犯罪现场调查:我的电脑-Akamai的netsession_win.exe是什么,它如何进入我的系统?

I know my system backwards and forwards and I do not like noticing stuff running in the background that I don't recognize. Recently I was checking out the Task Manager (right click on the clock, and select Task Manager or press Ctrl-Alt-Del and click Task Manager) and noticed TWO copies of "netsession_win.exe" running with a peak memory working set of about 25 megs. Ok, what's this? It's the Akamai Net Session Interface. Ick.

我知道我的系统来回移动,并且我喜欢注意到在后台运行的我不认识的东西。 最近,我正在检查任务管理器(右键单击时钟,然后选择“任务管理器”,或者按Ctrl-Alt-Del并单击“任务管理器”),并注意到“ netsession_win.exe”的两个副本运行时的峰值内存工作集大约为25兆好,这是什么? 这是Akamai网络会话界面。 ck

netsession_win.exe in my Windows Task Manager

You can always right click on suspicious processes and click Open File Location. This little tip is often enough to jog your memory and go, "Oh, THAT."

您始终可以右键单击可疑进程,然后单击“打开文件位置”。 这个小技巧通常足以使您记忆犹新,“哦,那样”。

Open File Location in Task Manager's Context Menu

Hm, that dropped me into C:\Users\scottha\AppData\Local\Akamai. I know who Akamai is. They are a download accelerator used by lots of companies. Kind of the first large Content Distribution Network or CDN.

嗯,这让我进入了C:\ Users \ scottha \ AppData \ Local \ Akamai。 我知道赤衣是谁它们是许多公司使用的下载加速器。 第一个大型内容分发网络或CDN的种类。

Am I sure it's them and not someone evil trying to fake me out? Right click on netsession_win.exe, then Properties.

我确定是他们,而不是一个邪恶的人试图假冒我吗? 右键单击netsession_win.exe,然后单击“属性”。

Akamai's NetSession digital signature is legit

Well, they have a legitimate digital signature, interestingly they signed this on the 11th of November. Looks like this was recently installed automatically by something, perhaps Flash or Adobe Acrobat.

好吧,他们有一个合法的数字签名,有趣的是,他们在11月11日对此进行了签名。 看起来这是由某些东西(例如Flash或Adobe Acrobat)自动安装的。

I wonder if someone needs to tell Akamai that their freshly installed service that just (kinda, a little) snuck on my system has a digital certificate that expires in 5 weeks. Are they or one of the companies that uses them going to update this client and cert soon?

我想知道是否有人需要告诉Akamai,他们刚安装在我系统上的新安装的服务具有在5周内过期的数字证书。 他们还是使用它们的公司之一即将更新此客户端并进行认证?

Akamai's digital certiticate expires before Christmas

Running services.msc from Start | Run tells me that this runs as an Automatic Service. At least it's a Delayed Start so it doesn't slow down my boot.

从开始|运行service.msc。 运行告诉我这是作为自动服务运行的。 至少这是一个延迟启动,因此不会降低启动速度。

Services (158)

The only thing I installed on my machine on the 11th was an automatic update to Adobe Flash. That's my #1 suspect right now as it's the only thing that I ran as Administrator that day.

我11日在机器上安装的唯一一件事是对Adobe Flash的自动更新。 那是我目前的第一嫌疑人,因为那是我当天作为管理员运行的唯一事情。

For now, I'll keep it on my machine because it:

现在,我将其保留在我的机器上,因为它:

  • Is from a reputable (so far) company

    来自知名(到目前为止)的公司
  • Is known to be used by folks like Netflix, etc to speed up downloads

    众所周知,Netflix等人可以使用它来加快下载速度
  • Has an uninstall available in Installed Programs

    已安装程序中有可用的卸载
  • Feels legit

    感觉合法
  • Has a control panel icon and a Read Me with lots of info about what it does (except who installed them)

    具有控制面板图标和自述文件,其中包含有关其功能的大量信息(安装者除外)
  • Has a customer bill of rights online with details with test demo pages about their API.

    在线拥有客户权利清单,其中包含有关其API的测试演示页的详细信息。

I will say this, though. Whatever program installed it should have told me first before chaining it in. At least with Evil Toolbars I can see them. Not cool Akamai. Who installed you?

我会这样说。 无论安装什么程序,它在链接之前都应该先告诉我。至少可以使用Evil工具栏看到它们。 不酷的Akamai。 谁安装了你?

You're on notice.

您正在注意。

UPDATE: Looks like this is using my own computers bandwidth to upload to other Akamai users. They're using our computers and network to make other people's uploads faster. That sounds like I'm running a Torrent and no one asked if it was OK. I'm continuing to dig into this, like disk space usage, etc.

更新:看来这是在使用我自己的计算机带宽上载到其他Akamai用户。 他们正在使用我们的计算机和网络来加快其他人的上传速度。 听起来好像我正在运行Torrent,但没人问这是否还可以。 我将继续深入探讨这一问题,例如磁盘空间使用情况等。

翻译自: https://www.hanselman.com/blog/csi-my-computer-what-is-netsessionwinexe-from-akamai-and-how-did-it-get-on-my-system

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值