<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MVPdream.org</title>
	<atom:link href="http://blog.donews.com/shixinyu/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.donews.com/shixinyu</link>
	<description></description>
	<lastBuildDate>Sat, 21 May 2005 01:56:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>MVPDream.org 更新动态～</title>
		<link>http://blog.donews.com/shixinyu/archive/2005/05/21/390397.aspx</link>
		<comments>http://blog.donews.com/shixinyu/archive/2005/05/21/390397.aspx#comments</comments>
		<pubDate>Sat, 21 May 2005 01:50:00 +0000</pubDate>
		<dc:creator>石头</dc:creator>
				<category><![CDATA[关于博客自己]]></category>

		<guid isPermaLink="false">http://blog.donews.com/shixinyu/archive/2005/05/21/390397.aspx</guid>
		<description><![CDATA[MVPDream.org LiveUpdate]]></description>
			<content:encoded><![CDATA[<p><strong><font size="3">www.mvpdream.org 隨筆更新動態：</font></strong></p>
<p><img src="http://www.mblogger.cn/new.image.blog?u=shixinyu1987&amp;c=20&amp;s=11&amp;f=%cb%ce%cc%e5&amp;o=Blue&amp;i=5&amp;b=ms" alt=""/></p>
<p><url></url><br/><br/>Welcome to visit MVPDream.org:<br/><br/><a href="http://www.mvpdream.org">http://www.mvpdream.org</a> <br/><url></url><a href="http://web.mvpdream.org">http://web.mvpdream.org</a><br/></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/shixinyu/archive/2005/05/21/390397.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>停止更新该Blog～</title>
		<link>http://blog.donews.com/shixinyu/archive/2005/01/19/247571.aspx</link>
		<comments>http://blog.donews.com/shixinyu/archive/2005/01/19/247571.aspx#comments</comments>
		<pubDate>Wed, 19 Jan 2005 11:06:00 +0000</pubDate>
		<dc:creator>石头</dc:creator>
				<category><![CDATA[关于博客自己]]></category>

		<guid isPermaLink="false">http://blog.donews.com/shixinyu/archive/2005/01/19/247571.aspx</guid>
		<description><![CDATA[说白了就是搬家了～
相信但凡现在用过Donews的User都会体谅我的，现在的Donews不如以往了，速度、质量、就连模板都染指了～（最上头多出的那些导航）
现在启用新Blog：
我的MVP梦～～～http://www.mvpdream.org
Stone.sxy&#8217;s Lifeloghttp://lifelog.mvpdream.org
【旧】我的MVP梦～～～http://donews.mvpdream.org
敬请关注新Blog～
]]></description>
			<content:encoded><![CDATA[<p>说白了就是搬家了～</p>
<p>相信但凡现在用过Donews的User都会体谅我的，现在的Donews不如以往了，速度、质量、就连模板都染指了～（最上头多出的那些导航）</p>
<p>现在启用新Blog：</p>
<p>我的MVP梦～～～<br/><a href="http://www.mvpdream.org">http://www.mvpdream.org</a></p>
<p>Stone.sxy&#8217;s Lifelog<br/><a href="http://lifelog.mvpdream.org">http://lifelog.mvpdream.org</a></p>
<p>【旧】我的MVP梦～～～<br/><a href="http://donews.mvpdream.org">http://donews.mvpdream.org</a></p>
<p>敬请关注新Blog～</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/shixinyu/archive/2005/01/19/247571.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>在WinXP SP2环境下用KV杀毒软件</title>
		<link>http://blog.donews.com/shixinyu/archive/2005/01/18/245096.aspx</link>
		<comments>http://blog.donews.com/shixinyu/archive/2005/01/18/245096.aspx#comments</comments>
		<pubDate>Tue, 18 Jan 2005 02:35:00 +0000</pubDate>
		<dc:creator>石头</dc:creator>
				<category><![CDATA[未分类]]></category>

		<guid isPermaLink="false">http://blog.donews.com/shixinyu/archive/2005/01/18/245096.aspx</guid>
		<description><![CDATA[用KV2004&#038;KV2005的用户可能常常发现，在更新完毕之后，SP2的安全中心会报告说是江民杀毒软件被关闭了之类的通知。]]></description>
			<content:encoded><![CDATA[<p>      用KV2004&amp;KV2005的用户可能常常发现，在更新完毕之后，SP2的安全中心会报告说是江民杀毒软件被关闭了之类的通知。但江民杀毒软件的实时监控“Ｋ”图标还好好的在系统栏中的啊，而且文件监控也是打开的啊。其实江民杀毒软件跟SP2安全中心的联系是通过一个服务“KVWSC”来实现的，而江民杀毒软件在偶然的更新时更新一些补丁包需要把江民杀毒实时监控服务先禁用然后更新之后才能启用。其实这不是什么问题，因为“KVWSC”服务是默认自动启动的，重新启动SP2即可正常识别江民杀毒软件。不过还有更好的办法并不用重启电脑就能让SP2正常识别江民杀毒软件。<br/>实现方法：<br/>在江民杀毒软件更新完毕后出现安全中心气泡通知江民杀毒软件被关闭之后，运行“Services.msc”，在其中寻找服务项“KVWSC”→右击之→启动该项。<br/>How to Run &#8220;Services.mcs&#8221;：<br/>1、Lift-Click the &#8220;Start&#8221;（左击“开始”菜单）<br/>2、Lift-Click the &#8220;Run&#8221;（左击“运行”）<br/>3、Type &#8220;services.msc&#8221;, and then click OK（输入“services.msc”，然后点击确定）</p>
<p>注：其实笔者提供的是无关紧要的技巧，实际上尽管SP2安全中心报告江民杀毒软件被关闭了，但只要江民杀毒软件的实时监控“Ｋ”显示着，并且其中的“文件监控”已打开，那么实时监控其实是在工作着的，只不过更新程序做的还不够，把服务“KVWCS”关闭之后没有启动罢了。不过看着那个安全中心的报告总是有些不舒服的，所以笔者提供的这个小技巧也是有存在的价值的。</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/shixinyu/archive/2005/01/18/245096.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>微软恶意软件清除工具在线版</title>
		<link>http://blog.donews.com/shixinyu/archive/2005/01/13/237940.aspx</link>
		<comments>http://blog.donews.com/shixinyu/archive/2005/01/13/237940.aspx#comments</comments>
		<pubDate>Thu, 13 Jan 2005 01:33:00 +0000</pubDate>
		<dc:creator>石头</dc:creator>
				<category><![CDATA[Windows&NetWork]]></category>

		<guid isPermaLink="false">http://blog.donews.com/shixinyu/archive/2005/01/13/237940.aspx</guid>
		<description><![CDATA[微软恶意软件清除工具的在线版：
http://www.microsoft.com/security/malwareremove/default.mspx
在该页下方的
Scan and Clean Your PC中的
Run the Removal Tool
下方点击“Check My PC for Infection.”按钮即可。
前提是你的操作系统必须是WindowsXP、Windows2000以及Windows Server2003。
]]></description>
			<content:encoded><![CDATA[<p><font size="4">微软恶意软件清除工具的在线版：</font></p>
<p><a href="http://www.microsoft.com/security/malwareremove/default.mspx">http://www.microsoft.com/security/malwareremove/default.mspx</a></p>
<p>在该页下方的</p>
<p style="FONT-SIZE: 150%; MARGIN-BOTTOM: 5px; COLOR: #ff3300"><b>Scan and Clean Your PC<br/></b><font color="#000000"><br/>中的</font></p>
<p style="FONT-SIZE: 130%; MARGIN-BOTTOM: 5px"><b>Run the Removal Tool</b></p>
<p style="FONT-SIZE: 130%; MARGIN-BOTTOM: 5px"><strong>下方点击“<font size="2">Check My PC for Infection</font></strong><font size="2">.”按钮即可。</font></p>
<p style="FONT-SIZE: 130%; MARGIN-BOTTOM: 5px"><font size="2">前提是你的操作系统必须是WindowsXP、Windows2000以及Windows Server2003。</font></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/shixinyu/archive/2005/01/13/237940.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>微软恶意软件清除工具中文版</title>
		<link>http://blog.donews.com/shixinyu/archive/2005/01/12/237600.aspx</link>
		<comments>http://blog.donews.com/shixinyu/archive/2005/01/12/237600.aspx#comments</comments>
		<pubDate>Wed, 12 Jan 2005 12:16:00 +0000</pubDate>
		<dc:creator>石头</dc:creator>
				<category><![CDATA[Windows&NetWork]]></category>

		<guid isPermaLink="false">http://blog.donews.com/shixinyu/archive/2005/01/12/237600.aspx</guid>
		<description><![CDATA[通过Windows Update得到的恶意软件清除工具是英文的，下面下载地址是中文版的，在前面的Blog中已经有过介绍了，这里就不再介绍了下载地址：
http://download.microsoft.com/download/3/9/8/3982d61b-07a5-44cd-a7a7-1aa4565f0e93/Windows-KB890830-CHS.exe
     


]]></description>
			<content:encoded><![CDATA[<p><font size="4">通过Windows Update得到的恶意软件清除工具是英文的，下面下载地址是中文版的，<br/>在前面的Blog中已经有过介绍了，这里就不再介绍了<br/>下载地址：</font></p>
<p><a href="http://download.microsoft.com/download/3/9/8/3982d61b-07a5-44cd-a7a7-1aa4565f0e93/Windows-KB890830-CHS.exe">http://download.microsoft.com/download/3/9/8/3982d61b-07a5-44cd-a7a7-1aa4565f0e93/Windows-KB890830-CHS.exe</a></p>
<p><img src="http://www.donews.net/images/www_donews_net/shixinyu/37288/r_MSRTcn1.JPG" alt=""/>     </p>
<p><img src="http://www.donews.net/images/www_donews_net/shixinyu/37288/r_MSRTcn2.JPG" alt=""/></p>
<p><img src="http://www.donews.net/images/www_donews_net/shixinyu/37288/r_MSRTcn3.JPG" alt=""/></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/shixinyu/archive/2005/01/12/237600.aspx/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>微软最新“杀毒”软件抢先预览</title>
		<link>http://blog.donews.com/shixinyu/archive/2005/01/12/236544.aspx</link>
		<comments>http://blog.donews.com/shixinyu/archive/2005/01/12/236544.aspx#comments</comments>
		<pubDate>Wed, 12 Jan 2005 04:49:00 +0000</pubDate>
		<dc:creator>石头</dc:creator>
				<category><![CDATA[IT资讯]]></category>

		<guid isPermaLink="false">http://blog.donews.com/shixinyu/archive/2005/01/12/236544.aspx</guid>
		<description><![CDATA[此工具可以检查您的计算机是否被特定的流行恶意软件（包括 Blaster、Sasser 和 Mydoom）感染，并且帮助删除发现的任何变种。您还应该使用反病毒产品，以删除可能存在的任何其他恶意软件。]]></description>
			<content:encoded><![CDATA[<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">笔者是通过<b style="mso-bidi-font-weight: normal"><span lang="EN-US">Windows Update</span></b>得到微软最新“杀毒”软件<b style="mso-bidi-font-weight: normal"><span lang="EN-US">MICROSOFT WINDOWS MALICIOUS SOFTWARE REMOVAL TOOL</span></b>。不过除了更新到这个恶意软件删除工具之外，还有个安全更新（<span lang="EN-US">KB890175</span>）。下面是我的<b style="mso-bidi-font-weight: normal"><span lang="EN-US">Windows Update</span></b>于太平洋时间<span lang="EN-US">1</span>月<span lang="EN-US">11</span>号 中午<span lang="EN-US">12</span>点时刻的更新名单：<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">恶意软件删除工具<span lang="EN-US"> &#8211; 2005 </span>年<span lang="EN-US"> 1 </span>月<span lang="EN-US"> (KB890830)
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><font size="3"><font face="宋体"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体">Microsoft XP </span><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体">安全更新程序<span lang="EN-US"> (KB890175)
<p/></span></span></font></font></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体">
<p><font face="宋体" size="3"> </font></p>
<p></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">微软官方对于该恶意软件删除工具的介绍：<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">恶意软件删除工具<span lang="EN-US"> &#8211; 2005 </span>年<span lang="EN-US"> 1 </span>月<span lang="EN-US"> (KB890830)
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">上次发布日期<span lang="EN-US">: <chsdate w:st="on" isrocdate="False" islunardate="False" day="11" month="1" year="2005">2005/1/11</chsdate>
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">下载大小<span lang="EN-US">: 256 KB
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">此工具可以检查您的计算机是否被特定的流行恶意软件（包括<span lang="EN-US"> Blaster</span>、<span lang="EN-US">Sasser </span>和<span lang="EN-US"> Mydoom</span>）感染，并且帮助删除发现的任何变种。您还应该使用反病毒产品，以删除可能存在的任何其他恶意软件。此工具可帮助维护您的计算机；出现此工具，并非意味着您的计算机已受恶意软件的感染。安装本项目后，可能需要重新启动计算机。 <span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">系统要求<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">推荐的<span lang="EN-US"> CPU: </span>未指定。<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">推荐的内存<span lang="EN-US">: </span>未指定。<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">推荐的硬盘空间<span lang="EN-US">: </span>未指定。 <span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">帮助和支持<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">http://go.microsoft.com/fwlink/?LinkId=39987
<p/></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">详细信息<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">http://go.microsoft.com/fwlink/?LinkId=39987
<p/></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体">
<p><font face="宋体" size="3"> </font></p>
<p></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体"><span style="mso-spacerun: yes"> </span>
<p/></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">概述：此工具运行时，本软件将检查您的设备中是否存在<span lang="EN-US"> http://go.microsoft.com/fwlink/?LinkId=39249 </span>中列出的恶意软件（“恶意软件”）；如果检测到“恶意软件”，本软件会将其从您的设备中删除。必须在特定设备上再次运行此工具，以检测并删除随后的“恶意软件”更新。<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">如果您是通过“自动更新”收到更新的，完全关闭“自动更新”只能阻止接收对该软件的更新（不建议采用此方法）。<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">隐私声明：当本软件检查您的设备是否存在“恶意软件”时，从设备中收集的信息仅用于向您报告是否检测到“恶意软件”以及是否将其从您的设备中删除。但是，<span lang="EN-US">Microsoft </span>可能会收集并公布有关软件使用情况的汇总数据。如果您需要，可按照<span lang="EN-US"> http://go.microsoft.com/fwlink/?LinkId=39987 </span>上的说明禁用本软件的报告功能。<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体">
<p><font face="宋体" size="3"> </font></p>
<p></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">很明显的，这个<b style="mso-bidi-font-weight: normal"><span lang="EN-US">MICROSOFT WINDOWS MALICIOUS SOFTWARE REMOVAL TOOL</span></b>离所谓的杀毒软件的标准还有很大一段距离，首先<b style="mso-bidi-font-weight: normal"><span lang="EN-US">MICROSOFT WINDOWS MALICIOUS SOFTWARE REMOVAL TOOL</span></b>仅仅只能清除<b style="mso-bidi-font-weight: normal"><span lang="EN-US" style="COLOR: blue">Blaster</span><span style="COLOR: blue">、<span lang="EN-US">Sasser</span></span></b><span lang="EN-US"> </span>和<span style="COLOR: blue"> <b style="mso-bidi-font-weight: normal"><span lang="EN-US">Mydoom</span></b></span>等少数恶意软件。不过<b style="mso-bidi-font-weight: normal"><span lang="EN-US" style="COLOR: blue">Blaster</span><span style="COLOR: blue">、<span lang="EN-US">Sasser</span></span></b><span lang="EN-US"> </span>和 <b style="mso-bidi-font-weight: normal"><span lang="EN-US" style="COLOR: blue">Mydoom</span></b>倒是<span lang="EN-US">XP</span>中最流行的病毒，都有一个相同的特点：利用了<b style="mso-bidi-font-weight: normal"><span lang="EN-US">WindowsXP</span></b>的漏洞（<span lang="EN-US">including <b style="mso-bidi-font-weight: normal">Windows2000</b>)</span>！这次的恶意软件清楚工具的“病毒定义”是<span lang="EN-US">2005</span>年<span lang="EN-US">1</span>月，可以预见的，微软会对其进行更新以清除更多恶意软件。<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体">
<p><font face="宋体" size="3"> </font></p>
<p></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">通过<b style="mso-bidi-font-weight: normal"><span lang="EN-US">Windows Update</span></b>得到<b style="mso-bidi-font-weight: normal"><span lang="EN-US">MICROSOFT WINDOWS MALICIOUS SOFTWARE REMOVAL TOOL</span></b>之后需要接受<b style="mso-bidi-font-weight: normal"><span lang="EN-US">EULA</span></b>（最终用户许可协议）才能安装（可能在接受之前需要重启计算机）。<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">当笔者接受了<b style="mso-bidi-font-weight: normal"><span lang="EN-US">EULA</span></b>之后，<b style="mso-bidi-font-weight: normal"><span lang="EN-US">Windows Update</span></b>将其下载到本地来，并通知已经完成更新。不过笔者在这里碰到一个麻烦，就是从开始菜单找到附件，从控制面板找到管理工具，甚至到添加<span lang="EN-US">/</span>删除程序中找，愣是<img src="http://www.donews.net/fckeditor/editor/images/smiley/msn/whatchutalkingabout_smile.gif" border="0" alt=""/>没有找到这个<b style="mso-bidi-font-weight: normal"><span lang="EN-US">MICROSOFT WINDOWS MALICIOUS SOFTWARE REMOVAL TOOL</span></b>的快捷方式。后来在<span lang="EN-US">Windows</span>目录下的<span lang="EN-US">SoftwareDistribution</span>目录下找到的。笔者的<span lang="EN-US">XP</span>系统装在<span lang="EN-US">C</span>盘下，那么这个恶意软件清除工具的运行文件的具体位置应为<span lang="EN-US">C:\WINDOWS\SoftwareDistribution\Download\Install</span>，运行文件名应为<span lang="EN-US">Windows-KB890830-ENU.exe</span>。碰到和笔者一样的情况请参照上面位置去找运行文件。<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体">
<p><font face="宋体" size="3"> </font></p>
<p></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">运行这个<b style="mso-bidi-font-weight: normal"><span lang="EN-US">MICROSOFT WINDOWS MALICIOUS SOFTWARE REMOVAL TOOL</span></b>，会先有个<b style="mso-bidi-font-weight: normal"><span lang="EN-US">End User license agreement</span></b>（最终用户许可协议），需要勾选<span lang="EN-US">&#8220;Accept all terms of the preceding license agreement&#8221;</span>（同意许可协议的所有上述的条款），之后就会在极短的时间完成扫描（这可以理解，因为仅仅只查几种病毒，只需要查找病毒所影响的区域就可以确定）。</font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><img src="http://www.donews.net/images/www_donews_net/shixinyu/37288/r_MSRT1.JPG" alt=""/></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体"><shapetype id="_x0000_t75" stroked="f" filled="f" path="m@4@5l@4@11@9@11@9@5xe" o:preferrelative="t" o:spt="75" coordsize="21600,21600"><stroke joinstyle="miter"/><br />
<formulas><f eqn="if lineDrawn pixelLineWidth 0"/><f eqn="sum @0 1 0"/><f eqn="sum 0 0 @1"/><f eqn="prod @2 1 2"/><f eqn="prod @3 21600 pixelWidth"/><f eqn="prod @3 21600 pixelHeight"/><f eqn="sum @0 0 1"/><f eqn="prod @6 1 2"/><f eqn="prod @7 21600 pixelWidth"/><f eqn="sum @8 21600 0"/><f eqn="prod @7 21600 pixelHeight"/><f eqn="sum @10 21600 0"/></formulas>
<path o:connecttype="rect" gradientshapeok="t" o:extrusionok="f"/><lock aspectratio="t" v:ext="edit"/></shapetype><shape id="_x0000_i1025" style="WIDTH: 393pt; HEIGHT: 307.5pt" type="#_x0000_t75"><imagedata o:title="r_MSRT1" src="file:///C:\DOCUME~1\shixinyu\LOCALS~1\Temp\msohtml1\01\clip_image001.jpg"/></shape>
<p/></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">如果没有可以扫描到的病毒，那么就会反馈<span lang="EN-US">&#8220;No malicious software was detected.&#8221;</span>（没有发觉恶意软件）。<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体"><shape id="_x0000_i1026" style="WIDTH: 393pt; HEIGHT: 307.5pt" type="#_x0000_t75"><imagedata o:title="r_MSRT3" src="file:///C:\DOCUME~1\shixinyu\LOCALS~1\Temp\msohtml1\01\clip_image002.jpg"/></shape>
<p/></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体"><img src="http://www.donews.net/images/www_donews_net/shixinyu/37288/r_MSRT3.JPG" alt=""/></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">你可以点击<span lang="EN-US">&#8220;View detailed results of the scan.&#8221;</span>（观看详细的扫描结果）。<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><font size="3"><font face="宋体"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体">Not infected</span><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体">（没有感染）<span lang="EN-US">
<p/></span></span></font></font></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体"><shape id="_x0000_i1027" style="WIDTH: 393pt; HEIGHT: 307.5pt" type="#_x0000_t75"><imagedata o:title="r_MSRT2" src="file:///C:\DOCUME~1\shixinyu\LOCALS~1\Temp\msohtml1\01\clip_image003.jpg"/></shape>
<p/></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体"><img src="http://www.donews.net/images/www_donews_net/shixinyu/37288/r_MSRT2.JPG" alt=""/></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><font size="3"><font face="宋体">点击那些病毒名称，可以获得更多关于这些病毒的信息。<span lang="EN-US">
<p/></span></font></font></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体">
<p><font face="宋体" size="3"> </font></p>
<p></span></p>
<p class="MsoPlainText" style="MARGIN: 0cm 0cm 0pt"><font size="3"><font face="宋体"><span lang="EN-US" style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体"><span style="mso-spacerun: yes">                                             </span></span><span style="mso-hansi-font-family: 宋体; mso-bidi-font-family: 宋体">————<b style="mso-bidi-font-weight: normal"><span lang="EN-US">By Stone.sxy</span></b><span lang="EN-US">
<p/></span></span></font></font></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/shixinyu/archive/2005/01/12/236544.aspx/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Microsoft AntiSpyware&#8217;s Real-Time Protection 2</title>
		<link>http://blog.donews.com/shixinyu/archive/2005/01/11/235591.aspx</link>
		<comments>http://blog.donews.com/shixinyu/archive/2005/01/11/235591.aspx#comments</comments>
		<pubDate>Tue, 11 Jan 2005 09:42:00 +0000</pubDate>
		<dc:creator>石头</dc:creator>
				<category><![CDATA[IT资讯]]></category>

		<guid isPermaLink="false">http://blog.donews.com/shixinyu/archive/2005/01/11/235591.aspx</guid>
		<description><![CDATA[本文尝试解释Microsoft AntiSpyware (Beta1)的Real-Time Protection（实时监控）到底监控了什么项目以及那些项目的一些概念和应用，以便于读者对于该软件进一步的了解。]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font face="Times New Roman"><b><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt">Real-time Protection</span></b><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体">
<p/></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">实时监控到底在监控什么？</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体">
<p/></span></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 7.5pt 0cm 7.5pt 134.9pt; TEXT-ALIGN: left; mso-pagination: widow-orphan; mso-para-margin-top: 7.5pt; mso-para-margin-right: 0cm; mso-para-margin-bottom: 7.5pt; mso-para-margin-left: 12.85gd" align="justify"><font face="Times New Roman"><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt"> </span><span lang="EN-US" style="FONT-FAMILY: Verdana; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-bidi-font-size: 10.5pt">
<p/></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; TEXT-ALIGN: left; mso-pagination: widow-orphan; mso-char-indent-count: 2.0" align="justify"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">本文尝试解释</span><b><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt"><font face="Times New Roman">Microsoft AntiSpyware (Beta1)</font></span></b><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">的</span><b><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt"><font face="Times New Roman">Real-Time Protection</font></span></b><b><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">（实时监控）</span></b><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">到底监控了什么项目以及那些项目的一些概念和应用，以便于读者对于该软件进一步的了解。</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体">
<p/></span></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（下文中的</span><b><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt"><font face="Times New Roman">Real-Time Protection</font></span></b><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">将以“</span><b><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt"><font face="Times New Roman">RTP</font></span></b><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">”表示）</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体">
<p/></span></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 7.5pt 0cm; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font face="Times New Roman"><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt"> </span><span lang="EN-US" style="FONT-FAMILY: Verdana; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-bidi-font-size: 10.5pt">
<p/></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; TEXT-ALIGN: left; mso-pagination: widow-orphan; mso-char-indent-count: 2.0" align="justify"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">在<b><span style="COLOR: blue">《</span></b></span><b><span lang="EN-US" style="FONT-SIZE: 12pt; COLOR: blue; mso-font-kerning: 0pt"><font face="Times New Roman">Microsoft AntiSpyware (Beta1) </font></span></b><b><span style="FONT-SIZE: 12pt; COLOR: blue; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">简易使用手册》</span></b><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">中可以看到</span><b><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt"><font face="Times New Roman">RTP</font></span></b><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">中监控了三大项目：</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体">
<p/></span></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font face="Times New Roman"><b><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt">Internet Agents</span></b><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体">
<p/></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font face="Times New Roman"><b><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt">Application Agents</span></b><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体">
<p/></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><b><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt"><font face="Times New Roman">System Agents
<p/></font></span></b></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><b><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt">
<p><font face="Times New Roman"> </font></p>
<p></span></b></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-bidi-font-weight: bold">上次介绍过了</span><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-bidi-font-weight: bold"><font face="Times New Roman"><strong>Internet Agents</strong></font></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-bidi-font-weight: bold">，这次该应上次的承诺，介绍</span><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-bidi-font-weight: bold"><font face="Times New Roman"><strong>System Agents</strong></font></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-bidi-font-weight: bold">了</span><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-bidi-font-weight: bold">
<p/></span></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-bidi-font-weight: bold"><font face="Times New Roman">1</font></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-bidi-font-weight: bold">、</span><font size="3"><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">AppInit DLL</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（程序动态链接库）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控未经授权的改动或添加到</span><span lang="EN-US"><font face="Times New Roman">APPInit_DLL Files</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（程序动态链接库文件）注册值</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0.9pt 0pt 0cm; TEXT-ALIGN: left; tab-stops: 36.0pt; mso-layout-grid-align: none" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">AppInit DLL</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：当</span><span lang="EN-US"><font face="Times New Roman">User32.dll</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">被读取时，在</span><span lang="EN-US"><font face="Times New Roman">AppInit_DLL</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">注册值包括的名单中的</span><span lang="EN-US"><font face="Times New Roman">.dll</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件也会都被读取。因为大多数</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">执行要读取</span><span lang="EN-US"><font face="Times New Roman">User32.dll</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">，而在</span><span lang="EN-US"><font face="Times New Roman">AppInit_DLL</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件注册值名单中所列的</span><span lang="EN-US"><font face="Times New Roman">.dll</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">也都会被读取。这使得</span><span lang="EN-US"><font face="Times New Roman">.dll</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件很难被移除，因为其读取过程是多重的，除非停止操作系统，否则这种联动读取的过程是不会停止的。</span><span lang="EN-US"><font face="Times New Roman">User32.dll</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件在每次你登录电脑的时候会被自动启动的进程读取。这样子意味那些</span><span lang="EN-US"><font face="Times New Roman">AppInit_DLL</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">名单中的</span><span lang="EN-US"><font face="Times New Roman">.dll</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件会跟随</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">运行，同时允许了那些间谍软件在你得到授权使用系统之前把自身隐藏或者保护自身。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">2</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Approved Shell Extensions</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（合法的外观扩展）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控未经授权的改动</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">外观及扩展。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Approved Shell Extensions</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">Shell extensions</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">允许开发者给现有的</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">外壳添加一些功能，一个标准的</span><span lang="EN-US"><font face="Times New Roman">Shell extensions</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">带有上下菜单、特定操作、</span><span lang="EN-US"><font face="Times New Roman">ICO</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">图标和文件夹等。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">3</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Context Menu Handler</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（上下文菜单管理）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控未经授权的改动</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">上下文菜单。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Context Menu Handler</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：该</span><span lang="EN-US"><font face="Times New Roman">Context Menu Handler</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">功能为向特定类型的文件对象增添上下文相关菜单。（如安装了</span><span lang="EN-US"><font face="Times New Roman">WinZip</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">之后右键点击文件会有个上下文菜单出现）</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">4</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Control.ini Policy</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Control.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">参数）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控未经授权的更改</span><span lang="EN-US"><font face="Times New Roman">Control.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">以改变控制面板。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Control.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：即控制面板的参数文件，你可以在其中在某个控制面板的项目</span><span lang="EN-US"><font face="Times New Roman">.cpl=</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">之后输入</span><span lang="EN-US"><font face="Times New Roman">Yes</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">或</span><span lang="EN-US"><font face="Times New Roman">No</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">来决定是否在控制面板中显示某项目。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">5</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><font color="#ff0000"><strong><span lang="EN-US"><font face="Times New Roman">Explorer Trojan</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（资源管理器特洛伊）</span></strong></font></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控已知的资源管理器特洛伊木马。