C:\WINDOWS\SYSTEM32\CPWMON2K.DLL
C:\WINDOWS\SYSTEM32\DWMONNT.DLL
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\PDFPORTS.DLL
C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\DISTILLR\ADISTRES.DLL
C:\WINDOWS\SYSTEM32\RC4MON.DLL
C:\WINDOWS\SYSTEM32\RPNV2MON.DLL
C:\WINDOWS\SYSTEM32\RPNV2JOB.DLL
C:\WINDOWS\SYSTEM32\RPNV2EN.DLL
C:\WINDOWS\SYSTEM32\PMOBSERVINP.DLL
C:\WINDOWS\SYSTEM32\WFXMNT40.DLL
C:\WINDOWS\SYSTEM32\WFXMNTHQ.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DWPP.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\WFXPNT40.DLL
C:\WINDOWS\PMCOMMON.DLL
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\WINFAX\WFXSEH32.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\INTERNET EXPLORER\MUI\0404\BROWSELC.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\MUI\0404\SHDOCLC.DLL
C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\WINDOWS\SYSTEM32\MNMSRVC.EXE
C:\PROGRAM FILES\LOTUS\NOTES\NTMULTI.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\OFFICESCAN NT\NTRTSCAN.EXE
C:\OFFICESCAN NT\OFCDOG.DLL
C:\OFFICESCAN NT\OFCPLUGINAPI.DLL
C:\OFFICESCAN NT\TIMESTRING.DLL
C:\OFFICESCAN NT\OFCPIPC.DLL
C:\OFFICESCAN NT\OFCPLUGINMAIN.DLL
C:\OFFICESCAN NT\OFCPLUGINTRAY.DLL
C:\OFFICESCAN NT\TMLISTEN.EXE
C:\OFFICESCAN NT\TMSOCK.DLL
C:\OFFICESCAN NT\LOADHTTP.DLL
C:\OFFICESCAN NT\OFCPLUGINAPI.DLL
C:\OFFICESCAN NT\OFCPIPC.DLL
C:\OFFICESCAN NT\LIBTMCAV.DLL
C:\OFFICESCAN NT\PWD.DLL
C:\OFFICESCAN NT\OFCDOG.DLL
C:\OFFICESCAN NT\TMDBG20.DLL
C:\OFFICESCAN NT\OFCPLUGINMAIN.DLL
C:\OFFICESCAN NT\OFCPLUGINTRAY.DLL
C:\OFFICESCAN NT\TMUPDATE.DLL
C:\WINDOWS\SYSTEM32\WFXSVC.EXE
C:\OFFICESCAN NT\OFCPFWSVC.EXE
C:\OFFICESCAN NT\OFCPFWCOMMON.DLL
C:\OFFICESCAN NT\ZLIB.DLL
C:\OFFICESCAN NT\OFCPIPC.DLL
C:\OFFICESCAN NT\TMDBG20.DLL
C:\OFFICESCAN NT\TMCFWAPI.DLL
C:\PROGRAM FILES\WINFAX\WFXMOD32.EXE
C:\PROGRAM FILES\WINFAX\DCCDA32I.DLL
C:\PROGRAM FILES\WINFAX\DCCUTILI.DLL
C:\PROGRAM FILES\WINFAX\WFXUT32I.DLL
C:\PROGRAM FILES\WINFAX\RTFCTL32.DLL
C:\PROGRAM FILES\WINFAX\WFXIIF32.DLL
C:\PROGRAM FILES\WINFAX\WFXVW32I.DLL
C:\PROGRAM FILES\WINFAX\SENGINE.DLL
C:\PROGRAM FILES\WINFAX\WFXUTILU.DLL
C:\PROGRAM FILES\WINFAX\DCCUTILC.DLL
C:\PROGRAM FILES\WINFAX\WFXUT32C.DLL
C:\PROGRAM FILES\WINFAX\DCCTBP32.DLL
C:\PROGRAM FILES\WINFAX\SCTRL.DLL
C:\PROGRAM FILES\WINFAX\DCCRES32.DLL
C:\PROGRAM FILES\WINFAX\WFXRES32.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\USERINIT.EXE
C:\WINDOWS\SYSTEM32\WUAUCLT.EXE
C:\PROGRAM FILES\LOTUS\NOTES\NLNOTES.EXE
C:\PROGRAM FILES\LOTUS\NOTES\NNOTESWS.DLL
C:\PROGRAM FILES\LOTUS\NOTES\NNOTES.DLL
C:\PROGRAM FILES\LOTUS\NOTES\NXMLPAR.DLL
C:\PROGRAM FILES\LOTUS\NOTES\NXMLCOMMON.DLL
C:\PROGRAM FILES\LOTUS\NOTES\JS32.DLL
C:\PROGRAM FILES\LOTUS\NOTES\NLSCCSTR.DLL
C:\PROGRAM FILES\LOTUS\NOTES\NDGTS.DLL
C:\PROGRAM FILES\LOTUS\NOTES\LTOUIN22.DLL
C:\PROGRAM FILES\LOTUS\NOTES\NPLUGINS.DLL
C:\PROGRAM FILES\LOTUS\NOTES\NSTRINGS.DLL
C:\PROGRAM FILES\LOTUS\NOTES\NAMHOOK.DLL
C:\PROGRAM FILES\LOTUS\NOTES\SMLNPWX.DLL
C:\PROGRAM FILES\LOTUS\NOTES\NTCP.DLL
C:\PROGRAM FILES\LOTUS\NOTES\NSTCLIENTU.DLL
C:\PROGRAM FILES\LOTUS\NOTES\NIMUIU.DLL
C:\PROGRAM FILES\LOTUS\NOTES\MUI\ZH-TW\NIMUIRES.DLL.MUI
C:\DOCUMENTS AND SETTINGS\ADMIN.KS\DESKTOP\RSDETECT.EXE
Standard Autorun Registry Items
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WinFaxAppPortStarter = WFXSNT40.EXE
WFXSwtch = C:\PROGRA~1\WINFAX\WFXSWTCH.EXE
PHIMETIPSYNC = C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSYNC
MplSetUp = C:\PROGRAM FILES\RMCLIENT\MPLSETUP.EXE
JobHisInit = C:\PROGRAM FILES\RMCLIENT\JOBHISINIT.EXE
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
IMJPMIG9.0 = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /PRELOAD /MIGRATION32
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
IMEKRMIG6.1 = C:\WINDOWS\IME\IMKR6_1\IMEKRMIG.EXE
CJIMETIPSYNC = C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSYNC
OfficeScanNT Monitor = "C:\OFFICESCAN NT\PCCNTMON.EXE" -HIDEWINDOW
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE