个人认为日志中可疑项目如下:
注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
[(Verified)Beijing Rising Science and Technology Corporation Limited]
<{00070007-0007-0007-0007-00070007BB15}><C:\WINDOWS\system32\dpvvoxmh.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<dpvvoxmh.dll><C:\WINDOWS\system32\dpvvoxmh.dll> []
驱动程序
[1c0c93f84a00ebe5 / 1c0c93f84a00ebe5][Stopped/Manual Start]
<\??\C:\1c0c93f84a00ebe5.dat><N/A>
[30addf68dfad0a5d / 30addf68dfad0a5d][Stopped/Manual Start]
<\??\C:\30addf68dfad0a5d.dat><N/A>
[39897eac2037efbb / 39897eac2037efbb][Stopped/Manual Start]
<\??\C:\39897eac2037efbb.dat><N/A>
[42e305548873889f / 42e305548873889f][Stopped/Manual Start]
<\??\C:\42e305548873889f.dat><N/A>
[45f3ea38089f8026 / 45f3ea38089f8026][Stopped/Manual Start]
<\??\C:\45f3ea38089f8026.dat><N/A>
[5613fa085518810f / 5613fa085518810f][Stopped/Manual Start]
<\??\C:\5613fa085518810f.dat><N/A>
[59c99e4ccb22db05 / 59c99e4ccb22db05][Stopped/Manual Start]
<\??\C:\59c99e4ccb22db05.dat><N/A>
[78692fc48adc3062 / 78692fc48adc3062][Stopped/Manual Start]
<\??\C:\78692fc48adc3062.dat><N/A>
[8d8862986e99aaaa / 8d8862986e99aaaa][Stopped/Manual Start]
<\??\C:\8d8862986e99aaaa.dat><N/A>
[901b6018f4706769 / 901b6018f4706769][Stopped/Manual Start]
<\??\C:\901b6018f4706769.dat><N/A>
[98f6ff5c6f94faef / 98f6ff5c6f94faef][Stopped/Manual Start]
<\??\C:\98f6ff5c6f94faef.dat><N/A>
[a513baf013891450 / a513baf013891450][Stopped/Manual Start]
<\??\C:\a513baf013891450.dat><N/A>
[aca5db74a780c955 / aca5db74a780c955][Stopped/Manual Start]
<\??\C:\aca5db74a780c955.dat><N/A>
[bc4803e017c20558 / bc4803e017c20558][Stopped/Manual Start]
<\??\C:\bc4803e017c20558.dat><N/A>
[bedb016088b9c597 / bedb016088b9c597][Stopped/Manual Start]
<\??\C:\bedb016088b9c597.dat><N/A>
[c3b34c684cb6ad55 / c3b34c684cb6ad55][Stopped/Manual Start]
<\??\C:\c3b34c684cb6ad55.dat><N/A>
[c47ee3c4819b812d / c47ee3c4819b812d][Stopped/Manual Start]
<\??\C:\c47ee3c4819b812d.dat><N/A>
[c64649e8fbed1594 / c64649e8fbed1594][Running/Manual Start]
<\??\C:\c64649e8fbed1594.dat><N/A>
正在运行的进程
C:\WINDOWS\system32\dpvvoxmh.dll
另:系统无关服务开启过多