==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 200, C:\WINNT\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 228, C:\WINNT\SYSTEM32\SERVICES.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 240, C:\WINNT\SYSTEM32\LSASS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 472, C:\WINNT\SYSTEM32\SPOOLSV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 528, C:\PROGRAM FILES\COMMON FILES\EPSON\EEBAPI\EEBSVC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 540, C:\PROGRAM FILES\EPSONNET\COMMON\BIN\ENSRVMGR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 564, C:\WINNT\SYSTEM32\SVCHOST.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 584, C:\PROGRAM FILES\EPSONNET\COMMON\BIN\EMWCHSRV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 592, C:\WINNT\SYSTEM32\HIDSERV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 608, C:\KAV6\KAVSVC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 636, C:\PROGRAM FILES\PANASONIC\TRAPMONITOR\TRAPMNNT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 652, C:\WINNT\QQUPDATE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 660, C:\WINNT\SYSTEM32\REGSVC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 988, C:\WINNT\SYSTEM32\MSTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1084, C:\WINNT\SYSTEM32\WBEM\WINMGMT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1096, C:\PROGRAM FILES\REALVNC\VNC4\WINVNC4.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1132, C:\WINNT\SYSTEM32\SVCHOST.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1144, C:\PROGRAM FILES\NETGEAR\NETGEAR STORAGE CENTRAL MANAGER UTILITY\Z-SANSERVICE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1152, C:\PROGRAM FILES\EPSONNET\EPSONNET SOAP SERVER\BIN\EMSOAPRR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1172, C:\WINNT\SYSTEM32\SVCHOST.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1192, C:\PROGRAM FILES\EPSONNET\EPSONNET WEB PAGES SERVICE\BIN\EWPSRR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1200, C:\PROGRAM FILES\EPSONNET\COMMON\BIN\EMALMMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1224, C:\PROGRAM FILES\EPSONNET\EPSONNET HTTP SERVER\BIN\APACHE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1284, C:\PROGRAM FILES\EPSONNET\EPSONNET HTTP SERVER\BIN\APACHE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2392, C:\WINNT\EXPLORER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2512, C:\WINNT\LOGI_MWX.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2536, C:\KAV6\KULANSYN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2544, C:\KAV6\KPOPMON.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2552, C:\KAV6\KAVPFW.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2552, C:\KAV6\KAVPFW.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2592, C:\KAV6\KWATCHUI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2600, C:\PROGRAM FILES\ANALOG DEVICES\CORE\SMAX4PNP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 644, C:\WINNT\SYSTEM32\INTERNAT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2576, C:\PROGRAM FILES\KINGSOFT\KSYSCLEANER\KASSTART.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2648, C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2684, C:\PROGRAM FILES\JAVA\JRE1.5.0\BIN\JUSCHED.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2612, C:\KAV6\MAILMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2612, C:\KAV6\MAILMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 572, C:\KAV6\KAVPLUS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3476, C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 300, C:\WINNT\SYSTEM32\WISPTIS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 276, C:\PROGRAM FILES\ADOBE\ADOBE ILLUSTRATOR CS2\SUPPORT FILES\CONTENTS\WINDOWS\ILLUSTRATOR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3372, C:\DOCUME~1\USER~1.USE\LOCALS~1\TEMP\ADOBELM_CLEANUP.0001]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3440, C:\PROGRAM FILES\COMMON FILES\ADOBE SYSTEMS SHARED\SERVICE\ADOBELMSVC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3428, C:\DOCUME~1\USER~1.USE\LOCALS~1\TEMP\ADOBELM_CLEANUP.0001]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3344, C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE]
==================================
API HOOK
入口点错误:LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: C:\KAV6\KMailFun.dll)
==================================
隐藏进程
N/A
==================================
[/CODE]