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Explorer Trojan</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：当你启动你的电脑时，</span><span lang="EN-US"><font face="Times New Roman">Microsoft Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">会在指定的</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">目录中读取</span><span lang="EN-US"><font face="Times New Roman">explorer.exe</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件。无论用何种办法，只要在</span><span lang="EN-US"><font face="Times New Roman">C</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">盘根目录中存在</span><span lang="EN-US"><font face="Times New Roman">explorer.exe</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">，就会代替</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">的</span><span lang="EN-US"><font face="Times New Roman">explorer.exe</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">而被执行。如果</span><span lang="EN-US"><font face="Times New Roman">C</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">盘根目录下的</span><span lang="EN-US"><font face="Times New Roman">explorer.exe</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件已经被破坏，你就会被强制无法使用你的电脑。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">6</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Ini File Mapping</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件映射）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控已经被安装了的程序的一个</span><span lang="EN-US"><font face="Times New Roman">ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件映射位置。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">IniFileMapping</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">Microsoft Windows2000</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><span lang="EN-US"><font face="Times New Roman">WindowsXP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">和其它的最近发布的</span><span lang="EN-US"><font face="Times New Roman">Microsoft</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">操作系统版本，一般不会用</span><span lang="EN-US"><font face="Times New Roman">system.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">和</span><span lang="EN-US"><font face="Times New Roman">win.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件。出于兼容性考虑，它们用一个叫做</span><span lang="EN-US"><font face="Times New Roman">IniFileMapping</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">的功能。</span><span lang="EN-US"><font face="Times New Roman">IniFileMapping</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">将所有目录中的</span><span lang="EN-US"><font face="Times New Roman">.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件注册入注册表的</span><span lang="EN-US"><font face="Times New Roman">.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件键值中。当你运行一个程序，一般会先读取其中的</span><span lang="EN-US"><font face="Times New Roman">.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件的参数，</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">会先检查注册表键</span><span lang="EN-US"><font face="Times New Roman">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">中的</span><span lang="EN-US"><font face="Times New Roman">.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">映射。如果找到了，</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">就会从其中的键值中的设置参数代替该</span><span lang="EN-US"><font face="Times New Roman">.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">7</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Shared TaskScheduler</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（共享任务调度程序）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控那些可以将自己添加进入任务调度表中让</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">运行的未知程序。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Shared TaskScheduler</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：在任务调度程序中列出的文件都会在你启动</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">时被运行。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">8</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><span lang="EN-US"><font face="Times New Roman" color="#ff0000"><strong>Shell Execute Hook</strong></font></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控改动系统</span><span lang="EN-US"><font face="Times New Roman">Shell Execute Hooks</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Shell Execute Hooks</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">Shell Execute Hooks</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">是一个被</span><span lang="EN-US"><font face="Times New Roman">Windows Shell</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">，资源管理器读取的一个项目。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">9</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><span lang="EN-US"><font face="Times New Roman" color="#ff0000"><strong>Shell Open Commands</strong></font></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控改动系统的</span><span lang="EN-US"><font face="Times New Roman">Shell Open Commands</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Shell Open Commands</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">执行指示在注册表的部分：</span><span lang="EN-US"><font face="Times New Roman">HKEY_CLASSES_ROOT\exefile\shell\open\command &#8220;%1&#8243; %*</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">。一些命令被隐藏在这里，直到一些</span><span lang="EN-US"><font face="Times New Roman">.exe</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件被执行，这些命令也会打开。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">10</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><span lang="EN-US"><font face="Times New Roman" color="#ff0000"><strong>Shell Service Object Delay Load</strong></font></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控未经授权的程序把它们自身加入启动键值，让</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">读取。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">ShellServiceObjectDelayLoad</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：每当你启动电脑时，在</span><span lang="EN-US"><font face="Times New Roman">ShellServiceObjectDelayLoad</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">列出文件的文件都会由</span><span lang="EN-US"><font face="Times New Roman">Explorer.exe</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">自动读取。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">11</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><font color="#ff0000"><strong><span lang="EN-US"><font face="Times New Roman">User Shell Folders</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（用户自定义文件夹外观）</span></strong></font></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控未经授权的更改用户自定义文件夹外观设置。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">User Shell Folders</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">User Shell Folders</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">是</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">会以默认显示某些类型的设置和数据的文件夹。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">12</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Windows Directory Trojans</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">目录特洛伊）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控可以读取</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">启动时需要读取的文件的间谍软件。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">13</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><font color="#ff0000"><strong><span lang="EN-US"><font face="Times New Roman">Windows Extensions</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">扩展）</span></strong></font></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控未经授权的更改</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">扩展的系统目录。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">14</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Windows Password Protection</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">密码保护）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控未经授权的更改</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">自动登录的参数。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Auto-logon Password</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：在</span><span lang="EN-US"><font face="Times New Roman">Microsoft WindowsXP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">专业版中，你可以使登录过程自动化，密码和一些相关信息已被存储进注册表。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">15</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Windows Protocols</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">协议）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控有威胁的来自重要的标准协议驱动的转向器。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Protocols</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：有一种间谍软件技术：利用控制</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">协议渗入和操作你的电脑用来发送和接收一些信息。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">16</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Windows Update Service</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">更新服务）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控修正你的</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">更新访问设置</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Windows Update Service</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：最新版本的</span><span lang="EN-US"><font face="Times New Roman">Microsoft Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">操作系统加进了一个自动更新的功能：当你的电脑在线时一个可以从</span><span lang="EN-US"><font face="Times New Roman">Microsoft.com</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">自动下载最新安全和应用程序更新的功能。