==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
C:\WINDOWS\system32\TcpIpDog0.dll(, N/A)
MSAFD Tcpip [UDP/IP]
C:\WINDOWS\system32\TcpIpDog0.dll(, N/A)
MSAFD Tcpip [RAW/IP]
C:\WINDOWS\system32\TcpIpDog0.dll(, N/A)
RSVP UDP Service Provider
C:\WINDOWS\system32\TcpIpDogR0.dll(, N/A)
RSVP TCP Service Provider
C:\WINDOWS\system32\TcpIpDogR0.dll(, N/A)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 www.3448.com
127.0.0.1 www.4199.com
127.0.0.1 www.7255.com
127.0.0.1 www.allxun.com
127.0.0.1 www.feixue.net
127.0.0.1 4199.com
127.0.0.1 www.4199.com
127.0.0.1 06.jacai.com
127.0.0.1 www.my123.com
127.0.0.1 www.piaoxue.com
127.0.0.1 about-blank.cc
127.0.0.1 www.ooooos.com
127.0.0.1 8749.com
127.0.0.1 www.8749.com
127.0.0.1 www.souxse.cn
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 420, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 560, C:\WINDOWS\SOUNDMAN.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1820, D:\系统文件\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1820, D:\系统文件\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2244, D:\系统文件\MAGICSET\SRIECLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3308, D:\DR.COM宽带认证客户端3.39\ISHARE_USER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2776, D:\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3820, D:\THUNDER\COMPONENTS\INMEDIA\THUNDERMINISITE.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]