%systemroot%\ShellNew\ElnorB.exe
C:\Documents and Settings\用户名\「开始」菜单\程序\启动\ Empty.pif
C:\Documents and Settings\用户名\Local Settings\Application Data\smss.exe
C:\Documents and Settings\用户名\Local Settings\Application Data\csrss.exe
C:\Documents and Settings\用户名\Local Settings\Application Data\winlogon.exe
C:\Documents and Settings\用户名\Local Settings\Application Data\inetinfo.exe
C:\Documents and Settings\用户名\Templates\bararontok.com
……