[ShellService
ObjectDelayLoad]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
1_Name=PostBootReminder
1_Value={7849596a-48ea-486e-8937-a2a3009f31a9}
1_ClsidName=PostBootReminder 对象
1_FileName=%SystemRoot%\system32\SHELL32.dll
1_FileSize=8311296
1_FileDate=2006-7-13 21:34:56
1_FileVersion=6.0.2900.2951
1_FileCompanyName=Microsoft Corporation
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
2_Name=CDBurn
2_Value={fbeb8a05-beee-4442-804e-409d6c4515e9}
2_ClsidName=烧 CD 的 ShellFolder
2_FileName=%SystemRoot%\system32\SHELL32.dll
2_FileSize=8311296
2_FileDate=2006-7-13 21:34:56
2_FileVersion=6.0.2900.2951
2_FileCompanyName=Microsoft Corporation
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
3_Name=WebCheck
3_Value={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
3_ClsidName=WebCheck
3_FileName=%SystemRoot%\system32\webcheck.dll
3_FileSize=265728
3_FileDate=2004-8-7
3_FileVersion=6.0.2900.2180
3_FileCompanyName=Microsoft Corporation
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
4_Name=SysTray
4_Value={35CEC8A3-2BE6-11D2-8773-92E220524153}
4_ClsidName=SysTray
4_FileName=C:\WINDOWS\system32\st
object.dll
4_FileSize=121344
4_FileDate=2004-8-7
4_FileVersion=5.1.2600.2180
4_FileCompanyName=Microsoft Corporation
Max=4
[SharedTaskScheduler]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
1_Name={438755C2-A8BA-11D1-B96B-00A0C90312E1}
1_Value=Browseui 预加载程序
1_FileName=%SystemRoot%\system32\browseui.dll
1_FileSize=1016832
1_FileDate=2004-8-7
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
2_Name={8C7461EF-2B13-11d2-BE35-3078302C2030}
2_Value=组件类别缓存程序
2_FileName=%SystemRoot%\system32\browseui.dll
2_FileSize=1016832
2_FileDate=2004-8-7
Max=2
[ProtocolDefaults]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
1_Name=http
1_Value=3
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
2_Name=https
2_Value=3
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
3_Name=ftp
3_Value=3
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
4_Name=file
4_Value=3
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
5_Name=@ivt
5_Value=1
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
6_Name=shell
6_Value=0
Max=6
[BootExecute]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\Session Manager
1_Name=BootExecute
1_Value=autocheck autochk *
Max=1
[Startup]
1_LnkFile=C:\Documents and Settings\All Users\「开始」菜单\程序\启动\WanSo.lnk
1_ExeFile=WanSo
Max=1
[AutoRun]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=Software\Microsoft\Windows\CurrentVersion\Run
1_Name=IMJPMIG8.1
1_Value="c:\windows\ime\imjp8_1\imjpmig.exe" /spoil /remadvdef /migration32
1_FileSize=208952
1_FileDate=2004-8-7 8:00:00
1_FileVersion=8.1.4202.0
1_FileCompanyName=Microsoft Corporation
2_HKey=HKEY_LOCAL_MACHINE
2_Key=Software\Microsoft\Windows\CurrentVersion\Run
2_Name=PHIME2002ASync
2_Value=c:\windows\system32\ime\tintlgnt\tintsetp.exe /sync
2_FileSize=455168
2_FileDate=2004-8-7 8:00:00
2_FileVersion=5.2.0.2801
2_FileCompanyName=Microsoft Corporation
3_HKey=HKEY_LOCAL_MACHINE
3_Key=Software\Microsoft\Windows\CurrentVersion\Run
3_Name=PHIME2002A
3_Value=c:\windows\system32\ime\tintlgnt\tintsetp.exe /imename
3_FileSize=455168
3_FileDate=2004-8-7 8:00:00
3_FileVersion=5.2.0.2801
3_FileCompanyName=Microsoft Corporation
4_HKey=HKEY_LOCAL_MACHINE
4_Key=Software\Microsoft\Windows\CurrentVersion\Run
4_Name=SiSPower
4_Value=rundll32.exe sispower.dll,modeagent
4_FileSize=49152
4_FileDate=2006-5-5 21:13:40
4_FileVersion=6.14.10.3740
4_FileCompanyName=Silicon Integrated Systems Corporation
5_HKey=HKEY_LOCAL_MACHINE
5_Key=Software\Microsoft\Windows\CurrentVersion\Run
5_Name=SoundMan
5_Value=soundman.exe
5_FileSize=577536
5_FileDate=2006-1-11 15:08:36
5_FileVersion=5.1.0.51
5_FileCompanyName=Realtek Semiconductor Corp.
