托盘处的动作是弹出(Eject),与卸载驱动(Uninstall)有根本不同。选择Eject动作后,通常后启动一个rundll32进程,执行hotplug.dll中的函数...
000007fe`fa8c5f20 hotplug!HotPlugEjectDevice = <no type information>000007fe`fa8c1270 hotplug!_imp_CM_Request_Device_Eject_ExW = <no type information>000007fe`fa8c40ac hotplug!HotPlugWarmEjectVetoedW = <no type information>000007fe`fa8c5f30 hotplug!HotPlugEjectDeviceEx = <no type information>000007fe`fa8c31d8 hotplug!AddEjectToRemoval = <no type information>000007fe`fa8c5db8 hotplug!HotPlugEjectDeviceStub = <no type information>000007fe`fa8c5df4 hotplug!HotPlugEjectDeviceAsync = <no type information>000007fe`fa8c5c68 hotplug!HotPlugEjectDeviceBase = <no type information>000007fe`fa8c4034 hotplug!HotPlugEjectVetoedW = <no type information>
多年前的事了,有点不记得了,找个注册表监视工具,然后插个U盘到系统...这就说来话长了,要慢慢积累经验
不必客气