ãŸããWindowsãå®è¡ããŠããã³ã³ãã¥ãŒã¿ãŒã¯ãæéã®çµéãšãšãã«ã¡ã¢ãªã倱ãåŸåããããŸãã ãŸããå°ãªããšãç§ã«ãšã£ãŠã¯ãç§ã®äœ¿ãæ¹ã§ã åèµ·åããã«2é±éåŸïŒãŸãã¯ãChromeã300ååæ§ç¯ããé±æ«ãªã©ïŒãã¿ã¹ã¯ãããŒãžã£ãŒãéåžžã«å°éã®ç©ºãRAMã衚瀺ãå§ããã®ã«æ°ä»ãå§ããŸããããåæã«ã·ã¹ãã ã«ã¯ããã»ã¹ããããŸãããã®ã¡ã¢ãªã¯ç©æ¥µçã«äœ¿çšãããŸãã äžèšã®äŸïŒChromeã®300ã®ã¢ã»ã³ããªïŒã§ãã¿ã¹ã¯ãããŒãžã£ãŒã¯ãã·ã¹ãã ã49.8 GBãš4.4 GBã®å§çž®ã¡ã¢ãªã䜿çšããŠããããåæã«ããã€ãã®ããã»ã¹ã®ã¿ãéå§ãããããããã¹ãŠãããã»ã©å€ãã®ã¡ã¢ãªãã䜿çšããªããšèšã£ãïŒ

ç§ã®ã³ã³ãã¥ãŒã¿ãŒã«ã¯96 GBã®RAMãããïŒã¯ããç§ã¯å¹žéã§ãïŒãå®è¡äžã®ããã»ã¹ããŸã£ãããªãå Žå-ãã®ã¡ã¢ãªãŒã®å°ãªããšãååã解æŸããããšæããŸãã æ¬åœã«æåŸ ããŠããŸãã ããããæã«ã¯ãããéæã§ãããOSãåèµ·åããå¿ èŠããããŸãã Windowsã«ãŒãã«ã¯é«å質ãšä¿¡é Œæ§ ïŒåè«ãªãïŒã§äœæãããŠãããããã¡ã¢ãªã¯ãã¬ãŒã¹ãªãã§æ¶ããŠã¯ãªããŸããã ããããããã§ã圌女ã¯å§¿ãæ¶ããŸãã
ç§ã®æåã®æšæž¬ã¯ã ååã®èª°ããäœããã®åœ¢ã§ãŸã³ãããã»ã¹ã«ã€ããŠäžå¹³ãèšã£ãããšãæãåºããã 圌ã¯ããã®ãããªããã»ã¹ã®ãªã¹ãïŒååãšçªå·ïŒã衚瀺ããç¹å¥ãªãŠãŒãã£ãªãã£ãäœæããŸããã ãã¹ãã§ãã®ãŠãŒãã£ãªãã£ãå®è¡ãããšãéåžžã®Windowsãã·ã³ã§æ倧æ°çŸã®ãŸã³ãããã»ã¹ãåãåããŸããã ç§ã¯åœŒã®ããŒã«ãèŠã€ãããããã³ã³ãã¥ãŒã¿ãŒã§èµ·åãã506,000ã®ãŸã³ãããã»ã¹ãååŸããŸããã ã¯ãã506åïŒ
ããã»ã¹ãããŸã³ããç¶æ ã«ç§»è¡ããå¯èœæ§ã®ããçç±ã®1ã€ã¯ãä»ã®ããã»ã¹ããã®ãã³ãã«ãéãããŸãŸã«ããŠããããšãããããªãããšãæãåºããŸããã ç§ã®å Žåãå€æ°ã®ãŸã³ãããã»ã¹ãç§ã®æã«ããããŸãããããããé ãããšã¯å°é£ã§ããã ã¿ã¹ã¯ãããŒãžã£ãŒãéããåããã»ã¹ã®éããŠããèšè¿°åã®æ°ã瀺ãåã[詳现]ã¿ãã«è¿œå ããŸããã 次ã«ããã®åã®å€ã®éé ã§ãªã¹ãããœãŒãããŸããã ç§ã¯ããã«ãã®ç©èªã®ããŒããŒãèŠã€ããŸãã-CcmExec.exeããã»ã¹ïŒ Microsoft System Management Serverã®äžéšïŒã«ã¯508,000ã®ãªãŒãã³èšè¿°åããããŸããã ããã¯ã第äžã«ãå€ãããããŠç¬¬äºã«ã506,000ã®ãŸã³ãããã»ã¹ã§ç§ãèŠã€ããæ°ã«çãããã»ã©è¿ãã£ãã

