Summary of the invention
In view of the above problems, the present invention is proposed to provide a kind of overcoming method that the problems referred to above or a kind of No starting item that solves the problem at least in part start and the device that corresponding a kind of No starting item starts.
According to one aspect of the present invention, provide a kind of method that No starting item starts, comprising:
Target start item in determination operation system, described target start item forbids the application of self-starting for the need of specifying;
Obtain the startup project relevant to described target start item;
The startup project relevant to described target start item is write in configuration file;
When os starting, read described configuration file;
Forbid that corresponding target start item starts according to the described startup project in described configuration file.
Alternatively, described target start item is included in and first carries out No starting operation, and the startup item of No starting failure.
Alternatively, the step of the target start item in described determination operation system comprises:
The startup item of scan operation system;
Generate the operation prompt information of described startup item;
When receiving the No starting instruction for described operation prompt information, determine that the startup item of described No starting instruction correspondence is target start item.
Alternatively, the step of the target start item in described determination operation system comprises:
The startup item of scan operation system;
Detect and whether formerly No starting operation is carried out to described startup item, and No starting failure; If so, then judge that described startup item is target start item.
Alternatively, describedly forbid that the step that corresponding target start item starts comprises according to the described startup project in described configuration file:
In the kernel mode of operating system, tackle described startup item object call, to forbid that corresponding target start item starts.
Alternatively, describedly in the kernel mode of operating system, tackle described startup item object call, to forbid that the step that corresponding target start item starts comprises:
In the kernel mode of operating system, link up with the application programming interface of specifying, call to tackle described startup item object.
According to a further aspect in the invention, provide the device that a kind of No starting item starts, comprising:
Determination module, is suitable for the target start item in determination operation system, and described target start item forbids the application of self-starting for the need of specifying;
Acquisition module, is suitable for obtaining the startup project relevant to described target start item;
Writing module, is suitable for the startup project relevant to described target start item to write in configuration file;
Read module, is suitable for, when os starting, reading described configuration file;
Disabled module, is suitable for forbidding that corresponding target start item starts according to the described startup project in described configuration file.
Alternatively, described target start item is included in and first carries out No starting operation, and the startup item of No starting failure.
Alternatively, described determination module also starts from:
The startup item of scan operation system;
Generate the operation prompt information of described startup item;
When receiving the No starting instruction for described operation prompt information, determine that the startup item of described No starting instruction correspondence is target start item.
Alternatively, described determination module also starts from:
The startup item of scan operation system;
Detect and whether formerly No starting operation is carried out to described startup item, and No starting failure; If so, then judge that described startup item is target start item.
Alternatively, described disabled module is also suitable for:
In the kernel mode of operating system, tackle described startup item object call, to forbid that corresponding target start item starts.
Alternatively, described disabled module is also suitable for:
In the kernel mode of operating system, link up with the application programming interface of specifying, call to tackle described startup item object.
Target start item in embodiment of the present invention determination operation system, by in startup project write configuration file relevant for startup item, when os starting, read the startup project in configuration file, to forbid that corresponding target start item starts, by formerly startup project relevant for target start item being write in configuration file, forbid when subsequent operation system starts, what solve that some application program carries out that the situations such as registration table write-back cause forbids invalid problem, achieve forbidding obstinate startup item, improve the efficiency of No starting.
The embodiment of the present invention is when os starting, the startup of interception, No starting item in kernel mode, the No starting when startup item does not also start completely on the one hand, decrease the system resource starting this startup item and consume, on the other hand, decrease the probability that startup item gets around quiescing, further increase the efficiency of No starting.
Above-mentioned explanation is only the general introduction of technical solution of the present invention, in order to technological means of the present invention can be better understood, and can be implemented according to the content of instructions, and can become apparent, below especially exemplified by the specific embodiment of the present invention to allow above and other objects of the present invention, feature and advantage.
