**** Run Keys ****
RUN: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
RUN: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
RUN: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
RUN: [TrackPointSrv] tp4serv.exe
RUN: [AGRSMMSG] AGRSMMSG.exe
RUN: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
RUN: [TPHOTKEY] d:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
RUN: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
RUN: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
RUN: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
RUN: [TP4EX] tp4ex.exe
RUN: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
RUN: [vptray] D:\PROGRA~1\SYMANT~1\VPTray.exe
RUN: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
RUN: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
RUN: [msnmsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
RUN: [MSMSGS] ; "C:\Program Files\Messenger\msmsgs.exe" /background
**** Browser Helper
Objects ****
BHO: [] D:\PROGRA~1\SPYBOT~1\SDHelper.dll
**** IE Toolbars ****
**** IE Extensions ****
IEExt: [更新 ThinkPad 软件] d:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
IEExt: [FlashGet] D:\Program Files\FlashGet\flashget.exe
IEExt: [Messenger] C:\Program Files\Messenger\msmsgs.exe
**** Hosts File Entries ****
HOSTS: 127.0.0.1 localhost
HOSTS: 127.0.0.1 localhost
**** IE Settings ****
IEProxy: 10.76.32.2:80
IEBypass: 10.*;*.dg.cnpc.com.cn;<local>
Default Page: http://www.microsoft.com/windows/ie_intl/cn/start/
Default Search: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Local Page:
about:blank
Search Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
**** IE Context Menu (Right click) ****
IEContext: [使用网际快车下载] D:\Program Files\FlashGet\jc_link.htm
IEContext: [使用网际快车下载全部链接] D:\Program Files\FlashGet\jc_all.htm
**** Layered Service Providers ****
LSP: MSAFD Irda [IrDA]
LSP: MSAFD Tcpip [TCP/IP]
LSP: MSAFD Tcpip [UDP/IP]
LSP: RSVP UDP Service Provider
LSP: RSVP TCP Service Provider
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DBA77A-529A-4AC9-A790-B79976534E0B}] SEQPACKET 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DBA77A-529A-4AC9-A790-B79976534E0B}] DATAGRAM 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{40852D4C-EB40-497C-8B8B-892D90573311}] SEQPACKET 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{40852D4C-EB40-497C-8B8B-892D90573311}] DATAGRAM 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{834062C8-6D69-42AD-9F55-6118F77DB16C}] SEQPACKET 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{834062C8-6D69-42AD-9F55-6118F77DB16C}] DATAGRAM 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4D347E2D-15AB-421C-9D51-6AE02BE357DC}] SEQPACKET 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4D347E2D-15AB-421C-9D51-6AE02BE357DC}] DATAGRAM 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8E827227-AF6D-4501-B174-B17EB443872C}] SEQPACKET 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8E827227-AF6D-4501-B174-B17EB443872C}] DATAGRAM 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{07D81F1F-6A1F-4BEA-990A-F035390F122E}] SEQPACKET 5
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{07D81F1F-6A1F-4BEA-990A-F035390F122E}] DATAGRAM 5
**** Blocked Control Panel Items ****
BLOCKED: [ncpa.cpl] No
BLOCKED: [odbccp32.cpl] No
**** Downloaded Program Files ****
{6414512B-B978-451D-A0D8-FCFDF33E833C} [http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139565127956] C:\WINDOWS\system32\wuweb.dll
{D27CDB6E-AE6D-11CF-96B8-444553540000} [http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab]
