Morgan's beautiful life - ËຬŪÀ¸³èϲ̡ι
ÇçÀ§°ì²ôµÛÚÀÃμ±Åª´¥³¤ÌÊ............î®Ãø»þ´ÖËýËýËÄıËÄı
·î曆

07 | 2008/08 | 09
Æü ·î ²Ð ¿å ÌÚ ¶â ÅÚ
- - - - - 1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31 - - - - - -



ºÇ¶á¤Îµ­»ö



·îÊÌ»ñÎÁ¸Ë



ºÇ¿·²óʤ



ºÇ¿·°úÍÑ



ÌÜ錄°¿Ê¬Îà



¥Ö¥í¤È¤â¿½ÀÁ¥Õ¥©¡¼¥à

¤³¤Î¿Í¤È¥Ö¥í¤È¤â¤Ë¤Ê¤ë



ÙÓ¿Òʸ¾Ï



RSS¥Õ¥£¡¼¥É



Ï¢·ë

¤³¤Î¥Ö¥í¥°¤ò¥ê¥ó¥¯¤ËÄɲ乤ë



ïð±÷²æ.BLOG»ñ¿Ö

Morgan

Author:Morgan
Øáé´ÅØÎÏçи¬虛Ä«¸þÀ®¸ùŪƻϩ°ì步°ì步Ê



Microsoft Sysinternals Suite-¹¥µÉ¿·´ñËô¹¥´á


î®ÃøWindowsÈÇËÜ¿äÄĽп·¡¤·ÏÅýÆü±×ãÓÄꡤ´Ç»÷ͧÁ±Åª»ëãÙÔ¦·Á²ðÌ̴ǵ¯ÐÔ쪿ÍÊü¿´¡¤Á³¼©ÇظåÒʲÄǽð¬é¶Ãø»ÈÍѼԡ¢·ÏÅý´ÉÍý¼Ôçг«â¤¼Ô¶Ñ̵ˡ⤸½ÅªÌäÂê¡£Îãǡ̤崻ÈÍѼԵö²ÄÅªØæÍÑÄø¼°¼¹¹ÔçÐÌÖϩ¸¼è¡¤Çç½¢ÉÔÀ§°ìÈ̸ĿÍü·ÏÅýÄ´¹»¹©¶ñǽ夠ÐöÅþŪ¡¨Â¨ÊØÀ§¾¦¶ÈØæÍÑÎΰè¾å¡¤Ìé×̾¯IT¾³¾¦ÕóÌç¿ËÕô Windows·ÏÅýÂçÎÌÄó¶¡ÇçÎàÍÑÅÓŪ¹©¶ñ¡¤SysinternalsÒÊÐöÅþλ¡ª¼©³îºß·ÏÅý°Ý¸îŪÎΰèÃæ¡¤SysinternalsÀ§ÌÜÁ°½Å½ê¸øÇ§ºÇ¹¥Åª¹©¶ñÇ·°ì¡£


2006ǯÈùÆðÊ»¹Ø SysinternalsŪÊì¸ø»ÊWinternals¸å¡¤ÈùÆðºßTechEd 2007ÃæÆÃÊÌ說ÌÀ´ë¶È»ÈÍÑ Sysinternals³ºÃí°ÕŪ»ö¹à¡£Â¾Ðîɽ¼¨¡¤Õòåëåôìª Sysinternals°Ý»ýÌÈÈñ²¼ºÜ¡¤°ìÈÌ´ë¶È²Ä°Êºß¸ø»Ê內Éô¼«¹Ô»ÈÍÑ¡¤ÉԸ¼øÜÞÚËÎÌ¡¤Ã¢Ç¡²ÌÀ§Éþ̳Äó¶¡¾³¾¦Í×»ÈÍѻ꺳¹©¶ñ¡¤½¢¼ûÍ׸þÈùÆð¿½ÀÁ¼øÜÞ¡£°ø°Ù SysinternalsÀ§Ìµ½þ»ÈÍÑ¡¤ÉÔÏÀÀ§´ë¶È°¿¸Ä¿Í¡¤¶Ñ̵ˡ×ÏÈùÆðÆÀÅþ¶¨½õ¡¤Ã¢°ø°Ù»ÈÍÑÀß·²×Ì×¢Â硤ÈùÆð·¹¸þ쪻ÈÍѼԸþÀß·²µá½õ¡¢»ðëΡ£

ìª你ÀºÄÌWindows·ÏÅý´ÉÍý¡¢ÌÖÏ©´ÉÍý°¿Äø¼°³«â¤ÅªÌÈÈñ¹©¶ñ
ÉÔÆ±±÷¹âµ®Åª·ÏÅý´ÉÍýÊ¿çÊÏÂIT¸¶¾³¸ÜÌ䡤ÕÜÐò»ÈÍÑWindows Sysinternals Suite¡¤你Õò¹¹Í­Ç½ÎÏÑÝÍýWindowsŪ³Æ¼ïÌäÂꡤ¼©³îÉÔ²Ö°ìÌÓ£

Á±Íѹ©¶ñ¡¤ºÍǽé»Åþɽü
SysinternalsÇçÅ幩¶ñºß´Ô̤ʻÆþÈùÆðTechNetÇ·Á°¡¤ºßÌÖÏ©µÚ·ÏÅý´ÉÍý³¦½¢Öáå´¼õÅþ×¢Þ¢»ÈÍÑλ¡£´ûÁ³Sysinternalsºß·ÏÅý¹©¶ñ¾åÖáÀêÍ­°ìÀÊÇ·ÃÏ¡¤ÆáIT¿ÍÊ¿»þËôÀ§Ç¡²¿»ÈÍÑÇ纳¹©¶ñŪ¡©

¾ïÍÑŪSysinternalsÑÝÍýÄø½ø´ÉÍý¹©¶ñ
²Ä±óü查ëÎçдÉÍý·ÏÅýŪPsTools
PsToolsÊñ´Þ12¼ï±óü´ÉÍý¹©¶ñ¡¤²Ä²ò·è·ÏÅý¡¢¼§碟¡¢檔°Æ°¿ÌÖÏ©ÅùÌäÂꡤ³ÓÆÃÊÌŪÀ§PsTools內Ū½êÍ­¹©¶ñ»ÈÍѾ塤ÅÔɬ¿Ü°ÊºßÌ¿ÎáÎóÅëÇÛÒÔÚËŪÊý¼°¼¹¹Ô¡¤»ÈÍѾåÈæÔ¦·Á²ðÌÌÐÔÆÀ¹¹Ä¾ÀÜ¡£

¾ïÍÑŪSysinternals·ÏÅý»ñ¿Ö查ëι©¶ñ
Á´Ì̴ƹµ·ÏÅý狀ÂÖŪProcess Monitor
ÍøÍÑÓŰìÄø¼°¡¤ÊØÇ½Â¨»þ´Æ¹µWindows·ÏÅýŪ檔°Æ¡¢ÅÐ錄µ¡âûçÐÄø½ø¡¤Ç½¶¨½õIT¿Í°÷¿ÒÙ²·ÏÅýϳƶ¡¢¸åÌçÄø¼°°¿¿Ê¹Ôºø¸íÜý¬¡£

¾ïÍÑŪSysinternalsÌÖÏ©¹©¶ñ
Æ©»ëWindows TCP/UDPÏ¢ÀþŪTCPView
Üý»ëÅÅçªÅªTCPµÚUDPüóÚÏ¢Àþ»ñ¿Ö¡¢½ê»ÈÍÑŪϢÀÜÉÖ¡¤°ÊµÚÏ¢Àþ狀ÂÖ¡¤幫½õ你ÑÝÍýÌÖÏ©ÁêïðŪ¾×ÆÍ»ö·ï°¿Ù²½Ð°Û¾ïÏ¢Àþ¡£

ìª你ÀºÄÌWindows·ÏÅý´ÉÍý¡¢ÌÖÏ©´ÉÍý°¿Äø¼°³«â¤ÅªÌÈÈñ¹©¶ñ
IT¿Í°÷ÑÝÍýÌäÂ꽢ǡƱîлմÇÉÂÌä¿Ç¡¤µ»½ÑÀºÎÉŪîлձý±ý´Ç°ì´ã½¢ÃÎÆ»Ç¡²¿ÑÝÃÖÉÂÎ㡤âͭ»þ²æÐîåÁÐò¶øÅþ槸«Åªµ¿Æñð¸¾É¡¤áÄÝóÍ­Á°Îã²Ä¿Ò»þ¡¤´ÔÀ§Íׯ©²áÚÒÁØÁÝÉÁ¡¢Ä¶²»ÇȰ¿內»ë¶ÀÅù¹â²Êµ»´ïºàÊå½õ¡¤ºÍǽٲ½Ðɰø¡£

Sysinternals SuiteΣŪ¹©¶ñ¡¤½¢ÁüÀ§Ç纳´ïºà¡¤Ã¢ÉÔ¼ûÍײÖï¢Â¨²Ä²¼ºÜ»ÈÍÑ¡¤Ç¡²Ì懂ÆÀÇ¡²¿±¿ÍÑÇ纳´ïºàŪIT¿Í°÷¡¤É¬Á³Ç½ÈæÂþÍÑ¡Öæå¿Ç´ï¡×Ū¿Íλ²ò¹¹¿¼Æþ¡£ÉÔÆ±±÷¹âµ®Åª·ÏÅý´ÉÍýÊ¿çÊÏÂIT¸¶¾³¸ÜÌ䡤ÕÜÐò»ÈÍÑWindows Sysinternals Suite¡¤你Õò¹¹Í­Ç½ÎÏÑÝÍýWindowsŪ³Æ¼ïÌäÂꡤ¼©³îÉÔ²Ö°ìÌÓ£

