[C:\应用工具\WangWang\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762]
[C:\应用工具\WangWang\AliViewMedia.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 2]
[C:\应用工具\WangWang\VideoCap.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 4]
[C:\应用工具\WangWang\VLAudio.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 5]
[C:\应用工具\WangWang\JsmShow.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 4]
[C:\应用工具\WangWang\AliSkin.dll] [阿里巴巴软件(上海)有限公司, 1.0.0.1]
[C:\应用工具\WangWang\PngLib.dll] [阿里巴巴软件(上海)有限公司, 1, 0, 0, 1]
[C:\应用工具\WangWang\zlib.dll] [, 1.2.3]
[C:\应用工具\WangWang\ww_network.dll] [阿里巴巴软件(上海)有限公司, 1, 0, 2, 2]
[C:\Program Files\360safe\safemon\safemon.dll] [, 3, 6, 1, 1001]
[C:\应用工具\WangWang\Ali_Res.DLL] [N/A, ]
[C:\WINDOWS\system32\w2pxdrv.dll] [Proxy Labs, 3, 0, 2, 0]
[C:\应用工具\WangWang\WangWangX4.dll] [阿里巴巴软件(上海)有限公司, 1, 0, 0, 1]
[C:\应用工具\WangWang\RICHED32.DLL] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\应用工具\WangWang\RICHED20.dll] [Microsoft Corporation, 5.30.23.1221]
[C:\应用工具\WangWang\RichOne.dll] [阿里巴巴软件(上海)有限公司, 1.0.0.1]
[C:\应用工具\WangWang\TBProgress.dll] [阿里巴巴软件(上海)有限公司, 1.0.0.1]
[C:\应用工具\WangWang\MessageNotify.dll] [, 1, 0, 0, 1]
[C:\应用工具\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
PROXYCAP MSAFD Tcpip [TCP/IP]
w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP MSAFD Tcpip [UDP/IP]
w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP RSVP UDP Service Provider
w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP RSVP TCP Service Provider
w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP LSP
w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2004, C:\PROGRAM FILES\NIKON\WIRELESS CAMERA SETUP UTILITY\NKPTPENUM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2584, C:\PROGRAM FILES\JAVA\JRE1.5.0\BIN\JUSCHED.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2628, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2628, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2636, C:\PROGRAM FILES\SAMSUNG\SAMSUNG EDS\EDSAGENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2668, C:\PROGRAM FILES\SAMSUNG\SAMSUNG BATTERY MANAGER\BATTERYMANAGER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2700, C:\PROGRA~1\CYBERL~1\INSTAN~1\WIN2K\IBURN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2732, C:\PROGRAM FILES\SAMSUNG\AVSTATION PREMIUM 3.75\AVSAGENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2744, C:\PROGRAM FILES\SAMSUNG\SAMSUNG RECOVERY SOLUTION II\WCSCHEDULER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2812, C:\PROGRAM FILES\SAMSUNG\EASY DISPLAY MANAGER\DMHKCORE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2840, C:\应用工具\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2884, C:\应用工具\RISING\RAV\RAVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2900, C:\PROGRAM FILES\SAMSUNG\MAGICKBD\MAGICKBD.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2916, C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2916, C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2944, C:\PROGRAM FILES\SAMSUNG\MAGICKBD\PERFORMANCEMANAGER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2860, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2860, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2896, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2896, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3824, C:\应用工具\迅雷\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3172, C:\应用工具\WANGWANG\WANGWANG.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]