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">17</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Windows Host File</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Windows Host</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控对于</span><span lang="EN-US"><font face="Times New Roman">Windows Host</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件的修改，如果添加了新的</span><span lang="EN-US"><font face="Times New Roman">Host</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">进入或者旧的覆盖或者删除，那么会有一个弹出对话框提醒你是否允许。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Windows Host File</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：你的</span><span lang="EN-US"><font face="Times New Roman">Host</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件是用来执行域名到</span><span lang="EN-US"><font face="Times New Roman">IP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">地址的转换的，如信件转寄一样</span><span lang="EN-US"><font face="Times New Roman">Host File</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">是</span><span lang="EN-US"><font face="Times New Roman">Web</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">网站的转寄地址。例如，假定下列入口在</span><span lang="EN-US"><font face="Times New Roman">Hosts File</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">192.168.0.12 </font><a href="http://www.microsoft.com/"><font face="Times New Roman">www.microsoft.com</font></a><font face="Times New Roman">.</font></span><font color="#0000ff"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;"><font>（</font><strong>《</strong></span><span lang="EN-US"><font face="Times New Roman"><strong>Microsoft AntiSpyware (Beta1)</strong></font></span></font><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;"><font color="#0000ff"><strong>简易使用手册》</strong></font>提过我们可以在</span><span lang="EN-US"><font face="Times New Roman"><strong>Advanced Tools</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">中的</span><span lang="EN-US"><font face="Times New Roman" color="#ff00ff"><strong>Networking</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">中修正</span><span lang="EN-US"><font face="Times New Roman">Hosts File</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">）</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">18</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><font color="#ff0000"><strong><span lang="EN-US"><font face="Times New Roman">Windows Logon Policies</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">登录参数）</span></strong></font></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控未经授权的添加或修改</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">登录参数。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Windows Logon</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">Windows Logon</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">可以有效的管理用户登录和注销行为。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">19</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Windows System.ini File</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Windows System.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控添加或修改</span><span lang="EN-US"><font face="Times New Roman">System.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件，同</span><span lang="EN-US"><font face="Times New Roman">Windows Host</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">一样，如果有此行为，</span><span lang="EN-US"><font face="Times New Roman">AntiSpyware</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">会有弹出窗口提醒是否允许该操作。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">System.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">The C:\windows\system.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件是一个设定初值的文件用户</span><span lang="EN-US"><font face="Times New Roman">Microsoft Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">用以初始化系统设置诸如字体、键盘、语言以及其它的各种各样的设置。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">20</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Windows Restrict Anonymous</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">匿名用户限制）</span></font></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控修改</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">匿名用户限制。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Restrict Anonymous</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：限制匿名用户的权限，减少非法用户操作的可能，增强你的系统的安全。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">21</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><font color="#ff0000"><strong><span lang="EN-US"><font face="Times New Roman">Windows Win.ini File</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Windows Win.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件）</span></strong></font></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">RTP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控添加或修改</span><span lang="EN-US"><font face="Times New Roman">Win.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件，同</span><span lang="EN-US"><font face="Times New Roman">Windows system.ini</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">一样，如果有此行为，</span><span lang="EN-US"><font face="Times New Roman">AntiSpyware</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">会有弹出窗口提醒是否允许该操作。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">22</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><span lang="EN-US"><font face="Times New Roman" color="#ff0000"><strong>Winlogon Userinit</strong></font></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="left"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控未经授权的更改</span><span lang="EN-US"><font face="Times New Roman">Winlogon Userinit</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">设置。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Winlogon Userinit</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：一种进程，</span><span lang="EN-US"><font face="Times New Roman">UserInit</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">程序运行登陆脚本，建立网络连接和启动</span><span lang="EN-US"><font face="Times New Roman">Shell</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">壳。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">23</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><span lang="EN-US"><font face="Times New Roman" color="#ff0000"><strong>Winlogon Shell</strong></font></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控未经授权的更改</span><span lang="EN-US"><font face="Times New Roman">Winlogon Shell</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">设置。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Winlogon Shell</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：每当你登录</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">时，</span><span lang="EN-US"><font face="Times New Roman">Winlogon Shell</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">会随之自动运行。</span><span lang="EN-US"><font face="Times New Roman">Winlogon Shell</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">是你用来管理</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">的主要用户界面。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman">24</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><span lang="EN-US"><font face="Times New Roman" color="#ff0000"><strong>WOW Boot Shell</strong></font></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控每当</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">启动时，间谍软件能启动某种特殊程序的威胁。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">WOW\Boot\Shell</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">WOW\Boot\Shell</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">是一种注册表条目，其中可以设置每当</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">启动时也随之运行的特殊程序。</span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><span lang="EN-US">
<p><font face="Times New Roman" size="3"> </font></p>
<p></span></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">对于</span><span lang="EN-US"><font face="Times New Roman"><strong>System Agents</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">的介绍到此为止，下次推出</span><span lang="EN-US"><font face="Times New Roman"><strong>Real-Time Protection</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">中的最后一个项目：</span><strong><span lang="EN-US"><font face="Times New Roman">Application Agents</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">。</span></strong></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><span lang="EN-US">
<p><font face="Times New Roman" size="3"> </font></p>
<p></span></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">参考文献：</span><span lang="EN-US"><font face="Times New Roman"><strong>Microsoft AntiSpyware Help</strong></font></span></font></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><span lang="EN-US">
<p><font face="Times New Roman" size="3"> </font></p>
<p></span></p>
<p class="MsoNormal" style="BACKGROUND: white; MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan" align="justify"><font size="3"><span lang="EN-US"><span style="mso-spacerun: yes"><font face="Times New Roman">                                                         </font></span></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">————</span><span lang="EN-US"><font face="Times New Roman"><strong>By Stone.sxy</strong></font></span></font></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/shixinyu/archive/2005/01/11/235591.aspx/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Microsoft AntiSpyware&#8217;s Real-time Protection</title>
		<link>http://blog.donews.com/shixinyu/archive/2005/01/09/232075.aspx</link>
		<comments>http://blog.donews.com/shixinyu/archive/2005/01/09/232075.aspx#comments</comments>
