进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2568, C:\WINDOWS\MHOTKEY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2568, C:\WINDOWS\MHOTKEY.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2632, C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 6\DRAGTODISC\DRGTODSC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2632, C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 6\DRAGTODISC\DRGTODSC.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2644, C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 6\AUDIOCENTRAL\RXMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2644, C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 6\AUDIOCENTRAL\RXMON.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2688, C:\PROGRAM FILES\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2688, C:\PROGRAM FILES\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2808, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2808, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2824, C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 6\AUDIOCENTRAL\PLAYLIST.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2824, C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 6\AUDIOCENTRAL\PLAYLIST.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2940, C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQTRA08.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2940, C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQTRA08.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2952, C:\PROGRAM FILES\FLVPLAYER\FLVPLAYER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2952, C:\PROGRAM FILES\FLVPLAYER\FLVPLAYER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3088, C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSTE08.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3088, C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSTE08.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3332, C:\PROGRAM FILES\HP\DIGITAL IMAGING\PRODUCT ASSISTANT\BIN\HPRBLOG.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3332, C:\PROGRAM FILES\HP\DIGITAL IMAGING\PRODUCT ASSISTANT\BIN\HPRBLOG.EXE]

==================================
API HOOK
入口点错误:CreateProcessA (危险等级: 高,  被下面模块所HOOK: 0x00E81FFD)
入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: 0x00E820E5)

==================================
隐藏进程
N/A

==================================


[/CODE]