[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Spooler SubSystem App><C:\WINDOWS\System32\spooIsv.exe> []
[Secdrv / Secdrv][Stopped/Manual Start]
<System32\DRIVERS\secdrv.sys><N/A>
[PID: 740][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\Eset\pr_imon.dll] [N/A, ]
[PID: 812][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\Eset\pr_imon.dll] [N/A, ]
[PID: 868][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\Eset\pr_imon.dll] [N/A, ]
[PID: 1280][D:\Eset\nod32kui.exe] [Eset , 2, 51, 26 ]
[D:\Eset\pr_dmon.dll] [N/A, ]
[D:\Eset\pr_emon.dll] [N/A, ]
[D:\Eset\pr_imon.dll] [N/A, ]
[D:\Eset\pr_upd.dll] [N/A, ]
[PID: 1356][D:\Eset\nod32krn.exe] [Eset , 2, 51, 26 ]
[D:\Eset\pr_dmon.dll] [N/A, ]
[D:\Eset\pr_emon.dll] [N/A, ]
[D:\Eset\pr_imon.dll] [N/A, ]
[D:\Eset\pr_upd.dll] [N/A, ]
[PID: 300][C:\WINDOWS\System32\spooIsv.exe] [N/A, ]
[D:\Eset\pr_imon.dll] [N/A, ]
[D:\Eset\pr_imon.dll] [N/A, ]
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 300, C:\WINDOWS\SYSTEM32\SPOOISV.EXE]