
î®ÃøWindowsÈÇËÜ¿äÄĽп·¡¤·ÏÅýÆü±×ãÓÄꡤ´Ç»÷ͧÁ±Åª»ëãÙÔ¦·Á²ðÌ̴ǵ¯ÐÔ쪿ÍÊü¿´¡¤Á³¼©ÇظåÒʲÄǽð¬é¶Ãø»ÈÍѼԡ¢·ÏÅý´ÉÍý¼Ôçг«â¤¼Ô¶Ñ̵ˡ⤸½ÅªÌäÂê¡£Îãǡ̤崻ÈÍѼԵö²ÄÅªØæÍÑÄø¼°¼¹¹ÔçÐÌÖϩ¸¼è¡¤Çç½¢ÉÔÀ§°ìÈ̸ĿÍü·ÏÅýÄ´¹»¹©¶ñǽ夠ÐöÅþŪ¡¨Â¨ÊØÀ§¾¦¶ÈØæÍÑÎΰè¾å¡¤Ìé×̾¯IT¾³¾¦ÕóÌç¿ËÕô Windows·ÏÅýÂçÎÌÄó¶¡ÇçÎàÍÑÅÓŪ¹©¶ñ¡¤SysinternalsÒÊÐöÅþλ¡ª¼©³îºß·ÏÅý°Ý¸îŪÎΰèÃæ¡¤SysinternalsÀ§ÌÜÁ°½Å½ê¸øÇ§ºÇ¹¥Åª¹©¶ñÇ·°ì¡£ 2006ǯÈùÆðÊ»¹Ø SysinternalsŪÊì¸ø»ÊWinternals¸å¡¤ÈùÆðºßTechEd 2007ÃæÆÃÊÌ說ÌÀ´ë¶È»ÈÍÑ Sysinternals³ºÃí°ÕŪ»ö¹à¡£Â¾Ðîɽ¼¨¡¤Õòåëåôìª Sysinternals°Ý»ýÌÈÈñ²¼ºÜ¡¤°ìÈÌ´ë¶È²Ä°Êºß¸ø»Ê內Éô¼«¹Ô»ÈÍÑ¡¤ÉԸ¼øÜÞÚËÎÌ¡¤Ã¢Ç¡²ÌÀ§Éþ̳Äó¶¡¾³¾¦Í×»ÈÍѻ꺳¹©¶ñ¡¤½¢¼ûÍ׸þÈùÆð¿½ÀÁ¼øÜÞ¡£°ø°Ù SysinternalsÀ§Ìµ½þ»ÈÍÑ¡¤ÉÔÏÀÀ§´ë¶È°¿¸Ä¿Í¡¤¶Ñ̵ˡ×ÏÈùÆðÆÀÅþ¶¨½õ¡¤Ã¢°ø°Ù»ÈÍÑÀß·²×Ì×¢Â硤ÈùÆð·¹¸þ쪻ÈÍѼԸþÀß·²µá½õ¡¢»ðëΡ£
ìª你ÀºÄÌWindows·ÏÅý´ÉÍý¡¢ÌÖÏ©´ÉÍý°¿Äø¼°³«â¤ÅªÌÈÈñ¹©¶ñ ÉÔÆ±±÷¹âµ®Åª·ÏÅý´ÉÍýÊ¿çÊÏÂIT¸¶¾³¸ÜÌ䡤ÕÜÐò»ÈÍÑWindows Sysinternals Suite¡¤你Õò¹¹ÍǽÎÏÑÝÍýWindowsŪ³Æ¼ïÌäÂꡤ¼©³îÉÔ²Ö°ìÌÓ£
Á±Íѹ©¶ñ¡¤ºÍǽé»Åþɽü SysinternalsÇçÅ幩¶ñºß´Ô̤ʻÆþÈùÆðTechNetÇ·Á°¡¤ºßÌÖÏ©µÚ·ÏÅý´ÉÍý³¦½¢Öáå´¼õÅþ×¢Þ¢»ÈÍÑλ¡£´ûÁ³Sysinternalsºß·ÏÅý¹©¶ñ¾åÖáÀêͰìÀÊÇ·ÃÏ¡¤ÆáIT¿ÍÊ¿»þËôÀ§Ç¡²¿»ÈÍÑÇ纳¹©¶ñŪ¡©
¾ïÍÑŪSysinternalsÑÝÍýÄø½ø´ÉÍý¹©¶ñ ²Ä±óü查ëÎçдÉÍý·ÏÅýŪPsTools PsToolsÊñ´Þ12¼ï±óü´ÉÍý¹©¶ñ¡¤²Ä²ò·è·ÏÅý¡¢¼§碟¡¢檔°Æ°¿ÌÖÏ©ÅùÌäÂꡤ³ÓÆÃÊÌŪÀ§PsTools內Ū½ê͹©¶ñ»ÈÍѾ塤ÅÔɬ¿Ü°ÊºßÌ¿ÎáÎóÅëÇÛÒÔÚËŪÊý¼°¼¹¹Ô¡¤»ÈÍѾåÈæÔ¦·Á²ðÌÌÐÔÆÀ¹¹Ä¾ÀÜ¡£
¾ïÍÑŪSysinternals·ÏÅý»ñ¿Ö查ëι©¶ñ Á´Ì̴ƹµ·ÏÅý狀ÂÖŪProcess Monitor ÍøÍÑÓŰìÄø¼°¡¤ÊØÇ½Â¨»þ´Æ¹µWindows·ÏÅýŪ檔°Æ¡¢ÅÐ錄µ¡âûçÐÄø½ø¡¤Ç½¶¨½õIT¿Í°÷¿ÒÙ²·ÏÅýϳƶ¡¢¸åÌçÄø¼°°¿¿Ê¹Ôºø¸íÜý¬¡£
¾ïÍÑŪSysinternalsÌÖÏ©¹©¶ñ Æ©»ëWindows TCP/UDPÏ¢ÀþŪTCPView Üý»ëÅÅçªÅªTCPµÚUDPüóÚÏ¢Àþ»ñ¿Ö¡¢½ê»ÈÍÑŪϢÀÜÉÖ¡¤°ÊµÚÏ¢Àþ狀ÂÖ¡¤幫½õ你ÑÝÍýÌÖÏ©ÁêïðŪ¾×ÆÍ»ö·ï°¿Ù²½Ð°Û¾ïÏ¢Àþ¡£
ìª你ÀºÄÌWindows·ÏÅý´ÉÍý¡¢ÌÖÏ©´ÉÍý°¿Äø¼°³«â¤ÅªÌÈÈñ¹©¶ñ IT¿Í°÷ÑÝÍýÌäÂ꽢ǡƱîлմÇÉÂÌä¿Ç¡¤µ»½ÑÀºÎÉŪîлձý±ý´Ç°ì´ã½¢ÃÎÆ»Ç¡²¿ÑÝÃÖÉÂÎ㡤âͻþ²æÐîåÁÐò¶øÅþ槸«Åªµ¿Æñð¸¾É¡¤áÄÝóÍÁ°Îã²Ä¿Ò»þ¡¤´ÔÀ§Íׯ©²áÚÒÁØÁÝÉÁ¡¢Ä¶²»ÇȰ¿內»ë¶ÀÅù¹â²Êµ»´ïºàÊå½õ¡¤ºÍǽٲ½Ðɰø¡£
Sysinternals SuiteΣŪ¹©¶ñ¡¤½¢ÁüÀ§Ç纳´ïºà¡¤Ã¢ÉÔ¼ûÍײÖï¢Â¨²Ä²¼ºÜ»ÈÍÑ¡¤Ç¡²Ì懂ÆÀÇ¡²¿±¿ÍÑÇ纳´ïºàŪIT¿Í°÷¡¤É¬Á³Ç½ÈæÂþÍÑ¡Öæå¿Ç´ï¡×Ū¿Íλ²ò¹¹¿¼Æþ¡£ÉÔÆ±±÷¹âµ®Åª·ÏÅý´ÉÍýÊ¿çÊÏÂIT¸¶¾³¸ÜÌ䡤ÕÜÐò»ÈÍÑWindows Sysinternals Suite¡¤你Õò¹¹ÍǽÎÏÑÝÍýWindowsŪ³Æ¼ïÌäÂꡤ¼©³îÉÔ²Ö°ìÌÓ£
Sysinternalsǽ¿¼ÆþWindows³Ë¿´ SysinternalsÅþÄìÀ§²¿Êý¿ÀÀ»¡©
SysinternalsÇ·Á°°ÙWinternals¸ø»ÊÄó¶¡ÅªÌÈÈñ¹©¶ñ¡¤Winternals¸¶ËÜÀ§°ì´Ö¼çÎÏ產ÉʰٷÏÅýÉü¸¶çлñÎÁÊݸîŪ¸ø»Ê¡¤°Ùλ²ò·è¹©Äø»ÕÊ¿¾ïºß¹©ºî¾å¶øÅþŪ³Æ¼ïÌäÂê¡¤ÊØ³«â¤½Ðµö¿¾®¹©¶ñ¡£Ç·¸å¾ÐîÕòÇ纳¹©¶ñ½¸¹çµ¯ÐÔãʰÙSysinternals¡¤ÊÂÊüºßÌÖÏ©¶¡¿ÍÌÈÈñ²¼ºÜ¡¤Â¶ÃæÌéÊñ´ÞÉôʬ¹©¶ñŪ¸¶»Ïâû¡¤°ìľ°ÊÐÔÅÔ¿ü¼õITÕó²È¼Ò·²Åª¹¥É¾¡£
