==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[C:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\打开(&O)\command=setup.exe
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeSystemtimePrivilege [PID = 1468, C:\WINDOWS\SYSTEM32\RESETSERVICE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2036, C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\POINT32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2036, C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\POINT32.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2044, C:\WINDOWS\VM_STI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2044, C:\WINDOWS\VM_STI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 192, F:\CYBERLINK DVD\POWERDVD\PDVDSERV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 192, F:\CYBERLINK DVD\POWERDVD\PDVDSERV.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2868, C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2868, C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 444, F:\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 444, F:\THUNDER\PROGRAM\THUNDER5.EXE]
==================================
API HOOK
RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
==================================
隐藏进程
N/A
==================================