CcmExec.exeããã»ã¹ã匷å¶çµäºãã次ã®çµæãåŸãŸããã

ãã¹ãŠãç§ãæåŸ ãããšããã«ãªããŸããã äžèšã§ç®èãªãæžããããã«ãWindowsã«ãŒãã«ã¯éåžžã«ããŸãæžãããŠãããããã»ã¹ãç Žå£ããããšãããã«ãã£ãŠå æãããŠãããã¹ãŠã®ãªãœãŒã¹ã解æŸãããŸãã CcmExec.exeãéãããšã508,000ã®èšè¿°åã解æŸããã506,000ã®ãŸã³ãããã»ã¹ãå®å šã«éããããšãã§ããŸããã 空ãRAMã®éãå³åº§ã«32 GBå¢å ããŸããã è¬ãæããã«ãªããŸããïŒ
ãŸã³ãããã»ã¹ãšã¯äœã§ããïŒ
ãã®æç¹ãŸã§ãããããã¹ãŠã®ããã»ã¹ãäžç¢ºå®ã«ãã³ã°ã¢ããããåé€ãããªãã£ãåå ã¯ãŸã 解æãããŠããŸããã ã¢ããªã±ãŒã·ã§ã³ã®äºçŽ°ãªãã°ãåŠçããŠããããã§ãïŒOSã®ã«ãŒãã«ã§ã¯ãããŸããïŒã äžè¬çãªã«ãŒã«ã¯ãããã»ã¹ãäœæãããšããã®ãã³ãã«ãšãã®ã¡ã€ã³ã¹ã¬ããã®ãã³ãã«ãååŸããããšã§ãã ãããã®èšè¿°åãéããå¿ èŠããããŸãã ã¿ã¹ã¯ãããã»ã¹ãéå§ããã ãã®å Žåã¯ãããã«éããããšãã§ããŸãïŒããã«ãããå®è¡äžã®ããã»ã¹ã¯åŒ·å¶çµäºããããããã»ã¹ãšã®æ¥ç¶ãåæãããŸãïŒã äœãã®æ°ããããã»ã¹ãå¿ èŠãªå ŽåïŒããšãã°ãäœæ¥ã®çµäºãåŸ ã£ãŠããå ŽåããŸãã¯ãããè¿ãã³ãŒããå¿ èŠãªå ŽåïŒãé©åãªé¢æ°ïŒããšãã°ãWaitForSingleObjectïŒhProcessãINFINITEïŒã䜿çšããŠçµäºãŸãã¯GetExitCodeProcessïŒhProcessãïŒexitCode ïŒæ»ãã³ãŒããååŸããŸãïŒåããã»ã¹ããå¿ èŠãªãã®ããã¹ãŠååŸããåŸã§ããèšè¿°åãéããŸãã OpenProcessïŒïŒé¢æ°ã䜿çšããŠäœãã®ããã«éããããã»ã¹èšè¿°åã§ãåãããšãè¡ãå¿ èŠããããŸãã
ããããã®ãå¿ããããã»ã¹ãã·ã¹ãã ã®ãã®ã«é¢é£ããŠããå Žåãããã¯ããªããããªãã®ã¢ã«ãŠã³ããããã°ã¢ãŠãããŠå床ãã°ã€ã³ããã®ãå©ãããããªããããããŸãããå®å šãªãªããŒãã ãã
èšæ¶ã¯ã©ãã«è¡ããŸããïŒ
ç§ã®ç 究ã§äœ¿çšãããã1ã€ã®ããŒã«ã¯ã RamMapãŠãŒãã£ãªãã£ã§ãã ã¡ã¢ãªã®åããŒãžã®äœ¿çšç¶æ³ã瀺ããŠããŸãã [ããã»ã¹ã¡ã¢ãª]ã¿ãã«ã¯ãããããã32 KBã®RAMãå æããæ°åäžã®ããã»ã¹ã衚瀺ãããŸããããã¯æããã«ãŸã³ãã§ãã ãããããããã32 KBã§çŽ500,000åã¯çŽ16 GBã«ãªããŸããæ®ãã®ã¡ã¢ãªã¯ã©ãã«è¡ããŸãããïŒ ãŸã³ãããã»ã¹ãéããååŸã®ã¡ã¢ãªã®ç¶æ ãæ¯èŒãããšããã®è³ªåã«å¯ŸããçããåŸãããŸãã