Sysinternalsǽ¿¼ÆþWindows³Ë¿´
SysinternalsÅþÄìÀ§²¿Êý¿ÀÀ»¡©

SysinternalsÇ·Á°°ÙWinternals¸ø»ÊÄó¶¡ÅªÌÈÈñ¹©¶ñ¡¤Winternals¸¶ËÜÀ§°ì´Ö¼çÎÏ產ÉʰٷÏÅýÉü¸¶çлñÎÁÊݸîŪ¸ø»Ê¡¤°Ùλ²ò·è¹©Äø»ÕÊ¿¾ïºß¹©ºî¾å¶øÅþŪ³Æ¼ïÌäÂê¡¤ÊØ³«â¤½Ðµö¿¾®¹©¶ñ¡£Ç·¸å¾ÐîÕòÇ纳¹©¶ñ½¸¹çµ¯ÐÔãʰÙSysinternals¡¤ÊÂÊüºßÌÖÏ©¶¡¿ÍÌÈÈñ²¼ºÜ¡¤Â¶ÃæÌéÊñ´ÞÉôʬ¹©¶ñŪ¸¶»Ïâû¡¤°ìľ°ÊÐÔÅÔ¿ü¼õITÕó²È¼Ò·²Åª¹¥É¾¡£

2006ǯ7·î18Æü¡¤ÈùÆðÀëÉÛÊ»¹ØWinternals¸ø»Ê¡¤ÉÔâÕò½ÏÃÎWindows·ÏÅýŪWinternals¸ø»Ê¶¦Æ±ÁÏ辦¿Í¨¡¨¡Mark Russinovich °ÊµÚ Bryce Cogswell¨¡¨¡Ç¼Æþ´ú²¼¡¤Æ±»þÌéÕòSysinternalsÇçÅ幩¶ñÚÀÊÔ»êTechNetÌÖãë¡£

¸½Ç¤¿¦±÷ÈùÆðÊ¿çʵÚÉþ̳ÉôÌçŪMark Russinovich¡¤À§Âç²È³Ó¾ï¼ªÊ¹ÅªÑ£´ñ¿Íʪ¡¤Â¾ÕôWindows³Ë¿´Äø¼°âûÍ­¶Ë¿¼ÆþŪǧ¼±¡¤Á½ºß1996ǯ⤸½Windows NT ServerÏÂWorkstationÈǶñÍ­ÁêÆ±Åª³Ë¿´Äø¼°¡¤ÂþÍ×¹¹Æ°ÑÀ¸ÄÅÐ錄µ¡âû¡¤½¢Ç½ÕòÈÇËÜÚι¹¡£¼©ºß2005ǯ¡¤Mark⤸½ì¦¼èSony BMGŪ²»ÜÛCD»þ¡¤Windows·ÏÅýÐòÁøð¬é¶ºßCDÃæÅªrookitËÉÝ¹Äø¼°ãâ²þ¡¤³î»ÈÍѼԴ°Á´ÉÔÃξð¡£Çç¸Ä⤸½ÉÔâ»ÈÆÀSonyµÉ¾å´±»Ê¡¤Mark Ìé°ø¼©æá̾ÂçÓä¡£

ͳ±÷MarkËÜ¿ÈŪµ»½ÑÃμ±ì´ÉÙ¡¤°øº¡Â¾Ðî½ê³«â¤ÅªÆðñó¡¤Êñ´ÞSysinternalsºß內ŪµöÂ¿ØæÍÑÄø¼°¡¤ÌéÀ®°Ù»ÈÍÑWindows·ÏÅýŪIT ¿Í°÷¡¤²ò·èÌäÂêçпÒٲب°ÕÄø¼°Åª¼çÍ×¹©¶ñ¡£ºßçÊßÔÈùÆðTechNetƤÏÀÒ¿Ãæ¡¤ËòÍ­ÉÔ¾¯MVP¡ÊMost Valuable Professional¡¤ºÇÍ­Ñ«值Õó²È¡Ëɽ¼¨½½Ê¬¶Õ¾ÞMarkŪÕó¶È¡¤°ÊµÚͦ±÷揭Ϫ»öÕéŪ¹Ô°Ù¡£

Ï¢ÈùÆðµ»½Ñ¿Í°÷ÅÔ¿äÁ¦»ÈÍÑ
SysinternalsÇçÅ幩¶ñºß´Ô̤ʻÆþÈùÆðTechNetÇ·Á°¡¤ºßÌÖÏ©µÚ·ÏÅý´ÉÍý³¦½¢Öáå´¼õÅþ×¢Þ¢»ÈÍÑλ¡£

Ĺ´üٿǤµ»½Ñ¸ÜÌä¡¢ÌÜÁ°Ç¤¿¦±÷Ë¿¶âÍ»Éþ̳¶ÈŪÈùÆðTechNet MVPÍûÌÀ¼ôɽ¼¨¡¤Í³±÷¾ËܿȰìľ°ÊÐÔÊØÕôÄø¼°³«â¤¡¤°ÊµÚ·ÏÅý½üºøÊÝ»ý¹âÅÙŪ¶½¼ñ¡¤°øº¡Ìéå´¾ïÍøÍÑ¿¼ïǽ¿¼Æþë·»¡ÌäÂꡤÊÂʬÀÏ·ÏÅý³Ë¿´±¿ºî²áÄøÅª¹©¶ñ¡£¼©ºßÇ纳¾ïÍÑŪ½ÅÍ×¹©¶ñáÄÃæ¡¤ÊØÍ­´ö¹àÀ§½Ð¼«Sysinternals¡£

ÍûÌÀ¼ô說¡¤°ì³«»ÏÀÜë½ÅþÇçÅ幩¶ñ¡¤Â¾À§°ÊËܿȶøÅþŪÌäÂêÐö°Ùï𸰻ú¡¤Æ©²áÙÓ¿Ò°úú²ºÍ⤸½Åª¡¤Æ±»þÌéÃí°ÕÅþµö¿¶È³¦¿Í»ÎÅÔÁêáÄ¿ä¿ò Sysinternals¡£¸åÐԺ߹©ºî¾åÑÝÍýÅþÍ­ïðWindows·ÏÅýŪÌäÂ꼩̵ˡ²ò·è»þ¡¤µá½õÈùÆðµ»½Ñ¿Í°÷»Ù±çŪ²áÄøÃæ¡¤Ìéͭ¿¼¡Èï¿äÁ¦»ÈÍÑ SysinternalsŪå´ñä¡£

»ê±÷É÷㻲ʵ»ñäëúŪ·ÏÅý¹©Äø»ÕÅ¢»Òû±ÌéÍ­Îà»÷å´ñä¡£áĽéÅ¢»Òû±À§ºßÄø¼°³«â¤»þ¡¤¶øÅþ°ìº³WindowsÄø½øºø¸íŪÌäÂê̵ˡ²ò·è¡¤ÊظþÈùÆðµá½õ¡¤¼©ÈùÆðŪµ»½Ñ»Ù±ç¿Í°÷·úµÄ¾»ÈÍÑáÄ»þл֤±÷Winternals¸ø»Ê¡¤ÈÇËܳÓÁá´üŪProcessExplorer¹©¶ñ¡¤ÈùÆð´õ˾Ţ»Òû±Ç½ÍøÍѺ¡¹©¶ñ¡¤ÕòÄø½øºø¸íŪ歷Äø´°À°Ãϵ­錄²¼ÐÔ¡¤ºÆÍ³Â¾ÐîŪµ»½Ñ¿Í°÷Äó¶¡Õô¾É²¼é»Åª½¤Àµ»Ù±ç¡£

º¡³°¡¤ÌÜÁ°Õ󿦱÷ÕíºîµÚËÝ죸¶Ê¸½ñŪÈùÆðTechNet MVPûòÜÆÜ䡤Ìé°øÁá´üÁ½»ÈÍѲáWinternals¸ø»ÊŪ產ÉÊNTFSDOS¡¤Ùεßλ»ÔÕ¹Å碟ÃæÅª»ñÎÁ¡¤¼©³«»ÏÃí°ÕÅþλWinternals¸ø»ÊŪÁÏ辦¿ÍMark ¡¤Æ±»þ³«»Ï¸¦µæÇç´Ö¸ø»ÊŪ產ÉÊ¡¤áÄÁ³¡¤Â¶ÃæÌéÊñ´ÞλWindows Sysinternals Suite¡£

Ê»¹Ø¸å¡¤¹¹¿·µÚ°Ý¸îÉÔÐòÄä»ß
Markºß²ÃÆþÈùÆð¸å¡¤¼óÀèÕòÉÂÆÇµÚ´ÖĵÆðñ󸦵æ¿Í°÷¡¤å´¾ï»ÈÍÑŪRegmonÏÂFilemonÑÀ¹à¹©¶ñ¡¤À°¹ç»ê¿·¹©¶ñProcess MonitorÃæ¡¤Æ±»þÌéºßÇç¹à¿·¹©¶ñÃæ²ÃÆþÉôʬŪProcess Explorer¸ùǽ¡¤ìªIT´ÉÍý¿Í°÷ÉÔÍѺߵö¿»ëãÙ´ÖÀÚ´¹¡¤ÊØÇ½Äå¬ب°ÕÄø¼°Åª³èư¹Ô°Ù¡£º¡³°¡¤ê­Á³ÉԺƹ¹¿·PsUptimeÇç¹à¹©¶ñ¡¤Ã¢ÈùÆðºß PsInfoÃæ²ÃÆþ¸¶ËÜPsUptimeŪ¸ùǽ¡¤ºÆÕò°ì·ÏÎóŪPs¹©¶ñÒ»½¸¸å½Å¿·Ì¿Ì¾°ÙPsTools¡¤³îîٽлٱçVistaºî¶È·ÏÅýŪÈÇËÜ¡£

ÈùÆðÊ»¹ØWinternalsÇ·¸å¡¤µö¿Ū»ÈÍѼÔÉÔÌÈÙ¿¿´¡¤¸¶ËÜÌÈÈñŪ¹©¶ñÐòÚÎÀ®ÚÀÈñÆðñ󡤰¿À§¹©¶ñŪ¹¹¿·Â®ÅÙÉÔÇ¡°Ê±ý¡¤¿Ó»êÉԺƹ¹¿·Åù¡£

»öÕé¾å¡¤Windows Sysinternals SuiteÉÔâùá²ÃλProcess Monitor¡¢PsToolsÅù¿·¹©¶ñ¡¤ÁüProcess Explorer°¿TCPViewÅùÕéÍѹ©¶ñÌéΦåô¿ä½Ð¿·ÈÇËÜ¡¤°øº¡ÇçÅ幩¶ñŪ¹¹¿·Â®ÅÙ¡¤ÊÂ̤°ø´¹Î»¾·Ç×¼©Í­±Æ¶Á¡£

ºßçÊßÔ¡¤ÁêïðŪ»ñ¿Ö§×ÌÍ­¸Â¡£ÌÜÁ°çÊßÔÈùÆðTechNetÌÖãë¾å¡¤ïð±÷SysinternalsÓŰ칩¶ñŪ說ÌÀлͭµö¿°Ù±Ñʸ»ñÎÁ¡¤ÉÔ²áçÊßÔÈùÆð»ÇÉþ´ïÊ¿çÊ»ö¶ÈÉô¹ÔîùÉûÍý¡¤Æ±»þÌéÀ§TechNetŪÉéÀÕ¿Íס¹À»Ö¡¤ËÜ¿ÈÌé¶ñÍ­SysinternalsŪ»ÈÍÑå´ñ䡤¾ɽ¼¨ÈùÆðÕòÐòÍ¥ÀèÑÝÍýÁêïðÌÖÊÇŪËÝ죹©ºî¡¤°Ê¶¨½õIT¿Í°÷¹¹²Ãλ²òSysinternals SuiteŪ»ÈÍÑÊý¼°¡£

Á±Íѹ©¶ñ¡¤ºÍǽé»Åþɽü
Sysinternalsºß·ÏÅý¹©¶ñ¾åÖáÀêÍ­°ìÀÊÇ·ÃÏ¡¤IT¿ÍÊ¿»þËôÀ§Ç¡²¿»ÈÍÑÇ纳¹©¶ñŪ¡©

ºßSysinternals¾°Ì¤À°Ê»ÅþTechNetÇ·Á°¡¤ÍûÌÀ¼ôºÇ¾ï»ÈÍÑŪ¹©¶ñ¡¤áÄÖ¤RegmonÏÂFilemonλ¡£°øRegmon²Ä°ÊÍÑÐÔë·»¡ØæÍÑÄø¼°»ÈÍÑÅÐ錄µ¡âûŪ²áÄø¡¤ºÆÇÛ¹çFilemon查ëΡ¤ÊØÇ½²÷®⤸½°ø檔°ÆÉÔ¸ºß¡¤°¿ÜÞ¸ÂÉÔ­̵ˡ»ÈÍѤÀ®Åªºø¸í¡£ÍûÌÀ¼ôɽ¼¨¡¤¼ãFile MonitorŪ²áßÉï𸰻ú²¼ÆÀÀº½à¡¤ÉÔÍÑÑÀʬ¾â½¢Ç½Ù²½ÐÌäÂꡤÆá¼ï¶øÅþĩ٥¼©Ëôǽ²÷®²ò·èŪÀ®½¢´¶¡¤ÌéÀ§ìªÂ¾»Ï½ªÜÛº¡ÉÔÈèŪ¼ç°ø¡£

Á³¼©RegmonÏÂFilemonÀèÁ°À§Ê¬³«ÅªÑÀ¸Ä¹©¶ñ¡¤²áµî»ÈÍÑ»þå´¾ï¼û³«啟ÑÀ¸Ä»ëãÙ¡¤ºÆ°ÊÆù´ã¸òºµÈæÕô¡¤²Ä°Ê說ÁêáÄÉÔÊýÊØ¡£ÈùÆð¸åÐÔ¿·¿ä½ÐλÀ°¹çÇçÑÀ¼Ô¸ùǽŪ¿·¹©¶ñProcess Monitor¡¤ÕôÍûÌÀ¼ô¼©¸À¡¤²Ä說À§´°Á´ÀÚÃæÍ׳²¡¤ÌéÀ®°ÙÌÜÁ°Â¾¹©ºî¾å»ÈÍÑΨºÇ¹âŪ°ì¸Ä¹©¶ñ¡£

½üλProcess MonitorÇ·³°¡¤ÍûÌÀ¼ôÌéå´¾ï»ÈÍÑProcess Explorer¡¤Õà²Ä說À§¿Ê³¬Èǹ©ºî´ÉÍý°÷¡¤ÉÔâǽÍÑÐÔÑè½ü¹©ºî´ÉÍý°÷̵ˡÑè½üÅªÄø½ø¡¤Ìé²Ä¾ÜºÙÜý查Äø½ø»ÈÍÑÅþŪDLL檔¡¢³«啟Ū檔°ÆµÚÌÖÏ©»ÈÍÑ狀¶·Åù¾ÜºÙ»ñ¿Ö¡£¼©Í­»þÑè½ü檔°Æ»þÐòâ¤À¸檔°ÆÖáÈﺿÄêŪ¾ð·Á¡¤º¡»þÍøÍÑProcess ExplorerÌéǽٲ½Ð¸µ¶¤¡£

°Ê±ýÁ½°ÙλÅÅ窳«µ¡ÌüÐÔÌüËýŪÌäÂꡤ¼©´¶Åþ½½Ê¬º¤¾ñŪûòÜÆÜäÌéÃÌÅþÕôSysinternalsŪÁÛË¡¡¤Â¾說ê­Á³ÍøÍÑWindowsŪ msconfig»ØÎᡤ°¿À§ÅþÅÐ錄µ¡âûÃæÜý查¡¤Ìé²Ä°Ê⤸½ºß³«µ¡²áÄøÃæÍ­哪º³Ðò¼«Æ°¼¹¹ÔÅªÄø¼°¡¤²ÄǽÀ§Â¤À®·ÏÅýÚÃΨ¹ßÄãŪ¸µ¶¤¡¤Ã¢¸ùǽÒʲá±÷ÍÛ½Õ¡£¼© Sysinternals AutoRunsÉÔâ¶ñÍ­²÷®ʬÎà查ëθùǽ¡¤Ëò²ÄľÀܽ¤²þ¼¹¹Ô檔ÏÂÅÐ錄µ¡âûŪ值¡¤Æ±»þÔ¦·Á²ðÌÌÁàºîµ¯ÐÔÌéÉÔº¤Æñ¡¤À§ÁêáÄÕéÍÑŪ¹©¶ñ¡£

Áá´ü°ÙÎ»ÎÆ²ò·ÏÅýI/OŪ±¿ºî¡¤ûòÜÆÜäÌéÁ½ÍøÍÑRegmon´Æ¹µÅÐ錄µ¡âûŪ¸¼è¾ð·Á¡£áÄ»þŪRegmonºß¼¹¹ÔÁ°¼ûÀè³ÝºÜ°ì¸ÄSYS檔¡¤»ÈÍѾåÊÂÉÔÊýÊØ¡£¼©WinternalsÈïÈùÆðÊ»¹Ø¸å½ê¿·¿ä½ÐŪProcess Monitor¡¤ÓÅÓÅÍøÍѰì¸Ä¹©¶ñ¡¤ÊØÇ½ë·»¡³Æ¼ïÎ෿Ū檔°Æ°¿µ¡âû¸¼è狀¶·¡¤Àá¾ÊÉÔ¾¯Äø¼°³«â¤°¿·ÏÅý½üºøÅª»þ´Ö¡£

å´¾ï¼ûÑÝÍýÅÅçªÃæÆÇÅù»ñ°ÂÌäÂêŪŢ»Òû±Â§É½¼¨¡¤ÌµÏÀ¹©ºî°¿Æü¾ïÀ¸³èÃæ¡¤ºß眾¿¹©¶ñΣ¾ºÇ¾ï»ÈÍÑŪ¡¤ÊØÀ§´Æ¹µÄø¼°ProcessExplorerµÚ TCPView¡£Â¾¾ïÍøÍÑÄø½ø±¿¹Ô狀¶·¡¤°ÊµÚÌÖÏ©ÄÌ¿ÖÉÖŪ»ÈÍѾð·Á¡¤ÐÔȽÚÒÀ§ÈÝÁø¼õÌÚÇϰ¿¸åÌçÄø¼°¹¶擊¡¤ºÆÍøÍÑÌÖÏ©»ñ¸»¾å½êÄÌÊóŪ»ñ¿Ö¡¤°¿ËܿȽêÕÜÕò°Ò¶¼ÇÓ½ü¡£

Å¢»Òû±ÄóÅþ¡¤SysinternalsÊä­λWindwos·ÏÅýËÜ¿ÈŪÉÔ­¡£ºßWindows XPÇ·Á°ÅªÈÇËÜ¡¤ºî¶È·ÏÅý內·úŪ¡Ö¹©ºî´ÉÍý°÷¡×¡¤ÊÂÝóÍ­ðý¼¨±¿¹ÔÄø½øÅª¸¶»ÏÏ©×Í¡£IT¿Í°÷ê­Á³²Ä°ÊÜý查ÌÜÁ°±¿¹ÔÅªÄø½ø狀¶·¡¤°ìö⤸½Í­ÌäÂêÅªÄø½ø»þ¡¤ÒÊ̵ˡΩ¹ïÆÀÃÎÄø½øÅª½êºß°ÌÃÖ¡¤Ç¡º¡áÄÄø½øÌ¾ãÊ崲ᵶ¤»þ¡¤ÊØ×ÌÆñȽÚÒÀ§Í³²¿¼ïØæÍÑÄø¼°啟ưλ³ºÄø½ø¡£º¡»þÍøÍÑProcessExplorerÄó¶¡Åª´°À°絕ÕôÏ©×Í¡¤ÊØÇ½²÷®ٲÅþºß·ÏÅý內ºî²øÅª»ÏºîÐܼԡ£Æ±Íý¡¤ÍøÍÑTCPView§²ÄÙ´½ÐÈóå´°ôµö¡¤¼©ÍøÍÑÆÃÄêÌÖÏ©çг°³¦ÄÌ¿ÖŪ¸åÌçÄø¼°¡£Ç纳Áàºî´ÊÓż©¸ùǽ¶¯ÂçŪ¹©¶ñ¡¤°ìľ°ÊÐÔÅÔÀ§Â¾ÍÑÐÔ²ò·èÀñÕíÄø¼°ÌäÂêŪ½ÅÍ×Éð´ï¡£

½¼Õ鼫¿È½êÕܺÍǽÍÑÕô¹©¶ñ
ͳ±÷Ç纳¹©¶ñŪ¸ùǽÅÔÁêá͝Â硤ͭº³¿Ó»ê²Ä°ÊľÀÜ´ÉÍý·ÏÅýŪ½ÅÍ×檔°Æ¡¤°øº¡IT¿Í°÷ºß»ÈÍÑÇ·Á°¡¤Øæ³ºÍ×ÀèŰÄìλ²òÇ纳¹©¶ñŪ¸ùǽ¡¤Ê¾Üì¦說ÌÀʸ·ï¡£ûòÜÆÜäǧ°ÙSysinternals SuiteÌéÈæ³ÓŬ¹çÕó¶ÈIT¿Í°÷»ÈÍÑ¡¤ÝóÍ­å´ñäŪ»ÈÍѼԳÓÉÔµ¹î®Êؾ¨»î¡¤°ÊÌÈÕô·ÏÅý產À¸ÉÔÎÉŪ±Æ¶Á¡£°ø°ÙSysinternals SuiteÊñ´ÞŪ¹©¶ñÚËÎÌÁêáÄ¿¡¤IT¿Í°÷ºÇ¹¥Ç½夠ÀèÀ¶Á¿Î»²ò½ê¶øÅþÌäÂêŪ̮Íí¡¤ºÆé´Í³Sysinternals SuiteÌÖãë¾åŪʬÎࡤºÍǽ°ÊºÇ¾¯»þ´ÖÄ©ÅþÉä¹ç¼ûµáŪ¹©¶ñ¡£

Ê¿¾ï½üλ»ÈÍѹ©¶ñ³°¡¤SysinternalsîÙ½ÐŪ¸»âûÌéÀ§°ì¹à¹¥Åª¶µºà¡£é´Í³¸¦µæÇ纳¹©¶ñŪ¸»âû¡¤ûòÜÆÜäǧ°Ù²Ä°Ê²òÀÏÄø¼°À§Ç¡²¿Õò»ñÎÁ×ÏWindowsŪµö¿»ñ¿ÖÃæ擷¼è½ÐÐÔ¡¤ÌéǽÕôWindowsÀ°¸Ä·ÏÅýŪ±¿ºî²áÄø¹¹²Ã½Ï¼½¡£

Äó¶¡À°¹ç¼°Ê¿çÊØæÇ½¹ßÄã»ÈÍÑÌçÝ£
ê­Á³SysinternalsÌÜÁ°Êñ´ÞÏ»½½Â¿¸Ä¾®¹©¶ñ¡¤´ö¸Ã²Ä°Ê²ò·èǤ²¿IT¿Í°÷ºßÆðñó³«â¤¡¢ÌÖÏ©ËÉñϰ¿·ÏÅý°Ý½¤ÅùÌäÂꡤâÕàÐîÈມ̤崴°À°ÅªÊ¬Îà°¿·ÏÅý²½¡¤ºß»ÈÍѾåл·ù²á±÷ʣ𸡣

ÚªÎãÐÔ說¡¤¾®Äø¼°ºß¼¹¹Ô¾å®ÅÙ³Ó²÷¡¤Ã¢Í­µö¿Ʊ¼ÁÀ­Åª¹©¶ñ¡¤Â¶ÕéÅÔÍ­Îà»÷Ū¸ùǽ¡£Á³¼©Áàºî²ðÌÌÉÔÆ±¡¤¼ãIT¿Í°÷»ÈÍѵ¯ÐÔ¡¤²ÄǽлÍ××ÏÆ¬Õܽ¬¡¤Â¨»ÈÇçÑÀÅ幩¶ñŪ¸ùǽº¹°ÛÊÂÉÔÀ§ÂÀÂç¡£°øº¡¼ãǽÕò¸ùǽÎà»÷Ū¹©¶ñ¡¤À°¹çÀ®³ÓÂ緿ŪÓŰìÄø¼°¡¤ÕòÍ­½õ±÷¿·¿Ê¿Í°÷²÷®Äó¾£²ò·èÌäÂêŪǽÎÏ¡£º¡³°°ìº³Ì¿ÎáÎó¼°Åª¾®¹©¶ñ¡¤¼ãǽÄó¶¡Ô¦·Á²ðÌÌ¡¤Ìé²Ä»ÈIT¿Í°÷¹¹½¼Ê¬Î»²ò³ÆÒÔÚ˽êÄó¶¡Åª¸ùǽ¡¤Ê½Ìû閱ì¦說ÌÀʸ·ïŪ»þ´Ö¡£

ÌÜÁ°Windows Sysinternals Suite¶ÏÀ§Õò³Æ¹©¶ñ½¸¹çÀ®ÔÚ½Ì檔¡¤ÈùÆð°¿µö²Ä°ÍÄø¼°Åª»ÈÍÑΨ°¿²¼ºÜ¼¡ÚË¡¤Îó½ÐTop 10Ç·ÎàŪ¿äÁ¦Ì¾ÓÅ¡¤Å¢»Òû±Ç§°ÙÇ¡º¡IT¿Í°÷ºßÁªÚ¤¹©¶ñ»þ¡¤ÉÔÃ×±÷̵½êŬ×Ï¡£

ê­Á³Windows內·úŪ·ÏÅý¹©¶ñ¸ùǽ³Ó¾¯¡¤Ã¢ÊÂÉÔÀ§每çÊÅÅçªÃæÅÔ¼ûÍ×°ÂêæSysinternals Suite¹©¶ñ¡¤¼©³î²á±÷Îí»¶Åª¾®Äø¼°ÌéÉÔ°×ÌÙ¸±÷È碟Ãæ»ÈÍÑ¡¤°øº¡ûòÜÆÜäÌéÄóÀÃIT¿Í°÷ÉÔµ¹²áÅÙ°ÍûòÇçÅ幩¶ñ¡¤ºÇ¹¥´ÔÀ§Í×¶ñÈ÷°ÊWindows¹©¶ñ²ò·èÌäÂêŪǽÎÏ¡£Í³±÷Windows Sysinternals SuiteΣÊñ´ÞŪ眾¿¹©¶ñÂþÀ§½¸·ë¡¤ÕéºÝ¾åºßîٽп·ÈÇËÜ»þл¼û¸ÄÊ̹¹¿·¡¤°ÊÌÜÁ°Åª¾ð¶·ê­Ì¾°ÙSuite¡¤Ã¢ÕéºÝ¾åлÀ§Í³µö¿à×ΩŪ¾®Äø¼°Êñêæ¼©À®¡¤ÊÂÉÔÀ§ÓŰìŪÀ°¹çÀ­產ÉÊ¡¤°øº¡È¿¼©Ðò¤À®»ÈÍѼԹ¹¿·¾åŪº¤¾ñ¡£ûòÜÆÜäÌé·úµÄÈùÆð¡¤Ì¤ÐÔ¼ãǽ°ÙSysinternals·úΩ°ì¸Ä¶¦ÄÌÀ­ÅªÊ¿çÊ¡¤°¿Äó¶¡¹¹ÀººÙŪʬÎàçÐ說ÌÀ¡¤°¿µöáÄIT¿Í°÷¶øÅþÌäÂê¾åÌÖ¿ÒÙ²¹©¶ñ»þ¡¤Ðò¹¹ÊØÍø¡£

ÌÖÊǴƹµ¸ùǽ³Óåþ˳
Sysinternals SuiteÄó¶¡Åª¹©¶ñ¡¤¼çÍ×À§¿ËÕôWindows³Ë¿´·ÏÅýÀ߷ס¤°øº¡´Æ¹µ¹©¶ñðý¼¨Åª»ñÎÁÌé³ÓÄìÁØ¡¤Õô±÷ÁüHTTPÌÖÊǿ֩¡¤°¿À§API¡ÊØæÍÑÄø¼°²ðÌ̡˸¼è¾ð·ÁÅù»ñ¿ÖŪÜý»ëçÐÒ»À°½¢Î¬ðýÉÔ­¡£

Á³¼©×ÏÈùÆðÊ»¹ØWinternals¸åŪÇç°ìǯ¿ÐÔ´Ç¡¤²æÐî²Ä°ÊÂç缿䬡¤Ì¤ÐÔSysinternals SuiteŪµö¿¸ùǽ¡¤É¬ÐòΦåôÀ°¹ç»êºî¶È·ÏÅý¡¤°¿Windows Server SystemŪIT´ÉÍýÊ¿çÊSystem Center內¡¤ÊÂâ¤Å¸°Ù¹¹Í­ÚÃŪ·ÏÅý´ÉÍý¹©¶ñ¡¤¿Ê°ì步Ú²½¼çÐWindwos PowerShellÁêïðŪ¸ùǽ¡¨Ëò°¿À§À®°ÙWindows SDK¡ÊSoftware Development Kit¡¤Æðñóâ¤Å¸Åå·ï¡ËŪ°ì°÷¡£

̵ÏÀÀ§¶áÄøÅªËÉñϽüºø¡¤°¿À§°Ùλ±ý¸åǽ¹¹Î»²òWindows·ÏÅýŪ±¿ºî¾ð·Á¡¤ Windows Sysinternals Suiteê­Á³ÉÔ夠´°Èþ¡¤Ã¢¿Í¼ê°ìÅå½Ï¼½Õࡤ絕Õô²Ä°Ê幫½õ你Ú´Ê¿×Ì¿Æñ搞Ū¾®ÌäÂê¡£

²Ä±óü查ëÎçдÉÍý·ÏÅýŪPsTools
PsTools內åÁ¶¦Êñ´Þλ12¼ï¹©¶ñ¡¤²Ä¶¨½õIT¿Í°÷²ò·è·ÏÅý¡¢ÌÖÏ©¡¢¼§碟檔°Æ°¿Äø½øÅùÉÔÆ±ÌäÂê¡£³ÓÆÃÊÌŪÀ§PsTools內Ū½êÍ­¹©¶ñ»ÈÍѾ塤ÅÔɬ¿Ü°ÊºßÌ¿ÎáÎóÅëÇÛÒÔÚËŪÊý¼°¼¹¹Ô¡¤»ÈÍѾåÈæÔ¦·Á²ðÌÌÐÔÆÀ¹¹Ä¾ÀÜ¡£

PsExec¡§¼¹¹Ô±óüÅÅ窾åŪ»ØÎá
PsExecºÇ¼çÍ×Ū¸ùǽ½¢À§啟ư±óüÅÅ窾åŪ̿Îá¼°È㼡»ØÎᡤ°¿À§RegeditÅùÆÃÄêŪ·ÏÅý¹©¶ñÄø¼°¡£ÚªÎãÐÔ說¡¤¼ã²æÐîÍߺß̾ãʰÙiThomeŪ±óüÅÅ窾塤¼¹¹Ôtest.exeÄø¼°¡¤Â§²Ä¸°Æþ¡Öpsexec \\iThome -u user -p passwd -c c:\test.exe¡×¡¤Â¶ÃæuserçÐpasswd°Ù·ÏÅý´ÉÍý°÷Ä¢é˵ÚÌ©âû¡¤¼©ÇçÑÀ¸ÄÌéÀ§PsToolsŪ¸øÍÑÒÔÚË¡¨»ê±÷-c§ÂåɽÀèÕòØæÍÑÄø¼° test.exe¡¤Ê£À½Åþ±óüÅÅçª¸åºÆ¼¹¹Ô¡£值ÆÀÃí°ÕŪÀ§¡¤¼ã»ÈÍѼÔ̤»ØÄêÍß¼¹¹ÔÅªØæÍÑÄø¼°Ï©×Í¡¤Â§Ðò»ÈÍÑÍÂÀßŪ¸¶»ÏÌÜ錄¡¤Ëò¨Windowsº¬ÌÜ錄¡Ê¡ó SystemRoot¡ó¡Ë¡£

ÍøÍÑPsExecŪÆÃÄêÒÔÚË¡Ö-i¡×¡¤²Ä°Ê¸ßưÊý¼°ºß±óü·ÏÅý¾å¼¹¹ÔØæÍÑÄø¼°¡¤Êر÷쪻ÈÍѼÔÜý»ëØæÍÑÄø¼°Åª»ÈÍѼԲðÌÌ¡¨º¡³°ÒÔÚË¡Ö-f¡×¡¤Â§À§¶¯À©ÕòËܵ¡ÅªØæÍÑÄø¼°Ê£À½Åþ±óü·ÏÅý¸åºÆ¼¹¹Ô¡¤ÌµÏÀ±óü·ÏÅýÀ§ÈÝÖá¶ñÈ÷º¡ØæÍÑÄø¼°¡¤°Ê³ÎÊÝ»ÈÍѼԼ¹¹ÔÅªÄø¼°°ÙºÇ¿·¡Ê°¿ÆÃÄê¡ËÈÇËÜ¡£

PsFile¡§查ëÎ檔°Æ»ñëÎ
PsFileÕà¼çÍ×À§ÍÑÐÔ查ëαóüÅÅ窾åÖáå´³«啟Ū檔°Æ¡¤°ÊµÚ³«啟檔°ÆÅª»ÈÍѼÔ̾ãÊ¡£ÎãÇ¡ºß½Å¿·啟ư»ÇÉþ´ïÇ·Á°¡¤ÂþÍ×ÍøÍÑPsFile»ØÎὢǽ²÷®ÄÉåÔ½êÍ­ÀµÑݱ÷³«啟狀ÂÖŪ檔°Æ¡¤Æ±»þÌéǽλ²òÍ­哪º³檔°ÆÖáÈﺿÄꡤ°ÊÊØ±÷ÄÌÃαóüÍÑ戶¼êưïðÊÄ¡£Æ©²áPsFileŪÆÃÄêÒÔÚË¡Öpath¡×¡¤²Äðý¼¨ØæÍÑÄø¼°Åª´°À°°¿Éôʬϩ×Í¡£¼©¡Ö-c¡×ÒÔÚ˧ǽ°ÍID°¿Ï©×ÍïðÊÄÈïɸ¼¨ÅªÄø¼°¡£

PsGetSid¡§查ëÎSID
PsGetSidçÐPsFile½½Ê¬Îà»÷¡¤ÌéÀ§ÍÑÐÔðý¼¨ÆÃÄê»ñ¿ÖŪ¹©¶ñ¡£PsGetSid»ØÎáǽ查ëÎÍ­ïðÅÅ窡¢»ÈÍѼԵڻÈÍѼԷ²ÁÈŪ°ÂÁ´¼±Ê̹à¡ÊSID¡Ë¡£PsGetSidÊÂÝóÍ­ÆÃÊÌŪà×ΩÒÔÚË¡¤ÉÔ²á»ÈÍѼÔÐ»Ç½ÍøÍÑÁüÀ§¡Öpsgetsid \\iThome user¡×Çç¼ï»ØÎᡤ查ëΰ̱÷±óüiThomeÅÅ窾åuser»ÈÍѼÔŪSID¿Ö©¡£

PsInfo¡§查ëιÅñó»ñ¿Öçг«µ¡»þ´Ö
PsInfo²ÄÄó¶¡Ëܵ¡°¿±óüÅÅçªÅª·ÏÅý»ñ¿Ö¡¤Â¶ÃæÊñ´Þ°ÂêæÎà·¿¡¢³Ë¿´ÈÇËÜ¡¢Ãðºý¸ø»ÊµÚ½êÍ­¿Í¡¢ÑÝÍý´ïÚËÎ̵ÚÎà·¿¡¢ðý¼¨卡·¿éË¡¢Õéñóµ­²±ñóåÁÎÌ¡¢·ÏÅýŪ°ÂêæÆü´ü¡¤°ÊµÚ»îÍÑÈÇËÜŪÅþ´üÆüÅù»ñ¿Ö¡£PsInfoÍÂÀß值°Ùðý¼¨Ëܵ¡Åª·ÏÅý»ñ¿Ö¡¤Ç¡Æ±PsToolsŪ¶¾¹©¶ñ°ìÜ롤²Ä查ëαóüÅÅ窡¤ÉÔ²á»ÈÍѼԼû¶ñÈ÷¸¼è±óüÅÅ窵¡âûÃæHKLM\System¹àÌÜŪÜ޸¡£

ºÇ¿·ÅªPsInfoÈÇËܰÙ1.74ÈÇ¡¤ÌéÀ°¹çλǷÁ°Íѱ÷ðý¼¨·ÏÅý¾å¼¡½Å³«µ¡»þ´ÖŪ¹©¶ñPsUptime¡£

PsInfoŪÆÃÄêÒÔÚË¡Ö-s¡×¡¤²Äðý¼¨·ÏÅý¾å°ÂêæÅª½êÍ­ØæÍÑÄø¼°¡¨¡Ö-d¡×§²Äðý¼¨Í­ïð·ÏÅýŪ¼§碟¡¿¼§Ò¿»ñ¿Ö¡£

PsKill¡§½ª»ßÆÃÄêÑÝÍýÄø½ø
PsKillºîÍÑçСÖWindows¹©ºî´ÉÍý°÷¡×ÃæÅª¡Ö·ë«ÑÝÍýÄø½ø¡×ÁêÆ±¡¤Ã¢PsKill²ÄÍøÍÑ»ØÄêÄø½øIDŪÊý¼°½ª»ß¡¤Ìé²Ä°Êºß±óü¼¹¹Ô¡£

PsList¡§查ëηÏÅýÄø½ø»ñ¿Ö
PsListçÐProcess Explorer°ÊµÚProcess MonitorŪµö¿¸ùǽÁêÆ±¡¤Ã¢ÕàÆÃÊÌÇ·Ñݺ߱÷²Ä»Ù±ç±óü´ÉÍý¡¤°øº¡áÄÍÑ戶¼ûºß±óüÅÅ窴ÉÍý°ì¸Ä°¿Â¿¸ÄÄø½ø»þ¡¤ÊØÆÀÍ×ÍøÍÑPsList¡£PsListŪ¸ùǽÎà»÷¡ÖWindows¹©ºî´ÉÍý°÷¡×ÃæÅª¡ÖÑÝÍýÄø½ø¡×Îóɽ¡¤Ç½ðý¼¨Ëܵ¡°¿±óüÅÅ窼¹¹ÔÃæÄø½øÅªÌ¾ãÊ¡¢PID°¿ÀêÍÑŪ虛µ¼µ­²±ñóÅù»ñ¿Ö¡£

PsList²Ä»ÈÍÑŪÒÔÚËÃæ³ÓÆÃÊÌŪͭ¡Ö-d¡×¡¤²Äðý¼¨³ÆÑÝÍýÄø½ø¼¹¹Ô½ïÁصéŪ»ñ¿Ö¡¨¡Öname¡×²Ä°Êðý¼¨ÆÃÄê̾ãʳ«Æ¬ÅªÄø½øÁêïð»ñ¿Ö¡¨¡Ö-t¡×§²Ä°ÊÎà»÷Process ExplorerŪ¼ù狀·ë¹½ðý¼¨»ñ¿Ö¡£

PsLoggedOn¡§查ëÎÅÐÆþ狀ÂÖ
×Ï̾ãʨ²Ä´Ç½Ð¡¤PsLoggedOnÀ§ÍÑÐÔ查ëλÈÍѼÔÅÐÆþ¾ð·ÁŪ¹©¶ñ¡£PsLoggedOnÉÔâǽðý¼¨Ëܵ¡ÅÐÆþŪÍÑ戶¡¤×ϱóüÌÖÏ©ÅÐÆþŪÍÑ戶Ìé²ÄÁªÚ¤À­ÃÏÎó½Ð¡£ÍøÍÑÇç¸Ä¹©¶ñ×ÌÍÆ°×½¢Ç½Ñþ¼±Àµºß»ÈÍÑ»ÇÉþ´ïŪÍÑ戶¡¤¼©ÉÔÍѳ«啟°ìÂÏ»ëãÙÐÔ¸òºµÈæÕô¡£¼¹¹ÔPsLoggedOn»þ¡¤²ÄÆ©²á¡Ö-l¡×ÒÔÚËÕòÌÖÏ©»ÈÍѼÔÇÓ½ü¡¤¶Ïðý¼¨Ëܵ¡ÅÐÆþŪ»ÈÍѼԡ£

PsLogList¡§查ëÎÆÃÄê»ö·ïµ­錄
PsLogListŪ¸ùǽçÐWindows·ÏÅý´ÉÍý¹©¶ñ內Ū»ö·ïµ­錄´ïÁêÆ±¡¤²Ä°Êðý¼¨·ÏÅý¡¢ØæÍÑÄø¼°µÚ°ÂÁ´À­Åù»ö·ïµ­錄¡£ÕàÉÔ¶Ïǽðý¼¨Ëܵ¡µ­錄¡¤Ìéǽ查ëαóüÆÃÄêÅÅ窡¤¿Ó»êÀ§ÌÖ°è內½êÍ­ÅÅçªÅª»ö·ï¡£Çç¸Ä¹©¶ñ´ÔǽÕò»ö·ïµ­錄檔¹àÌÜ¡¤×ϸ¶ËÜŪÆó¿Ê°Ì³Ê¼°¡¤íÛ´¹À®Â¶Â¾³Ê¼°¡£

PsLogList²Ä»ÈÍÑŪÒÔÚËÁêáÄ¿¡¤ÎãÇ¡¡Ö-e¡×²ÄÇÓ½üÊñ´Þ»ØÄê»ö·ï¼±ÊÌâûŪ»ö·ï¡¤ºÇ¿²Ä»ØÄê10¸Ä¡¨¼©¡Ö-m¡×À§Âþðý¼¨»ØÄêʬ¾âÚË內Ū»ñ¿ÖÅù¡£

PsPasswd¡§¹¹²þ»ÈÍѼÔÄ¢éËçÐÌ©âû
PsPasswd²ÄÍÑÐÔ¹¹²þËܵ¡°¿±óüÅÅçªÅª»ÈÍѼÔ̾ãʵÚÌ©âû¡£Õô±÷¼û¼þ´üÀ­¹¹´¹Ì©âûŪÌÖ°è內ÅÅ窡¤ÍøÍÑÇç¸Ä»ØÎáÊØÇ½²÷®ãÀ®ÌÜŪ¡£

PsService¡§Üý»ëÏÂÀßÄê·ÏÅýÉþ̳
PsServiceÀ§WindowsÉþ̳¹àŪÜý»ëÏÂÊÔ½´´ï¡¤Ëò²ÄáÄÐö¡Ö·ÏÅýÀßÄê¸øÍÑÄø¼°¡×Ãæ¡ÖÉþ̳¡×ÍóÌÜŪ²Ã¶¯ÈÇ¡£½üλǽ´ÉÍý±óüÅÅçªÅªÉþÌ³Äø½ø³°¡¤Ìé²Ä啟ư¡¢½ª»ß¡¢»ÃÄä¡¢åëåôϽſ·啟ưWindowsÉþ̳¹à¡¤Æ±»þ´Ôǽ¿ËÕôÆÃÄêŪÉþ̳¹à¡¤»ØÄêÎó½ÐçжÁêïðŪ¶¾Éþ̳¡£

PsServiceŪÒÔÚË»ÈÍÑÊý¼°çж¾¹©¶ñάͭÉÔÆ±¡¤每¸ÄÒÔÚËÅÔÍ­ÉÔÆ±Åª¹µÀ©¸ìË¡¡¤»ÈÍѼԲĺßÒÔÚ˸å²Ã¡Ö¡Ý¡×»ú¸µ查ëΡ£

Æ©²á¡Öquery¡×ÒÔÚË¡¤²Ä查ëλØÄêŪÉþ̳¡¨¼©¡Öfind¡×²ÄºßÌÖÏ©Ãæ¿ÒÙ²Àµºß¼¹¹Ô»ØÄêÉþ̳ŪÅÅ窡¨¡Ösecurity¡×ÒÔÚ˧²ÄÄó¶¡»ØÄêÉþ̳Ū°ÂÁ´À­»ñ¿Ö¡£

PsShutdown¡§¶¯²½ï𵡸ùǽ
ê­Á³¾È»úḬ̀ջ״ÇÐÔ¡¤PsShutdownŪ¸ùǽÏÂWindows內·úŪshutdown.exe»÷¸Ã°ìÜ롤ÅÔÀ§ÍÑÐÔïðÊÄÅÅ窡£Ã¢ PsShutdown´Ô¶ñÍ­±óü´ÉÍý¡¢½Å¿·啟ưÅÅ窡¤°ÊµÚ»ØÄêÅÅçª¿ÊÆþµÙ̲°¿ÂÔµ¡Ìϼ°Åù¸ùǽ¡¨¿Ó»ê´Ôǽº¿ÄêÅÅ窡¤°¿Àèðý¼¨°ìÃʿ֩¸å¡¤ºÆ±÷°ìÄê»þ´Ö¸å½Å¿·啟ưÅÅ窡£

»ÈÍѼÔÍøÍÑÒÔÚË¡Ö-a¡×²ÄÃæ»ßͳPsShutdown啟ư¡¤³îÀµºß¿Ê¹ÔÃæÅªï𵡺î¶È¡¤¼©²áµîÁ½°ø¼ÀÉ÷ÉÂÆÇÞ¢Íô¡¤Â¤À®×Ì¿ÅÅçªå´¾ï¼«Æ°ï𵡡¤µö¿IT´ÉÍý¿Í°÷ÌéÐòÍøÍÑÇç¸ÄÒÔÚËÐÔ½ª»ßïðµ¡Äø½ø¡¨º¡³°ÒÔÚË¡Ö-v¡×²Ä쪻ÈÍѼÔÍ¢ÆþÆÃÄê¿Ö©¡¤°Êºßïðµ¡Á°¸þ±óüÍÑ戶ðý¼¨¡£

PsSuspend¡§»ÃÄä¼¹¹ÔÃæÅªÆÃÄêÄø½ø
áÄË¿¸ÄØæÍÑÄø¼°ÀêÍÑ×ÌÂçÈæÎãŪÑÝÍý´ï»ñ¸»¡¤ÍÑ戶Áۻô˼¹¹Ô¡¤ÒÊËôÉÔ´ê°ä¼ºçгºØæÍÑÄø¼°ÁêïðŪ»ñÎÁ°¿內ÍÆ»þ¡¤Çç¸Ä¹©¶ñÊØÇ½ÇɾåÍѾ졣ê­Á³ Process ExplorerÌéÍ­Äó¶¡Îà»÷Ū¸ùǽ¡¤ÉÔ²áÒʶÏǽºßËܵ¡¼¹¹Ô¡£¼©PsSuspend»ÈÍÑŪÆÃÄêÒÔÚ˶ÏÍ­¡Ö-r¡×¡¤ÍÑÐԽſ·啟ư»ÃÄäÃæÅªÄø½ø¡£

Á´Ì̴ƹµ·ÏÅý狀ÂÖŪProcess Monitor
Process MonitorÀ§ÈùÆðÊ»¹ØÎ»Winternals¸å½ê¿·ùáŪ¹©¶ñÇ·°ì¡¤ÌÜÁ°ÈÇËܰÙ1.12ÈÇ¡¤»Ù±çWindows 2000 SP4¡¢Windows XP SP2¡¢Windows Server 2003 SP1¡¢Windows Vista¡¤°ÊµÚ64°Ì¸µÅªWindows XP¡¢Windows Server 2003 SP1ÏÂWindows Vista¡£

»ÈÍѼԲļ«ÄûÍó°Ì
Process MonitorÀ§·ë¹çλFilemon¡¢Regmon¡¢Process ExplorerçÐPslistÅù¹©¶ñÅªÄø¼°¡¤ê­Á³Õô±÷ÑÝÍýÄø½ø´Æ¹µÅª¸ùǽÁª¹à¡¤ÉÔÇ¡Process ExplorerÐÔÆÀ¿¡¤Ã¢Ç¤²¿檔°Æ°¿ÅÐ錄µ¡âûŪ¸¼è¡¤ÅÔǽƩ²áProcess Monitor¨»þðý¼¨¡£¼ç»ëãÙŪº¸²¼ÊýŪÚË»ú¡¤É½¼¨ÌÜÁ°Process Explorerµ­錄Ū»ö·ïÚË¡¢·ÏÅýåÁ¶¦產À¸Î»Â¿¾¯»ö·ï¡¤°ÊµÚÈïµ­錄Ū»ö·ïÀêåÁ»ö·ïÅªÈæÎãÅù¡£

¼©»ÈÍѼÔÌé²ÄÍøÍÑProcess Monitor Column Selection¼«ÄûÍó°Ì¡¤ÁªÚ¤ÁÛÍ×查ëÎŪ¹àÌÜ¡£Column SelectionÕòÍó°Ìʬ°ÙApplication Details¡¢Event DetailsµÚProcess Management»°ÂçÎࡤðý¼¨Åª»ñ¿ÖÊñ´Þ½ç½ø¡¢ì¦ÕíŪ»þ´Ö¡¢¹ÔÄøÅª ID¡¢Îà·¿¡¢Ï©×Í¡¢Äø¼°À½ºî¸ø»Ê¡¢ÈÇËÜ¡¤°ÊµÚ±¿¹Ô»þ´ÖÅù22¼ïÉÔÆ±¹àÌÜ¡£

Äó¶¡»ö·ï²áßÉ´ï°Ê´Ê²½µ­錄
Process MonitorŪ»ö·ïµ­錄ÍÂÀß°Ù¼«Æ°·þư¡¤Í³±÷°ìÈÌÅÅ窺߱¿ºî»þ¸¼èŪµ­錄»ñÎÁÎÌÁêáÄ龐Â硤°øº¡¿Ö©ķưŪÉÑΨÁêáIJ÷¡£ê­Á³»ÈÍѼԲİÊÕò¼«Æ°·þưïðÊİÊÍøÙÓ¿Ò¡¤Ã¢°ì³«»ÏÍ×Ù²Åþ»ØÄêŪ¹àÌÜ¡¤ÆñÅÙÅùƱ±÷Â糤Ùý¿Ë¡£

º¡»þÍÑ戶²ÄÍøÍѰ̱÷¼çÁàºî»ëãÙ±¦¾åÊýŪ²÷®¹©¶ñÎ󡤺߼¹¹ÔÄø½ø¡¢檔°ÆÂ¸¼èÏÂÅÐ錄µ¡âû»°¼ïÎà·¿Ãæ¡¤ÁªÚ¤Í×ðý¼¨²¿¼ï»ñ¿Ö¡£ÚªÎãÐÔ說¡¤¼ãÂþ°Ä²¼¡ÖShow Process and Thread Activity¡×¹©¶ñîæ¡¤ÆáÖ÷»ö·ïµ­錄Ãæ½¢ÂþÐòðý¼¨çм¹¹ÔÄø½øÍ­ïðŪ»ñÎÁ¡¤Ç¡Äø½ø³«»Ï¡¢·ë«»þ´Ö¡¤°ÊµÚDLL檔ºÜÆþÅù¡£

»ê±÷Process Monitor Filter§Äó¶¡¹¹¿Ê³¬Åª²áßɸùǽ¡¤ÍÑ戶²ÄÁªÚ¤ºßÄø½øÌ¾ãÊ¡¢Ï©×Í¡¢Äø½øÃðºý¸ø»Ê°¿»þ´ÖÅùÉÔÆ±¹àÌܼ«Äûï𸰻ú¡¤·èÄêðý¼¨Åªµ­錄ÃæÀ§ÈÝÍ×Êñ´Þ¡¢ÇÓ½ü°¿´°Á´Éä¹ç³ºï𸰻ú¡£Í³±÷·ÏÅý產À¸Åª»ö·ïÚËÎÌÁêáÄ龐Â硤Process MonitorŪÍÂÀß值ÃæÊØÖáå´¼¹¹Ôλµö¿²áßɸ¶Â§¡£

º¡³°ÍÑ戶Ìé²ÄÍøÍÑProcess Monitor Highlighting¡¤¼«Í³ÁªÚ¤°ÊÉÔÆ±ðú¿§É¸ÃðÉä¹çË¿¸ÄÛê·ïŪ»ö·ï¡¤ÉÔ²áÉä¹çƱ°ì¼ïÛê·ïŪ»ö·ï¡¤¶Ïǽ°Ê°ì¼ïðú¿§É¸Ãð¡£¼©ºßProcess MonitorÖáðý¼¨Åª»ñÎÁÃæ¡¤ÍÑ戶Æ©²áCtrl﹢FŪÁÈ¹ç¸°ÊØÇ½²÷®¿ÒÙ²ÆÃÄêŪ»ñÎÁ¡¨Ã¢¼ãÀ§³º»ñÎÁÖ¤±÷ð¬é¶Íó°Ì¡¤Â§¼ûÀè»êColumn SelectionÃæÕòÀßÄê°Ùðý¼¨Íó°Ì¸å¡¤ºÍ²ÄÙÓ¿Ò¡£

Process MonitorŪԦ·Á²ðÌÌÁàºîê­Á³´ÊÓÅ¡¤µ­錄Ū»ñÎÁÎÌÒÊÁêáĶÿ͡¤°øº¡Ìéǽ¶¨½õIT¿Í°÷¿ÒÙ²·ÏÅýϳƶ¡¢¸åÌçÄø¼°°¿¿Ê¹Ôºø¸íÜý¬¡¨Ã¢Í³±÷»ñÎÁ·¿ÂÖʣ𸡤ºß»ÈÍÑÁ°Øæ¾Ü즻ÈÍѼêºý¡¤ÊÂλ²ò·ÏÅý±¿ºîÊý¼°¡¤ºÍÍÆ°×Ù²ÅþÌäÂêóÚ¡£

Æ©»ëWindows TCP/UDPÏ¢ÀþŪTCPView
TCPView for Windows v2.4À§°ìÅå²Ä°ÊÍÑÔ¦·Á²ðÌÌ´°À°ë·»¡WindowsÌÜÁ°Ï¢ÀþŪ¹©¶ñ¡¤你²Ä°ÊÍÑÕàÜý»ëÅÅ窾åŪÌÖÏ©»ñ¿Ö¡¤´Æ´ÇTCP/UDPŪÉõÊñή¸þŪÌÖÏ©IP°ÌÔ®¡¢½ê»ÈÍÑŪϢÀÜÉÖ¡¤°ÊµÚÏ¢Àþ狀ÂÖ¡£

