c盘
C:\boot\ghos\1key_su.exe PE_PARITE.A
C:\boot\ghos\Ghostexp.exe PE_PARITE.A
C:\boot\ghos\gho_cfg.exe PE_PARITE.A
C:\boot\ghos\gho_run.exe PE_PARITE.A
C:\Documents and Settings\linhongwei\Application Data\Microsoft\Installer\{219412F0-378E-4B8D-8770-AE3D4E4544DC}\NewShortcut11_219412F0378E4B8D8770AE3D4E4544DC.exe PE_PARITE.A
C:\Documents and Settings\linhongwei\Application Data\Microsoft\Installer\{219412F0-378E-4B8D-8770-AE3D4E4544DC}\NewShortcut1_219412F0378E4B8D8770AE3D4E4544DC.exe PE_PARITE.A
C:\Documents and Settings\linhongwei\Local Settings\Temp\qac1A.tmp PE_PARITE.A-O
C:\Documents and Settings\linhongwei\Local Settings\Temporary Internet Files\Content.IE5\IF8TIT2L\WindowsXP-KB835935-SP2-CHS[1].exe PE_PARITE.A
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig708\CHS\instmsiw.exe PE_PARITE.A
C:\Program Files\AvRack\avrack.exe PE_PARITE.A
C:\Program Files\Common Files\InstallShield\Driver\10\Intel 32\IDriver.exe PE_PARITE.A
C:\Program Files\Common Files\InstallShield\Driver\10\Intel 32\IDriver2.exe PE_PARITE.A
C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\IKernel.exe PE_PARITE.A
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe PE_PARITE.A
C:\Program Files\Common Files\Microsoft Shared\Equation\EQNEDT32.EXE PE_PARITE.A
C:\Program Files\Common Files\Microsoft Shared\MSSearch\Bin\SrchAdmStp.exe PE_PARITE.A
C:\Program Files\Common Files\Microsoft Shared\Office10\DW.EXE PE_PARITE.A
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe PE_PARITE.A
C:\Program Files\Common Files\VMware\VMware Virtual Machine Importer\gnu\gzip.exe PE_PARITE.A
C:\Program Files\Common Files\VMware\VMware Virtual Machine Importer\exe2cab.exe PE_PARITE.A
C:\Program Files\Common Files\VMware\VMware Virtual Machine Importer\extract.exe PE_PARITE.A
C:\Program Files\Messenger\msmsgs.exe PE_PARITE.A
C:\Program Files\Messenger\msmsgsin.exe PE_PARITE.A
C:\Program Files\MSN\MSNCoreFiles\Setup\msnunin.exe PE_PARITE.A
C:\Program Files\MSN\MSNCoreFiles\copymar.exe PE_PARITE.A
C:\Program Files\MSN\MSNCoreFiles\dw.exe PE_PARITE.A
C:\Program Files\MSN\MSNCoreFiles\msn6.exe PE_PARITE.A
C:\Program Files\MSN\MSNCoreFiles\update.exe PE_PARITE.A
C:\Program Files\MSN Messenger\dw.exe PE_PARITE.A
C:\Program Files\MSN Messenger\msnmsgr.exe PE_PARITE.A
C:\Program Files\Vimicro\VM301B\Driver AutoInstall\Action Files\AfterCopy.exe PE_PARITE.A
C:\Program Files\Vimicro\VM301B\Driver AutoInstall\Action Files\BeforeRemove.exe PE_PARITE.A
C:\Program Files\Vimicro\VM301B\Driver AutoInstall\Driver Files\amcap.exe PE_PARITE.A
C:\Program Files\Vimicro\VM301B\Driver AutoInstall\Driver Files\StillCap.exe PE_PARITE.A
C:\Program Files\Vimicro\VM301B\Driver AutoInstall\Driver Files\vidcap32.Exe PE_PARITE.A
C:\Program Files\Vimicro\VM301B\Driver AutoInstall\Driver Files\VMCap.exe PE_PARITE.A
C:\Program Files\Vimicro\VM301B\Driver AutoInstall\Driver Files\Vm_sti.exe PE_PARITE.A
C:\Program Files\Windows Media Player\Installer\microsoft media player 9.exe PE_PARITE.A
C:\Program Files\Windows Media Player\migrate.exe PE_PARITE.A
C:\Program Files\Windows NT\hypertrm.exe PE_PARITE.A
C:\WINDOWS\AU_Backup\2\268435712\backup.000 PE_PARITE.A
C:\WINDOWS\Downloaded Program Files\dwusplay.exe PE_PARITE.A
C:\WINDOWS\LastGood\SOUNDMAN.EXE PE_PARITE.A
C:\WINDOWS\LastGood.Tmp\System32\wuauclt1.exe PE_PARITE.A
C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdllreg.exe PE_PARITE.A
C:\WINDOWS\SoftwareDistribution\Download\e9b0377463edd4b6480f6148a1f88bac\WindowsXP-KB842773-v2-x86-enu.exe PE_PARITE.A
C:\WINDOWS\system32\BLiveUp\0\bg_AJJL.exe PE_PARITE.A
C:\WINDOWS\system32\BLiveUp\0\set9991.exe PE_PARITE.A
C:\WINDOWS\system32\BLiveUp\0\UpWizardQM.exe PE_PARITE.A
C:\WINDOWS\system32\BLiveUp\0\xdzk.exe PE_PARITE.A
C:\WINDOWS\system32\IME\Unispim\instupim.exe PE_PARITE.A
C:\WINDOWS\system32\IME\Unispim\isearch.exe PE_PARITE.A
C:\WINDOWS\system32\IME\Unispim\unins000.exe PE_PARITE.A
C:\WINDOWS\system32\IME\Unispim\upcfgwiz5.exe PE_PARITE.A
C:\WINDOWS\system32\IME\Unispim\upimcfg5.exe PE_PARITE.A
C:\WINDOWS\system32\IME\Unispim\upimrad.exe PE_PARITE.A
C:\WINDOWS\system32\IME\Unispim\uwadd.exe PE_PARITE.A
C:\WINDOWS\system32\IME\Unispim\wlbackup.exe PE_PARITE.A
C:\WINDOWS\system32\IME\Unispim\wlimport.exe PE_PARITE.A
C:\WINDOWS\system32\IME\Unispim\wlman.exe PE_PARITE.A
C:\WINDOWS\system32\IME\Unispim\wlmerge.exe PE_PARITE.A
C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe PE_PARITE.A
C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe PE_PARITE.A
C:\WINDOWS\system32\cliconfg.exe PE_PARITE.A
C:\WINDOWS\system32\clspack.exe PE_PARITE.A
C:\WINDOWS\system32\dxdllreg.exe PE_PARITE.A
C:\WINDOWS\system32\jdbgmgr.exe PE_PARITE.A
C:\WINDOWS\system32\jview.exe PE_PARITE.A
C:\WINDOWS\system32\keystone.exe PE_PARITE.A
C:\WINDOWS\system32\migpwd.exe PE_PARITE.A
C:\WINDOWS\system32\netsetup.exe PE_PARITE.A
C:\WINDOWS\system32\nvappbar.exe PE_PARITE.A
C:\WINDOWS\system32\nvcolor.exe PE_PARITE.A
C:\WINDOWS\system32\nvdspsch.exe PE_PARITE.A
C:\WINDOWS\system32\nvudisp.exe PE_PARITE.A
C:\WINDOWS\system32\NVUNINST.EXE PE_PARITE.A
C:\WINDOWS\system32\nwiz.exe PE_PARITE.A
C:\WINDOWS\system32\uninstall.exe PE_PARITE.A
C:\WINDOWS\system32\UnregSkyPfw.exe PE_PARITE.A
C:\WINDOWS\system32\vmnat.exe PE_PARITE.A
C:\WINDOWS\system32\vmnetdhcp.exe PE_PARITE.A
C:\WINDOWS\system32\wjview.exe PE_PARITE.A
C:\WINDOWS\system32\wuauclt1.exe PE_PARITE.A
C:\WINDOWS\Temp\aoa1.tmp PE_PARITE.A-O
C:\WINDOWS\Temp\doa1.tmp PE_PARITE.A-O
C:\WINDOWS\Temp\eoa1.tmp PE_PARITE.A-O
C:\WINDOWS\Temp\lla1.tmp PE_PARITE.A-O
C:\WINDOWS\Temp\lua2.tmp PE_PARITE.A-O
C:\WINDOWS\Temp\mjh124.tmp PE_PARITE.A-O
C:\WINDOWS\Temp\myh125.tmp PE_PARITE.A-O
C:\WINDOWS\Temp\qoa1.tmp PE_PARITE.A-O
C:\WINDOWS\Temp\soundman.exe PE_PARITE.A
C:\WINDOWS\alcrmv.exe PE_PARITE.A
C:\WINDOWS\alcupd.exe PE_PARITE.A
C:\WINDOWS\amcap.exe PE_PARITE.A
C:\WINDOWS\iun6002.exe PE_PARITE.A
C:\WINDOWS\PATCH.EXE PE_PARITE.A
C:\WINDOWS\runtsckl.exe PE_PARITE.A
C:\WINDOWS\setdebug.exe PE_PARITE.A
C:\WINDOWS\SOUNDMAN.EXE PE_PARITE.A
C:\WINDOWS\StillCap.exe PE_PARITE.A
C:\WINDOWS\unvise32.exe PE_PARITE.A
C:\WINDOWS\UNWISE.EXE PE_PARITE.A
C:\WINDOWS\vidcap32.Exe PE_PARITE.A
C:\WINDOWS\VMCap.exe PE_PARITE.A
C:\WINDOWS\Vm_sti.exe PE_PARITE.A