ã16 GBãããã»ã¹ãã©ã€ããŒãã¡ã¢ãªã«äœ¿çšãããããšãæ確ã«ããããŸãã ãŸããå¥ã®16 GBãããŒãžããŒãã«ã¡ã¢ãªã«åãŸã£ãŠããããšãããããŸãã æããã«ãåãŸã³ãããã»ã¹ã¯ã¡ã¢ãªããŒãžã®ããŒãã«ã§32 KBã䜿çšããå人ã¡ã¢ãªãšããŠå¥ã®32 KBã䜿çšããŸãã ãŸã³ãããã»ã¹ã«ããã»ã©å€ãã®ã¡ã¢ãªãããçç±ã¯ããããŸããããããããããã®ãããªããã»ã¹ã®æ°ãæ°åäžåäœã§æž¬å®ã§ãããšã¯èããŠããŸããã
CcmExec.exeããã»ã¹ãéããåŸãäž»ã«ãããããããã¡ã€ã«ãšã¡ã¿ãã¡ã€ã«ã䜿çšããåŸã«ã䜿çšãããã¡ã¢ãªã®çš®é¡ãå¢å ããŸããã ãªããããèµ·ãã£ãã®ãæ£ç¢ºã«ã¯ããããŸããã ç§ã®æšæž¬ã®1ã€ã¯ãOSãååãªç©ºãã¡ã¢ãªããããšå€æããããèªäœã«äœãããã£ãã·ã¥ããããšã§ãã ããã¯ãäžè¬çã«ã¯æªããããŸããã ç§ã¯OSã®ããŒãºã®ããã«ã¡ã¢ãªãåŸæããŠããªããç§ã¯ãã ãããå®å šã«ç®çãªãã«æ¶ããŠã»ãããããŸããã
éèŠãªæ³šæïŒRamMapã¯ãã¹ãŠã®ããã»ã¹ã®èšè¿°åãéããŸãããã®ããããŸã³ãããã»ã¹ãéãããå Žåã¯ããã®ãŠãŒãã£ãªãã£ãéããå¿ èŠããããŸãã
ç§ã¯èªåã®çºèŠã«ã€ããŠãã€ãŒããããã®ãã°ãåçŸããŠãã€ã¯ããœããã®éçºè ã«æ å ±ãæž¡ãããšãã§ããå¥ã®ããã°ã©ããŒãç 究ãç¶ããŸããã
ãã®åé¡ãããã«ä¿®æ£ãããããšãé¡ã£ãŠããŸãã
ã³ã³ãã¥ãŒã¿ãŒã§ãã®ãããªå¥åŠãªåé¡ãçºçããã®ã¯ãªãã§ããïŒ
ç§ã¯Chromeã®WindowsããŒãžã§ã³ã®ã³ãŒãã«åãçµãã§ãããç§ã®ã¿ã¹ã¯ã®1ã€ã¯ãã®OSäžã§ã¢ã»ã³ããªãæé©åããããšã§ãããããã«ã¯ãã®ã¢ã»ã³ããªã®è€æ°ã®èµ·åãå¿ èŠã§ãã Chromeã®åã¢ã»ã³ããªã¯ãéžæããèšå®ã«å¿ããŠ28,000ã37,000ã®éåžžã«å€æ§ãªããã»ã¹ãéå§ããŸãã åæ£ã¢ã»ã³ããªã·ã¹ãã ïŒ goma ïŒã䜿çšããŠããããã®ããã»ã¹ã¯éåžžã«è¿ éã«äœæããã³çµäºãããŸãã ç§ã®æé«ã®Chromeãã«ãçµæã¯200ç§ã§ãã ãããããã®ãããªç©æ¥µçãªããã»ã¹éå§ããªã·ãŒã¯ãWindowsã«ãŒãã«ãšãã®ã³ã³ããŒãã³ãã®åé¡ãæããã«ããŸãã
- ããã»ã¹ããã°ããåé€ãããšããŠãŒã¶ãŒå ¥åãããªãŒãºãã
- ã¿ããããããã©ã€ããŒã¯ãããã»ã¹ãäœæããããã³ã«ã¡ã¢ãªãå²ãåœãŠãŸããã 解æŸããŸãã
- App Verifierã¯OïŒn ^ 2ïŒåã®ãã°ãã¡ã€ã«ãäœæããŸã ïŒããã«ã€ããŠã¯å¥ã®æçš¿ãæžãå¿ èŠããããŸãïŒïŒ
- Windowsã«ãŒãã«ã«ã¯ãã¡ã€ã«ãããã¡ãªã³ã°ãæ±ããã°ãããããã®ãã°ã¯Server 2008 R2ããWindows 10ãŸã§ã®ãã¹ãŠã®Windowsã§çºçããŸãã
- Windows Defenderã¯åãŽãããã»ã¹ã®éå§ã250ããªç§é ãããŸã
次ã¯ïŒ
äŒç€Ÿã®ããªã·ãŒã«ãã£ãŠå¶åŸ¡ãããŠããã³ã³ãã¥ãŒã¿ãŒã§äœæ¥ããŠããªãå ŽåãCmmExec.exeããã»ã¹ã¯å®è¡ãããããã®ç¹å®ã®ãã°ã¯çºçããŸããã ãŸããChromeãåéããããåæ§ã®ããšãè¡ãå Žåã«ã®ã¿åœ±é¿ããæ°äžã®ããã»ã¹ãçæéã§äœæããã³çµäºããŸãã
ãããïŒ
CcmExecã¯ãäžçã§å¯äžã®ãã°ããã°ã©ã ã§ã¯ãããŸããã ç§ã¯ããŸã³ãããã»ã¹ã®äœæã«ã€ãªãããŸã£ããåãã¿ã€ãã®ãšã©ãŒãå«ãä»ã®å€ãã®ãã®ãèŠã€ããŸããã ãããŠãç§ãèŠã€ããŠããªããã®ããã£ãšãããããããŸãã
ãã¹ãŠã®çµéšè±å¯ãªããã°ã©ããŒãç¥ã£ãŠããããã«ãæ瀺çã«ä¿®æ£ãŸãã¯èŠåãããŠããªããšã©ãŒã¯å¿ ãçºçããŸãã ããã®ãã³ãã«ãéããŠãã ããããšããããã¥ã¡ã³ããæžãã ãã§ã¯ååã§ã¯ãããŸããã ããã§ããã®çš®ã®ãšã©ãŒãèŠã€ããããããããã®ç§ã®è²¢ç®ã以äžã«ç€ºããŸããä¿®æ£ã¯ããçŸå®çã§ãã FindZombieHandlesã¯ã NtApiDotNetãš@tiraniddoã®ã³ãŒãã«åºã¥ããããŒã«ã§ããŸã³ãããã»ã¹ã®ãªã¹ããšã誰ããŸã³ãã«ãªã£ããã«é¢ããæ å ±ã衚瀺ããŸãã ã³ã³ãã¥ãŒã¿ãŒã§å®è¡ãããŠãããã®ãŠãŒãã£ãªãã£ã®åºåã®äŸã次ã«ç€ºããŸãã
274 total zombie processes. 249 zombies held by IntelCpHeciSvc.exe(9428) 249 zombies of Video.UI.exe 14 zombies held by RuntimeBroker.exe(10784) 11 zombies of MicrosoftEdgeCP.exe 3 zombies of MicrosoftEdge.exe 8 zombies held by svchost.exe(8012) 4 zombies of ServiceHub.IdentityHost.exe 2 zombies of cmd.exe 2 zombies of vs_installerservice.exe 3 zombies held by explorer.exe(7908) 3 zombies of MicrosoftEdge.exe 1 zombie