[WOW]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\WOW
1_Name=cmdline
1_Value=%SystemRoot%\system32\ntvdm.exe -o
1_Filename=C:\WINDOWS\SYSTEM32\NTVDM.EXE
1_FileSize=393216
1_FileDate=2003-3-15 8:00:00
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SYSTEM\CurrentControlSet\Control\WOW
2_Name=wowcmdline
2_Value=%SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386
2_Filename=C:\WINDOWS\SYSTEM32\NTVDM.EXE
2_FileSize=393216
2_FileDate=2003-3-15 8:00:00
Max=2
[ShellExecuteHooks]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
1_Name={AEB6717E-7E19-11d0-97EE-00C04FD91972}
1_ClsidName=URL 执行挂钩
1_FileName=C:\WINDOWS\System32\shell32.dll
1_FileSize=8194048
1_FileDate=2003-3-15 8:00:00
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
2_Name={D157330A-9EF3-49F8-9A67-4141AC41ADD4}
2_ClsidName=CnsHook Class
2_FileName=C:\WINDOWS\downlo~1\cnshook.dll
2_FileSize=77824
2_FileDate=2006-10-16 16:03:40
Max=2
[ShellService
ObjectDelayLoad]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
1_Name=PostBootReminder
1_Value={7849596a-48ea-486e-8937-a2a3009f31a9}
1_ClsidName=PostBootReminder 对象
1_FileName=%SystemRoot%\system32\SHELL32.dll
1_FileSize=8194048
1_FileDate=2003-3-15 8:00:00
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
2_Name=CDBurn
2_Value={fbeb8a05-beee-4442-804e-409d6c4515e9}
2_ClsidName=烧 CD 的 ShellFolder
2_FileName=%SystemRoot%\system32\SHELL32.dll
2_FileSize=8194048
2_FileDate=2003-3-15 8:00:00
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
3_Name=WebCheck
3_Value={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
3_ClsidName=WebCheck
3_FileName=%SystemRoot%\System32\webcheck.dll
3_FileSize=247296
3_FileDate=2003-3-15 8:00:00
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
4_Name=SysTray
4_Value={35CEC8A3-2BE6-11D2-8773-92E220524153}
4_ClsidName=SysTray
4_FileName=C:\WINDOWS\System32\st
object.dll
4_FileSize=117248
4_FileDate=2003-3-15 8:00:00
Max=4
[SharedTaskScheduler]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
1_Name={438755C2-A8BA-11D1-B96B-00A0C90312E1}
1_Value=Browseui 预加载程序
1_FileName=%SystemRoot%\System32\browseui.dll
1_FileSize=1021952
1_FileDate=2003-3-15 8:00:00
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
2_Name={8C7461EF-2B13-11d2-BE35-3078302C2030}
2_Value=组件类别缓存程序
2_FileName=%SystemRoot%\System32\browseui.dll
2_FileSize=1021952
2_FileDate=2003-3-15 8:00:00
Max=2
[ProtocolDefaults]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
1_Name=http
1_Value=3
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
2_Name=https
2_Value=3
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
3_Name=ftp
3_Value=3
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
4_Name=file
4_Value=3
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
5_Name=@ivt
5_Value=1
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
6_Name=shell
6_Value=0
Max=6
[BootExecute]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\Session Manager
1_Name=BootExecute
1_Value=autocheck autochk *
Max=1
[AutoRun]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=Software\Microsoft\Windows\CurrentVersion\Run
1_Name=IMJPMIG8.1
1_Value=; "c:\windows\ime\imjp8_1\imjpmig.exe" /spoil /remadvdef /migration32