2006ǯ7·î18Æü¡¤ÈùÆðÀëÉÛÊ»¹ØWinternals¸ø»Ê¡¤ÉÔâÕò½ÏÃÎWindows·ÏÅýŪWinternals¸ø»Ê¶¦Æ±ÁÏ辦¿Í¨¡¨¡Mark Russinovich °ÊµÚ Bryce Cogswell¨¡¨¡Ç¼Æþ´ú²¼¡¤Æ±»þÌéÕòSysinternalsÇçÅ幩¶ñÚÀÊÔ»êTechNetÌÖãë¡£
¸½Ç¤¿¦±÷ÈùÆðÊ¿çʵÚÉþ̳ÉôÌçŪMark Russinovich¡¤À§Âç²È³Ó¾ï¼ªÊ¹ÅªÑ£´ñ¿Íʪ¡¤Â¾ÕôWindows³Ë¿´Äø¼°âûͶ˿¼ÆþŪǧ¼±¡¤Á½ºß1996ǯ⤸½Windows NT ServerÏÂWorkstationÈǶñÍÁêÆ±Åª³Ë¿´Äø¼°¡¤ÂþÍ×¹¹Æ°ÑÀ¸ÄÅÐ錄µ¡âû¡¤½¢Ç½ÕòÈÇËÜÚι¹¡£¼©ºß2005ǯ¡¤Mark⤸½ì¦¼èSony BMGŪ²»ÜÛCD»þ¡¤Windows·ÏÅýÐòÁøð¬é¶ºßCDÃæÅªrookitËÉÝ¹Äø¼°ãâ²þ¡¤³î»ÈÍѼԴ°Á´ÉÔÃξð¡£Çç¸Ä⤸½ÉÔâ»ÈÆÀSonyµÉ¾å´±»Ê¡¤Mark Ìé°ø¼©æá̾ÂçÓä¡£
ͳ±÷MarkËÜ¿ÈŪµ»½ÑÃμ±ì´ÉÙ¡¤°øº¡Â¾Ðî½ê³«â¤ÅªÆðñó¡¤Êñ´ÞSysinternalsºß內ŪµöÂ¿ØæÍÑÄø¼°¡¤ÌéÀ®°Ù»ÈÍÑWindows·ÏÅýŪIT ¿Í°÷¡¤²ò·èÌäÂêçпÒٲب°ÕÄø¼°Åª¼çÍ×¹©¶ñ¡£ºßçÊßÔÈùÆðTechNetƤÏÀÒ¿Ãæ¡¤ËòÍÉÔ¾¯MVP¡ÊMost Valuable Professional¡¤ºÇÍÑ«值Õó²È¡Ëɽ¼¨½½Ê¬¶Õ¾ÞMarkŪÕó¶È¡¤°ÊµÚͦ±÷揭Ϫ»öÕéŪ¹Ô°Ù¡£
Ï¢ÈùÆðµ»½Ñ¿Í°÷ÅÔ¿äÁ¦»ÈÍÑ SysinternalsÇçÅ幩¶ñºß´Ô̤ʻÆþÈùÆðTechNetÇ·Á°¡¤ºßÌÖÏ©µÚ·ÏÅý´ÉÍý³¦½¢Öáå´¼õÅþ×¢Þ¢»ÈÍÑλ¡£
Ĺ´üٿǤµ»½Ñ¸ÜÌä¡¢ÌÜÁ°Ç¤¿¦±÷Ë¿¶âÍ»Éþ̳¶ÈŪÈùÆðTechNet MVPÍûÌÀ¼ôɽ¼¨¡¤Í³±÷¾ËܿȰìľ°ÊÐÔÊØÕôÄø¼°³«â¤¡¤°ÊµÚ·ÏÅý½üºøÊÝ»ý¹âÅÙŪ¶½¼ñ¡¤°øº¡Ìéå´¾ïÍøÍÑ¿¼ïǽ¿¼Æþë·»¡ÌäÂꡤÊÂʬÀÏ·ÏÅý³Ë¿´±¿ºî²áÄøÅª¹©¶ñ¡£¼©ºßÇ纳¾ïÍÑŪ½ÅÍ×¹©¶ñáÄÃæ¡¤ÊØÍ´ö¹àÀ§½Ð¼«Sysinternals¡£
ÍûÌÀ¼ô說¡¤°ì³«»ÏÀÜë½ÅþÇçÅ幩¶ñ¡¤Â¾À§°ÊËܿȶøÅþŪÌäÂêÐö°Ùï𸰻ú¡¤Æ©²áÙÓ¿Ò°úú²ºÍ⤸½Åª¡¤Æ±»þÌéÃí°ÕÅþµö¿¶È³¦¿Í»ÎÅÔÁêáÄ¿ä¿ò Sysinternals¡£¸åÐԺ߹©ºî¾åÑÝÍýÅþÍïðWindows·ÏÅýŪÌäÂ꼩̵ˡ²ò·è»þ¡¤µá½õÈùÆðµ»½Ñ¿Í°÷»Ù±çŪ²áÄøÃæ¡¤ÌéÍ¿¼¡Èï¿äÁ¦»ÈÍÑ SysinternalsŪå´ñä¡£
»ê±÷É÷㻲ʵ»ñäëúŪ·ÏÅý¹©Äø»ÕÅ¢»Òû±ÌéÍÎà»÷å´ñä¡£áĽéÅ¢»Òû±À§ºßÄø¼°³«â¤»þ¡¤¶øÅþ°ìº³WindowsÄø½øºø¸íŪÌäÂê̵ˡ²ò·è¡¤ÊظþÈùÆðµá½õ¡¤¼©ÈùÆðŪµ»½Ñ»Ù±ç¿Í°÷·úµÄ¾»ÈÍÑáÄ»þл֤±÷Winternals¸ø»Ê¡¤ÈÇËܳÓÁá´üŪProcessExplorer¹©¶ñ¡¤ÈùÆð´õ˾Ţ»Òû±Ç½ÍøÍѺ¡¹©¶ñ¡¤ÕòÄø½øºø¸íŪ歷Äø´°À°Ãϵ錄²¼ÐÔ¡¤ºÆÍ³Â¾ÐîŪµ»½Ñ¿Í°÷Äó¶¡Õô¾É²¼é»Åª½¤Àµ»Ù±ç¡£
º¡³°¡¤ÌÜÁ°Õ󿦱÷ÕíºîµÚËÝ죸¶Ê¸½ñŪÈùÆðTechNet MVPûòÜÆÜ䡤Ìé°øÁá´üÁ½»ÈÍѲáWinternals¸ø»ÊŪ產ÉÊNTFSDOS¡¤Ùεßλ»ÔÕ¹Å碟ÃæÅª»ñÎÁ¡¤¼©³«»ÏÃí°ÕÅþλWinternals¸ø»ÊŪÁÏ辦¿ÍMark ¡¤Æ±»þ³«»Ï¸¦µæÇç´Ö¸ø»ÊŪ產ÉÊ¡¤áÄÁ³¡¤Â¶ÃæÌéÊñ´ÞλWindows Sysinternals Suite¡£
Ê»¹Ø¸å¡¤¹¹¿·µÚ°Ý¸îÉÔÐòÄä»ß Markºß²ÃÆþÈùÆð¸å¡¤¼óÀèÕòÉÂÆÇµÚ´ÖĵÆðñ󸦵æ¿Í°÷¡¤å´¾ï»ÈÍÑŪRegmonÏÂFilemonÑÀ¹à¹©¶ñ¡¤À°¹ç»ê¿·¹©¶ñProcess MonitorÃæ¡¤Æ±»þÌéºßÇç¹à¿·¹©¶ñÃæ²ÃÆþÉôʬŪProcess Explorer¸ùǽ¡¤ìªIT´ÉÍý¿Í°÷ÉÔÍѺߵö¿»ëãÙ´ÖÀÚ´¹¡¤ÊØÇ½Äå¬ب°ÕÄø¼°Åª³èư¹Ô°Ù¡£º¡³°¡¤êÁ³ÉԺƹ¹¿·PsUptimeÇç¹à¹©¶ñ¡¤Ã¢ÈùÆðºß PsInfoÃæ²ÃÆþ¸¶ËÜPsUptimeŪ¸ùǽ¡¤ºÆÕò°ì·ÏÎóŪPs¹©¶ñÒ»½¸¸å½Å¿·Ì¿Ì¾°ÙPsTools¡¤³îîٽлٱçVistaºî¶È·ÏÅýŪÈÇËÜ¡£