held by devenv.exe(24284) 1 zombie of MSBuild.exe 1 zombie held by SynTPEnh.exe(10220) 1 zombie of SynTPEnh.exe 1 zombie held by tphkload.exe(5068) 1 zombie of tpnumlkd.exe 1 zombie held by svchost.exe(1872) 1 zombie of userinit.exe
274人ã®ãŸã³ãã¯ããã»ã©æªãã¯ãããŸããã ããããããã§ããç¹å®ã®åé¡ãçºèŠããŠä¿®æ£ããããšãã§ããŸãã ãã®ãªã¹ãã®IntelCpHeciSvc.exeããã»ã¹ã«ã¯æ倧ã®åé¡ããããŸã-Windowsãšã¯ã¹ãããŒã©ãŒã§ãããªãéããã³ã«ããã»ã¹ãã³ãã«ãéãããã«èŠããŸãïŒéãå¿ããŠããããã§ãïŒã
Visual Studioã¯ãå°ãªããšã2ã€ã®ããã»ã¹ã®èšè¿°åãéããããšãå¿ããŠãããããå Žåã«ã¯åžžã«åçããŸãã ãããžã§ã¯ãã®ãã«ããéå§ããMSBuild.exeããã»ã¹ãçµäºãããŸã§15åã»ã©åŸ ã¡ãŸãã ãŸãããset MSBUILDDISABLENODEREUSE = 1ããªãã·ã§ã³ãèšå®ãããšãã¢ã»ã³ããªãå®äºãããšMSBuild.exeãããã«éãããã倱ããããã³ãã«ãããã«è¡šç€ºãããŸãã æ®å¿µãªãããMicrosoftã®äžéšã®ã©ã¹ã«ã«ã¯ãã®åé¡ãä¿®æ£ãããããVS 15.6ã¢ããããŒãã§ä¿®æ£ããªãªãŒã¹ããå¿ èŠããããŸãã ïŒ
äžã«ç€ºãããã«äžéšããã«ãèšå®ããããšã«ããã Process Explorerããã°ã©ã ã䜿çšããŠå¿ããããããã»ã¹ã衚瀺ããããšãã§ããŸãïŒãã®å Žåãå¿ããããèšè¿°åãããã»ã¹ãšã¹ã¬ããã®äž¡æ¹ã«è¡šç€ºãããããšã«æ³šæããŠãã ããïŒïŒ

èŠã€ãã£ããã°ã®äŸãããã€ã瀺ããŸãïŒäžéšã¯éçºè ã«å ±åãããŠããŸããããã¹ãŠã§ã¯ãããŸããïŒã
- CcmExec.exeã®ãªãŒã¯ïŒäžèšã®500,000ã®ãŸã³ãã®å ŽåïŒ-éçºè ã¯ä¿®æ£ã«åãçµãã§ããŸã
- ããã°ã©ã äºææ§ã¢ã·ã¹ã¿ã³ããµãŒãã¹ã®ãªãŒã¯-åé¡ã¯èª¿æ»äžã§ã
- devenv.exe + MSBuild.exeã®ãªãŒã¯ïŒåé¡ã¯æ¢ã«ä¿®æ£ãããŠããŸãïŒ
- devenv.exe + ServiceHub.Host.Node.x86.exeã®ãªãŒã¯ïŒãã°ã¬ããŒããéä¿¡ãããŸãã ïŒ
- éããŠãããããªãã¡ã€ã«ããšã«IntelCpHeciSvc.exe + Video.UI.exeã®ãªãŒã¯ïŒIntelã¯ãã°ã¬ããŒããåãå ¥ããLenovoã«è»¢éããŸããïŒ