		<pubDate>Sun, 09 Jan 2005 15:11:00 +0000</pubDate>
		<dc:creator>石头</dc:creator>
				<category><![CDATA[IT资讯]]></category>

		<guid isPermaLink="false">http://blog.donews.com/shixinyu/archive/2005/01/09/232075.aspx</guid>
		<description><![CDATA[本文尝试解释Microsoft AntiSpyware (Beta1)的Real-Time Protection（实时监控）到底监控了什么项目以及那些项目的一些概念和应用，以便于读者对于该软件进一步的了解。]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US"><font face="Times New Roman" size="3"><strong>Real-time Protection</strong></font></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;"><font size="3">实时监控到底在监控什么？</font></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US">
<p><font face="Times New Roman" size="3"> </font></p>
<p></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">本文尝试解释</span><span lang="EN-US"><font face="Times New Roman"><strong>Microsoft AntiSpyware (Beta1)</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">的</span><span lang="EN-US"><font face="Times New Roman"><strong>Real-Time Protection</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'"><strong>（实时监控）</strong>到底监控了什么项目以及那些项目的一些概念和应用，以便于读者对于该软件进一步的了解。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（下文中的</span><span lang="EN-US"><font face="Times New Roman"><strong>Real-Time Protection</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">将以“</span><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">”表示）</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US">
<p><font face="Times New Roman" size="3"> </font></p>
<p></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">在<font color="#0000ff"><strong>《</strong></font></span><span lang="EN-US"><font face="Times New Roman" color="#0000ff"><strong>Microsoft AntiSpyware (Beta1) </strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;"><font color="#0000ff"><strong>简易使用手册》</strong></font>中可以看到</span><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">中监控了三大项目：</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US"><font face="Times New Roman" size="3"><strong>Internet Agents</strong></font></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US"><font face="Times New Roman" size="3"><strong>Application Agents</strong></font></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US"><font face="Times New Roman" size="3"><strong>System Agents</strong></font></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US">
<p><font face="Times New Roman" size="3"> </font></p>
<p></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">这次先介绍</span><strong><span lang="EN-US"><font face="Times New Roman">Internet Agents</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">～～</span></strong></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Internet Agents</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">到底监控什么</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt 18pt; TEXT-INDENT: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 18.0pt"><font face="Times New Roman"><span lang="EN-US" style="mso-fareast-font-family: &quot;Times New Roman&quot;"><span style="mso-list: Ignore"><font size="3">1、</font><span style="FONT: 7pt &quot;Times New Roman&quot;">  </span></span></span><span lang="EN-US"><font color="#ff0000" size="3"><strong>Application Connections</strong></font></span></font><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;"><font color="#ff0000" size="3"><strong>（应用程序连接）</strong></font></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控应用程序的网络连接或在你的网络监听程序所用的端口</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Application</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：诸如最流行的</span><span lang="EN-US"><font face="Times New Roman">IM</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">工具</span><span lang="EN-US"><font face="Times New Roman">QQ</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><span lang="EN-US"><font face="Times New Roman">MSN</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">需要跟网络连接的程序都是所谓的</span><span lang="EN-US"><font face="Times New Roman">Application</font></span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman">2</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><font color="#ff0000"><strong><span lang="EN-US"><font face="Times New Roman">Dial-up Connection</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（拨号上网连接）</span></strong></font></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控防止未经授权的拨号程序通过你的</span><span lang="EN-US"><font face="Times New Roman">Modem</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">连接网络，这个检查点可以帮助防止拨号间谍程序在你的机子上运行</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为未经授权的拨号程序？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：例如某些色情网站为了获得非法收入，会悄悄在机子里植入拨号程序，并改为默认拨号，实际上拨号会拨一些高收费的号码如国际电话。这些并非用户的意愿，所以称之为未经授权的拨号程序。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman">3</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Internet Proxy Server</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（因特网代理服务器）</span></font></strong></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控防止未经授权的改动或添加代理服务器。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为代理服务器？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：代理服务器是一个作为你的</span><span lang="EN-US"><font face="Times New Roman">Internet Explorer Web</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">浏览器和网络服务器之间的桥梁的服务器，代理服务器主要有两个作用：改善网络访问性能和过滤非法网络请求</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman">4</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Internet Safe Sites</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（因特网安全站点）</span></font></strong></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控防止那些未经授权的站点把自己添加到你的“安全站点”名单中。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为安全站点？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：安全站点就是你信任的不会侵害你的电脑的站点。当你访问他们时，</span><span lang="EN-US"><font face="Times New Roman">Internet Explorer</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">会允许以较低的安全设置、所有的脚本包括有潜在危害的在你的电脑上运行。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman">5</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><font color="#ff0000"><strong><span lang="EN-US"><font face="Times New Roman">Layered Service Provider</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（分层的服务提供者）</span></strong></font></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控智能的添加或修正</span><span lang="EN-US"><font face="Times New Roman">Windows Winsock layered service providers</font></span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Layered Service Provider</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">Layered Service Provider</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">可以智能处理由于</span><span lang="EN-US"><font face="Times New Roman">Winsock redirectors</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">而出名的间谍软件。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman">6</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><font color="#ff0000"><strong><span lang="EN-US"><font face="Times New Roman">Namer Server Protection</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（域名解析服务器保护）</span></strong></font></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控可以改变你的</span><span lang="EN-US"><font face="Times New Roman">DNS</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（域名解析服务器）地址的间谍软件</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为域名解析服务器？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：众所周知的，网络上的每个用户都有一个身份证</span><span lang="EN-US"><font face="Times New Roman">ID</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">，就是“</span><span lang="EN-US"><font face="Times New Roman">IP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">”，每个网站都有他的固定</span><span lang="EN-US"><font face="Times New Roman">IP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">，但</span><span lang="EN-US"><font face="Times New Roman">IP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">的形式不方便记忆，故而衍生出域名这个产物为了方便人记忆，域名解析服务器就是为了把域名解析为</span><span lang="EN-US"><font face="Times New Roman">IP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">，才能正常访问网站。所以有些间谍软件可以改变的</span><span lang="EN-US"><font face="Times New Roman">DNS</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">，让你无法正常访问网站。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman">7</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Spam Zombie Prevention</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（预防垃圾僵尸）</span></font></strong></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控间谍软件从你的电脑发送垃圾。（被这样的间谍软件侵入了，你的电脑就成了电视上说的“僵尸”了，也会去咬别人了<img src="http://www.donews.net/fckeditor/editor/images/smiley/msn/devil_smile.gif" border="0" alt=""/>）</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Spam Zombie </font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：用银屏上的“僵尸”的概念来解释更为方便，看过僵尸片的都知道一旦被僵尸咬了，不会死，但也会变成另一个僵尸，也会去咬别的正常人（咬僵尸没什么用了<img src="http://www.donews.net/fckeditor/editor/images/smiley/msn/shades_smile.gif" border="0" alt=""/>）。那么如果你的电脑变成了</span><span lang="EN-US"><font face="Times New Roman">Spam</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">僵尸，也就会通过网络给别的正常的电脑发送垃圾并让他人的电脑也变成“</span><span lang="EN-US"><font face="Times New Roman">Spam</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">僵尸”。