第一批
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\PROGRAM FILES\GEMPLUS\GEMSAFE LIBRARIES\BIN\RRMSVR.EXE
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\BTHCRP.DLL
C:\WINDOWS\SYSTEM32\WIDCOMMSDK.DLL
C:\WINDOWS\SYSTEM32\WBTAPI.DLL
C:\WINDOWS\SYSTEM32\CNAB4LMK.DLL
C:\WINDOWS\SYSTEM32\CNAB4SMK.DLL
C:\WINDOWS\SYSTEM32\CNAB4PTU.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\WINDOWS\SYSTEM32\EBPMON2.DLL
C:\WINDOWS\SYSTEM32\ZLHP1018.DLL
C:\WINDOWS\SYSTEM32\ZLM.DLL
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\XRXW1LMK.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\IMFPRINT.DLL
C:\WINDOWS\SYSTEM32\IMF32.DLL
C:\WINDOWS\SYSTEM32\ZTAG32.DLL
C:\WINDOWS\SYSTEM32\ZSPOOL.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\WINDOWS\SYSTEM32\CNAB4EMU.DLL
C:\WINDOWS\SYSTEM32\SCARDSVR.EXE
C:\PROGRAM FILES\RISING\RAV\RAVSTUB.EXE
C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\GEMPLUS\GEMSAFE LIBRARIES\BIN\REGTOOL.EXE
C:\PROGRAM FILES\GEMPLUS\GEMSAFE LIBRARIES\BIN\GWSCM.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\GEMPLUS\GEMSAFE LIBRARIES\BIN\GEMPPM.DLL
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\PROGRAM FILES\GEMPLUS\COMMON\RESOURCES\LOCHUB.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\PROGRAM FILES\GEMPLUS\GEMSAFE LIBRARIES\BIN\GHIDWSC.DLL
C:\PROGRAM FILES\GEMPLUS\GEMSAFE LIBRARIES\BIN\RRM.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACPRFMGRSVC.EXE
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACLOCSETTINGS.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACPRFMGR.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACCRYPTHLPR.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACHELPER.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACON.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACLOCMIGRATOR.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\THINQCON.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\WEBTHUNDER.EXE
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\TASKMANAGER.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\DOWNLOAD_INTERFACE.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\STLPORT_VC646.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\ASYN_DNS.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\STREAMMEDIALIB.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\AL.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\XLDC.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\BD.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\REGISTERDLL.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\CACHESERVER.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\XLSAFE\SAFEINFO.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\XLSAFE\RMFSCAN.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\XLNET.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\DOWNANDPLAY\WEBDOWNANDPLAY.DLL
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\XLSTATISTIC\XLSTATISTICADDIN.DLL
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\PROGRAM FILES\THINKPAD\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACNOTIFY.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACSVCSTUB.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACLOCSETTINGS.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACHELPER.DLL
C:\WINDOWS\SYSTEM32\ATI2EVXX.DLL
C:\WINDOWS\SYSTEM32\PSQLPWD.DLL
C:\PROGRAM FILES\THINKVANTAGE FINGERPRINT SOFTWARE\INFRA.DLL
C:\PROGRAM FILES\THINKVANTAGE FINGERPRINT SOFTWARE\HOMEFUS2.DLL
C:\WINDOWS\SYSTEM32\BIOLOGON.DLL
C:\PROGRAM FILES\THINKVANTAGE FINGERPRINT SOFTWARE\HOMEPASS.DLL
C:\PROGRAM FILES\THINKVANTAGE FINGERPRINT SOFTWARE\BIO.DLL
C:\PROGRAM FILES\THINKVANTAGE FINGERPRINT SOFTWARE\REMOTE.DLL
C:\PROGRAM FILES\THINKVANTAGE FINGERPRINT SOFTWARE\PS2CSS.DLL
C:\WINDOWS\SYSTEM32\TPHKLOCK.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\PSQLPWD.DLL
C:\PROGRAM FILES\THINKVANTAGE FINGERPRINT SOFTWARE\INFRA.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\THINKVANTAGE FINGERPRINT SOFTWARE\HOMEFUS2.DLL
C:\PROGRAM FILES\NGSRV\NGSLOTD.EXE
