注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WPDShServiceObj><?{AAA288BA-9A4C-45B0-95D7-94D524869DB5}> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
==================================
正在运行的进程
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\cdfview.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[PID: 2832 / SYSTEM][d:\altera\quartus51\bin\JTAGServer.exe] [N/A, ]
[d:\altera\quartus51\bin\ccl_ver.dll] [N/A, ]
[d:\altera\quartus51\bin\std-vc-mt.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\System32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\System32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\System32\iettmn.dll] [N/A, ]
[C:\WINDOWS\System32\iompys.dll] [N/A, ]
[C:\WINDOWS\System32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\System32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\System32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\System32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\System32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
[C:\WINDOWS\system32\pnxsfc.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\iettmn.dll] [N/A, ]
[C:\WINDOWS\system32\iompys.dll] [N/A, ]
[C:\WINDOWS\system32\gqqumk.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop02.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosptfs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosmnsf02.dll] [N/A, ]
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1024, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2640, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1248, D:\PROGRAM FILES\MAXTHON\MAXTHON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1248, D:\PROGRAM FILES\MAXTHON\MAXTHON.EXE]
看下这些是什么?