Ungazithola kanjani izinqubo ezifihliwe ezingaveli Kusiphathi Somsebenzi

Isibuyekezo sokugcina: 28/11/2025

  • Izinqubo ezifihliwe kungaba uhlelo olungayilungele ikhompuyutha, amasevisi esistimu, noma izinsalela zesofthiwe ezisebenzisa izinsiza ngaphandle kokubonakala ngokucacile.
  • Isiphathi Somsebenzi, kanye nethebhu Yemininingwane kanye ne-Resource Monitor, ikuvumela ukuthi uthole izinqubo ezisolisayo nokuxhumana.
  • Amathuluzi athuthukile njenge-Autoruns kanye ne-Process Explorer (nge-VirusTotal) anikeza ukulawula okuphelele kuzinqubo, ukuqalisa, nezinsalela ze-phantom.
  • Ukuhlanganisa lawa mathuluzi nokuhlolwa kokubhalisa kanye ne-antivirus enhle kuyisihluthulelo sokugcina ukusebenza nokuphepha ku-Windows.

Ungazithola kanjani izinqubo ezifihliwe ezingaveli Kusiphathi Somsebenzi

I-PC isebenza kancane ngaphandle kwesizathu esibonakalayo.Uma ukusetshenziswa kwakho kwe-RAM kukhula ngisho nalapho ungenalutho oluvulekile, noma uma uhlangabezana nokunensa ngenkathi udlala, ngokuvamile kuwuphawu lokuqala lokuthi kukhona okungahambi kahle. Ngokuvamile, sivula Isiphathi Somsebenzi sifuna umenzi wecala... futhi akukho okungajwayelekile okuvelayo. Kulapho izinsolo ziqala khona: kungase kube nezinqubo ezifihliwe ezisebenza ngemuva.

IWindows ihlale isebenzisa inqwaba yezinsizakalo nezinqubo. Okugijima ngemuva kunezinhlelo ezahlukene, ezinye zisemthethweni kanti ezinye zingase zibe yingozi noma ezisele kusukela kusofthiwe ekhishwe ngokungafanele. Ukufunda ukuthola ukuthi yini esebenzayo ngempela, ngale kwalokho okuvezwa Umphathi Womsebenzi ojwayelekile, kuyisihluthulelo sokuthuthukisa ukusebenza, ukuqinisa ukuvikeleka, nokuzingela uhlelo olungayilungele ikhompuyutha oluzama ukucasha. Masifunde ngakho konke. Ungazithola kanjani izinqubo ezifihliwe ezingaveli ku-Task Manager.

Yiziphi izinqubo ezifihliwe futhi kungani zingaveli ngokucacile ngaso sonke isikhathi?

Lonke uhlelo olusebenza kukhompuyutha lukhiqiza okungenani inqubo eyodwa okuhlala enkumbulweni ukuze kusebenze: kusukela kusiphequluli noma umdlalo kuya kumasevisi wesistimu encane. Inkinga ukuthi eziningi zalezi zinqubo azinalo igama "lomuntu" njenge-Chrome.exe noma i-Spotify.exe, kodwa kunalokho izihlonzi ezifihlekile ezenza kube nzima ukwazi ukuthi eze-Windows, uhlelo olusemthethweni, noma uhlelo olungayilungele ikhompuyutha.

Ngaphezu kwalokho, kunezinqubo ongeke uzibone ekuqaleni. kuthebhu ethi "Izinqubo" Yesiphathi Somsebenzi ngenxa yokuthi aqoqiwe, aboniswa ngaphansi kwamagama ajwayelekile, noma ancike ezinsizeni zesistimu. Ezinye izinhlobo zohlelo olungayilungele ikhompuyutha zisizakala ngalokhu, zifake amakhodi ezinqubweni ezisemthethweni noma zicashe ngezinsizakalo ezingacacile, okuzenze kube nzima kakhulu kumsebenzisi ojwayelekile ukuzithola.

Ngisho nangemva kokukhipha izinhleloKungase kube "ama-ghost remnants": imisebenzi yokuqalisa, izinsizakalo, noma okufakiwe kokubhalisa okuqhubeka nokuzama ukusebenza ngemuva. Ngeke ulubone uhlelo olufakiwe, kodwa uzobona inqubo ejwayelekile ebizwa ngokuthi "Uhlelo" noma into efanayo, edla izinsiza ngaphandle kokunikeza noma iyiphi isevisi ewusizo.

Kuvamile futhi ukuthi izinqubo ezifihliwe zithinte inethiwekhi: ukuxhumeka okungaqondakali, ukusetshenziswa komkhawulokudonsa lapho ungafanele ube nakho ukulanda noma ukuxhumana ne-inthanethi, noma ama-spikes angachazwanga ku-CPU kanye nokusetshenziswa kwememori lapho ikhompuyutha, ngokombono, iphumulile.

Ukusebenzisa Isiphathi Somsebenzi ngokugcwele: lokho ongakubona ku-Windows

Izinqubo Zesiphathi Somsebenzi

Ngaphambi kokuthi siqhubekele kumathuluzi athuthukileKuyafaneleka ukusebenzisa ngokugcwele lokho okunikezwa Isiphathi Somsebenzi ngokwaso. Ku-Windows 10 ne-11, inamandla kakhulu kunalokho okubonakala uma wazi ukuthi ubheke kuphi futhi uguqule ezinye izilungiselelo ezizenzakalelayo.

Ukuyivula ngokusheshaSebenzisa isinqamuleli sekhibhodi Ctrl + Shift + EscUngaphinda uchofoze kwesokudla kubha yomsebenzi bese ukhetha "Isiphathi Somsebenzi". Uma ivuleka ngemodi eyenziwe lula, chofoza "Eminye imininingwane" ukuze ubone isixhumi esibonakalayo esigcwele nawo wonke amathebhu.

Kuthebhu "Izinqubo" uzobona ukubuka konke I-CPU, i-RAM, idiski, i-GPU, nokusetshenziswa kwenethiwekhi ngohlelo lokusebenza. Lapha ungakwazi ukubona kalula "abadlali abakhulu" (umdlalo, isiphequluli, umhleli wevidiyo...). Kodwa uma ufuna ukubamba izinqubo ezisolisayo, kufanele uqhubeke kancane.

Isinyathelo esibalulekile ukwenza "Bonisa izinqubo ezivela kubo bonke abasebenzisi" (ezinguqulweni ezindala ze-Windows) noma qinisekisa ukuthi Isiphathi Somsebenzi sibonisa yonke into esebenza ngaphansi kwama-akhawunti namasevisi ahlukene. Lokhu kuzokunikeza uhlu oluphelele, okuhlanganisa namasevisi esistimu ngezinye izikhathi angasetshenziswa uhlelo olungayilungele ikhompuyutha.

Ithebhu Yemininingwane, I-Resource Monitor kanye Nokuhlaziywa Kwenethiwekhi

Ithebhu "Imininingwane" Yesiphathi Somsebenzi Yilapho uhlu oluphelele lwezinqubo ezisebenzayo luvela khona ngempela. Ngayinye esebenzisekayo iboniswa lapha, ngaphandle kokuhlanganiswa, kusetshenziswa igama layo langaphakathi. Ukubuka okuseduze kakhulu kwalokho okubonwa isistimu yokusebenza ngokwayo.

Kule thebhu ungathola izinqubo ezibukeka zixakile. Bheka izinqubo ongazazi, ezinamagama ajwayelekile, noma ezisebenzisa izinsiza ngokungavamile. Uma uchofoza kwesokudla kunoma iyiphi inqubo, ungakwazi "Ukuvula indawo yefayela," okubalulekile ukwazi ukuthi lokho okusebenzisekayo kwavelaphi ngempela.

Okuqukethwe okukhethekile - Chofoza Lapha  Abiwa kanjani amaphasiwedi ne-1Password?

Enye ikholomu ewusizo kakhulu ikholomu “yendlela yesithombe”. (Kwezinye izinguqulo, lokhu kuvela njengokuthi "Indlela Yesithombe"). Ungayivula ngokuchofoza kwesokudla kumaheda ekholomu, ukhethe okuthi "Khetha Amakholomu," bese uhlola le nketho. Lokhu kuzokubonisa indlela egcwele yefayela ngemuva kwenqubo ngayinye.