- RuntimeBroker.exe + MicrosoftEdgeããã³Video.UI.exeã®ãªãŒã¯ïŒRuntimeBroker.exeã®ä»ã®ãã°ã«é¢é£ããŠããå¯èœæ§ããããŸãïŒ
- AudioSrv + Video.UI.exeã®ãªãŒã¯
- å€ãããŒãžã§ã³ã®psutilã®äœ¿çšã«ãã1ã€ã®å éšGoogleããŒã«ã®ãªãŒã¯
- LenovoãŠãŒãã£ãªãã£ãªãŒã¯ïŒtphkload.exeã¯1ã€ã®èšè¿°åã倱ããSUService.exeã¯3ã€ã®èšè¿°åã倱ããŸã
- Synapticã®SynTPEnh.exeã®ãªãŒã¯
ãã®æ¹æ³ã§ãªãŒã¯ããå¯èœæ§ãããã®ã¯ãããã»ã¹èšè¿°åã ãã§ã¯ãããŸããã ããšãã°ããIntel®Online Connect AccessãµãŒãã¹ãïŒIntelTechnologyAccessService.exeïŒã¯4 MBã®RAMãã䜿çšããŸãããã30æ¥éå®è¡ããåŸã27,504åã®èšè¿°åãäœæããŸãã ãã®åé¡ã¯ãã¿ã¹ã¯ãããŒãžã£ãŒã䜿çšããŠæ€åºã§ããŸããéçºè ã«ãã°ã¬ããŒããéä¿¡ããŸããã

ããã»ã¹ãšã¯ã¹ãããŒã©ãŒã䜿çšããŠãNVDisplay.Container.exeã\ BaseNamedObjects \ NvXDSyncStop-61F8EBFF-D414-46A7-90AE-98DD58E4BC99ã€ãã³ãã«å¯ŸããŠã5000åã®èšè¿°åãéãã2åããšã«æ°ããèšè¿°åãäœæããããšã«æ°ä»ããŸããã ç§ã¯ãããç解ããŠããããã«ã圌ãã¯åœŒããNvXDSyncãåæ¢ã§ããããšãéåžžã«èªä¿¡ãæã¡ããã§ããïŒ Nvidiaãã°ã¬ããŒããéä¿¡ãããŸãã ã

Corsair Link Serviceã¯1ç§ãããçŽ15åã®èšè¿°åãäœæããŸããããããã¯ãŸã£ãã解æŸãããŸããã Bagreportãéä¿¡ãããŸãã ã
Adobeã®Creative Cloudã¯æ°åã®èšè¿°åã倱ã£ãŠããŸã ïŒ1æ¥ãããçŽ6,500ãç§ã¯æšå®ïŒã Bagreportãéä¿¡ãããŸãã ã
Razer Chroma SDKãµãŒãã¹ã¯ãéåžžã«å€ãã®èšè¿°åã倱ããŸãïŒ 1æéããã150,000ã§ããïŒ ïŒã Bagreportãéä¿¡ãããŸãã ã
é©ãã¹ãããšã«ããã®ãããªãã°ã«ãããŸã§ããŸã泚æãæã£ã人ã¯ããŸããã§ããã ããããã€ã¯ããœããããããããã®ãããªå Žåã®çµ±èšãåéããããã«ã€ããŠäœãããã䟡å€ãããã®ã§ããããïŒ ã¡ãã£ãšIntelãšNvidiaãããªãã®ã³ãŒããå°ããããã«ããŠãã ããã èŠããŠãããŠãç§ã¯ããªããèŠãŠããŸãã
ããã§ã FindZombieHandlesãŠãŒãã£ãªãã£ã䜿çšããŠãã·ã³ã§å®è¡ãã調æ»çµæã«ã€ããŠè©±ãããšãã§ããŸãã å®éšã§ã¯ãã¿ã¹ã¯ãããŒãžã£ãŒãšããã»ã¹ãšã¯ã¹ãããŒã©ãŒã䜿çšããããšãã§ããŸãã