.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[F:\]
[AUTORUN]
ShellExecute=Info.exe protect.ed 480 480
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1584, C:\PROGRAM FILES\HEWLETT-PACKARD\HP QUICK LAUNCH BUTTONS\QLBCTRL.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1644, C:\WINDOWS\SMINST\SCHEDULER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1668, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1700, C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1964, C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2024, C:\WINDOWS\MSMSGS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 220, C:\PROGRAM FILES\WIDCOMM\BLUETOOTH SOFTWARE\BTTRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 596, C:\PROGRAM FILES\WIDCOMM\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2452, C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]