1_FileSize=208953
1_FileDate=2003-3-15 8:00:00
1_FileVersion=8.1.4005.0
2_HKey=HKEY_LOCAL_MACHINE
2_Key=Software\Microsoft\Windows\CurrentVersion\Run
2_Name=PHIME2002ASync
2_Value=; c:\windows\system32\ime\tintlgnt\tintsetp.exe /sync
2_FileSize=455168
2_FileDate=2003-3-15 8:00:00
2_FileVersion=5.2.0.2801
3_HKey=HKEY_LOCAL_MACHINE
3_Key=Software\Microsoft\Windows\CurrentVersion\Run
3_Name=PHIME2002A
3_Value=; c:\windows\system32\ime\tintlgnt\tintsetp.exe /imename
3_FileSize=455168
3_FileDate=2003-3-15 8:00:00
3_FileVersion=5.2.0.2801
4_HKey=HKEY_LOCAL_MACHINE
4_Key=Software\Microsoft\Windows\CurrentVersion\Run
4_Name=ATIPTA
4_Value=; c:\program files\ati technologies\ati control panel\atiptaxx.exe
4_FileSize=344064
4_FileDate=2004-9-29 7:15:00
4_FileVersion=6.14.10.5125
5_HKey=HKEY_LOCAL_MACHINE
5_Key=Software\Microsoft\Windows\CurrentVersion\Run
5_Name=TkBellExe
5_Value="c:\program files\common files\real\update_ob\realsched.exe" -osboot
5_FileSize=180269
5_FileDate=2006-9-14 13:11:07
5_FileVersion=0.1.0.3510
6_HKey=HKEY_LOCAL_MACHINE
6_Key=Software\Microsoft\Windows\CurrentVersion\Run
6_Name=KernelFaultCheck
6_Value=%systemroot%\system32\dumprep 0 -k
7_HKey=HKEY_LOCAL_MACHINE
7_Key=Software\Microsoft\Windows\CurrentVersion\Run
7_Name=桌面图标文字自动透明
7_Value=e:\program files\wom\winmem.exe xp
7_FileSize=198144
7_FileDate=2004-3-7 17:37:38
7_FileVersion=2.9.4.307
8_HKey=HKEY_LOCAL_MACHINE
8_Key=Software\Microsoft\Windows\CurrentVersion\Run
8_Name=RavTask
8_Value="c:\program files\rising\rav\ravtask.exe" -system
8_FileSize=114688
8_FileDate=2006-10-18 17:57:56
8_FileVersion=18.0.0.22
9_HKey=HKEY_LOCAL_MACHINE
9_Key=Software\Microsoft\Windows\CurrentVersion\Run
9_Name=RfwMain
9_Value="c:\program files\rising\rfw\rfwmain.exe" -startup
9_FileSize=417792
9_FileDate=2006-10-17 18:48:30
9_FileVersion=4.0.0.52
10_HKey=HKEY_LOCAL_MACHINE
10_Key=Software\Microsoft\Windows\CurrentVersion\Run
10_Name=yassistse
10_Value="c:\progra~1\yahoo!\assistant\yassistse.exe"
10_FileSize=73728
10_FileDate=2006-9-13 21:27:36
10_FileVersion=3.0.2.1003
11_HKey=HKEY_LOCAL_MACHINE
11_Key=Software\Microsoft\Windows\CurrentVersion\RunServices
11_Name=RavMon
11_Value=c:\program files\rising\rav\ravmon.exe /auto
11_FileSize=610304
11_FileDate=2006-10-18 18:02:07
11_FileVersion=18.0.1.33
12_HKey=HKEY_LOCAL_MACHINE
12_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
12_Name=Nice
12_Value=c:\program files\common files\microsoft shared\msinfo\rehtemp.exe
12_FileSize=6814
12_FileDate=2006-10-23 22:56:26
12_FileVersion=
13_HKey=HKEY_LOCAL_MACHINE
13_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
13_Name=load
13_Value=
14_HKey=HKEY_LOCAL_MACHINE
14_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
14_Name=run
14_Value=
15_HKey=HKEY_CURRENT_USER
15_Key=Software\Microsoft\Windows\CurrentVersion\Run
15_Name=ctfmon.exe
15_Value=c:\windows\system32\ctfmon.exe
15_FileSize=13312
15_FileDate=2003-3-15 8:00:00
15_FileVersion=5.1.2600.1106
16_HKey=HKEY_CURRENT_USER
16_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
16_Name=load
16_Value=
17_HKey=HKEY_CURRENT_USER
17_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
17_Name=run
17_Value=
Max=17