高手可以来分析下他的行为
(Unk) 000000F1 \Device\RasAcd
Clsid -------------------------------
File/Key -------------------------------
Image -------------------------------
Image c:\program files\***123\***123bind.dll
Image c:\windows\system32\cryptdll.dll
Image c:\windows\system32\digest.dll
Image c:\windows\system32\dnsapi.dll
Image c:\windows\system32\hnetcfg.dll
Image c:\windows\system32\iphlpapi.dll
Image c:\windows\system32\msapsspc.dll
Image c:\windows\system32\msnsspc.dll
Image c:\windows\system32\msv1_0.dll
Image c:\windows\system32\msvcrt40.dll
Image c:\windows\system32\mswsock.dll
Image c:\windows\system32\netapi32.dll
Image c:\windows\system32\rasadhlp.dll
Image c:\windows\system32\rasapi32.dll
Image c:\windows\system32\rasman.dll
Image c:\windows\system32\rtutils.dll
Image c:\windows\system32\schannel.dll
Image c:\windows\system32\sensapi.dll
Image c:\windows\system32\tapi32.dll
Image c:\windows\system32\urlmon.dll
Image c:\windows\system32\userenv.dll
Image c:\windows\system32\wshtcpip.dll
Image c:\windows\system32\wsock32.dll
Ipc -------------------------------
Ipc \BaseNamedObjects\_!MSFTHISTORY!_
Ipc \BaseNamedObjects\c:!documents and settings!administrator!cookies!
Ipc \BaseNamedObjects\c:!documents and settings!administrator!local settings!history!history.ie5!
Ipc \BaseNamedObjects\c:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Ipc \BaseNamedObjects\C:_Documents and Settings_Administrator_Cookies_index.dat_245760
Ipc \BaseNamedObjects\C:_Documents and Settings_Administrator_Local Settings_History_History.IE5_index.dat_1867776
Ipc \BaseNamedObjects\C:_Documents and Settings_Administrator_Local Settings_Temporary Internet Files_Content.IE5_index.dat_9469952
Ipc \BaseNamedObjects\shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}
Ipc \BaseNamedObjects\UrlZonesSM_Administrator
Ipc \BaseNamedObjects\userenv: User Profile setup event
Ipc \BaseNamedObjects\Vpn123BindMutexName_{04A8142B-9687-4b74-B7DF-D39D3FBD1B69}
Ipc \BaseNamedObjects\VpnBindGlobalControlBlock_{05F607A4-6E2F-42e8-AFE0-7F56211E6B88}_2.2.0.2
Ipc \BaseNamedObjects\ZonesCacheCounterMutex
Ipc \BaseNamedObjects\ZonesCounterMutex
Ipc \BaseNamedObjects\ZonesLockedCacheCounterMutex
Ipc O \BaseNamedObjects\MSCTF.SendReceive.Event.EDN.IC
Ipc O \BaseNamedObjects\MSCTF.SendReceive.Event.INB.IC
Ipc O \BaseNamedObjects\MSCTF.SendReceive.Event.INB.IKAC
Ipc O \BaseNamedObjects\MSCTF.SendReceiveConection.Event.EDN.IC
Ipc O \BaseNamedObjects\MSCTF.SendReceiveConection.Event.INB.IC
Ipc O \BaseNamedObjects\MSCTF.SendReceiveConection.Event.INB.IKAC
Ipc O \BaseNamedObjects\MSCTF.Shared.MUTEX.EDN
Ipc O \BaseNamedObjects\MSCTF.Shared.SFM.EDN
Ipc O \BaseNamedObjects\RasPbFile
Ipc O \BaseNamedObjects\SENS Information Cache
Ipc O \BaseNamedObjects\WininetConnectionMutex
Ipc O \BaseNamedObjects\WininetProxyRegistryMutex
Ipc O \BaseNamedObjects\WininetStartupMutex
Ipc O \KnownDlls\MSVCRT40.dll
Ipc O \KnownDlls\NETAPI32.dll
Ipc O \KnownDlls\urlmon.dll
Ipc O \KnownDlls\USERENV.dll
Ipc O \LsaAuthenticationPort
Ipc O \NLS\NlsSectionCP1250
Ipc O \NLS\NlsSectionCP1251
Ipc O \NLS\NlsSectionCP1257
Ipc O \NLS\NlsSectionCP932
Ipc O \NLS\NlsSectionCP949
Ipc O \NLS\NlsSectionCP950
Ipc O \RPC Control\DNSResolver
Ipc O \RPC Control\SbieSvcPort
Ipc O \RPC Control\senssvc
Ipc O \RPC Control\tapsrvlpc
Ipc O \Security\LSA_AUTHENTICATION_INITIALIZED
Ipc X $:ctfmon.exe
Ipc X \BaseNamedObjects\_!MSFTHISTORY!_
Ipc X \BaseNamedObjects\c:!documents and settings!administrator!cookies!
Ipc X \BaseNamedObjects\c:!documents and settings!administrator!local settings!history!history.ie5!
Ipc X \BaseNamedObjects\c:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Ipc X \BaseNamedObjects\C:_Documents and Settings_Administrator_Cookies_index.dat_245760
Ipc X \BaseNamedObjects\C:_Documents and Settings_Administrator_Local Settings_History_History.IE5_index.dat_1867776
Ipc X \BaseNamedObjects\C:_Documents and Settings_Administrator_Local Settings_Temporary Internet Files_Content.IE5_index.dat_9469952
Ipc X \BaseNamedObjects\VpnBindGlobalControlBlock_{05F607A4-6E2F-42e8-AFE0-7F56211E6B88}_2.2.0.2
Pipe -------------------------------
Pipe O \Device\Afd
Pipe O \Device\Afd\Endpoint
Pipe O \Device\NamedPipe\
Pipe O \Device\NamedPipe\ROUTER
Pipe X \Device\NamedPipe\lsarpc
WinCls -------------------------------
WinCls O $:中国联通 海南四方 内部刷农场牧场经验工具 BY:小超制作 .exe
WinCls O CicLoaderWndClass
WinCls O CicMarshalWndClass
WinCls X Progman