ÈùÆðÊ»¹ØWinternalsÇ·¸å¡¤µö¿Ū»ÈÍѼÔÉÔÌÈÙ¿¿´¡¤¸¶ËÜÌÈÈñŪ¹©¶ñÐòÚÎÀ®ÚÀÈñÆðñ󡤰¿À§¹©¶ñŪ¹¹¿·Â®ÅÙÉÔÇ¡°Ê±ý¡¤¿Ó»êÉԺƹ¹¿·Åù¡£
»öÕé¾å¡¤Windows Sysinternals SuiteÉÔâùá²ÃλProcess Monitor¡¢PsToolsÅù¿·¹©¶ñ¡¤ÁüProcess Explorer°¿TCPViewÅùÕéÍѹ©¶ñÌéΦåô¿ä½Ð¿·ÈÇËÜ¡¤°øº¡ÇçÅ幩¶ñŪ¹¹¿·Â®ÅÙ¡¤ÊÂ̤°ø´¹Î»¾·Ç×¼©Í±Æ¶Á¡£
ºßçÊßÔ¡¤ÁêïðŪ»ñ¿Ö§×Ì͸¡£ÌÜÁ°çÊßÔÈùÆðTechNetÌÖãë¾å¡¤ïð±÷SysinternalsÓŰ칩¶ñŪ說ÌÀл͵ö¿°Ù±Ñʸ»ñÎÁ¡¤ÉÔ²áçÊßÔÈùÆð»ÇÉþ´ïÊ¿çÊ»ö¶ÈÉô¹ÔîùÉûÍý¡¤Æ±»þÌéÀ§TechNetŪÉéÀÕ¿Íס¹À»Ö¡¤ËÜ¿ÈÌé¶ñÍSysinternalsŪ»ÈÍÑå´ñ䡤¾ɽ¼¨ÈùÆðÕòÐòÍ¥ÀèÑÝÍýÁêïðÌÖÊÇŪËÝ죹©ºî¡¤°Ê¶¨½õIT¿Í°÷¹¹²Ãλ²òSysinternals SuiteŪ»ÈÍÑÊý¼°¡£
Á±Íѹ©¶ñ¡¤ºÍǽé»Åþɽü Sysinternalsºß·ÏÅý¹©¶ñ¾åÖáÀêͰìÀÊÇ·ÃÏ¡¤IT¿ÍÊ¿»þËôÀ§Ç¡²¿»ÈÍÑÇ纳¹©¶ñŪ¡©
ºßSysinternals¾°Ì¤À°Ê»ÅþTechNetÇ·Á°¡¤ÍûÌÀ¼ôºÇ¾ï»ÈÍÑŪ¹©¶ñ¡¤áÄÖ¤RegmonÏÂFilemonλ¡£°øRegmon²Ä°ÊÍÑÐÔë·»¡ØæÍÑÄø¼°»ÈÍÑÅÐ錄µ¡âûŪ²áÄø¡¤ºÆÇÛ¹çFilemon查ëΡ¤ÊØÇ½²÷®⤸½°ø檔°ÆÉÔ¸ºß¡¤°¿ÜÞ¸ÂÉÔÂ̵ˡ»ÈÍѤÀ®Åªºø¸í¡£ÍûÌÀ¼ôɽ¼¨¡¤¼ãFile MonitorŪ²áßÉï𸰻ú²¼ÆÀÀº½à¡¤ÉÔÍÑÑÀʬ¾â½¢Ç½Ù²½ÐÌäÂꡤÆá¼ï¶øÅþĩ٥¼©Ëôǽ²÷®²ò·èŪÀ®½¢´¶¡¤ÌéÀ§ìªÂ¾»Ï½ªÜÛº¡ÉÔÈèŪ¼ç°ø¡£
Á³¼©RegmonÏÂFilemonÀèÁ°À§Ê¬³«ÅªÑÀ¸Ä¹©¶ñ¡¤²áµî»ÈÍÑ»þå´¾ï¼û³«啟ÑÀ¸Ä»ëãÙ¡¤ºÆ°ÊÆù´ã¸òºµÈæÕô¡¤²Ä°Ê說ÁêáÄÉÔÊýÊØ¡£ÈùÆð¸åÐÔ¿·¿ä½ÐλÀ°¹çÇçÑÀ¼Ô¸ùǽŪ¿·¹©¶ñProcess Monitor¡¤ÕôÍûÌÀ¼ô¼©¸À¡¤²Ä說À§´°Á´ÀÚÃæÍ׳²¡¤ÌéÀ®°ÙÌÜÁ°Â¾¹©ºî¾å»ÈÍÑΨºÇ¹âŪ°ì¸Ä¹©¶ñ¡£
½üλProcess MonitorÇ·³°¡¤ÍûÌÀ¼ôÌéå´¾ï»ÈÍÑProcess Explorer¡¤Õà²Ä說À§¿Ê³¬Èǹ©ºî´ÉÍý°÷¡¤ÉÔâǽÍÑÐÔÑè½ü¹©ºî´ÉÍý°÷̵ˡÑè½üÅªÄø½ø¡¤Ìé²Ä¾ÜºÙÜý查Äø½ø»ÈÍÑÅþŪDLL檔¡¢³«啟Ū檔°ÆµÚÌÖÏ©»ÈÍÑ狀¶·Åù¾ÜºÙ»ñ¿Ö¡£¼©Í»þÑè½ü檔°Æ»þÐòâ¤À¸檔°ÆÖáÈﺿÄêŪ¾ð·Á¡¤º¡»þÍøÍÑProcess ExplorerÌéǽٲ½Ð¸µ¶¤¡£
°Ê±ýÁ½°ÙλÅÅ窳«µ¡ÌüÐÔÌüËýŪÌäÂꡤ¼©´¶Åþ½½Ê¬º¤¾ñŪûòÜÆÜäÌéÃÌÅþÕôSysinternalsŪÁÛË¡¡¤Â¾說êÁ³ÍøÍÑWindowsŪ msconfig»ØÎᡤ°¿À§ÅþÅÐ錄µ¡âûÃæÜý查¡¤Ìé²Ä°Ê⤸½ºß³«µ¡²áÄøÃæÍ哪º³Ðò¼«Æ°¼¹¹ÔÅªÄø¼°¡¤²ÄǽÀ§Â¤À®·ÏÅýÚÃΨ¹ßÄãŪ¸µ¶¤¡¤Ã¢¸ùǽÒʲá±÷ÍÛ½Õ¡£¼© Sysinternals AutoRunsÉÔâ¶ñͲ÷®ʬÎà查ëθùǽ¡¤Ëò²ÄľÀܽ¤²þ¼¹¹Ô檔ÏÂÅÐ錄µ¡âûŪ值¡¤Æ±»þÔ¦·Á²ðÌÌÁàºîµ¯ÐÔÌéÉÔº¤Æñ¡¤À§ÁêáÄÕéÍÑŪ¹©¶ñ¡£
Áá´ü°ÙÎ»ÎÆ²ò·ÏÅýI/OŪ±¿ºî¡¤ûòÜÆÜäÌéÁ½ÍøÍÑRegmon´Æ¹µÅÐ錄µ¡âûŪ¸¼è¾ð·Á¡£áÄ»þŪRegmonºß¼¹¹ÔÁ°¼ûÀè³ÝºÜ°ì¸ÄSYS檔¡¤»ÈÍѾåÊÂÉÔÊýÊØ¡£¼©WinternalsÈïÈùÆðÊ»¹Ø¸å½ê¿·¿ä½ÐŪProcess Monitor¡¤ÓÅÓÅÍøÍѰì¸Ä¹©¶ñ¡¤ÊØÇ½ë·»¡³Æ¼ïÎ෿Ū檔°Æ°¿µ¡âû¸¼è狀¶·¡¤Àá¾ÊÉÔ¾¯Äø¼°³«â¤°¿·ÏÅý½üºøÅª»þ´Ö¡£
å´¾ï¼ûÑÝÍýÅÅçªÃæÆÇÅù»ñ°ÂÌäÂêŪŢ»Òû±Â§É½¼¨¡¤ÌµÏÀ¹©ºî°¿Æü¾ïÀ¸³èÃæ¡¤ºß眾¿¹©¶ñΣ¾ºÇ¾ï»ÈÍÑŪ¡¤ÊØÀ§´Æ¹µÄø¼°ProcessExplorerµÚ TCPView¡£Â¾¾ïÍøÍÑÄø½ø±¿¹Ô狀¶·¡¤°ÊµÚÌÖÏ©ÄÌ¿ÖÉÖŪ»ÈÍѾð·Á¡¤ÐÔȽÚÒÀ§ÈÝÁø¼õÌÚÇϰ¿¸åÌçÄø¼°¹¶擊¡¤ºÆÍøÍÑÌÖÏ©»ñ¸»¾å½êÄÌÊóŪ»ñ¿Ö¡¤°¿ËܿȽêÕÜÕò°Ò¶¼ÇÓ½ü¡£