{D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} [http://navs.dg.cnpc.com.cn/webinst/webinst.cab]
**** Windows Services ****
[Alerter] %SystemRoot%\system32\svchost.exe -k LocalService
[ALG] %SystemRoot%\System32\alg.exe
[AppMgmt] %SystemRoot%\system32\svchost.exe -k netsvcs
[AudioSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
[BITS] %SystemRoot%\system32\svchost.exe -k netsvcs
[Browser] %SystemRoot%\system32\svchost.exe -k netsvcs
[ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
[ccPwdSvc] "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"
[ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
[CiSvc] %SystemRoot%\system32\cisvc.exe
[ClipSrv] %SystemRoot%\system32\clipsrv.exe
[COMSysApp] C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
[CryptSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[DcomLaunch] %SystemRoot%\system32\svchost -k DcomLaunch
[DefWatch] "D:\Program Files\Symantec AntiVirus\DefWatch.exe"
[Dhcp] %SystemRoot%\system32\svchost.exe -k netsvcs
[dmadmin] %SystemRoot%\System32\dmadmin.exe /com
[dmserver] %SystemRoot%\System32\svchost.exe -k netsvcs
[Dnscache] %SystemRoot%\system32\svchost.exe -k NetworkService
[ERSvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[Eventlog] %SystemRoot%\system32\services.exe
[EventSystem] C:\WINDOWS\system32\svchost.exe -k netsvcs
[FastUserSwitchingCompatibility] %SystemRoot%\System32\svchost.exe -k netsvcs
[helpsvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[HidServ] %SystemRoot%\System32\svchost.exe -k netsvcs
[HTTPFilter] %SystemRoot%\System32\svchost.exe -k HTTPFilter
[IBMPMSVC] %SystemRoot%\system32\ibmpmsvc.exe
[ImapiService] C:\WINDOWS\system32\imapi.exe
[Irmon] %SystemRoot%\system32\svchost.exe -k netsvcs
[lanmanserver] %SystemRoot%\system32\svchost.exe -k netsvcs
[lanmanworkstation] %SystemRoot%\system32\svchost.exe -k netsvcs
[LmHosts] %SystemRoot%\system32\svchost.exe -k LocalService
[Messenger] %SystemRoot%\system32\svchost.exe -k netsvcs
[mnmsrvc] C:\WINDOWS\system32\mnmsrvc.exe
[MSDTC] C:\WINDOWS\system32\msdtc.exe
[MSIServer] C:\WINDOWS\system32\msiexec.exe /V
[NetDDE] %SystemRoot%\system32\netdde.exe
[NetDDEdsdm] %SystemRoot%\system32\netdde.exe
[Netlogon] %SystemRoot%\system32\lsass.exe
[Netman] %SystemRoot%\System32\svchost.exe -k netsvcs
[NetSvc] C:\Program Files\Intel\NCS\Sync\NetSvc.exe
[Nla] %SystemRoot%\system32\svchost.exe -k netsvcs
[NtLmSsp] %SystemRoot%\system32\lsass.exe
[NtmsSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[PlugPlay] %SystemRoot%\system32\services.exe
[PolicyAgent] %SystemRoot%\system32\lsass.exe
[ProtectedStorage] %SystemRoot%\system32\lsass.exe
[QCONSVC] System32\QCONSVC.EXE
[RasAuto] %SystemRoot%\system32\svchost.exe -k netsvcs
[RasMan] %SystemRoot%\system32\svchost.exe -k netsvcs
[RDSessMgr] C:\WINDOWS\system32\sessmgr.exe
[RemoteAccess] %SystemRoot%\system32\svchost.exe -k netsvcs
[RemoteRegistry] %SystemRoot%\system32\svchost.exe -k LocalService
[rpcapd] "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini"
[RpcLocator] %SystemRoot%\system32\locator.exe
[RpcSs] %SystemRoot%\system32\svchost -k rpcss
[RSVP] %SystemRoot%\system32\rsvp.exe
[SamSs] %SystemRoot%\system32\lsass.exe
[SavRoam] "D:\Program Files\Symantec AntiVirus\SavRoam.exe"
[SCardSvr] %SystemRoot%\System32\SCardSvr.exe
[Schedule] %SystemRoot%\System32\svchost.exe -k netsvcs
[seclogon] %SystemRoot%\System32\svchost.exe -k netsvcs
[SENS] %SystemRoot%\system32\svchost.exe -k netsvcs
[SharedAccess] %SystemRoot%\system32\svchost.exe -k netsvcs