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman">8</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><font color="#ff0000"><strong><span lang="EN-US"><font face="Times New Roman">TCP/IP Parameters</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（传输控制协议</span><span lang="EN-US"><font face="Times New Roman">/</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">网间协议议参数）</span></strong></font></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控可以更改各种各样的</span><span lang="EN-US"><font face="Times New Roman">TCP/IP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">参数以通过</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">发送和接收数据的间谍软件。同时保护</span><span lang="EN-US"><font face="Times New Roman">Tcpip.sys</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">文件等与</span><span lang="EN-US"><font face="Times New Roman">TCP/IP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">相关的系统文件。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">TCP/IP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">TCP/IP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（传输控制协议</span><span lang="EN-US"><font face="Times New Roman">/</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">网间协议）是一种网络通信协议，它规范了网络上的所有通信设备，尤其是一个主机与另一个主机之间的数据往来格式以及传送方式。可以这么说</span><span lang="EN-US"><font face="Times New Roman">TCP/IP</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">就是整个</span><span lang="EN-US"><font face="Times New Roman">Internet</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">的根基。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman">9</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">WiFi Connection</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">WiFi</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">连接）</span></font></strong></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控在你的无线网络的其它用户，当有其他的在你的无线网络的用户访问你的机子，</span><span lang="EN-US"><font face="Times New Roman">AntiSpyware</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">会通报你。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">WiFi</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：以</span><span lang="EN-US"><font face="Times New Roman">Intel</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">公司为首开发的一种无线网络技术。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman">10</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">、</span><strong><font color="#ff0000"><span lang="EN-US"><font face="Times New Roman">Windows Messenger Service</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">（</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">信史服务）</span></font></strong></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>RTP</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">监控</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">信史服务，预防他人通过</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">信史服务发送垃圾信息到你的电脑。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span lang="EN-US"><font face="Times New Roman"><strong>Q</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：何为</span><span lang="EN-US"><font face="Times New Roman">Windows Messenger Service</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">？</span><span lang="EN-US"><font face="Times New Roman"><strong>A</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">：</span><span lang="EN-US"><font face="Times New Roman">Windows</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">信史服务，可以在</span><span lang="EN-US"><font face="Times New Roman">CMD</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">黑白终端中使用“</span><span lang="EN-US"><font face="Times New Roman">net send to</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">”命令给在网络中的朋友发送短消息，前提是对方也开启了</span><span lang="EN-US"><font face="Times New Roman">Messenger Service</font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US">
<p><font face="Times New Roman" size="3"> </font></p>
<p></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><span lang="EN-US">
<p><font face="Times New Roman" size="3"> </font></p>
<p></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">关于</span><span lang="EN-US"><font face="Times New Roman"><strong>Internet Agents</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">的介绍就到此为止，下次将出品</span><span lang="EN-US"><font face="Times New Roman"><strong>System Agents</strong></font></span><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">的监控详单。</span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;"/></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">参考文献：<strong>Microsoft AntiSpyware Help文档</strong></span></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;"/></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;"/></font></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt"><font size="3"><span style="FONT-FAMILY: 宋体; mso-ascii-font-family: &quot;Times New Roman&quot;; mso-hansi-font-family: &quot;Times New Roman&quot;">                                                  ————<strong>By Stone.sxy</strong></span></font></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/shixinyu/archive/2005/01/09/232075.aspx/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Microsoft AntiSpyware (Beta 1)简易使用手册 【续】</title>
		<link>http://blog.donews.com/shixinyu/archive/2005/01/08/229656.aspx</link>
		<comments>http://blog.donews.com/shixinyu/archive/2005/01/08/229656.aspx#comments</comments>
		<pubDate>Sat, 08 Jan 2005 03:24:00 +0000</pubDate>
		<dc:creator>石头</dc:creator>
				<category><![CDATA[Windows&NetWork]]></category>

		<guid isPermaLink="false">http://blog.donews.com/shixinyu/archive/2005/01/08/229656.aspx</guid>
		<description><![CDATA[     在前面的Microsoft AntiSpyware （Beta 1）简易使用手册中少提到了一些东西，在这里补上。
      Microsoft AntiSpyware （Beta 1）的安装系统需求：      操作系统：      Windows 2000 Professional       Windows XP Professional/Home Edition       Windows 2003 Server      很不幸的，Win9x已经在支持名单外了，Win9x确实是老了！      上面各个操作系统中运行的硬件需求：      Windows 2000 Professional Edition, Service Pack 3 or greater（Windows2000 Pro，SP3或更新）      Intel Pentium processor (or compatible) at 133 MHz or higher （Pentium或兼容处理器133赫兹或更高速度）      64 MB of RAM (128 recommended if running real-time AntiSpyware)（64MB内存，如果想要运行实时监控推荐128MB）      20 MB of [...]]]></description>
			<content:encoded><![CDATA[<p>     在前面的<strong>Microsoft AntiSpyware （Beta 1）</strong>简易使用手册中少提到了一些东西，在这里补上。</p>
<p>      <strong>Microsoft AntiSpyware （Beta 1）</strong>的安装系统需求：<br/>      操作系统：<br/>      Windows 2000 Professional <br/>      Windows XP Professional/Home Edition <br/>      Windows 2003 Server<br/>      <font color="#ff00ff">很不幸的，Win9x已经在支持名单外了，Win9x确实是老了！</font><br/>      上面各个操作系统中运行的硬件需求：<br/>      <b>Windows 2000 Professional Edition, Service Pack 3 or greater（Windows2000 Pro，SP3或更新）<br/>      </b>Intel Pentium processor (or compatible) at 133 MHz or higher （Pentium或兼容处理器133赫兹或更高速度）<br/>      64 MB of RAM (128 recommended if running real-time AntiSpyware)（64MB内存，如果想要运行实时监控推荐128MB）<br/>      20 MB of available hard disk space （20MB可用磁盘空间）<br/>      Internet Explorer 6.0 or later（IE6.0或更新版本）</p>
<p>      <b>Windows XP Professional/Home Edition</b>, <strong>Service Pack 1 or greater（WinXP Pro/Home SP1或更新）</strong><br/>      Intel Pentium processor (or compatible) at 300 MHz or higher （Pentium或兼容处理器300赫兹或更高速度）<br/>     128 MB of RAM （128MB内存）<br/>     20 MB of available hard disk space（20MB可用空间）<br/>      Internet Explorer 6.0 or later（IE6.0或更新版本）</p>
<p>      <strong>Windows 2003 Server的硬件需求与Windows2000基本一致。</strong></p>
<p><strong>      <font color="#0000ff">（PS：这些只是官方声明最低配置，实际上Win2000推荐至少128MB以上，WinXP/Win2003 Server推荐至少256MB以上）</font></strong></p>
<p><strong>      需要Internet连接。<br/>      安装此软件需要拥有Administator权限。</strong></p>
<p><strong>       参考文献：Microsoft AntiSpyware (beta 1) Help</strong></p>
<p><strong>                                                                                         &#8212;&#8212;&#8212;-by Stone.sxy</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/shixinyu/archive/2005/01/08/229656.aspx/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft AntiSpyware （Beta1）简易使用手册</title>
		<link>http://blog.donews.com/shixinyu/archive/2005/01/07/229132.aspx</link>
		<comments>http://blog.donews.com/shixinyu/archive/2005/01/07/229132.aspx#comments</comments>
		<pubDate>Fri, 07 Jan 2005 10:06:00 +0000</pubDate>
		<dc:creator>石头</dc:creator>
				<category><![CDATA[IT资讯]]></category>
		<category><![CDATA[Windows&NetWork]]></category>

		<guid isPermaLink="false">http://blog.donews.com/shixinyu/archive/2005/01/07/229132.aspx</guid>
		<description><![CDATA[近日微软发布了Microsoft AntiSpyware (Beta1)，微软对于这款软件的大致介绍是“Help protect your PC from spyware and other potentially unwanted software”，根据调查，这个AntiSpyware并不是微软的原创，而是微软对自己并购的GIANT软件公司的反间谍软件进行了一个新包装罢了，但无论如何，只有微软最了解自己的OS，对Giant的反间谍软件进行更深的强化是绝对可能的事情。]]></description>
			<content:encoded><![CDATA[<p>    近日微软发布了<strong>Microsoft AntiSpyware (Beta1)</strong>，微软对于这款软件的大致介绍是“<u>Help protect your PC from spyware and other potentially unwanted software</u>”，根据调查，这个<strong>AntiSpyware</strong>并不是微软的原创，而是微软对自己并购的<strong>GIANT</strong>软件公司的反间谍软件进行了一个新包装罢了，但无论如何，只有微软最了解自己的<strong>OS</strong>，对<strong>Giant</strong>的反间谍软件进行更深的强化是绝对可能的事情。</p>
<p>    Microsoft AntiSpyware (beta1)的官方下载地址：<br/>    <a href="http://download.microsoft.com/download/8/1/5/815d2d60-49b5-44dc-ae35-fca2f2c6f0cc/MicrosoftAntiSpywareInstall.exe">http://download.microsoft.com/download/8/1/5/815d2d60-49b5-44dc-ae35-fca2f2c6f0cc/MicrosoftAntiSpywareInstall.exe</a></p>
<p>    比较遗憾的是<strong>Microsoft AntiSpyware （beta1）</strong>仅仅只有英文版，看来还要有一段时间才能推出中文版。可能是地域服务差异吧，北美地区总是优先于其他地区享受到Microsoft的服务，愿Microsoft对于全球用户，尤其是亚洲用户中比例最大的中国用户能一视同仁。</p>
<p>    下载下来，安装步骤很标准，过程中只需要“I Agree” And 更改安装目录，其它的一律可以按下“Next”即可。在Finish时，有个选项：“Launch Microsoft AntiSpywares”。</p>
