[HP Photosmart Premier 快速启动 ]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\HP Photosmart Premier 快速启动 .lnk --> C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [Hewlett-Packard Development Company, L.P.]><N>
[update]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\update.exe --> [N/A]><N>
[IRDFQ1O24]
<C:\Documents and Settings\xuwen\「开始」菜单\程序\启动\IRDFQ1O24.exe --> [N/A]><H>
特殊特权被允许: SeLoadDriverPrivilege [PID = 316, C:\WINDOWS\SYSTEM32\F47SO86Z2.SCR]
特殊特权被允许: SeSystemtimePrivilege [PID = 316, C:\WINDOWS\SYSTEM32\F47SO86Z2.SCR]
特殊特权被允许: SeLoadDriverPrivilege [PID = 396, C:\WINDOWS\SYSTEM32\F47SO86Z2.SCR]
特殊特权被允许: SeSystemtimePrivilege [PID = 396, C:\WINDOWS\SYSTEM32\F47SO86Z2.SCR]
特殊特权被允许: SeSystemtimePrivilege [PID = 2564, C:\WINDOWS\SYSTEM32\CONIME.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2564, C:\WINDOWS\SYSTEM32\CONIME.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2564, C:\WINDOWS\SYSTEM32\CONIME.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3116, C:\WINDOWS\SYSTEM32\MOUSIE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3116, C:\WINDOWS\SYSTEM32\MOUSIE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3116, C:\WINDOWS\SYSTEM32\MOUSIE.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3156, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3156, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3156, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3200, C:\PROGRAM FILES\HP\QUICKPLAY\QPSERVICE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3200, C:\PROGRAM FILES\HP\QUICKPLAY\QPSERVICE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3200, C:\PROGRAM FILES\HP\QUICKPLAY\QPSERVICE.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3248, C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3248, C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3248, C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3256, C:\PROGRAM FILES\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3256, C:\PROGRAM FILES\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3256, C:\PROGRAM FILES\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 3264, C:\PROGRAM FILES\TENCENT\QQLIVE\MINIQQLIVE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3264, C:\PROGRAM FILES\TENCENT\QQLIVE\MINIQQLIVE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3264, C:\PROGRAM FILES\TENCENT\QQLIVE\MINIQQLIVE.EXE]
API HOOK
入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x00EC1FFD)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x00EC20E5)
入口点错误:FreeLibrary (危险等级: 高, 被下面模块所HOOK: 0x5F00002D)
自己看看这些是什么??

我看不出来!