Ukuze ujule ekuziphatheni kwenethiwekhiVula ithebhu "Ukusebenza" bese uchofoza "Vula Isiqaphi Sensiza." Kuthebhu "Inethiwekhi" ye-Resource Monitor, uzobona ukuthi iziphi izinqubo ezisungula ukuxhumana, ukuthi zingakanani ithrafikhi abayithumelayo nabayitholayo, nokuthi imaphi amakheli e-IP. Uma uthola uhlelo lokusebenza olungajwayelekile oluxhuma kumakheli angajwayelekile, kuyinkomba enamandla yokuthi kukhona okungalungile.

Buyekeza izinhlelo zokuqalisa kanye nesofthiwe esele ekhishiwe

Indlela Yokungcwelisa I-Task Manager kanye ne-Resource Monitor

Izinqubo eziningi ezifihliwe zingena ngenqubo yokuqalisa iWindows.ngakho ziqala ngokuzenzakalelayo njalo uma uvula ikhompuyutha yakho. Lokhu kuchaza ukuthi kungani, ngisho nangemva "kokuvala yonke into," ukusetshenziswa kwe-RAM kuhlala kuphezulu noma uhlelo luthatha isikhathi eside ukuthi lusebenziseke.

Kusiphathi Somsebenzi unengxenye ethi "Ukuqalisa". (Ku-Windows 11, ivela kumenyu eseceleni njengokuthi "Izinhlelo zokusebenza zokuqalisa," futhi ku-Windows 10 njengethebhu "Yokuqalisa"). Lapho uzobona zonke izinhlelo eziziqalisa ngokuzenzakalelayo lapho ungena.

Kuyinto evamile ukuthola izinsiza zekhadi lezithombe (NVIDIA, AMD), ikhadi lomsindo, noma igundane.Futhi nezinhlelo zokusebenza oncamela ukuzivula ngokuzenzakalelayo ngoba uzisebenzisa nsuku zonke. Kodwa uma ubona okungenayo ngaphandle kwamagama acacile, izinqubo ezijwayelekile njengokuthi "Uhlelo," noma izinkomba zezinhlelo ozikhiphe kudala, zifanele ukunakwa nguwe.

Ungakhubaza noma iyiphi into yokuqala ngokuchofoza kwesokudla. ukuthi awufuni. Lokhu akulususi uhlelo, kuvele kuluvimbe ukuthi luqale ngeWindows. Kuyindlela esheshayo yokuhlola ukuthi ngabe leyo nqubo engaqondakali yayiyimbangela yokushiyeka noma ukusetshenziswa ngokweqile kwe-RAM.

Uma uhlelo lukhishwe ngokungalungileKuvamile ukuthi iWindows ishiye imikhondo ezinhlelweni zokuqalisa, imisebenzi ehleliwe, noma izinsiza elokhu izama ukuziqalisa nakuba okusebenzisekayo kungasekho. Lezi zibizwa ngokuthi "izinqubo zesipoki" noma "izinqubo ezisele." Ukuze uzikhombe kahle, udinga ithuluzi elikhethekile.

I-Autoruns yeWindows: Thola futhi ususe izinqubo ze-phantom nezinto ezisele

I-Microsoft inikeza ithuluzi elinamandla kakhulu elibizwa ngokuthi i-Autoruns ye-Windows mahhala.Ingxenye yeqoqo le-Sysinternals elidalwe ngu-Mark Russinovich, lolu hlelo lokusebenza lubonisa ngokuphelele YONKE INTO esebenza ekuqaleni kwesistimu noma ixhumeke kumaphoyinti abalulekile ku-Windows.

Kusuka kuwebhusayithi esemthethweni ye-Microsoft Sysinternals Ungalanda i-Autoruns ngefomethi ye-ZIP. Uma isikhishiwe, vele uvule okuthi “Autoruns.exe” noma “Autoruns64.exe” kuye ngohlelo lwakho. Akudingi ukufakwa; kuyinto ephathekayo ephathekayo.

Uma ivuliwe, i-Autoruns ibonisa uhlu olukhulu lokufakiweIzinhlelo zokuqalisa, amasevisi, Izandiso Zokuhlola, Izinto zasehhovisi, abashayeli, imisebenzi ehleliwe, njll. Phezulu ungahlunga ngezigaba (Ihhovisi, amasevisi, abahlinzeki benethiwekhi, i-LSA, izinsiza zokuphrinta…).

Ukunakwa okukhethekile kufanele kukhokhwe eminyango ebhalwe ngokuphuzi.Lokhu kuvame ukuhambisana nezinqubo noma izindlela ezingasatholakali ohlelweni: izinsalela zesofthiwe ekhishwe ngokushesha, izinqubo ezizenzakalelayo ezihlala zizama ukusebenza, noma izindlela ezonakele. Uzobona nama-elementi kweminye imibala abonisa izingxenye ezibalulekile noma ezikhethekile.

Uma uthola indawo yokungena eyinsalela ecacile noma esolisayo (Isibonelo, uma kuwuhlelo owaziyo ukuthi usuvele ulususile noma ingxenye engaziwa), ungachofoza kwesokudla kulo. Imenyu yokuqukethwe inikeza izinketho njengokuthi "Susa" ukuze uyisuse, uvule indawo yefayela, uskene amagciwane, noma useshe ku-inthanethi ngolwazi mayelana nokusebenzisekayo.

Ama-Autoruns anamandla kakhulu, kodwa futhi ayingozi uma ungazi ukuthi wenzani.Umbhali ngokwakhe uncoma ukuthi lokhu kusingathwe uchwepheshe noma, okungenani, umsebenzisi onolwazi oluthile. Ukususa okufakiwe kwesistimu ebalulekile, abashayeli be-GPU, noma izingxenye zehadiwe kungakushiya ungenayo imisebenzi ethile noma kubangele iWindows yehluleke ukuqalisa ngendlela efanele.

Inzuzo ukuthi, ngokunakekelwa okuthile, ungakwazi ukuhlanza uhlelo Isusa izinsalela zezinhlelo zokusebenza ongasenazo, isuse izinqubo zokuqalisa ze-phantom, futhi ithola ama-automation asolisayo angacacile kangako Kumphathi Womsebenzi ovamile.

I-Process Explorer: I-Microsoft "Supercharged Task Manager"

Uma Isiphathi Somsebenzi sihluleka kuweEnye indlela eqondile nesemthethweni ye-Microsoft yi-Process Explorer, elinye igugu elivela ku-Sysinternals suite. Idizayinelwe abalawuli besistimu nabasebenzisi abathuthukile abadinga ukulawula okuphelele kanye nemininingwane emihle kakhulu mayelana nenqubo ngayinye.

Okuqukethwe okukhethekile - Chofoza Lapha  Ungawakha kanjani futhi uwaphathe kanjani amaphasiwedi aqinile?

I-Process Explorer ingalandwa kuwebhusayithi ye-Sysinternals. Iza ngefayela elicindezelwe. Yivule kunoma iyiphi ifolda bese usebenzisa okuthi “procexp64.exe” uma isistimu yakho iyi-64-bit (noma inguqulo ye-32-bit uma ikhona). Ayidingi ukufakwa, futhi kuyanconywa ukuthi uyiqalise njengomlawuli ukuze ubone yonke imininingwane.

Isixhumi esibonakalayo sibonisa isihlahla senqubo ye-hierarchicallapho ungabona khona ngokucacile ukuthi yiluphi uhlelo olwethule ukuthi yiluphi, luvulekele luphi, lusebenzisa yiphi i-DLL, nokunye okuningi. Inqubo ngayinye ifakwa umbala ngokohlobo lwayo, futhi le mibala iyalungiseka kusukela kumenyu ethi Izinketho > Lungiselela Imibala.

Enye yezinzuzo ezinhle ze-Process Explorer Ikuvumela ukuthi uvule indawo esebenzisekayo, ubuke izici zayo zokuphepha, izintambo zombhalo wangaphakathi, izincazelo zokufinyelela, futhi uhlanganyele nayo kusukela kumugqa womyalo noma ukhiqize ukulahlwa kwememori ukuze kuhlaziywe okuthuthukile.

Uma kwenzeka ufuna ukufaka esikhundleni ngokuphelele Isiphathi SomsebenziKumenyu yezinketho, ungakhetha okuthi "Buyisela Isiphathi Somsebenzi". Ngemva kwalokho, uma usebenzisa isinqamuleli esithi Ctrl + Shift + Esc, i-Process Explorer izovuleka esikhundleni se-Windows Task Manager evamile.

Ukuhlanganiswa kwe-Process Explorer ne-VirusTotal ukuthola uhlelo olungayilungele ikhompuyutha

I-Process Explorer ayikona nje ukubona ukuthi yini esebenzayo.Kuyasiza futhi ukunquma ukuthi ithembekile yini. Esinye sezici zayo ezinhle kakhulu, ezihlanganiswe eminyakeni edlule, ukuhlanganiswa kwayo ne-VirusTotal, isevisi eyaziwa kakhulu ehlaziya amafayela anenqwaba yezinjini zokuvikela amagciwane kanyekanye.

Ukuze wenze lokhu kuhlanganiswa kusebenzeVula i-Process Explorer bese uya kumenyu yezinketho > VirusTotal. Nika amandla inketho yokuthumela ama-hashe enqubo ku-VirusTotal ukuze ihlaziywe (enguqulweni yamanje, lokhu kwenziwa ngokuvikelekile ngokuthumela kuphela izigxivizo zeminwe zefayela).

Ukwenza kanjalo kuzongeza ikholomu entsha efasiteleni eliyinhloko. ngomphumela wokuhlaziywa kwenqubo ngayinye. Uzobona okuthi "0/70", "1/70", njll., okubonisa ukuthi zingaki izinjini zokuvikela amagciwane zimaka njengokusolisayo kukho konke.

Izinqubo ezivela kokuluhlaza noma ezinokutholwa okungu-0 Ngokuvamile zibhekwa zihlanzekile, nakuba imibono engemihle engenzeka njalo. Uma inqubo ivela ngokubomvu noma nokutholwa okuningi, kungenzeka ukuthi uhlelo olungayilungele ikhompuyutha noma, okungenani, okuthile okufanele ukuphenywe.

Uma uchofoza umphumela we-VirusTotalIkhasi lokuhlaziya lizobe selivulwa ngolwazi olunwetshiwe: yiziphi izinjini eziyitholile, imuphi umndeni ongayilungele ikhompuyutha, ukuqaphela ukuziphatha, njll. Lolu lwazi lubalulekile ekunqumeni ukuthi uyayiqeda yini inqubo bese wenza ukuhlanza okujulile ngesofthiwe yakho yokuvikela amagciwane.

Isetshenziswa kanjani i-Process Explorer ukuthola indlela yohlelo olungayilungele ikhompuyutha

Ezindaweni zaselabhorethri noma emishinini ebonakalayoKuvamile ukuthi abafundi nabahlaziyi bezokuphepha basebenzise i-Process Explorer ukuze bathole uhlelo olungayilungele ikhompuyutha futhi bafunde ukuziphatha kwayo. Umsebenzi ojwayelekile ukuthola indlela okuyiyonayona yesenzo esinonya ukuze sikulayishe kusiqaqe.

Ngokuvamile, kwanele ukuthola inqubo esolisayo. Ohlwini, chofoza kwesokudla bese usebenzisa "Izakhiwo" noma "Vula indawo yefayela" ukuze uthole ukuthi iyiphi ifolda lapho kanambambili ikuyo. Ukusuka lapho, ungakwazi ukuyikopisha uye kwenye indawo elawulwayo ukuze uyihlaziye ngamathuluzi afana ne-IDA, i-Ghidra, noma ezinye iziqaqa.

Inkinga iba lapho i-malware engenafayela izama ukufihla umzila wayoLokhu kungenzeka ngenxa yokuthi ixhaphaza isistimu noma ifaka ikhodi yayo ezinqubweni ezisemthethweni. Kulezi zimo, i-Process Explorer ingase ikubonise inqubo kodwa ingawuhlonzi ngokucacile umthombo osebenzisekayo, noma ingase ibonise ulwazi olungaphelele.

Uma lokhu kwenzeka, kuhle ukuhlanganisa amathuluzi amaningana.: buyekeza ukubhaliswa (okhiye be-HKCU ne-HKLM Run and RunOnce), hlola imisebenzi ehleliwe, sebenzisa i-Autoruns ukuze ubone ukuthi yini eyethulwe ekuqaleni futhi, uma kudingekile, usebenzise amathuluzi athile okuhlaziya uhlelo olungayilungele ikhompuyutha noma imishini ebonakalayo enokuqapha kwesistimu okuthuthukisiwe.

Kunoma yikuphi, uma uthola inqubo enokuziphatha okusolisayo Uma i-VirusTotal ihlaba umkhosi ifayela njengenonya, isinyathelo sokuqala ukuhlukanisa umshini othintekile kunethiwekhi, unqamule inqubo uma kungenzeka, bese uskena noma ukhiphe isampula ngesixazululo esikhethekile sokuvikela. Ukuze uthole ulwazi olwengeziwe mayelana ne-Process Explorer, bona okulandelayo: iwebhusayithi esemthethweni yeWindows.

Veza amafayela afihliwe namafolda: isibonelo somhlaba wangempela sisebenzisa uhlelo olungayilungele ikhompuyutha oluthi “Streamerdata”

Olunye uhlelo olungayilungele ikhompuyutha alufihli nje njengezinquboAbagcini ngokufihla amafolda namafayela abo ukwenza ukususwa kube nzima kakhulu, kodwa futhi bayawafihla. Isibonelo esijwayelekile izifo ezidala izinkomba ezifihliwe kumkhombandlela wediski, njengokuthi "C:\Streamerdata", futhi ziphindaphinde izinqamuleli ezingenalutho kulo lonke uhlelo.

Okuqukethwe okukhethekile - Chofoza Lapha  Ungayikhubaza kanjani i-Avast

Kulolu hlobo lwesimo, i-antivirus ithola usongo ngokuqhubekayo (ngokwesibonelo, i-Win64:Malware-gen), iyithumela kungobo yomlando futhi iyisuse… kodwa izovela futhi maduze. Khonamanjalo, uyaqaphela ukuthi uhlelo luvilapha, ukuthi kukhona amafolda nezinqamuleli ezingajwayelekile, nokuthi inqubo enegama lomgunyathi “lethuluzi lokuvikela amagciwane” ivela ku-Task Manager.

Isu elisetshenziswe abanye abasebenzisi Kuhilela ukudala ifayela elithi .bat elinemiyalo esusa okufihliwe, isistimu, nezibaluli zokufunda kuphela kuwo wonke amafayela kudrayivu. Okuthile okufana ne:

attrib -r -a -h -s U:\*.* /S /D (lapho u-U eyidrayivu yokubulala amagciwane). Lokhu, uma kusetshenziswa njengomlawuli, kuphoqelela yonke into ukuba ibonakale, kuhlanganise nefolda eyingozi eyayifihlwe ngokuphelele ngaphambili, evumela ukuthi isuswe ngesandla.

Umphumela wokusebenzisa ngokweqile lezi zinhlobo zemibhalo Lokhu futhi kuveza inqwaba yamafolda esistimu namafayela avame ukufihlwa ngenxa yezizathu zokuphepha: amafolda okumisa, amafayela e-desktop.ini, njll. Uma unganakile futhi ususa okungafanele ukwenze, ungenza uhlelo lwakho lungazinzi.

Esibonelweni esithi "Streamerdata", ngokwembula yonke into Amafayela “edeskithophu” (desktop.ini) aqala ukuvela kumadeskithophu nakumafolda ahlukahlukene, futhi uhlelo ngokwalo lwabonisa amaphutha ekuqaleni ngenkathi luzama ukuthola ifolda ye-malware, ebisivele isusiwe. Lesi isibonelo esicacile sokuthi ukuhlanza mathupha ngaphandle kokuqonda kahle okwenzayo kungaba nemiphumela engahlosiwe.

Uma uzithola usesimweni esifanayoIndlela enconyiwe ukuhlanganisa i-antivirus enhle noma i-antimalware suite (I-Malwarebytes, i-Windows Defender ebuyekezwe kahle, njll.), ithuluzi lokuhlanza ukuqalisa njenge-Autoruns, futhi, uma uguqule izibaluli kakhulu, lungisa kabusha izinketho zefolda noma usebenzise amathuluzi afana Winaero Tweaker ukufihla amafayela wesistimu abalulekile futhi okungafanele abonwe noma athintwe nsuku zonke.

Ukulawula irekhodi namanye amasu ahambisanayo

Izinqubo ezifihliwe kanye nohlelo olungayilungele ikhompuyutha eziphikelelayo Bavame ukuthembela kurejista yeWindows ukuze iqale ngokuphindaphindiwe. Ukwazi okhiye bokubhalisa abajwayeleke kakhulu kusiza kakhulu ekubatholeni lapho amanye amathuluzi engaphelele.

Sebenzisa umyalo Win + R bese uthayipha "regedit"Bese ufinyelela ku-Registry Editor (sebenzisa leli thuluzi ngokuqapha okukhulu). Izindlela ezivame kakhulu lapho kubhaliswa khona izinhlelo eziqala ngohlelo yilezi:

HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run y HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Runlapho kugcinwa khona izinhlelo zokusebenza eziqalisayo lapho umsebenzisi wamanje nanoma yimuphi umsebenzisi engena, ngokulandelana. Kuyaphawuleka futhi RunOnce, eyenza okufakiwe kanye kuphela ekuqaliseni okulandelayo.

Ukubuyekeza laba khiye kungase kwembule okufakiwe okungaziwa enezindlela ezingavamile noma ezikhomba kumafolda esikhashana, izinkomba zephrofayela yomsebenzisi ezingajwayelekile, noma amagama amafayela angahleliwe. Kulezi zimo, kunengqondo ukusola futhi, ngemva kokwenza ikhophi yasenqolobaneni, susa okufakile noma ukukukhubaze ngenkathi uskena ngesofthiwe yokuvikela amagciwane.

Enye indlela ephumelela kakhulu ukusebenzisa umugqa womyaloUkuqalisa "uhlu lomsebenzi" efasiteleni lomyalo olunamalungelo omlawuli kuzobonisa uhlu oluphelele lwezinqubo. Ungakwazi ukuhlanganisa lokhu nezihlungi (ngegama, i-PID, njll.) noma ngamanye amathuluzi afana ne-"wmic" noma i-"powershell" ukuze uthole imininingwane eyengeziwe.

Okokugcina, akumelwe sikhohlwe indima yesofthiwe ye-antivirusUkuyigcina ibuyekeziwe nokusebenzisa izikena zesistimu egcwele kusiza ukuthola izinqubo ezifihliwe ezicashwe njengamasevisi asemthethweni. Imikhiqizo eminingi yamanje iphinde ihlole ukuziphatha ngesikhathi sangempela, ivimbe izinqubo eziziphatha njengohlelo olungayilungele ikhompuyutha ngisho noma ifayela ngokwalo lingakasayinwa kuzigcinalwazi.

Yiba nokulawula kwangempela kokuthi yini esebenza ku-PC yakho Kubandakanya ukuhlanganisa konke okungenhla: ukusebenzisa Isiphathi Somsebenzi ngempumelelo, ukusebenzisa i-Autoruns kanye ne-Process Explorer, ukuqapha ukubhalisa, nokuncika kuzixazululo eziqinile zokulwa namagciwane. Ngalawa mathuluzi, ukuthola izinqubo ezifihliwe ezingabonakali ngokushesha nokunquma ukuthi wenzeni ngazo kuyeka ukuba yimpicabadala futhi kuba umsebenzi okuthi, ngokuzijwayeza okuncane, ukwazi kahle ngaphandle kokudinga ukuba yi-hacker echwepheshile.

Vikela i-Windows PC yakho ekuhloleni okuthuthukile
I-athikili ehlobene:
Uyivikela kanjani i-Windows PC yakho ekuhloleni okuthuthukile njenge-APT35 nezinye izinsongo