[C:\应用工具\WangWang\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\应用工具\WangWang\AliViewMedia.dll]  [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 2]
    [C:\应用工具\WangWang\VideoCap.dll]  [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 4]
    [C:\应用工具\WangWang\VLAudio.dll]  [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 5]
    [C:\应用工具\WangWang\JsmShow.dll]  [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 4]
    [C:\应用工具\WangWang\AliSkin.dll]  [阿里巴巴软件(上海)有限公司, 1.0.0.1]
    [C:\应用工具\WangWang\PngLib.dll]  [阿里巴巴软件(上海)有限公司, 1, 0, 0, 1]
    [C:\应用工具\WangWang\zlib.dll]  [, 1.2.3]
    [C:\应用工具\WangWang\ww_network.dll]  [阿里巴巴软件(上海)有限公司, 1, 0, 2, 2]
    [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 6, 1, 1001]
    [C:\应用工具\WangWang\Ali_Res.DLL]  [N/A, ]
    [C:\WINDOWS\system32\w2pxdrv.dll]  [Proxy Labs, 3, 0, 2, 0]
    [C:\应用工具\WangWang\WangWangX4.dll]  [阿里巴巴软件(上海)有限公司, 1, 0, 0, 1]
    [C:\应用工具\WangWang\RICHED32.DLL]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\应用工具\WangWang\RICHED20.dll]  [Microsoft Corporation, 5.30.23.1221]
    [C:\应用工具\WangWang\RichOne.dll]  [阿里巴巴软件(上海)有限公司, 1.0.0.1]
    [C:\应用工具\WangWang\TBProgress.dll]  [阿里巴巴软件(上海)有限公司, 1.0.0.1]
    [C:\应用工具\WangWang\MessageNotify.dll]  [, 1, 0, 0, 1]
    [C:\应用工具\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
PROXYCAP MSAFD Tcpip [TCP/IP]
    w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP MSAFD Tcpip [UDP/IP]
    w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP RSVP UDP Service Provider
    w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP RSVP TCP Service Provider
    w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP LSP
    w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2004, C:\PROGRAM FILES\NIKON\WIRELESS CAMERA SETUP UTILITY\NKPTPENUM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2584, C:\PROGRAM FILES\JAVA\JRE1.5.0\BIN\JUSCHED.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2628, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2628, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2636, C:\PROGRAM FILES\SAMSUNG\SAMSUNG EDS\EDSAGENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2668, C:\PROGRAM FILES\SAMSUNG\SAMSUNG BATTERY MANAGER\BATTERYMANAGER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2700, C:\PROGRA~1\CYBERL~1\INSTAN~1\WIN2K\IBURN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2732, C:\PROGRAM FILES\SAMSUNG\AVSTATION PREMIUM 3.75\AVSAGENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2744, C:\PROGRAM FILES\SAMSUNG\SAMSUNG RECOVERY SOLUTION II\WCSCHEDULER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2812, C:\PROGRAM FILES\SAMSUNG\EASY DISPLAY MANAGER\DMHKCORE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2840, C:\应用工具\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2884, C:\应用工具\RISING\RAV\RAVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2900, C:\PROGRAM FILES\SAMSUNG\MAGICKBD\MAGICKBD.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2916, C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2916, C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2944, C:\PROGRAM FILES\SAMSUNG\MAGICKBD\PERFORMANCEMANAGER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2860, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2860, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2896, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2896, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3824, C:\应用工具\迅雷\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3172, C:\应用工具\WANGWANG\WANGWANG.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]