<p>    第一次运行会启动向导（<strong>Assistant</strong>）：（如图）<br/>    <img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_Assistant1.JPG" alt=""/></p>
<p>Next之后：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_Assistant2.JPG" alt=""/><br/>询问“是否愿意开启自动更新？”，推荐选“Yes”，之后Next：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_Assistant3.JPG" alt=""/><br/>询问“是否愿意实时的安全保护？”，同样推荐选“YES”，之后Next：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_Assistant4.JPG" alt=""/><br/>之后就会开启实时保护，然后：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_Assistant5.JPG" alt=""/><br/>询问“是否愿意加入SpyNet社区？”，推荐选“Yes”，之后Next：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_Assistant6.JPG" alt=""/><br/><strong>Assistant</strong>到这里已经是最后一个步骤了，这里只有一个可选项：Run a spyware scan every night at 2 a.m.(you can modify the time later).，这是计划扫描。虽然这里写的是凌晨的2点，但之后可以更改时间，同样是推荐选择的，不过你可以不选。这里没有Finish按钮，要想进行下一步，要么“Run Scan Now”，要么“Run Scan later”。</p>
<p>    <strong>Assistant </strong>结束后，第一次打开Spyware可能会有一点慢，因为Spyware要收集一些有关你的机子的信息，打开后的Spyware如图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware.JPG" alt=""/><br/>    从这副图中，我们可以看到这么些信息：最后一次扫描、最后一次扫描结果、扫描计划、实时监控情况、Spyware定义（类似于病毒库的定义，越新的定义能扫描到越新的Spyware）、AntiSpyware 自动更新。鼠标留在System Summary 中的诸如“Last Spyware Scan”项目中，会弹出小窗口显示该项目的具体情况。点击它们会显示更多信息和必要的可以操作的内容。这些是Summary中左边的内容。右上侧可以看到“Run Quick Scan Now”、“Real-time Protection”、“Advanced Tools”这三大选项。右下侧可以明显看到该Beta1可以使用205天。不知道是否能通过更改系统时间延长使用，估计不行，它可能会跟网络服务器联络检查时间。不过205天足够长了对于大部分人来说。</p>
<p>    先看看Spyware 的“<strong>Run Quick Scan Now</strong>”是如何的，望文生义的，直接点击即可直接开始扫描，看图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware1.JPG" alt=""/><br/>大致扫描了一会儿，笔者并没有让其扫描至结束，感觉扫描的速度挺快的。从这副图可以看到，Spyware将会扫描“内存中的进程”、“指定的范围的文件”、“注册表键”、“Cookies”，并且在这四个中的每项扫描的下方都有扫描出有问题的数量。看来，这个的确足够全面，把Windows的具有大部分安全隐患的方方面面都扫描到了。</p>
<p>    接下来看Summary中的<strong>Real-Time Protection</strong>是如何的，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20RL1.JPG" alt=""/><br/>可以看到实时监控监控的三个项目：“Internet监控”、“System监控”、“应用程序监控”，并且都处于激活状态（Active），后面的括号中也详细说明了监测点的数量。分别点击这三个项目都能看到监测点的详细内容。这一大Real-time Protection项目就不具体介绍了。</p>
<p>    接下来看Summary中的<strong>Advanced Tools</strong>项目，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Advanced%20tools1.JPG" alt=""/><br/>这一大项目<strong>Advanced Tools</strong>主要有两个项目：<font color="#0000ff"><strong>System Tools</strong></font>和<font color="#0000ff"><strong>Privacy Tools</strong></font>。<br/><font color="#0000ff"><strong>System Tools   探测和保护你的电脑<br/></strong></font>点击“<font color="#ff0000"><strong>System Explorers</strong></font>”可以看到关于你的系统的信息，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Advanced%20tools2.JPG" alt=""/><br/>可以看到<font color="#ff0000"><strong>System Explorer</strong></font>能探测到你的系统中的“应用程序”、Internet Explorer、网络、系统的具体信息，点击<font color="#ff00ff"><strong>Applictions</strong></font>中“Downloaded ActiveX”（已下载的ActiveX控件），图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Advanced%20tools3.JPG" alt=""/><br/>可以看到已经下载并安装的ActiveX程序，并且自动监测并分类（星星是安全的，三角形中有个感叹号是未知程序，方块且里面有个×的是危险的）。在这里你可以看到ActiveX控件的详细信息，包括安装目录和来自哪个网站甚至是版本，如果你发现出什么不安全的，你可以点击该项目，然后点击右下角的“Block this ActiveX”以禁止该ActiveX对你造成影响。如果实在不确定，你可以点击右下角的“Send to SpyNet for analysis&#8230;”（可能需要在最初的Assistant中同意加入SpyNet社区）。<br/>    点击<font color="#ff00ff"><strong>Applications</strong></font>中的Running Processes，望文生义的，可以看出应该是显示出当前系统内存中正在运行的进程，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Advanced%20tools4.JPG" alt=""/><br/>可以在这里看到正在运行的进程的进程名字、描述（文件名、运行目录、发布者、文件版本信息、CopyRight信息），这里没有自动将进程分类是否安全，所以如果你怀疑某进程为不安全的，你可以自行在右下角点击“×Stop the Processes from Running now&#8230;”。<br/>    点击<font color="#ff00ff"><strong>Applications</strong></font>中的StartUp Programme，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Advanced%20tools5.JPG" alt=""/><br/>可以看到启动项目中的应用程序和运行文件，并且可以看到描述、发布者、文件目录、文件版本等信息。同样的你可以分别点击右下角的“Block this Startup Programme”或“Permanently Remove Startup Programme”来禁止或移除该启动项。在这里，Spyware把启动项进行了分类。<br/>    点击<font color="#ff00ff"><strong>Internet Explorer</strong></font>中的IE BHOs，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Advanced%20tools8.JPG" alt=""/><br/>这是关于IE中的浏览器助手项目，同样的可以在右下角点击“Block”或者“Permanently”禁止或者移除。同样的显示出浏览器助手项目的文件名、描述、发布者、文件目录和文件版本。这里把浏览器助手项目进行了分类（笔者的机子装有NetTransport2和迅雷4，图中的两个项目即为这俩软件）。<br/>    点击<font color="#ff00ff"><strong>Internet Explorer</strong></font>中的IE Settings，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Advanced%20tools9.JPG" alt=""/><br/>在这里就可以设置：<br/>Internet Explorer Start Page<br/>Internet Explorer Search Page<br/>Internet Explorer Default_Page_URL<br/>Internet Explorer Local Page<br/>Internet Explorer Search Bar<br/>Internet Explorer Default_Search_URL<br/>Internet Explorer HomeOldSP<br/>Internet Explorer CustomizeSearch<br/>Internet Explorer SearchAssistant<br/>Internet Explorer SearchUrl Local page<br/>Internet Explorer SearchUrl Blank page<br/>Internet Explorer SearchUrl Desktop navigation failure<br/>Internet Explorer SearchUrl Navigation canceled<br/>Internet Explorer SearchUrl Navigation failure<br/>Internet Explorer SearchUrl Offline information<br/>Internet Explorer SearchUrl PostNotCached<br/>Internet Explorer SearchUrl mozilla<br/>这些项目。<br/>    点击<font color="#ff00ff"><strong>Internet Exploere</strong></font>中的IE Toolbars，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Advanced%20tools10.JPG" alt=""/><br/>在这里就可以设置IE浏览器上的Toolbar，不过笔者的机子上并没有安装任何的Toolbar，所以该图中没有任何选项，但是可以预见的，应该同样可以禁止或移除Toolbar，并且能浏览Toolbar的文件名、描述、发布者、文件目录、版本等信息。这里也对Toolbar进行了分类。<br/>    点击<font color="#ff00ff"><strong>NetWorking</strong></font>中的Window&#8217;s Host Files，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Advanced%20tools11.JPG" alt=""/><br/>在这里就可以设置Host表了，那些深受恶意站点恶意改动Host表而导致不能访问正常网站的朋友可有的“享福”了。在这里可以进行的操作有：Block（禁止）、Un-Block （解除禁止）、Permanently  remove Host&#8230;（移除）。<br/>    关于<font color="#ff0000"><strong>System Explorers</strong></font>的使用介绍就到此为止了</p>
<p>    点击<strong><font color="#0000ff">System Tools</font></strong>中的<font color="#ff0000"><strong>Browser Hijack Restore</strong></font>，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Advanced%20tools6.JPG" alt=""/><br/>在这里就可以更改或者修复被那些恶意网站修改并锁定了的各种页面。<br/>关于<strong><font color="#0000ff">System Tools</font></strong>的使用介绍到此为止。</p>
<p><font color="#0000ff"><strong>Privacy Tools   保护你的电脑和你的隐私文件不被入侵</strong></font><br/>其中仅只有<strong><font color="#ff0000">Tracks Eraser</font></strong>这一个工具，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Advanced%20tools7.JPG" alt=""/><br/>这个要是有人用过“超级兔子魔法设置”便会立刻感觉到这不就是其中的“清除垃圾”中的清除历史记录和文件和清除Windows临时目录嘛。没错，这个可以说是一模一样的，不过这个<strong><font color="#ff0000">Tracks Eraser</font></strong>相对于“超级兔子魔法设置”更为智能，Spyware可以扫描出已经安装的可以清除历史纪录的软件项目，并且可以清除拨号记录（这一点是超级兔子魔法设置没有的）。大致上国际流行的会产生使用记录的应用软件，在<strong><font color="#ff0000">Tracks Eraser</font></strong>名单中基本包括了。<br/>     关于<strong>Advanced Tools</strong>这一大项目的使用介绍基本就介绍完了。</p>
<p>     点击<strong>Microsoft AntiSpyware</strong>的菜单“Files”中的“Check for Update”，</p>
<p>图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20AutoUpdater.JPG" alt=""/><br/>Check for Update的速度基本令人满意，也许是因为才发布几天的缘故，现在并没有“程序和定义”可以更新。</p>
<p>点击菜单“Options”中的“Settings”，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Settings.JPG" alt=""/><br/>在这里可以设置<strong>Spyware</strong>的高级选项，包括最初的<strong>Assistant</strong>中的扫描计划也是在这里设置，具体设置就不在这里介绍了，有机会出个“<strong>Microsoft AntiSpyware (Beta1)高级设置面面观</strong>”<img alt="" src="http://www.donews.net/fckeditor/editor/images/smiley/msn/wink_smile.gif" border="0"/></p>
<p>大概的测试了一下实时监控的作用，我装了一个会在“启动项”中添加启动项的软件，实时监控弹出窗口询问是否允许通过的提示，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20Alert.JPG" alt=""/></p>
<p>看来实时监控确实是在起作用。</p>
<p>类似的反间谍软件不少，笔者并没有装，所以没有机会进行对比测试，所以就在这里贴一下<strong>Microsoft AntiSpyware （Beta1）</strong>运行占用的资源，图示：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20zy.JPG" alt=""/><br/>笔者的机子配置为：AMD Athlon Thunderbird 1G/256M pc133/，操作系统：WindowsXP with SP2，后台运行中的软件有卡巴斯基5.0、金山词霸2005。这样子的资源占用基本令人满意。</p>
<p>    在这里提出几点缺点：<br/>    1、NetTransport2和迅雷在国内相对来说很流行，QQ更是IM工具中的老大，但看的出来Spyware会把它们产生的Toolbar和Browswer Helper认成Unknown，我想Spyware应该针对它们更新程序识别和定义。<br/>    2、在Privacy Tools中的Tracks Eraser工具中的名单中没有国内普遍流行的QQ、POPO、UC等IM工具，甚至连Microsoft自己的MSN都没有，这一点需要加强。因为上网的人的大部分隐私和历史纪录都来源于这些IM工具。<br/>    3、Language，还是Language这一点，本来吧，Microsoft AntiSpyware （Beta1）是为了保护那些MS用户的安全的，但一般来说国内稍有能力的都可以自行使用第三方软件来实现保护安全的目的，那么那些没有能力的要想用这个Microsoft自家的软件可是相当费力的。所以最好推出各地的Language版本。</p>
<p>    在这里提出几点特点：<br/>    1、几乎每一个小项目，都有Learn More Information about&#8230;。可以让人认识到这一项目修复的内容和安全相关知识（可惜是英文）<br/>    2、每个主项目的子项目的目录是图形式的，而不是树状式的，如图：</p>
<p><img src="http://student.mblogger.cn/images/student.mblogger.cn/shixinyu/7756/r_AntiSpyware%20ml.JPG" alt=""/></p>
<p>上图显示的是主项目<strong>Advanced Tools</strong>中的子项目<strong><font color="#ff0000">System Exlporers</font></strong>的子项目<font color="#ff00ff"><strong>Downloaded ActiceX</strong></font>（即<strong>Advanced Tools</strong>的次子项目）。在这里可以直接点击<font color="#ff0000"><strong>System Explorers</strong></font>回到System Exlorers项目中，非常快捷方便！</p>
<p>    <strong>Microsoft AntiSpyware （Beta1）</strong>简易使用手册到这里就搁笔了。<img src="http://www.donews.net/fckeditor/editor/images/smiley/msn/regular_smile.gif" border="0" alt=""/></p>
<p>                                                                        </p>
<p>                                                                                                               <strong>————By Stone.sxy</strong><br/></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.donews.com/shixinyu/archive/2005/01/07/229132.aspx/feed</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
	</channel>
</rss>