Å¢»Òû±ÄóÅþ¡¤SysinternalsÊäÂλWindwos·ÏÅýËÜ¿ÈŪÉÔ¡£ºßWindows XPÇ·Á°ÅªÈÇËÜ¡¤ºî¶È·ÏÅý內·úŪ¡Ö¹©ºî´ÉÍý°÷¡×¡¤ÊÂÝóÍðý¼¨±¿¹ÔÄø½øÅª¸¶»ÏÏ©×Í¡£IT¿Í°÷êÁ³²Ä°ÊÜý查ÌÜÁ°±¿¹ÔÅªÄø½ø狀¶·¡¤°ìö⤸½ÍÌäÂêÅªÄø½ø»þ¡¤ÒÊ̵ˡΩ¹ïÆÀÃÎÄø½øÅª½êºß°ÌÃÖ¡¤Ç¡º¡áÄÄø½øÌ¾ãÊ崲ᵶ¤»þ¡¤ÊØ×ÌÆñȽÚÒÀ§Í³²¿¼ïØæÍÑÄø¼°啟ưλ³ºÄø½ø¡£º¡»þÍøÍÑProcessExplorerÄó¶¡Åª´°À°絕ÕôÏ©×Í¡¤ÊØÇ½²÷®ٲÅþºß·ÏÅý內ºî²øÅª»ÏºîÐܼԡ£Æ±Íý¡¤ÍøÍÑTCPView§²ÄÙ´½ÐÈóå´°ôµö¡¤¼©ÍøÍÑÆÃÄêÌÖÏ©çг°³¦ÄÌ¿ÖŪ¸åÌçÄø¼°¡£Ç纳Áàºî´ÊÓż©¸ùǽ¶¯ÂçŪ¹©¶ñ¡¤°ìľ°ÊÐÔÅÔÀ§Â¾ÍÑÐÔ²ò·èÀñÕíÄø¼°ÌäÂêŪ½ÅÍ×Éð´ï¡£
½¼Õ鼫¿È½êÕܺÍǽÍÑÕô¹©¶ñ ͳ±÷Ç纳¹©¶ñŪ¸ùǽÅÔÁêá͝Â硤ͺ³¿Ó»ê²Ä°ÊľÀÜ´ÉÍý·ÏÅýŪ½ÅÍ×檔°Æ¡¤°øº¡IT¿Í°÷ºß»ÈÍÑÇ·Á°¡¤Øæ³ºÍ×ÀèŰÄìλ²òÇ纳¹©¶ñŪ¸ùǽ¡¤Ê¾Üì¦說ÌÀʸ·ï¡£ûòÜÆÜäǧ°ÙSysinternals SuiteÌéÈæ³ÓŬ¹çÕó¶ÈIT¿Í°÷»ÈÍÑ¡¤ÝóÍå´ñäŪ»ÈÍѼԳÓÉÔµ¹î®Êؾ¨»î¡¤°ÊÌÈÕô·ÏÅý產À¸ÉÔÎÉŪ±Æ¶Á¡£°ø°ÙSysinternals SuiteÊñ´ÞŪ¹©¶ñÚËÎÌÁêáÄ¿¡¤IT¿Í°÷ºÇ¹¥Ç½夠ÀèÀ¶Á¿Î»²ò½ê¶øÅþÌäÂêŪ̮Íí¡¤ºÆé´Í³Sysinternals SuiteÌÖãë¾åŪʬÎࡤºÍǽ°ÊºÇ¾¯»þ´ÖÄ©ÅþÉä¹ç¼ûµáŪ¹©¶ñ¡£
Ê¿¾ï½üλ»ÈÍѹ©¶ñ³°¡¤SysinternalsîÙ½ÐŪ¸»âûÌéÀ§°ì¹à¹¥Åª¶µºà¡£é´Í³¸¦µæÇ纳¹©¶ñŪ¸»âû¡¤ûòÜÆÜäǧ°Ù²Ä°Ê²òÀÏÄø¼°À§Ç¡²¿Õò»ñÎÁ×ÏWindowsŪµö¿»ñ¿ÖÃæ擷¼è½ÐÐÔ¡¤ÌéǽÕôWindowsÀ°¸Ä·ÏÅýŪ±¿ºî²áÄø¹¹²Ã½Ï¼½¡£
Äó¶¡À°¹ç¼°Ê¿çÊØæÇ½¹ßÄã»ÈÍÑÌçÝ£ êÁ³SysinternalsÌÜÁ°Êñ´ÞÏ»½½Â¿¸Ä¾®¹©¶ñ¡¤´ö¸Ã²Ä°Ê²ò·èǤ²¿IT¿Í°÷ºßÆðñó³«â¤¡¢ÌÖÏ©ËÉñϰ¿·ÏÅý°Ý½¤ÅùÌäÂꡤâÕàÐîÈມ̤崴°À°ÅªÊ¬Îà°¿·ÏÅý²½¡¤ºß»ÈÍѾåл·ù²á±÷ʣ𸡣
ÚªÎãÐÔ說¡¤¾®Äø¼°ºß¼¹¹Ô¾å®ÅÙ³Ó²÷¡¤Ã¢Íµö¿Ʊ¼ÁÀŪ¹©¶ñ¡¤Â¶ÕéÅÔÍÎà»÷Ū¸ùǽ¡£Á³¼©Áàºî²ðÌÌÉÔÆ±¡¤¼ãIT¿Í°÷»ÈÍѵ¯ÐÔ¡¤²ÄǽлÍ××ÏÆ¬Õܽ¬¡¤Â¨»ÈÇçÑÀÅ幩¶ñŪ¸ùǽº¹°ÛÊÂÉÔÀ§ÂÀÂç¡£°øº¡¼ãǽÕò¸ùǽÎà»÷Ū¹©¶ñ¡¤À°¹çÀ®³ÓÂ緿ŪÓŰìÄø¼°¡¤Õòͽõ±÷¿·¿Ê¿Í°÷²÷®Äó¾£²ò·èÌäÂêŪǽÎÏ¡£º¡³°°ìº³Ì¿ÎáÎó¼°Åª¾®¹©¶ñ¡¤¼ãǽÄó¶¡Ô¦·Á²ðÌÌ¡¤Ìé²Ä»ÈIT¿Í°÷¹¹½¼Ê¬Î»²ò³ÆÒÔÚ˽êÄó¶¡Åª¸ùǽ¡¤Ê½Ìû閱ì¦說ÌÀʸ·ïŪ»þ´Ö¡£
ÌÜÁ°Windows Sysinternals Suite¶ÏÀ§Õò³Æ¹©¶ñ½¸¹çÀ®ÔÚ½Ì檔¡¤ÈùÆð°¿µö²Ä°ÍÄø¼°Åª»ÈÍÑΨ°¿²¼ºÜ¼¡ÚË¡¤Îó½ÐTop 10Ç·ÎàŪ¿äÁ¦Ì¾ÓÅ¡¤Å¢»Òû±Ç§°ÙÇ¡º¡IT¿Í°÷ºßÁªÚ¤¹©¶ñ»þ¡¤ÉÔÃ×±÷̵½êŬ×Ï¡£
êÁ³Windows內·úŪ·ÏÅý¹©¶ñ¸ùǽ³Ó¾¯¡¤Ã¢ÊÂÉÔÀ§每çÊÅÅçªÃæÅÔ¼ûÍ×°ÂêæSysinternals Suite¹©¶ñ¡¤¼©³î²á±÷Îí»¶Åª¾®Äø¼°ÌéÉÔ°×ÌÙ¸±÷È碟Ãæ»ÈÍÑ¡¤°øº¡ûòÜÆÜäÌéÄóÀÃIT¿Í°÷ÉÔµ¹²áÅÙ°ÍûòÇçÅ幩¶ñ¡¤ºÇ¹¥´ÔÀ§Í×¶ñÈ÷°ÊWindows¹©¶ñ²ò·èÌäÂêŪǽÎÏ¡£Í³±÷Windows Sysinternals SuiteΣÊñ´ÞŪ眾¿¹©¶ñÂþÀ§½¸·ë¡¤ÕéºÝ¾åºßîٽп·ÈÇËÜ»þл¼û¸ÄÊ̹¹¿·¡¤°ÊÌÜÁ°Åª¾ð¶·ê̾°ÙSuite¡¤Ã¢ÕéºÝ¾åлÀ§Í³µö¿à×ΩŪ¾®Äø¼°Êñêæ¼©À®¡¤ÊÂÉÔÀ§ÓŰìŪÀ°¹çÀ產ÉÊ¡¤°øº¡È¿¼©Ðò¤À®»ÈÍѼԹ¹¿·¾åŪº¤¾ñ¡£ûòÜÆÜäÌé·úµÄÈùÆð¡¤Ì¤ÐÔ¼ãǽ°ÙSysinternals·úΩ°ì¸Ä¶¦ÄÌÀŪʿçÊ¡¤°¿Äó¶¡¹¹ÀººÙŪʬÎàçÐ說ÌÀ¡¤°¿µöáÄIT¿Í°÷¶øÅþÌäÂê¾åÌÖ¿ÒÙ²¹©¶ñ»þ¡¤Ðò¹¹ÊØÍø¡£
ÌÖÊǴƹµ¸ùǽ³Óåþ˳ Sysinternals SuiteÄó¶¡Åª¹©¶ñ¡¤¼çÍ×À§¿ËÕôWindows³Ë¿´·ÏÅýÀ߷ס¤°øº¡´Æ¹µ¹©¶ñðý¼¨Åª»ñÎÁÌé³ÓÄìÁØ¡¤Õô±÷ÁüHTTPÌÖÊǿ֩¡¤°¿À§API¡ÊØæÍÑÄø¼°²ðÌ̡˸¼è¾ð·ÁÅù»ñ¿ÖŪÜý»ëçÐÒ»À°½¢Î¬ðýÉÔ¡£
Á³¼©×ÏÈùÆðÊ»¹ØWinternals¸åŪÇç°ìǯ¿ÐÔ´Ç¡¤²æÐî²Ä°ÊÂç缿䬡¤Ì¤ÐÔSysinternals SuiteŪµö¿¸ùǽ¡¤É¬ÐòΦåôÀ°¹ç»êºî¶È·ÏÅý¡¤°¿Windows Server SystemŪIT´ÉÍýÊ¿çÊSystem Center內¡¤ÊÂâ¤Å¸°Ù¹¹ÍÚÃŪ·ÏÅý´ÉÍý¹©¶ñ¡¤¿Ê°ì步Ú²½¼çÐWindwos PowerShellÁêïðŪ¸ùǽ¡¨Ëò°¿À§À®°ÙWindows SDK¡ÊSoftware Development Kit¡¤Æðñóâ¤Å¸Åå·ï¡ËŪ°ì°÷¡£
̵ÏÀÀ§¶áÄøÅªËÉñϽüºø¡¤°¿À§°Ùλ±ý¸åǽ¹¹Î»²òWindows·ÏÅýŪ±¿ºî¾ð·Á¡¤ Windows Sysinternals SuiteêÁ³ÉÔ夠´°Èþ¡¤Ã¢¿Í¼ê°ìÅå½Ï¼½Õࡤ絕Õô²Ä°Ê幫½õ你Ú´Ê¿×Ì¿Æñ搞Ū¾®ÌäÂê¡£
²Ä±óü查ëÎçдÉÍý·ÏÅýŪPsTools PsTools內åÁ¶¦Êñ´Þλ12¼ï¹©¶ñ¡¤²Ä¶¨½õIT¿Í°÷²ò·è·ÏÅý¡¢ÌÖÏ©¡¢¼§碟檔°Æ°¿Äø½øÅùÉÔÆ±ÌäÂê¡£³ÓÆÃÊÌŪÀ§PsTools內Ū½ê͹©¶ñ»ÈÍѾ塤ÅÔɬ¿Ü°ÊºßÌ¿ÎáÎóÅëÇÛÒÔÚËŪÊý¼°¼¹¹Ô¡¤»ÈÍѾåÈæÔ¦·Á²ðÌÌÐÔÆÀ¹¹Ä¾ÀÜ¡£
PsExec¡§¼¹¹Ô±óüÅÅ窾åŪ»ØÎá PsExecºÇ¼çÍ×Ū¸ùǽ½¢À§啟ư±óüÅÅ窾åŪ̿Îá¼°È㼡»ØÎᡤ°¿À§RegeditÅùÆÃÄêŪ·ÏÅý¹©¶ñÄø¼°¡£ÚªÎãÐÔ說¡¤¼ã²æÐîÍߺß̾ãʰÙiThomeŪ±óüÅÅ窾塤¼¹¹Ôtest.exeÄø¼°¡¤Â§²Ä¸°Æþ¡Öpsexec \\iThome -u user -p passwd -c c:\test.exe¡×¡¤Â¶ÃæuserçÐpasswd°Ù·ÏÅý´ÉÍý°÷Ä¢é˵ÚÌ©âû¡¤¼©ÇçÑÀ¸ÄÌéÀ§PsToolsŪ¸øÍÑÒÔÚË¡¨»ê±÷-c§ÂåɽÀèÕòØæÍÑÄø¼° test.exe¡¤Ê£À½Åþ±óüÅÅçª¸åºÆ¼¹¹Ô¡£值ÆÀÃí°ÕŪÀ§¡¤¼ã»ÈÍѼÔ̤»ØÄêÍß¼¹¹ÔÅªØæÍÑÄø¼°Ï©×Í¡¤Â§Ðò»ÈÍÑÍÂÀßŪ¸¶»ÏÌÜ錄¡¤Ëò¨Windowsº¬ÌÜ錄¡Ê¡ó SystemRoot¡ó¡Ë¡£
ÍøÍÑPsExecŪÆÃÄêÒÔÚË¡Ö-i¡×¡¤²Ä°Ê¸ßưÊý¼°ºß±óü·ÏÅý¾å¼¹¹ÔØæÍÑÄø¼°¡¤Êر÷쪻ÈÍѼÔÜý»ëØæÍÑÄø¼°Åª»ÈÍѼԲðÌÌ¡¨º¡³°ÒÔÚË¡Ö-f¡×¡¤Â§À§¶¯À©ÕòËܵ¡ÅªØæÍÑÄø¼°Ê£À½Åþ±óü·ÏÅý¸åºÆ¼¹¹Ô¡¤ÌµÏÀ±óü·ÏÅýÀ§ÈÝÖá¶ñÈ÷º¡ØæÍÑÄø¼°¡¤°Ê³ÎÊÝ»ÈÍѼԼ¹¹ÔÅªÄø¼°°ÙºÇ¿·¡Ê°¿ÆÃÄê¡ËÈÇËÜ¡£
PsFile¡§查ëÎ檔°Æ»ñëÎ PsFileÕà¼çÍ×À§ÍÑÐÔ查ëαóüÅÅ窾åÖáå´³«啟Ū檔°Æ¡¤°ÊµÚ³«啟檔°ÆÅª»ÈÍѼÔ̾ãÊ¡£ÎãÇ¡ºß½Å¿·啟ư»ÇÉþ´ïÇ·Á°¡¤ÂþÍ×ÍøÍÑPsFile»ØÎὢǽ²÷®ÄÉåÔ½êÍÀµÑݱ÷³«啟狀ÂÖŪ檔°Æ¡¤Æ±»þÌéǽλ²òÍ哪º³檔°ÆÖáÈﺿÄꡤ°ÊÊØ±÷ÄÌÃαóüÍÑ戶¼êưïðÊÄ¡£Æ©²áPsFileŪÆÃÄêÒÔÚË¡Öpath¡×¡¤²Äðý¼¨ØæÍÑÄø¼°Åª´°À°°¿Éôʬϩ×Í¡£¼©¡Ö-c¡×ÒÔÚ˧ǽ°ÍID°¿Ï©×ÍïðÊÄÈïɸ¼¨ÅªÄø¼°¡£
PsGetSid¡§查ëÎSID PsGetSidçÐPsFile½½Ê¬Îà»÷¡¤ÌéÀ§ÍÑÐÔðý¼¨ÆÃÄê»ñ¿ÖŪ¹©¶ñ¡£PsGetSid»ØÎáǽ查ëÎÍïðÅÅ窡¢»ÈÍѼԵڻÈÍѼԷ²ÁÈŪ°ÂÁ´¼±Ê̹à¡ÊSID¡Ë¡£PsGetSidÊÂÝóÍÆÃÊÌŪà×ΩÒÔÚË¡¤ÉÔ²á»ÈÍѼÔÐ»Ç½ÍøÍÑÁüÀ§¡Öpsgetsid \\iThome user¡×Çç¼ï»ØÎᡤ查ëΰ̱÷±óüiThomeÅÅ窾åuser»ÈÍѼÔŪSID¿Ö©¡£
PsInfo¡§查ëιÅñó»ñ¿Öçг«µ¡»þ´Ö PsInfo²ÄÄó¶¡Ëܵ¡°¿±óüÅÅçªÅª·ÏÅý»ñ¿Ö¡¤Â¶ÃæÊñ´Þ°ÂêæÎà·¿¡¢³Ë¿´ÈÇËÜ¡¢Ãðºý¸ø»ÊµÚ½êͿ͡¢ÑÝÍý´ïÚËÎ̵ÚÎà·¿¡¢ðý¼¨卡·¿éË¡¢Õéñóµ²±ñóåÁÎÌ¡¢·ÏÅýŪ°ÂêæÆü´ü¡¤°ÊµÚ»îÍÑÈÇËÜŪÅþ´üÆüÅù»ñ¿Ö¡£PsInfoÍÂÀß值°Ùðý¼¨Ëܵ¡Åª·ÏÅý»ñ¿Ö¡¤Ç¡Æ±PsToolsŪ¶¾¹©¶ñ°ìÜ롤²Ä查ëαóüÅÅ窡¤ÉÔ²á»ÈÍѼԼû¶ñÈ÷¸¼è±óüÅÅ窵¡âûÃæHKLM\System¹àÌÜŪÜ޸¡£
ºÇ¿·ÅªPsInfoÈÇËܰÙ1.74ÈÇ¡¤ÌéÀ°¹çλǷÁ°Íѱ÷ðý¼¨·ÏÅý¾å¼¡½Å³«µ¡»þ´ÖŪ¹©¶ñPsUptime¡£
PsInfoŪÆÃÄêÒÔÚË¡Ö-s¡×¡¤²Äðý¼¨·ÏÅý¾å°ÂêæÅª½êÍØæÍÑÄø¼°¡¨¡Ö-d¡×§²Äðý¼¨Íïð·ÏÅýŪ¼§碟¡¿¼§Ò¿»ñ¿Ö¡£
PsKill¡§½ª»ßÆÃÄêÑÝÍýÄø½ø PsKillºîÍÑçСÖWindows¹©ºî´ÉÍý°÷¡×ÃæÅª¡Ö·ë«ÑÝÍýÄø½ø¡×ÁêÆ±¡¤Ã¢PsKill²ÄÍøÍÑ»ØÄêÄø½øIDŪÊý¼°½ª»ß¡¤Ìé²Ä°Êºß±óü¼¹¹Ô¡£
PsList¡§查ëηÏÅýÄø½ø»ñ¿Ö PsListçÐProcess Explorer°ÊµÚProcess MonitorŪµö¿¸ùǽÁêÆ±¡¤Ã¢ÕàÆÃÊÌÇ·Ñݺ߱÷²Ä»Ù±ç±óü´ÉÍý¡¤°øº¡áÄÍÑ戶¼ûºß±óüÅÅ窴ÉÍý°ì¸Ä°¿Â¿¸ÄÄø½ø»þ¡¤ÊØÆÀÍ×ÍøÍÑPsList¡£PsListŪ¸ùǽÎà»÷¡ÖWindows¹©ºî´ÉÍý°÷¡×ÃæÅª¡ÖÑÝÍýÄø½ø¡×Îóɽ¡¤Ç½ðý¼¨Ëܵ¡°¿±óüÅÅ窼¹¹ÔÃæÄø½øÅªÌ¾ãÊ¡¢PID°¿ÀêÍÑŪ虛µ¼µ²±ñóÅù»ñ¿Ö¡£
PsList²Ä»ÈÍÑŪÒÔÚËÃæ³ÓÆÃÊÌŪ͡Ö-d¡×¡¤²Äðý¼¨³ÆÑÝÍýÄø½ø¼¹¹Ô½ïÁصéŪ»ñ¿Ö¡¨¡Öname¡×²Ä°Êðý¼¨ÆÃÄê̾ãʳ«Æ¬ÅªÄø½øÁêïð»ñ¿Ö¡¨¡Ö-t¡×§²Ä°ÊÎà»÷Process ExplorerŪ¼ù狀·ë¹½ðý¼¨»ñ¿Ö¡£
PsLoggedOn¡§查ëÎÅÐÆþ狀ÂÖ ×Ï̾ãʨ²Ä´Ç½Ð¡¤PsLoggedOnÀ§ÍÑÐÔ查ëλÈÍѼÔÅÐÆþ¾ð·ÁŪ¹©¶ñ¡£PsLoggedOnÉÔâǽðý¼¨Ëܵ¡ÅÐÆþŪÍÑ戶¡¤×ϱóüÌÖÏ©ÅÐÆþŪÍÑ戶Ìé²ÄÁªÚ¤ÀÃÏÎó½Ð¡£ÍøÍÑÇç¸Ä¹©¶ñ×ÌÍÆ°×½¢Ç½Ñþ¼±Àµºß»ÈÍÑ»ÇÉþ´ïŪÍÑ戶¡¤¼©ÉÔÍѳ«啟°ìÂÏ»ëãÙÐÔ¸òºµÈæÕô¡£¼¹¹ÔPsLoggedOn»þ¡¤²ÄÆ©²á¡Ö-l¡×ÒÔÚËÕòÌÖÏ©»ÈÍѼÔÇÓ½ü¡¤¶Ïðý¼¨Ëܵ¡ÅÐÆþŪ»ÈÍѼԡ£
PsLogList¡§查ëÎÆÃÄê»ö·ïµ錄 PsLogListŪ¸ùǽçÐWindows·ÏÅý´ÉÍý¹©¶ñ內Ū»ö·ïµ錄´ïÁêÆ±¡¤²Ä°Êðý¼¨·ÏÅý¡¢ØæÍÑÄø¼°µÚ°ÂÁ´ÀÅù»ö·ïµ錄¡£ÕàÉÔ¶Ïǽðý¼¨Ëܵ¡µ錄¡¤Ìéǽ查ëαóüÆÃÄêÅÅ窡¤¿Ó»êÀ§ÌÖ°è內½êÍÅÅçªÅª»ö·ï¡£Çç¸Ä¹©¶ñ´ÔǽÕò»ö·ïµ錄檔¹àÌÜ¡¤×ϸ¶ËÜŪÆó¿Ê°Ì³Ê¼°¡¤íÛ´¹À®Â¶Â¾³Ê¼°¡£
PsLogList²Ä»ÈÍÑŪÒÔÚËÁêáÄ¿¡¤ÎãÇ¡¡Ö-e¡×²ÄÇÓ½üÊñ´Þ»ØÄê»ö·ï¼±ÊÌâûŪ»ö·ï¡¤ºÇ¿²Ä»ØÄê10¸Ä¡¨¼©¡Ö-m¡×À§Âþðý¼¨»ØÄêʬ¾âÚË內Ū»ñ¿ÖÅù¡£
PsPasswd¡§¹¹²þ»ÈÍѼÔÄ¢éËçÐÌ©âû PsPasswd²ÄÍÑÐÔ¹¹²þËܵ¡°¿±óüÅÅçªÅª»ÈÍѼÔ̾ãʵÚÌ©âû¡£Õô±÷¼û¼þ´üÀ¹¹´¹Ì©âûŪÌÖ°è內ÅÅ窡¤ÍøÍÑÇç¸Ä»ØÎáÊØÇ½²÷®ãÀ®ÌÜŪ¡£
PsService¡§Üý»ëÏÂÀßÄê·ÏÅýÉþ̳ PsServiceÀ§WindowsÉþ̳¹àŪÜý»ëÏÂÊÔ½´´ï¡¤Ëò²ÄáÄÐö¡Ö·ÏÅýÀßÄê¸øÍÑÄø¼°¡×Ãæ¡ÖÉþ̳¡×ÍóÌÜŪ²Ã¶¯ÈÇ¡£½üλǽ´ÉÍý±óüÅÅçªÅªÉþÌ³Äø½ø³°¡¤Ìé²Ä啟ư¡¢½ª»ß¡¢»ÃÄä¡¢åëåôϽſ·啟ưWindowsÉþ̳¹à¡¤Æ±»þ´Ôǽ¿ËÕôÆÃÄêŪÉþ̳¹à¡¤»ØÄêÎó½ÐçжÁêïðŪ¶¾Éþ̳¡£
PsServiceŪÒÔÚË»ÈÍÑÊý¼°çж¾¹©¶ñάÍÉÔÆ±¡¤每¸ÄÒÔÚËÅÔÍÉÔÆ±Åª¹µÀ©¸ìË¡¡¤»ÈÍѼԲĺßÒÔÚ˸å²Ã¡Ö¡Ý¡×»ú¸µ查ëΡ£
Æ©²á¡Öquery¡×ÒÔÚË¡¤²Ä查ëλØÄêŪÉþ̳¡¨¼©¡Öfind¡×²ÄºßÌÖÏ©Ãæ¿ÒÙ²Àµºß¼¹¹Ô»ØÄêÉþ̳ŪÅÅ窡¨¡Ösecurity¡×ÒÔÚ˧²ÄÄó¶¡»ØÄêÉþ̳Ū°ÂÁ´À»ñ¿Ö¡£
PsShutdown¡§¶¯²½ï𵡸ùǽ êÁ³¾È»úḬ̀ջ״ÇÐÔ¡¤PsShutdownŪ¸ùǽÏÂWindows內·úŪshutdown.exe»÷¸Ã°ìÜ롤ÅÔÀ§ÍÑÐÔïðÊÄÅÅ窡£Ã¢ PsShutdown´Ô¶ñͱóü´ÉÍý¡¢½Å¿·啟ưÅÅ窡¤°ÊµÚ»ØÄêÅÅçª¿ÊÆþµÙ̲°¿ÂÔµ¡Ìϼ°Åù¸ùǽ¡¨¿Ó»ê´Ôǽº¿ÄêÅÅ窡¤°¿Àèðý¼¨°ìÃʿ֩¸å¡¤ºÆ±÷°ìÄê»þ´Ö¸å½Å¿·啟ưÅÅ窡£
»ÈÍѼÔÍøÍÑÒÔÚË¡Ö-a¡×²ÄÃæ»ßͳPsShutdown啟ư¡¤³îÀµºß¿Ê¹ÔÃæÅªï𵡺î¶È¡¤¼©²áµîÁ½°ø¼ÀÉ÷ÉÂÆÇÞ¢Íô¡¤Â¤À®×Ì¿ÅÅçªå´¾ï¼«Æ°ï𵡡¤µö¿IT´ÉÍý¿Í°÷ÌéÐòÍøÍÑÇç¸ÄÒÔÚËÐÔ½ª»ßïðµ¡Äø½ø¡¨º¡³°ÒÔÚË¡Ö-v¡×²Ä쪻ÈÍѼÔÍ¢ÆþÆÃÄê¿Ö©¡¤°Êºßïðµ¡Á°¸þ±óüÍÑ戶ðý¼¨¡£
