回复:新病毒?木马?
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2316, C:\PROGRAM FILES\OEM\ACCESSRUNNER ADSL\CNXDSLTB.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2316, C:\PROGRAM FILES\OEM\ACCESSRUNNER ADSL\CNXDSLTB.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2260, E:\迅雷\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2260, E:\迅雷\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1628, C:\WINDOWS\SYSTEM32\GGGG38.EXE]
特殊特权被允许: SeSystemtimePrivilege [PID = 1628, C:\WINDOWS\SYSTEM32\GGGG38.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3996, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.948\SRENGLDR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3996, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.948\SRENGLDR.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]