Embodiment
Below with reference to accompanying drawings exemplary embodiment of the present disclosure is described in more detail.Although show exemplary embodiment of the present disclosure in accompanying drawing, however should be appreciated that can realize the disclosure in a variety of manners and not should limit by the embodiment set forth here.On the contrary, provide these embodiments to be in order to more thoroughly the disclosure can be understood, and complete for the scope of the present disclosure can be conveyed to those skilled in the art.
With reference to Fig. 1, show the flow chart of steps of the embodiment of the method that a kind of according to an embodiment of the invention No starting item starts, specifically can comprise the steps:
Step 101, the target start item in determination operation system;
It should be noted that, target start item can forbid the application of self-starting for the need of specifying, and its essence can be the startup item in operating system, such as, and application program etc.
In specific implementation, described target start item can be included in and first carry out No starting operation, and the startup item of No starting failure.
Under this kind of situation, startup item is formerly by being prohibited to start, but operationally (before shutdown) can carry out registration table write-back, service write-back, still can self-starting when subsequent operation system starts, cause No starting failure, these startup items are also referred to as obstinate startup item.
In a kind of embodiment of the present invention, step 101 can comprise following sub-step:
Sub-step S11, the startup item of scan operation system;
In actual applications, can by reading the startup item of the mode scan operation systems such as registration table (as Run key, RunOnce key, RunServicesOnce key etc.).
Sub-step S12, generates the operation prompt information of described startup item;
In embodiments of the present invention, the operation prompt information of startup item can be generated, as " whether XX forbids ", show in user interface (User Interface, UI), select to allow user.
Sub-step S13, when receiving the No starting instruction for described operation prompt information, determines that the startup item of described No starting instruction correspondence is target start item.
In embodiments of the present invention, one can be configured for triggering the control of No starting instruction for each operation prompt information, if user triggers this control by modes such as mouse click, touch-control clicks, be equivalent to trigger No starting instruction, can judge that the startup item of this No starting instruction correspondence is target start item.
In a kind of embodiment of the present invention, step 101 can comprise following sub-step:
Sub-step S21, the startup item of scan operation system;
In actual applications, can by reading the startup item of the mode scan operation systems such as registration table (as Run key, RunOnce key, RunServicesOnce key etc.).
Sub-step S22, detects whether formerly carry out No starting operation to described startup item, and No starting failure; If so, then sub-step S23 is performed;
Sub-step S23, judges that described startup item is target start item.
In the embodiment of the present invention, can automatically recommend target start item.
Specifically, when No starting item starts, this startup item can be recorded, when rear No starting item starts, by Current Scan to startup item compare with the startup item formerly to record, if Current Scan to startup item identical with the startup item formerly recorded, and formerly permission start-up operation is not carried out to this startup item, then this startup item can be set to target start item.
Step 102, obtains the startup project relevant to described target start item;
In specific implementation, the project relevant to startup item has startup project can comprise registry information (as run item), serves, plan target etc.
Step 103, will write in configuration file to the relevant startup project of described target start item;
In embodiments of the present invention, can startup project be write in configuration file, to forbid target start item.
It should be noted that, those skilled in the art can arrange configuration file according to actual needs, and in configuration file except startup project, can also write other information, the embodiment of the present invention is not limited this.
Step 104, when os starting, reads described configuration file;
The embodiment of the present invention, when os starting, reads the startup project in configuration file, with the target start item of No starting.
According to the startup project in described configuration file, step 105, forbids that corresponding target start item starts.
The embodiment of the present invention is when os starting, and startup item corresponding to No starting project starts.
Target start item in embodiment of the present invention determination operation system, by in startup project write configuration file relevant for startup item, when os starting, read the startup project in configuration file, to forbid that corresponding target start item starts, by formerly startup project relevant for target start item being write in configuration file, forbid when subsequent operation system starts, what solve that some application program carries out that the situations such as registration table write-back cause forbids invalid problem, achieve forbidding obstinate startup item, improve the efficiency of No starting.
In a kind of embodiment of the present invention, step 104 can comprise following sub-step:
Sub-step S31, tackles described startup item object and calls in the kernel mode of operating system, to forbid that corresponding target start item starts;
In actual applications, cpu instruction is divided into 4 level of privilege from Ring0 to Ring3, in Windows operating system, can use these two ranks of Ring0 and Ring3 wherein, Ring3 and user model, Ring0 and kernel mode.
Under general application program all operates in Ring3, can only the API (Application Program Interface, application programming interface) that provides of calling system, operating system is operated in Ring0 layer, can access the data of all layers.
In the embodiment of the present invention, the authority of kernel mode can be obtained, during os starting, startup item can be tackled in kernel normal form within it.
In a kind of alternate exemplary of the embodiment of the present invention, sub-step S31 can comprise following sub-step:
Sub-step S311, links up with the application programming interface of specifying in the kernel mode of operating system, calls to tackle described startup item object.
In fact, if the power function that the function that application program will realize himself will be provided by interface interchange operating system, generally by DLL (Dynamic Link Library in Windows operating system, dynamic link library) inner API provides, therefore an application program has what kind of behavior (operation), just general clear by checking which type of API it have invoked.
Therefore, as a kind of preferred exemplary of the embodiment of the present invention, by linking up with the API of (HOOK) operating system in System kernel mode (Ring0), the creation operation of a process can be detected.
Startup item, when creating, can create corresponding process usually, and process creation is a quite complicated thing, and it comprises considerable work, in order to start a process, can use the following step:
1, executable file is opened by with FILE_EXECUTE access mode.
2, executable image is loaded into RAM.
3, process of setting up performs object (EPROCESS, KPROCESS and PEB structure).
4, be newly-built course allocation address space.
5, the thread execution object (ETHREAD, KTHREAD and TEBstructures) of the main thread of process is set up.
6, journey of serving as theme distributes storehouse.
7, the execution context of the main thread of process is set up.
8, the establishment situation of Win32 subsystem about this new process is notified.
For guaranteeing the success of any step in these steps, all steps before it must be successful execution (as one can not be set up when neither one can perform district's handle can executive process object; When file handle, you cannot map one and can perform district, etc.).
Therefore, if exit these steps any, all steps below also can be failed, to such an extent as to whole process creation can failure.
Steps all above can be realized by the mode calling some API, and this is understandable.Therefore, in order to monitoring process creates, these api functions can be hooked.
Such as, in order to the establishment of monitoring process, NtCreateFile () and NtOpenFile () can being linked up with, or hook NtCreateSection (), generally cannot run any executable file without calling these API.
Furthermore, SSDT shows (System Services Descriptor Table, system service descriptor table) API of Win32 API and Ring0 of Ring3 can be connected, can based on the characteristic of SSDT table, design hook interception process creation is correlated with the interception of API Calls, implementation process.
If the startup project intercepted is mated with the startup project in configuration file, can think that this startup project is the startup project of target start item, can forbid that this startup item object is called, to forbid the startup of target start item.
If the startup project intercepted is mated with the startup project in configuration file, can think that this startup project is not the startup project of target start item, this startup item object can be allowed to call, with the startup of target start item of letting pass.
The embodiment of the present invention is when os starting, the startup of interception, No starting item in kernel mode, the No starting when startup item does not also start completely on the one hand, decrease the system resource starting this startup item and consume, on the other hand, decrease the probability that startup item gets around quiescing, further increase the efficiency of No starting.
For embodiment of the method, in order to simple description, therefore it is all expressed as a series of combination of actions, but those skilled in the art should know, the embodiment of the present invention is not by the restriction of described sequence of movement, because according to the embodiment of the present invention, some step can adopt other orders or carry out simultaneously.Secondly, those skilled in the art also should know, the embodiment described in instructions all belongs to preferred embodiment, and involved action might not be that the embodiment of the present invention is necessary.
With reference to Fig. 2, show the structured flowchart of the device embodiment that a kind of according to an embodiment of the invention No starting item starts, specifically can comprise as lower module:
Determination module 201, is suitable for the target start item in determination operation system, and described target start item forbids the application of self-starting for the need of specifying;
Acquisition module 202, is suitable for obtaining the startup project relevant to described target start item;
Writing module 203, is suitable for the startup project relevant to described target start item to write in configuration file;
Read module 204, is suitable for, when os starting, reading described configuration file;
Disabled module 205, is suitable for forbidding that corresponding target start item starts according to the described startup project in described configuration file.
In specific implementation, described target start item can be included in and first carry out No starting operation, and the startup item of No starting failure.
In a kind of embodiment of the present invention, described determination module 201 can also start from:
The startup item of scan operation system;
Generate the operation prompt information of described startup item;
When receiving the No starting instruction for described operation prompt information, determine that the startup item of described No starting instruction correspondence is target start item.
In a kind of embodiment of the present invention, described determination module 201 can also start from:
The startup item of scan operation system;
Detect and whether formerly No starting operation is carried out to described startup item, and No starting failure; If so, then judge that described startup item is target start item.
In a kind of embodiment of the present invention, described disabled module 205 can also be suitable for:
In the kernel mode of operating system, tackle described startup item object call, to forbid that corresponding target start item starts.
In a kind of alternate exemplary of the embodiment of the present invention, described disabled module 205 can also be suitable for:
In the kernel mode of operating system, link up with the application programming interface of specifying, call to tackle described startup item object.
For device embodiment, due to itself and embodiment of the method basic simlarity, so description is fairly simple, relevant part illustrates see the part of embodiment of the method.
Intrinsic not relevant to any certain computer, virtual system or miscellaneous equipment with display at this algorithm provided.Various general-purpose system also can with use based on together with this teaching.According to description above, the structure constructed required by this type systematic is apparent.In addition, the present invention is not also for any certain programmed language.It should be understood that and various programming language can be utilized to realize content of the present invention described here, and the description done language-specific is above to disclose preferred forms of the present invention.
In instructions provided herein, describe a large amount of detail.But can understand, embodiments of the invention can be put into practice when not having these details.In some instances, be not shown specifically known method, structure and technology, so that not fuzzy understanding of this description.
Similarly, be to be understood that, in order to simplify the disclosure and to help to understand in each inventive aspect one or more, in the description above to exemplary embodiment of the present invention, each feature of the present invention is grouped together in single embodiment, figure or the description to it sometimes.But, the method for the disclosure should be construed to the following intention of reflection: namely the present invention for required protection requires feature more more than the feature clearly recorded in each claim.Or rather, as claims below reflect, all features of disclosed single embodiment before inventive aspect is to be less than.Therefore, the claims following embodiment are incorporated to this embodiment thus clearly, and wherein each claim itself is as independent embodiment of the present invention.
Those skilled in the art are appreciated that and adaptively can change the module in the equipment in embodiment and they are arranged in one or more equipment different from this embodiment.Module in embodiment or unit or assembly can be combined into a module or unit or assembly, and multiple submodule or subelement or sub-component can be put them in addition.Except at least some in such feature and/or process or unit be mutually repel except, any combination can be adopted to combine all processes of all features disclosed in this instructions (comprising adjoint claim, summary and accompanying drawing) and so disclosed any method or equipment or unit.Unless expressly stated otherwise, each feature disclosed in this instructions (comprising adjoint claim, summary and accompanying drawing) can by providing identical, alternative features that is equivalent or similar object replaces.
In addition, those skilled in the art can understand, although embodiments more described herein to comprise in other embodiment some included feature instead of further feature, the combination of the feature of different embodiment means and to be within scope of the present invention and to form different embodiments.Such as, in the following claims, the one of any of embodiment required for protection can use with arbitrary array mode.
All parts embodiment of the present invention with hardware implementing, or can realize with the software module run on one or more processor, or realizes with their combination.It will be understood by those of skill in the art that the some or all functions that microprocessor or digital signal processor (DSP) can be used in practice to realize the some or all parts in the equipment started according to the No starting item of the embodiment of the present invention.The present invention can also be embodied as part or all equipment for performing method as described herein or device program (such as, computer program and computer program).Realizing program of the present invention and can store on a computer-readable medium like this, or the form of one or more signal can be had.Such signal can be downloaded from internet website and obtain, or provides on carrier signal, or provides with any other form.
The present invention will be described instead of limit the invention to it should be noted above-described embodiment, and those skilled in the art can design alternative embodiment when not departing from the scope of claims.In the claims, any reference symbol between bracket should be configured to limitations on claims.Word " comprises " not to be got rid of existence and does not arrange element in the claims or step.Word "a" or "an" before being positioned at element is not got rid of and be there is multiple such element.The present invention can by means of including the hardware of some different elements and realizing by means of the computing machine of suitably programming.In the unit claim listing some devices, several in these devices can be carry out imbody by same hardware branch.Word first, second and third-class use do not represent any order.Can be title by these word explanations.
The embodiment of the invention discloses the method for A1, the startup of a kind of No starting item, comprising:
Target start item in determination operation system, described target start item forbids the application of self-starting for the need of specifying;
Obtain the startup project relevant to described target start item;
The startup project relevant to described target start item is write in configuration file;
When os starting, read described configuration file;
Forbid that corresponding target start item starts according to the described startup project in described configuration file.
A2, method as described in A1, described target start item is included in and first carries out No starting operation, and the startup item of No starting failure.
A3, method as described in A1 or A2, the step of the target start item in described determination operation system comprises:
The startup item of scan operation system;
Generate the operation prompt information of described startup item;
When receiving the No starting instruction for described operation prompt information, determine that the startup item of described No starting instruction correspondence is target start item.
A4, method as described in A1 or A2, the step of the target start item in described determination operation system comprises:
The startup item of scan operation system;
Detect and whether formerly No starting operation is carried out to described startup item, and No starting failure; If so, then judge that described startup item is target start item.
A5, method as described in A1 or A2, describedly forbid that the step that corresponding target start item starts comprises according to the described startup project in described configuration file:
In the kernel mode of operating system, tackle described startup item object call, to forbid that corresponding target start item starts.
A6, method as described in A5, describedly in the kernel mode of operating system, tackle described startup item object call, to forbid that the step that corresponding target start item starts comprises:
In the kernel mode of operating system, link up with the application programming interface of specifying, call to tackle described startup item object.
The embodiment of the invention also discloses the device of B7, the startup of a kind of No starting item, comprising:
Determination module, is suitable for the target start item in determination operation system, and described target start item forbids the application of self-starting for the need of specifying;
Acquisition module, is suitable for obtaining the startup project relevant to described target start item;
Writing module, is suitable for the startup project relevant to described target start item to write in configuration file;
Read module, is suitable for, when os starting, reading described configuration file;
Disabled module, is suitable for forbidding that corresponding target start item starts according to the described startup project in described configuration file.
B8, device as described in B7, described target start item is included in and first carries out No starting operation, and the startup item of No starting failure.
B9, device as described in B7 or B8, described determination module also starts from:
The startup item of scan operation system;
Generate the operation prompt information of described startup item;
When receiving the No starting instruction for described operation prompt information, determine that the startup item of described No starting instruction correspondence is target start item.
B10, device as described in B7 or B8, described determination module also starts from:
The startup item of scan operation system;
Detect and whether formerly No starting operation is carried out to described startup item, and No starting failure; If so, then judge that described startup item is target start item.
B11, device as described in B7 or B8, described disabled module is also suitable for:
In the kernel mode of operating system, tackle described startup item object call, to forbid that corresponding target start item starts.
B12, device as described in B11, described disabled module is also suitable for:
In the kernel mode of operating system, link up with the application programming interface of specifying, call to tackle described startup item object.