PsSuspend¡§»ÃÄä¼¹¹ÔÃæÅªÆÃÄêÄø½ø áÄË¿¸ÄØæÍÑÄø¼°ÀêÍÑ×ÌÂçÈæÎãŪÑÝÍý´ï»ñ¸»¡¤ÍÑ戶Áۻô˼¹¹Ô¡¤ÒÊËôÉÔ´ê°ä¼ºçгºØæÍÑÄø¼°ÁêïðŪ»ñÎÁ°¿內ÍÆ»þ¡¤Çç¸Ä¹©¶ñÊØÇ½ÇɾåÍѾ졣êÁ³ Process ExplorerÌéÍÄó¶¡Îà»÷Ū¸ùǽ¡¤ÉÔ²áÒʶÏǽºßËܵ¡¼¹¹Ô¡£¼©PsSuspend»ÈÍÑŪÆÃÄêÒÔÚ˶ÏÍ¡Ö-r¡×¡¤ÍÑÐԽſ·啟ư»ÃÄäÃæÅªÄø½ø¡£
Á´Ì̴ƹµ·ÏÅý狀ÂÖŪProcess Monitor Process MonitorÀ§ÈùÆðÊ»¹ØÎ»Winternals¸å½ê¿·ùáŪ¹©¶ñÇ·°ì¡¤ÌÜÁ°ÈÇËܰÙ1.12ÈÇ¡¤»Ù±çWindows 2000 SP4¡¢Windows XP SP2¡¢Windows Server 2003 SP1¡¢Windows Vista¡¤°ÊµÚ64°Ì¸µÅªWindows XP¡¢Windows Server 2003 SP1ÏÂWindows Vista¡£
»ÈÍѼԲļ«ÄûÍó°Ì Process MonitorÀ§·ë¹çλFilemon¡¢Regmon¡¢Process ExplorerçÐPslistÅù¹©¶ñÅªÄø¼°¡¤êÁ³Õô±÷ÑÝÍýÄø½ø´Æ¹µÅª¸ùǽÁª¹à¡¤ÉÔÇ¡Process ExplorerÐÔÆÀ¿¡¤Ã¢Ç¤²¿檔°Æ°¿ÅÐ錄µ¡âûŪ¸¼è¡¤ÅÔǽƩ²áProcess Monitor¨»þðý¼¨¡£¼ç»ëãÙŪº¸²¼ÊýŪÚË»ú¡¤É½¼¨ÌÜÁ°Process Explorerµ錄Ū»ö·ïÚË¡¢·ÏÅýåÁ¶¦產À¸Î»Â¿¾¯»ö·ï¡¤°ÊµÚÈïµ錄Ū»ö·ïÀêåÁ»ö·ïÅªÈæÎãÅù¡£
¼©»ÈÍѼÔÌé²ÄÍøÍÑProcess Monitor Column Selection¼«ÄûÍó°Ì¡¤ÁªÚ¤ÁÛÍ×查ëÎŪ¹àÌÜ¡£Column SelectionÕòÍó°Ìʬ°ÙApplication Details¡¢Event DetailsµÚProcess Management»°ÂçÎࡤðý¼¨Åª»ñ¿ÖÊñ´Þ½ç½ø¡¢ì¦ÕíŪ»þ´Ö¡¢¹ÔÄøÅª ID¡¢Îà·¿¡¢Ï©×Í¡¢Äø¼°À½ºî¸ø»Ê¡¢ÈÇËÜ¡¤°ÊµÚ±¿¹Ô»þ´ÖÅù22¼ïÉÔÆ±¹àÌÜ¡£
Äó¶¡»ö·ï²áßÉ´ï°Ê´Ê²½µ錄 Process MonitorŪ»ö·ïµ錄ÍÂÀß°Ù¼«Æ°·þư¡¤Í³±÷°ìÈÌÅÅ窺߱¿ºî»þ¸¼èŪµ錄»ñÎÁÎÌÁêáÄ龐Â硤°øº¡¿Ö©ķưŪÉÑΨÁêáIJ÷¡£êÁ³»ÈÍѼԲİÊÕò¼«Æ°·þưïðÊİÊÍøÙÓ¿Ò¡¤Ã¢°ì³«»ÏÍ×Ù²Åþ»ØÄêŪ¹àÌÜ¡¤ÆñÅÙÅùƱ±÷Â糤Ùý¿Ë¡£
º¡»þÍÑ戶²ÄÍøÍѰ̱÷¼çÁàºî»ëãÙ±¦¾åÊýŪ²÷®¹©¶ñÎ󡤺߼¹¹ÔÄø½ø¡¢檔°ÆÂ¸¼èÏÂÅÐ錄µ¡âû»°¼ïÎà·¿Ãæ¡¤ÁªÚ¤Í×ðý¼¨²¿¼ï»ñ¿Ö¡£ÚªÎãÐÔ說¡¤¼ãÂþ°Ä²¼¡ÖShow Process and Thread Activity¡×¹©¶ñîæ¡¤ÆáÖ÷»ö·ïµ錄Ãæ½¢ÂþÐòðý¼¨çм¹¹ÔÄø½øÍïðŪ»ñÎÁ¡¤Ç¡Äø½ø³«»Ï¡¢·ë«»þ´Ö¡¤°ÊµÚDLL檔ºÜÆþÅù¡£
»ê±÷Process Monitor Filter§Äó¶¡¹¹¿Ê³¬Åª²áßɸùǽ¡¤ÍÑ戶²ÄÁªÚ¤ºßÄø½øÌ¾ãÊ¡¢Ï©×Í¡¢Äø½øÃðºý¸ø»Ê°¿»þ´ÖÅùÉÔÆ±¹àÌܼ«Äûï𸰻ú¡¤·èÄêðý¼¨Åªµ錄ÃæÀ§ÈÝÍ×Êñ´Þ¡¢ÇÓ½ü°¿´°Á´Éä¹ç³ºï𸰻ú¡£Í³±÷·ÏÅý產À¸Åª»ö·ïÚËÎÌÁêáÄ龐Â硤Process MonitorŪÍÂÀß值ÃæÊØÖáå´¼¹¹Ôλµö¿²áßɸ¶Â§¡£
º¡³°ÍÑ戶Ìé²ÄÍøÍÑProcess Monitor Highlighting¡¤¼«Í³ÁªÚ¤°ÊÉÔÆ±ðú¿§É¸ÃðÉä¹çË¿¸ÄÛê·ïŪ»ö·ï¡¤ÉÔ²áÉä¹çƱ°ì¼ïÛê·ïŪ»ö·ï¡¤¶Ïǽ°Ê°ì¼ïðú¿§É¸Ãð¡£¼©ºßProcess MonitorÖáðý¼¨Åª»ñÎÁÃæ¡¤ÍÑ戶Æ©²áCtrl﹢FŪÁÈ¹ç¸°ÊØÇ½²÷®¿ÒÙ²ÆÃÄêŪ»ñÎÁ¡¨Ã¢¼ãÀ§³º»ñÎÁÖ¤±÷ð¬é¶Íó°Ì¡¤Â§¼ûÀè»êColumn SelectionÃæÕòÀßÄê°Ùðý¼¨Íó°Ì¸å¡¤ºÍ²ÄÙÓ¿Ò¡£
Process MonitorŪԦ·Á²ðÌÌÁàºîêÁ³´ÊÓÅ¡¤µ錄Ū»ñÎÁÎÌÒÊÁêáĶÿ͡¤°øº¡Ìéǽ¶¨½õIT¿Í°÷¿ÒÙ²·ÏÅýϳƶ¡¢¸åÌçÄø¼°°¿¿Ê¹Ôºø¸íÜý¬¡¨Ã¢Í³±÷»ñÎÁ·¿ÂÖʣ𸡤ºß»ÈÍÑÁ°Øæ¾Ü즻ÈÍѼêºý¡¤ÊÂλ²ò·ÏÅý±¿ºîÊý¼°¡¤ºÍÍÆ°×Ù²ÅþÌäÂêóÚ¡£
Æ©»ëWindows TCP/UDPÏ¢ÀþŪTCPView TCPView for Windows v2.4À§°ìÅå²Ä°ÊÍÑÔ¦·Á²ðÌÌ´°À°ë·»¡WindowsÌÜÁ°Ï¢ÀþŪ¹©¶ñ¡¤你²Ä°ÊÍÑÕàÜý»ëÅÅ窾åŪÌÖÏ©»ñ¿Ö¡¤´Æ´ÇTCP/UDPŪÉõÊñή¸þŪÌÖÏ©IP°ÌÔ®¡¢½ê»ÈÍÑŪϢÀÜÉÖ¡¤°ÊµÚÏ¢Àþ狀ÂÖ¡£
Ô¦·Á²½²ðÌÌŪ¨»þ´Æ¹µ ¼¹¹ÔÇ·¸å¡¤TCPViewÐò°ÊÀ¶ÓÅŪÊý¼°¡¤ðý¼¨ÅÅ窾åÌÜÁ°½êÍ»ÈÍÑTCP/UDPÌÖÏ©¶¨ÄêŪüóÚÏ¢ÀÜ»ñ¿Ö¡¤Ç纳»ñ¿ÖÊñ´Þλ啟ưϢ·ëÅªÄø¼°¡¢Äֶ̿¨Äê¡¢Ëܵ¡°ÌÔ®¡¢ÌÜŪ°ÌÔ®°ÊµÚ狀ÂÖÅù¡£Áê³Ó±÷WindowsÅå·ï內ŪNetstat»ØÎᡤ»ÈÍѼԲİÊé´Í³´ÊÓÅŪ»ëãÙáÁÌÌ¡¤¹¹Ä¾ÀÜÃϴƹµ¼«¸ÊŪÅÅ窷ÏÅý內ŪÌÖϩ¸¼è¡¤ë·»¡ÌÜÁ°ÀµÆ©²áÌÖϩϢ·ë¶¾¼çµ¡ÅªÄø¼°¡£
ÇçÅ幩¶ñŪԦ·Á²ðÌÌ»ÈÍѵ¯ÐÔ¡¤ÍÂÀß»ú·¿×̾®¡¤ºß²æÐî»ÈÍÑ1280×1024Ūê¥Ëë²òÀÏÅÙ²¼¡¤»ú·¿´ö¸Ã¾®ÅþÆñ°ÊÑþ»ë¡¤½ê°Ê»ÈÍѼ԰쳫»Ï¼¹¹Ô»þ¡¤ºÇ¹¥ÀèÀßÄê»ú·¿¡¤Ä´À°À®¹çŬŪ»úñóÂç¾®¡¤ÊýÊØ²æÐî°Ê¸å»ÈÍÑTCPView¡£»ú·¿ÅªÀßÄê²Ä°Ê×ϲ¼ÙǼ°ÁªÓÅŪÁª¹à¡ÊOptions¡ËÁª¼è»ú·¿¡ÊFont¡Ë¡¤½¢Ç½Ä´À°TCPView½êðý¼¨Åª»ú·¿Âç¾®¡£
TCPViewºßÍÂÀß¾åÀ§ðý¼¨Ï¢ÀþÀáóÚŪÌÖ°è̾ãÊÏÂÏ¢ÀÜÉÖéË¡¤»ÈÍѼԲİʰ;ȼûµá¡¤ºßÁª¹àÃæ¸ûÁª²òÀϰÌÔ®¡ÊResolve Addresses¡Ë¡¤ÕòÌÖ°è̾ãÊŪÉô份²þÀ®°ÊIP°ÌÔ®ðý¼¨¡¤Ëò²ÄºßÁª¹àÃæðý¼¨ÈóÏ¢ÀþÃæÅªÃ¼óÚ¡ÊShow Unconnected Endpoints¡Ë¡¤ð¬é¶¡¿ðý¼¨Èó»ÈÍÑÃæÅªÃ¼óÚÏ¢Àþ¡£
¼¹¹Ô»þ¡¤TCPViewÐò°Í¾ÈÀßÄêŪÉÑΨ¼«Æ°¹¹¿·´Æ¹µ»ñ¿Ö¡¤ÍÂÀß值°Ù1É᤻ÈÍѼԲİʰÍÚ¡¼ûµá¡¤ºßÜý»ë¡ÊView¡ËÃæÅª¹¹¿·Â®ÅÙ¡ÊUpdate Speed¡Ë¡¤Ä´À°°Ù2Éð¿3Éá¤Ìé²Ä°Ê¼êư¼¹¹Ô½Å¿·À°Íý¡ÊRefresh¡Ë°¿»ÃÄä¹¹¿·¡ÊPaused¡Ë¡¤ÊýÊØ»ÈÍѼÔÜý»ë»ñÎÁÎó¡£Ï¢·ë»ñ¿Öǡ͹¹¿·¡¤Ðòºß¹¹¿·Åª»ñÎÁÎó¾å°Êðú¿§ÆÍðý½ÐÐÔ¡¤ûÑ¿§É½¼¨ÌÜÁ°產À¸¿·ÅªÏ¢·ë¡¤¹È¿§É½¼¨Ï¢·ëÃæÚÒ¡¤黃¿§Â§À§É½¼¨Ã¼óÚÏ¢·ë內ÍÆÍ°ÛÆ°¡£
½üλÜý»ëÏ¢Àþ狀ÂÖµÚ³«啟Ï¢·ëÅªÄø¼°³°¡¤TCPViewËò²ÄÜý»ëÄø¼°½êºßŪÌÜ錄°ÌÃÖ¡¤ÂþÍ×óÚÁª²¼ÙǼ°ÁªÓÅ¡¤°¿À§±¦¸°ÁªÓÅÃæóÚÁªÄø¼°Ö¤À¡ÊProcess Properties¡Ë¡¤½¢²Ä°Ê´ÇÅþÄø¼°½êºßŪϩ×Í¡£Ç¡²ÌÍ×ÃæÚÒ³ºÏ¢Àþ¡¤Â§²Ä°ÊÍÑïðÊÄÏ¢Àþ¡ÊClose Connection¡ËÐÔÃæÚÒÏ¢Àþ¡¤¼ãÀ§Í×·ë«ϢÀþÃæÅªÄø¼°¡¤Â§²Ä°Êºß²¼ÙǼ°ÁªÓŰ¿±¦¸°¸ùǽɽ內»ÈÍÑ·ëÂ«Äø¼°¡ÊEnd Process¡Ë¸ùǽ¡¤Ä¾Àܷ뫳ºÄø¼°¡£
²ò·èÌÖÏ©ÌäÂê TCPView²Ä°Ê¶¨½õ²æÐîºßWindowsÊ¿çʾå²ò·èµö¿ÌÖÏ©ÌäÂꡤÁüÀ§ÌÚÇϰ¿ÉÂÆÇÇçÎàØ¨°ÕÄø¼°¡¤²ÄǽÐòºß̤崰ôµöŪ¾ð¶·²¼¡¤Ú£¼«¿Ê¹ÔÌÖϩϢÀþ¡¤±Æ¶Á»ñ¿Ö°ÂÁ´¡£¼©Æ©²áTCPView¡¤²Ä°Ê¶¨½õ²æÐîÜý»ëÌÜÁ°À§ÈÝÍÄø¼°Àµºß¿Ê¹Ô̤崰ôµöŪϢÀþ¡¤ÀÜÃøÂ¨²Ä查½ÐÇ纳ب°ÕÄø¼°Åª½êºß°ÌÃÖ¡¤°Ê°Ý¸î·ÏÅýÀµ¾ï±¿ºî¡£
另³°¡¤TCPViewÌé²Ä°Ê¶¨½õ²æÐîÑÝÍýÌÖÏ©ÉÖéË¾×ÆÍŪÌäÂꡣͻþÌִɿͰ÷啟ư˿º³Äø¼°»þ¡¤Ðò°ø°ÙÉÖéË¾×ÆÍ¼©Æ³Ã×Ï¢Àþ¼ºÇÔ¡¤±Æ¶Á·ÏÅý±¿ºî¡¤ÁüÀ§ IIS¡ÊInternet Information Service¡ËŪÉÖéË¾×ÆÍ¡¤°ì»þÇ·´Ö¡¤²æÐî²ÄǽÉÔÀ¶Á¿À§哪¸ÄÄø¼°½ê°úµ¯Åª¡¤Çç»þ¸õ½¢²Ä°Êé´Í³TCPViewÙ²½Ð¤À®ÉÖéË¾×ÆÍÅªÄø¼°¡¤Ê¿ҵáºÇŬÀÚŪ²ò·èÊý°Æ¡£
TCPView²Ä°ÊºßWindows 9ס¿Me¡¿NT¡¿2000¡¿XPÅùÈÇËܾåÌ̱¿ºî¡¤Ã¢¼ãÍ׺ßWindows 95¾å¼¹¹Ô¡¤ºî¶È·ÏÅýËÜ¿ÈŪÌÖÏ©¸µ·ï§¼ûÍ×¹¹¿·»êWinsock 2 UpdateºÍǽ½çÍø±¿ºî¡£
http://www.microsoft.com/technet/sysinternals/default.mspx
http://www.microsoft.com/technet/sysinternals/utilities/sysinternalssuite.mspx
|