[CODE] 2009-03-05,18:19:52 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows 2000 Professional Service Pack 4 (Build 2195) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows 2000 Publisher] [(Verified)Google Inc] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher, E=""] [Conexant Systems Inc.] <"D:\Program Files\Rising\AntiSpyware\rstray.exe" /startup> [(Verified)Beijing Rising Information Technology Corporation Limited] <"D:\Program Files\Rising\Rav\RsTray.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows 2000 Publisher] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] [(Verified)Microsoft Windows 2000 Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <"%SystemRoot%\system32\shmgrate.exe" OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <自定义浏览器> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <"%SystemRoot%\system32\shmgrate.exe" OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6A5110B5-E14B-4268-A065-EF89FF33C325}] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] <%SystemRoot%\system32\updcrl.exe -e -u %SystemRoot%\system32\verisignpub1.crl> [File is missing] ================================== 启动文件夹 N/A ================================== 服务 [Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start] [Google Update Service (gupdate1c8f7a7e2e72f70) / gupdate1c8f7a7e2e72f70][Stopped/Auto Start] <"D:\Program Files\Google\Update\GoogleUpdate.exe" /svc> [Google Updater Service / gusvc][Stopped/Manual Start] <"D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"> [Rav Process Communication Center / RavCCenter][Stopped/Auto Start] [Rising RavTask Manager / RavTask][Running/Auto Start] <"D:\Program Files\Rising\Rav\RavTask.exe" RavTask> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] [Rising Scan Service / RsScanSrv][Stopped/Auto Start] ================================== 驱动程序 [Service for Avance AC97 Audio (WDM) / ALCXWDM][Running/Manual Start] [Conexant AccessRunner USB ADSL LAN Adapter Filter Driver / CnxEtP][Running/Manual Start] [Conexant AccessRunner USB ADSL Interface Device Driver / CnxEtU][Running/Manual Start] [Conexant AccessRunner USB ADSL LAN Adapter Driver / CnxTgN][Running/Manual Start] [dmboot / dmboot][Stopped/Disabled] [Logical Disk Manager Driver / dmio][Running/Boot Start] <\SystemRoot\System32\drivers\dmio.sys> [dmload / dmload][Running/Boot Start] <\SystemRoot\System32\drivers\dmload.sys> [hookcont / hookcont][Running/System Start] [hooksys / hooksys][Running/System Start] [i81x / i81x][Running/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [WAN Miniport (PPP over Ethernet Protocol) / RMSPPPOE][Running/Manual Start] [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> ================================== 浏览器加载项 [IeCatch5 Class] {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [Google Toolbar Helper] {AA58ED58-01DD-4d91-8333-CF10577473F7} [gFlash Class] {F156768E-81EF-470C-9057-481BA8380DBA} [@shdoclc.dll,-866] {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, > [FlashGet] {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} [@msdxmLC.dll,-1@2052,电台(&R)] {8E718888-423F-11D2-876E-00A0C9082467} [&Google] {2318C2B1-4965-11d4-9B18-009027A5CD4F} [FlashGet Bar] {E0E899AB-F487-11D5-8D29-0050BA6940E3} [WUWebControl Class] {6414512B-B978-451D-A0D8-FCFDF33E833C} [MUWebControl Class] {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [AxSubmitControl Class] {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [使用网际快车下载] [使用网际快车下载全部链接] ================================== 正在运行的进程 [PID: 136][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601] [PID: 164][\??\D:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601] [PID: 184][\??\D:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6970] [D:\WINNT\system32\sfc.dll] [Microsoft Corporation, 5.00.2195.6673] [PID: 212][D:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2195.6700] [D:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3] [PID: 224][D:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.6902] [PID: 412][D:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1] [PID: 436][D:\WINNT\system32\spoolsv.exe] [Microsoft Corporation, 5.00.2195.7059] [D:\WINNT\system32\sfc.dll] [Microsoft Corporation, 5.00.2195.6673] [PID: 468][D:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1] [PID: 636][D:\WINNT\System32\WBEM\WinMgmt.exe] [Microsoft Corporation, 1.50.1085.0100] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [PID: 696][D:\Program Files\Google\Update\GoogleUpdate.exe] [Google Inc., 1.2.131.7] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [D:\Program Files\Google\Update\1.2.141.5\goopdate.dll] [Google Inc., 1.2.141.5] [PID: 792][D:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1] [D:\WINNT\system32\sfc.dll] [Microsoft Corporation, 5.00.2195.6673] [D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.60] [D:\WINNT\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\WINNT\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [PID: 828][D:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1] [PID: 872][D:\Program Files\Rising\Rav\rsnetsvr.exe] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 14] [D:\Program Files\Rising\Rav\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.9] [D:\Program Files\Rising\Rav\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [D:\Program Files\Rising\Rav\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [D:\Program Files\Rising\Rav\ProcComm.