C:\PROGRAM FILES\NGSRV\SLOTMON\HIDMON_GD.DLL
C:\PROGRAM FILES\NGSRV\SLOTMON\SCARDMON.DLL
C:\WINDOWS\SYSTEM32\WUAUCLT.EXE
C:\WINDOWS\SYSTEM32\WUPS2.DLL
C:\WINDOWS\SYSTEM32\IBMPMSVC.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EDXX.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WUPS2.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\REGSRVC.EXE
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\EVTENG.EXE
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\PSREGAPI.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\TRACEAPI.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24EVMON.EXE
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\TRACEAPI.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\PSREGAPI.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\LIBEAY32.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\INTSTNGS.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\IWMSPROV.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACSVC.EXE
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACLOCSETTINGS.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACPRFMGR.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACCRYPTHLPR.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACHELPER.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACON.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACSVCHLPR.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACADAPTERSINFO.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ANCA.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ANC.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACSVCSTUB.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACGOLAN.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\PFMGRAPI.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\TRACEAPI.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\PSREGAPI.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\DBENGINE.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\LIBEAY32.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\INTSTNGS.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\MUROCAPI.DLL
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24MUDLL.DLL
G:\RSDETECT.EXE
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\PROGRAM FILES\THINKPAD\BLUETOOTH SOFTWARE\BTTRAY.EXE
C:\WINDOWS\SYSTEM32\WBTAPI.DLL
C:\WINDOWS\SYSTEM32\BTOSIF.DLL
C:\WINDOWS\SYSTEM32\BTWHIDCS.DLL
C:\PROGRAM FILES\THINKPAD\BLUETOOTH SOFTWARE\BTBALLOON.DLL
C:\WINDOWS\SYSTEM32\BTREZ.DLL
C:\WINDOWS\SYSTEM32\CSH.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\THINKPAD\BLUETOOTH SOFTWARE\BTKEYIND.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\WINDOWS\SYSTEM32\ATI2EDXX.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\PROGRA~1\THINKPAD\UTILIT~1\PWRMGRTR.DLL
C:\PROGRA~1\THINKPAD\UTILIT~1\SC\PWRMGRRT.DLL
C:\PROGRA~1\THINKPAD\UTILIT~1\PWRMGRIF.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\WEBTHUNDERBHO_NOW.DLL
C:\PROGRAM FILES\360SAFE\SAFEMON\SAFEMON.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE
C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RFW\RFWCTRL.DLL
C:\PROGRAM FILES\RISING\RFW\RSXML.DLL
C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACTRAY.EXE
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACLOCSETTINGS.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACGUIHLPR.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACSVCSTUB.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACHELPER.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACPRFMGR.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACCRYPTHLPR.DLL
C:\WINDOWS\SYSTEM32\MFC71U.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\RES\SC\GUIHLPRRES.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\RES\SC\TRAYRES.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACWLICON.EXE
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACLOCSETTINGS.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACGUIHLPR.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACSVCSTUB.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACHELPER.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACPRFMGR.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACCRYPTHLPR.DLL
