Professional Documents
Culture Documents
Smallfrogs
[smallfrogs@gmail.com, http://www.KZTechs.com]
1.012005/4/19
1. Service
2.
3.
4.
Service
Smallfrogs ( http://www.KZTechs.com )
Service NT
services.msc service
Windows MMC1 snap-in services.msc
Service Service
Service
Service 2 service applicationdriver
service
Service Control Manager2
Service Service
- 3-
Service
Smallfrogs ( http://www.KZTechs.com )
Service
2.1
ControlSetNNN CurrentControlSet
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSetNNNNNN 001002
Windows
HKEY_LOCAL_MACHINE\SYSTEM\ControlSetNNN Windows
001 002
HKEY_LOCAL_MACHINE\SYSTEM\ControlSetNNN
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet
HKEY_LOCAL_MACHINE\SYSTEM\ControlSetNNN
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet
HKEY_LOCAL_MACHINE\SYSTEM\ControlSetNNN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSetNNN
/ HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet /
HKEY_LOCAL_MACHINE\SYSTEM\ControlSetNNN
ControlSetNNN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSetNNN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002
HKEY_LOCAL_MACHINE\SYSTEM\ControlSetNNN
Hive NNN NNN
HKEY_LOCAL_MACHINE\SYSTEM\Select\Current 1
001 2 002 HKEY_LOCAL_MACHINE\SYSTEM\Select\ Failed
Windows NNN 1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
HKEY_LOCAL_MACHINE\SYSTEM\Select LastKnownGood
NNN F8 Windows
- 4-
Service
Smallfrogs ( http://www.KZTechs.com )
LastKnownGood
HKEY_LOCAL_MACHINE\SYSTEM\ControlSetNNN LastKnownGood
2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
ErrorControl
REG_DWORD
/
Windows
ImagePath
REG_SZ
2 Windows
%systemroot%\system32\drivers
- 5-
Service
Smallfrogs ( http://www.KZTechs.com )
Path
DisplayName
REG_SZ
Description
REG_SZ
Start
REG_DWORD
Type
REG_DWORD
Windows /
/
5
0
Boot Start
Ntldr OSLoader
System Start
1
System Start
2
Auto Start
SCM services.exe
MMC Snap-in
3
Demand Start
SCM
MMC Snap-in
Windows
4
Disabled
MMC
Snap-in
1 2
- 6-
Service
Smallfrogs ( http://www.KZTechs.com )
ObjectName
REG_SZ
LocalSystem
2.2
Windows XP/Server 2003
Local SystemNetwork Service Local Service
Administrator Local System
Network Service Local Service
Local System
Network Service
Local Service
SYSTEM
NETWORK SERVICE
LOCAL SERVICE
z Local System
Administrators Administrators
NTFS
Local
System
Local System null session
Windows
system32\Smss.exe
- 7-
Service
Smallfrogs ( http://www.KZTechs.com )
HKEY_USERS\.Default
Network Service
Local System
HKEY_USERS\S-1-5-20
Documents
and
Settings\NetworkService
Local Service Network Service
Local Service
Local Service HKU\S-1-5-19 Documents and
Settings\LocalService
2.3
svchost.exe
2 DLL
DLL
Svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\SvcHost REG_MULTI_SZ
Svchost.exe
REG_MULTI_SZ svchost.exe netsvcs
svchost.exe netsvcs
netsvcs svchost.exe
svchost.exe netsvcs
svchost.exe
Windows
svchost.exe
svchost.exe Windows Server 2003 RpcSs
- 8-
Service
Smallfrogs ( http://www.KZTechs.com )
svchost.exe svchost.exe
svchost.exe 2
A A BB
B B B
svchost.exe A svchost.exe
svchost.exe
svchost.exe
svchost.exe tasklist /svc
(Windows XP/Server2003)
- 9-
Service
Smallfrogs ( http://www.KZTechs.com )
Troubleshooting Service
3.1 Troubleshooting
Troubleshooting
SC.EXE
SC.EXE
- 10-
Service
Smallfrogs ( http://www.KZTechs.com )
sc.exe sc create
sc create /?
sc.exe /
/ sc.exe /
sc.exe
//
SC.EXE /
Service
Smallfrogs ( http://www.KZTechs.com )
troubleshooting troubleshooting
set devmgr_show_nonpresent_devices=1
devmgmt.msc
PnP PnP
PnP
PnP
Outpost
- 12-
Service
Smallfrogs ( http://www.KZTechs.com )
3.2 /
Telnet Telnet
BUG
BUG
BUG
BUG PnP
- 13-
Service
Smallfrogs ( http://www.KZTechs.com )
Service
Service
Service
IO IO
Service /
2 Windows 2
%systemroot%\system32
MsConfig.EXE Services/Drivers Configure Tool /
regedit.exe
Windows
Load Hive
- 14-
Service
Smallfrogs ( http://www.KZTechs.com )
Service 10
Service Service
Email smallfrogs@gmail.com
Smallfrogs
2005/4/19
- 15-
Service
Smallfrogs ( http://www.KZTechs.com )
- 16-