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46] [D:\WINNT\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [D:\WINNT\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [PID: 1032][D:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [D:\WINNT\system32\igfxpph.dll] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\igfxdev.dll] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\igfxres.dll] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1757] [D:\PROGRA~1\FLASHGET\jccatch.dll] [FlashGet, 1, 1, 5, 0] [D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.60] [D:\WINNT\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\WINNT\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\Program Files\WinRAR\rarext.dll] [N/A, ] [D:\WINNT\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12] [PID: 1240][D:\WINNT\system32\igfxtray.exe] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [D:\WINNT\system32\igfxdev.dll] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\igfxres.dll] [Intel Corporation, 3,0,0,1757] [PID: 1256][D:\WINNT\system32\hkcmd.exe] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [D:\WINNT\system32\igfxdev.dll] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\igfxhk.dll] [Intel Corporation, 3,0,0,1757] [D:\WINNT\system32\igfxres.dll] [Intel Corporation, 3,0,0,1757] [PID: 1264][D:\WINNT\SOUNDMAN.EXE] [Avance Logic, Inc., 5, 0, 0, 0] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [PID: 1272][D:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe] [Conexant Systems Inc., 2.099.060.000] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [D:\Program Files\Conexant\AccessRunner ADSL\CnxDslWz.dll] [Conexant Systems Inc., 2.099.060.000] [D:\WINNT\system32\CnxHwIo.dll] [Conexant Systems Inc., 2.099.060.000] [PID: 1280][D:\Program Files\Rising\AntiSpyware\rstray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.16] [D:\Program Files\Rising\AntiSpyware\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11] [D:\Program Files\Rising\AntiSpyware\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [D:\Program Files\Rising\AntiSpyware\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [D:\Program Files\Rising\AntiSpyware\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.31] [D:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [D:\Program Files\Rising\AntiSpyware\rscommon.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.1.1] [D:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [D:\Program Files\Rising\AntiSpyware\pngdll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [D:\Program Files\Rising\AntiSpyware\runiep.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.42] [D:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11] [D:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Program Files\Rising\AntiSpyware\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Program Files\Rising\AntiSpyware\pscan.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.60] [D:\Program Files\Rising\AntiSpyware\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [PID: 1296][D:\WINNT\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [PID: 1304][D:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe] [Google Inc., 1, 2, 1128, 5462] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [D:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\res_en.dll] [Google Inc., 1, 2, 1128, 5462] [D:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\swg.dll] [Google Inc., 1, 2, 1128, 5462] [PID: 896][D:\WINNT\system32\wuauclt.exe] [Microsoft Corporation, 7.2.6001.788 (winmain_oob/wu_wsuswlc(wmbla).081016-1330)] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [D:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [D:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [PID: 1060][C:\Downloads\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [PID: 1628][C:\Downloads\sreng2\SREe67cc9fa.EXE] [Smallfrogs Studio, 2.7.0.1210] [D:\WINNT\system32\kmon.dll] [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 33] [D:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [D:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [D:\WINNT\system32\sfc.dll] [Microsoft Corporation, 5.00.2195.6673] [C:\Downloads\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT Error. [D:\WINNT\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [D:\WINNT\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 1272, D:\PROGRAM FILES\CONEXANT\ACCESSRUNNER ADSL\CNXDSLTB.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1060, C:\DOWNLOADS\SRENG2\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK 入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: 0x00C959CD) 入口点错误:NtCreateKey (危险等级: 高, 被下面模块所HOOK: 0x00C95B6D) 入口点错误:NtLoadDriver (危险等级: 高, 被下面模块所HOOK: 0x00C962BD) 入口点错误:NtSetValueKey (危险等级: 高, 被下面模块所HOOK: 0x00C95C3D) 入口点错误:NtWriteFile (危险等级: 高, 被下面模块所HOOK: 0x00C95A9D) 入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: 0x00C959CD) 入口点错误:ZwCreateKey (危险等级: 高, 被下面模块所HOOK: 0x00C95B6D) 入口点错误:ZwSetValueKey (危险等级: 高, 被下面模块所HOOK: 0x00C95C3D) 入口点错误:ZwWriteFile (危险等级: 高, 被下面模块所HOOK: 0x00C95A9D) 入口点错误:CreateServiceA (危险等级: 高, 被下面模块所HOOK: 0x00C95F7D) 入口点错误:CreateServiceW (危险等级: 高, 被下面模块所HOOK: 0x00C9604D) 入口点错误:LoadLibraryA (危险等级: 高, 被下面模块所HOOK: 0x00C96C7D) 入口点错误:LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: 0x00C9584D) 入口点错误:CreateFileW (危险等级: 高, 被下面模块所HOOK: 0x00C9679D) 入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x00C96BAD) 入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x00C96A0D) ================================== 隐藏进程 N/A ================================== [/CODE]