԔM˽һSvchost.exeM(jn)̰ɡ1.(g)(w)һ(g) Svchost.exeM(jn)c windows ϵy(w)֞骚M(jn)̺M(jn)̃ɷNwindows NTr(sh)ֻз(w)SCMServices.exeж(g)(w)S(zh)ϵy÷(w)windows 2000msְѺܶ(w)ɹʽsvchost.exe(dng)windows 2000һ2(g)svchostM(jn)һ(g)RPCSSRemote Procedure Call(w)M(jn)һ(g)tɺܶ(w)һ(g)svchost.exewindows XPtһ4(g)ϵsvchost.exe(w)M(jn)windows 2003 serverЄtԿѸϵy÷(w)ԹM(jn)̷ʽsvchost(dng)msһ(g)څ@һ̶ϜpϵyYԴ^(gu)Ҳ(li)һIJκһ(g)M(jn)̵ķ(w)e`˳M(jn)͕̾(hu )(g)M(jn)ез(w)˳һc(din)ȫ[ҪBһsvchost.exeČ(sh)FC2. SvchostԭSvchostֻ(w)(sh)Fκη(w)ҪSvchost(dng)ķ(w)Ԅ(dng)B(ti)朽ӎʽ(sh)Fڰb@Щ(w)r(sh)ѷ(w)ĿɈгָsvchost(dng)@Щ(w)r(sh)svchost{(w)Ą(dng)B(ti)朽ӎ(li)(dng)(w) |