N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 3632, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3632, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3672, C:\PROGRAM FILES\YAHOO!\ASSISTANT\YASSISTSE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3672, C:\PROGRAM FILES\YAHOO!\ASSISTANT\YASSISTSE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3724, C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\POINT32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3724, C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\POINT32.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3784, C:\PROGRAM FILES\HTIME\HTIME.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3784, C:\PROGRAM FILES\HTIME\HTIME.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1528, C:\DOCUME~1\TIGER\LOCALS~1\TEMP\RTKBTMNT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1528, C:\DOCUME~1\TIGER\LOCALS~1\TEMP\RTKBTMNT.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3296, C:\PROGRAM FILES\CHINA MOBILE\FETION\VMDOTNET\V2.0.50727\FETIONVM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3296, C:\PROGRAM FILES\CHINA MOBILE\FETION\VMDOTNET\V2.0.50727\FETIONVM.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 192, C:\PROGRAM FILES\TENCENT\QQGAME\QQGAME.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 192, C:\PROGRAM FILES\TENCENT\QQGAME\QQGAME.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 4184, C:\PROGRAM FILES\THUNDER NETWORK\THUNDERMINI\PROGRAM\THUNDERMINI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 4184, C:\PROGRAM FILES\THUNDER NETWORK\THUNDERMINI\PROGRAM\THUNDERMINI.EXE]
==================================
API HOOK
入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003D42F5)
入口点错误:NtWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003D4395)
入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003D42F5)
入口点错误:ZwWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003D4395)
入口点错误:CreateProcessA (危险等级: 高, 被下面模块所HOOK: 0x00FE1FFD)
入口点错误:CreateProcessW (危险等级: 高, 被下面模块所HOOK: 0x00FE20E5)
==================================
隐藏进程
N/A
==================================
[/CODE]