½â¾öÈñÆðCGO/³¬Ò×/5AVIP ³öÅÌ¿ª»úÂýµÄÎÊÌâ
¸Äwinlogonͬ²½´¦ÀíÈñÆð³öÅÌÇëÇóΪÒì²½,winlogon²»µÈ´ýÈñÆð³öÅÌÍê±Ï¾Í½øÈë×ÀÃæ,»Ö¸´Í£ÁôÔÚ¡°¼ÆËã»úÕýÔÚ¼ÓÔØ¸öÈËÉèÖá±µÄʱ¼äΪÕý³£Ê±¼ä
×¢²á±íÎļþ
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RTGSGENG] ;±íÃ÷ÊÇ·ñÒì²½´¦Àíwinlogonʼþ£¬Ä¬ÈÏΪ0,ͬ²½´¦Àí,ÈçÉèΪ1,ÔòΪÒì²½,winlogon½«Æô¶¯Ò»¸öÐÂÏß³ÌÀ´´¦ÀíCGO³öÅÌÇëÇó "Asynchronous"=dword:00000001 ;±íÃ÷ÊÇ·ñÒԵǽÓû§µÄȨÏÞÀ´´¦Àíʼþ,ĬÈÏΪ0,²»ÐÞ¸Ä "Impersonate"=dword:00000000
ÒÔÉϸ´ÖÆ´æ³Éºó׺.regµÄÎı¾Îļþ
¹ØÓÚΪʲôÈñÆðÂÌÉ«¿Í»§¶ËÔÚÊÖ¶¯³öÅ̺ó»áÏÔʾÒѶϿªµ«ÊÇ¿ÉÒÔÕý³£Ê¹ÓõÄÎÊÌ⣬ÊÇÒòΪÓÃrundll¼ÓÔØÁËRTGSGENG.dllºó£¬³É¹¦Á¬½ÓÉÏÁËÐéÄâÅ̺ó£¬RTGSGENG.dll¾ÍÍ˳öÄÚ´æÁË£¬ËùÒÔ½â¾ö·½·¨Ó¦¸ÃÊÇÓñà³ÌÊÖ¶ÎÀ´¹¹³ÉÑ»·Ê¹ÆäÓÀ¾ÃפÁôÄÚ´æÖУ¬ÒòΪÔʼ¿Í»§¶ËµÄDLLÊÇͨ¹ýwinlogonפÁôÄÚ´æµÄ |