C:\WINDOWS\SYSTEM32\MFC71U.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\RES\SC\GUIHLPRRES.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\RES\SC\ICONRES.DLL
C:\PROGRA~1\THINKPAD\UTILIT~1\EZEJMNAP.EXE
C:\PROGRA~1\THINKPAD\UTILIT~1\SC\EZMAPRES.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\PROGRA~1\LENOVO\PKGMGR\HOTKEY\TPHKMGR.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\OEMDSPIF.DLL
C:\PROGRA~1\LENOVO\PKGMGR\HOTKEY\TPFNF7.DLL
C:\PROGRAM FILES\LENOVO\PKGMGR\HOTKEY\TPONSCR.EXE
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\PROGRA~1\THINKPAD\UTILIT~1\PWRMGRTR.DLL
C:\PROGRA~1\THINKPAD\UTILIT~1\SC\PWRMGRRT.DLL
C:\PROGRA~1\THINKPAD\UTILIT~1\PWRMGRIF.DLL
C:\WINDOWS\SYSTEM32\OEMDSPIF.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\PROGRAM FILES\LENOVO\PKGMGR\HOTKEY_1\TPSCREX.EXE
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\PROGRAM FILES\THINKVANTAGE\AMSG\AMSG.EXE
C:\PROGRAM FILES\THINKVANTAGE\AMSG\AHLPRUNL.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\PROGRA~1\THINKV~1\AMSG\ACPPOLLINGENGINE.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\PROGRAM FILES\ANALOG DEVICES\CORE\SMAX4PNP.EXE
C:\PROGRAM FILES\ANALOG DEVICES\CORE\SMWDMIF.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRA~1\THINKV~1\PRDCTR\LPMGR.EXE
C:\PROGRA~1\THINKV~1\PRDCTR\SC\LPRESMGR.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MFC71U.DLL
C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\RES\SC\TRAYRES.DLL
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\WINDOWS\SYSTEM32\SYNCOM.DLL
C:\WINDOWS\SYSTEM32\SYNTPAPI.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\PROGRA~1\STORMII\STORMSET.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
C:\PROGRAM FILES\HEWLETT-PACKARD\ORDERREMINDER\ORDERREMINDER.EXE
C:\WINDOWS\SYSTEM32\CNAB4RPK.EXE
C:\PROGRAM FILES\NGSRV\EP2K_CERTD.EXE
C:\WINDOWS\SYSTEM32\EP2PK11.DLL
C:\WINDOWS\SYSTEM32\SYNTPFCS.DLL
C:\WINDOWS\SYSTEM32\UNISPIM.IME
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
TrackPointSrv = TP4SERV.EXE
ACTray = C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACTRAY.EXE
ACWLIcon = C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\ACWLICON.EXE
EZEJMNAP = C:\PROGRA~1\THINKPAD\UTILIT~1\EZEJMNAP.EXE
TPHOTKEY = C:\PROGRA~1\LENOVO\PKGMGR\HOTKEY\TPHKMGR.EXE
igfxtray = C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
igfxhkcmd = C:\WINDOWS\SYSTEM32\HKCMD.EXE
igfxpers = C:\WINDOWS\SYSTEM32\IGFXPERS.EXE
PWRMGRTR = RUNDLL32 C:\PROGRA~1\THINKPAD\UTILIT~1\PWRMGRTR.DLL,PWRMGRBKGNDMONITOR
BLOG = RUNDLL32 C:\PROGRA~1\THINKPAD\UTILIT~1\BATLOGEX.DLL,STARTBATTLOG
AMSG = C:\PROGRAM FILES\THINKVANTAGE\AMSG\AMSG.EXE
SoundMAXPnP = C:\PROGRAM FILES\ANALOG DEVICES\CORE\SMAX4PNP.EXE
LPManager = C:\PROGRA~1\THINKV~1\PRDCTR\LPMGR.EXE
BluetoothAuthenticationAgent = RUNDLL32.EXE BTHPROPS.CPL,,BLUETOOTHAUTHENTICATIONAGENT
SynTPLpr = C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
SynTPEnh = C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
PSQLLauncher = "C:\PROGRAM FILES\THINKVANTAGE FINGERPRINT SOFTWARE\LAUNCHER.EXE" /STARTUP
Storm2Set = C:\WINDOWS\SYSTEM32\RUNDLL32.EXE "C:\PROGRA~1\STORMII\STORMSET.DLL",CHECKENV
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
RfwMain = "C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP
OrderReminder = C:\PROGRAM FILES\HEWLETT-PACKARD\ORDERREMINDER\ORDERREMINDER.EXE
ep2k_certd = C:\PROGRAM FILES\NGSRV\EP2K_CERTD.EXE -R
gemstrmw = C:\WINDOWS\SYSTEM32\GEMSTRMW.EXE /R
MenuOrder = C:\PROGRAM FILES\ICBCCO~1\ICBC\GEMPLUS(CORP)\MENUORDER\MENUORDER.EXE
Gemplus Reader Resource Manager = C:\PROGRAM FILES\GEMPLUS\GEMSAFE LIBRARIES\BIN\RRMSVR.EXE
RegTool = C:\PROGRAM FILES\GEMPLUS\GEMSAFE LIBRARIES\BIN\REGTOOL.EXE
WebThunder = C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\WEBTHUNDER.EXE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = C:\WINDOWS\SYSTEM32\DLLCACHE\soundman.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde