Windows工具ProcessHacker, TCPView, Autoruns

来源:互联网 发布:ios9下载软件不动 编辑:程序博客网 时间:2024/05/20 12:50

ProcessHacker

参考:
https://github.com/processhacker2/processhacker2
A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware.

查看进程列表

这里写图片描述

在某进程内存中查找某字符串

这里写图片描述

TCPView

参考:
https://technet.microsoft.com/en-us/sysinternals/bb897437.aspx
TCPView provides a more informative and conveniently presented subset of the Netstat program that ships with Windows.
这里写图片描述

Autoruns

参考:
https://technet.microsoft.com/en-us/sysinternals/bb963902.aspx
This utility, which has the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system bootup or login, and when you start various built-in Windows applications like Internet Explorer, Explorer and media players.
这里写图片描述

HashMyFiles

参考:
http://www.nirsoft.net/utils/hash_my_files.html
查看文件Hash值的
这里写图片描述