Ô¦·Á²½²ðÌÌŪ¨»þ´Æ¹µ
¼¹¹ÔÇ·¸å¡¤TCPViewÐò°ÊÀ¶ÓÅŪÊý¼°¡¤ðý¼¨ÅÅ窾åÌÜÁ°½êÍ­»ÈÍÑTCP/UDPÌÖÏ©¶¨ÄêŪüóÚÏ¢ÀÜ»ñ¿Ö¡¤Ç纳»ñ¿ÖÊñ´Þλ啟ưϢ·ëÅªÄø¼°¡¢Äֶ̿¨Äê¡¢Ëܵ¡°ÌÔ®¡¢ÌÜŪ°ÌÔ®°ÊµÚ狀ÂÖÅù¡£Áê³Ó±÷WindowsÅå·ï內ŪNetstat»ØÎᡤ»ÈÍѼԲİÊé´Í³´ÊÓÅŪ»ëãÙáÁÌÌ¡¤¹¹Ä¾ÀÜÃϴƹµ¼«¸ÊŪÅÅ窷ÏÅý內ŪÌÖϩ¸¼è¡¤ë·»¡ÌÜÁ°ÀµÆ©²áÌÖϩϢ·ë¶¾¼çµ¡ÅªÄø¼°¡£

ÇçÅ幩¶ñŪԦ·Á²ðÌÌ»ÈÍѵ¯ÐÔ¡¤ÍÂÀß»ú·¿×̾®¡¤ºß²æÐî»ÈÍÑ1280×1024Ūê¥Ëë²òÀÏÅÙ²¼¡¤»ú·¿´ö¸Ã¾®ÅþÆñ°ÊÑþ»ë¡¤½ê°Ê»ÈÍѼ԰쳫»Ï¼¹¹Ô»þ¡¤ºÇ¹¥ÀèÀßÄê»ú·¿¡¤Ä´À°À®¹çŬŪ»úñóÂç¾®¡¤ÊýÊØ²æÐî°Ê¸å»ÈÍÑTCPView¡£»ú·¿ÅªÀßÄê²Ä°Ê×ϲ¼ÙǼ°ÁªÓÅŪÁª¹à¡ÊOptions¡ËÁª¼è»ú·¿¡ÊFont¡Ë¡¤½¢Ç½Ä´À°TCPView½êðý¼¨Åª»ú·¿Âç¾®¡£

TCPViewºßÍÂÀß¾åÀ§ðý¼¨Ï¢ÀþÀáóÚŪÌÖ°è̾ãÊÏÂÏ¢ÀÜÉÖéË¡¤»ÈÍѼԲİʰ;ȼûµá¡¤ºßÁª¹àÃæ¸ûÁª²òÀϰÌÔ®¡ÊResolve Addresses¡Ë¡¤ÕòÌÖ°è̾ãÊŪÉô份²þÀ®°ÊIP°ÌÔ®ðý¼¨¡¤Ëò²ÄºßÁª¹àÃæðý¼¨ÈóÏ¢ÀþÃæÅªÃ¼óÚ¡ÊShow Unconnected Endpoints¡Ë¡¤ð¬é¶¡¿ðý¼¨Èó»ÈÍÑÃæÅªÃ¼óÚÏ¢Àþ¡£

¼¹¹Ô»þ¡¤TCPViewÐò°Í¾ÈÀßÄêŪÉÑΨ¼«Æ°¹¹¿·´Æ¹µ»ñ¿Ö¡¤ÍÂÀß值°Ù1É᤻ÈÍѼԲİʰÍÚ¡¼ûµá¡¤ºßÜý»ë¡ÊView¡ËÃæÅª¹¹¿·Â®ÅÙ¡ÊUpdate Speed¡Ë¡¤Ä´À°°Ù2Éð¿3Éá¤Ìé²Ä°Ê¼êư¼¹¹Ô½Å¿·À°Íý¡ÊRefresh¡Ë°¿»ÃÄä¹¹¿·¡ÊPaused¡Ë¡¤ÊýÊØ»ÈÍѼÔÜý»ë»ñÎÁÎó¡£Ï¢·ë»ñ¿Öǡͭ¹¹¿·¡¤Ðòºß¹¹¿·Åª»ñÎÁÎó¾å°Êðú¿§ÆÍðý½ÐÐÔ¡¤ûÑ¿§É½¼¨ÌÜÁ°產À¸¿·ÅªÏ¢·ë¡¤¹È¿§É½¼¨Ï¢·ëÃæÚÒ¡¤黃¿§Â§À§É½¼¨Ã¼óÚÏ¢·ë內ÍÆÍ­°Ûư¡£

½üλÜý»ëÏ¢Àþ狀ÂÖµÚ³«啟Ï¢·ëÅªÄø¼°³°¡¤TCPViewËò²ÄÜý»ëÄø¼°½êºßŪÌÜ錄°ÌÃÖ¡¤ÂþÍ×óÚÁª²¼ÙǼ°ÁªÓÅ¡¤°¿À§±¦¸°ÁªÓÅÃæóÚÁªÄø¼°Ö¤À­¡ÊProcess Properties¡Ë¡¤½¢²Ä°Ê´ÇÅþÄø¼°½êºßŪϩ×Í¡£Ç¡²ÌÍ×ÃæÚÒ³ºÏ¢Àþ¡¤Â§²Ä°ÊÍÑïðÊÄÏ¢Àþ¡ÊClose Connection¡ËÐÔÃæÚÒÏ¢Àþ¡¤¼ãÀ§Í×·ë«ϢÀþÃæÅªÄø¼°¡¤Â§²Ä°Êºß²¼ÙǼ°ÁªÓŰ¿±¦¸°¸ùǽɽ內»ÈÍÑ·ëÂ«Äø¼°¡ÊEnd Process¡Ë¸ùǽ¡¤Ä¾Àܷ뫳ºÄø¼°¡£

²ò·èÌÖÏ©ÌäÂê
TCPView²Ä°Ê¶¨½õ²æÐîºßWindowsÊ¿çʾå²ò·èµö¿ÌÖÏ©ÌäÂꡤÁüÀ§ÌÚÇϰ¿ÉÂÆÇÇçÎàØ¨°ÕÄø¼°¡¤²ÄǽÐòºß̤崰ôµöŪ¾ð¶·²¼¡¤Ú£¼«¿Ê¹ÔÌÖϩϢÀþ¡¤±Æ¶Á»ñ¿Ö°ÂÁ´¡£¼©Æ©²áTCPView¡¤²Ä°Ê¶¨½õ²æÐîÜý»ëÌÜÁ°À§ÈÝÍ­Äø¼°Àµºß¿Ê¹Ô̤崰ôµöŪϢÀþ¡¤ÀÜÃøÂ¨²Ä查½ÐÇ纳ب°ÕÄø¼°Åª½êºß°ÌÃÖ¡¤°Ê°Ý¸î·ÏÅýÀµ¾ï±¿ºî¡£

另³°¡¤TCPViewÌé²Ä°Ê¶¨½õ²æÐîÑÝÍýÌÖÏ©ÉÖéË¾×ÆÍŪÌäÂꡣͭ»þÌִɿͰ÷啟ư˿º³Äø¼°»þ¡¤Ðò°ø°ÙÉÖéË¾×ÆÍ¼©Æ³Ã×Ï¢Àþ¼ºÇÔ¡¤±Æ¶Á·ÏÅý±¿ºî¡¤ÁüÀ§ IIS¡ÊInternet Information Service¡ËŪÉÖéË¾×ÆÍ¡¤°ì»þÇ·´Ö¡¤²æÐî²ÄǽÉÔÀ¶Á¿À§哪¸ÄÄø¼°½ê°úµ¯Åª¡¤Çç»þ¸õ½¢²Ä°Êé´Í³TCPViewÙ²½Ð¤À®ÉÖéË¾×ÆÍÅªÄø¼°¡¤Ê¿ҵáºÇŬÀÚŪ²ò·èÊý°Æ¡£

TCPView²Ä°ÊºßWindows 9ס¿Me¡¿NT¡¿2000¡¿XPÅùÈÇËܾåÌ̱¿ºî¡¤Ã¢¼ãÍ׺ßWindows 95¾å¼¹¹Ô¡¤ºî¶È·ÏÅýËÜ¿ÈŪÌÖÏ©¸µ·ï§¼ûÍ×¹¹¿·»êWinsock 2 UpdateºÍǽ½çÍø±¿ºî¡£


http://www.microsoft.com/technet/sysinternals/default.mspx


http://www.microsoft.com/technet/sysinternals/utilities/sysinternalssuite.mspx


¤³¤Îµ­»ö¤ËÂФ¹¤ë¥³¥á¥ó¥È

¤³¤Îµ­»ö¤ËÂФ¹¤ë¥³¥á¥ó¥È¤ÎÅê¹Æ














´ÉÍý¼Ô¤Ë¤À¤±É½¼¨¤òµö²Ä¤¹¤ë


¤³¤Îµ­»ö¤ËÂФ¹¤ë¥È¥é¥Ã¥¯¥Ð¥Ã¥¯
¥È¥é¥Ã¥¯¥Ð¥Ã¥¯URL
¢ªhttp://morganlife.blog59.fc2.com/tb.php/242-05b43fcc
¤³¤Îµ­»ö¤Ë¥È¥é¥Ã¥¯¥Ð¥Ã¥¯¤¹¤ë(FC2¥Ö¥í¥°¥æ¡¼¥¶¡¼)