6_HKey=HKEY_LOCAL_MACHINE
6_Key=Software\Microsoft\Windows\CurrentVersion\Run
6_Name=FASTKEY
6_Value=c:\program files\lenovo\功能键盘\hotkeyb.exe
6_FileSize=86016
6_FileDate=2005-11-7 9:35:52
6_FileVersion=2.2.0.1
6_FileCompanyName=联想电脑公司
7_HKey=HKEY_LOCAL_MACHINE
7_Key=Software\Microsoft\Windows\CurrentVersion\Run
7_Name=TkBellExe
7_Value="c:\program files\common files\real\update_ob\realsched.exe" -osboot
7_FileSize=180269
7_FileDate=2006-7-14 17:08:24
7_FileVersion=0.1.0.3208
7_FileCompanyName=RealNetworks, Inc.
8_HKey=HKEY_LOCAL_MACHINE
8_Key=Software\Microsoft\Windows\CurrentVersion\Run
8_Name=StormCodec_Helper
8_Value="c:\program files\ringz studio\storm codec\stormset.exe" /s /opti
8_FileSize=296631
8_FileDate=2006-4-8 15:17:26
8_FileVersion=
8_FileCompanyName=
9_HKey=HKEY_LOCAL_MACHINE
9_Key=Software\Microsoft\Windows\CurrentVersion\Run
9_Name=IMSCMig
9_Value=c:\progra~1\common~1\micros~1\ime\imsc40a\imscmig.exe /preload
9_FileSize=13368
9_FileDate=2003-7-14 22:57:20
9_FileVersion=6.0.0.2527
9_FileCompanyName=Microsoft Corporation
10_HKey=HKEY_LOCAL_MACHINE
10_Key=Software\Microsoft\Windows\CurrentVersion\Run
10_Name=RavTask
10_Value="c:\program files\rising\rav\ravtask.exe" -system
10_FileSize=118784
10_FileDate=2007-1-21 14:17:24
10_FileVersion=19.0.0.7
10_FileCompanyName=Beijing Rising Technology Co., Ltd.
11_HKey=HKEY_LOCAL_MACHINE
11_Key=Software\Microsoft\Windows\CurrentVersion\Run
11_Name=RfwMain
11_Value="c:\program files\rising\rfw\rfwmain.exe" -startup
11_FileSize=454656
11_FileDate=2007-1-21 14:30:12
11_FileVersion=5.0.0.70
11_FileCompanyName=Beijing Rising Technology Co., Ltd.
12_HKey=HKEY_LOCAL_MACHINE
12_Key=Software\Microsoft\Windows\CurrentVersion\Run
12_Name=Thunder
12_Value="c:\program files\thunder network\thunder\thunder.exe" /s
12_FileVersion=
12_FileCompanyName=
13_HKey=HKEY_LOCAL_MACHINE
13_Key=Software\Microsoft\Windows\CurrentVersion\Run
13_Name=runeip
13_Value=c:\program files\rising\antispyware\runiep.exe
13_FileSize=86016
13_FileDate=2007-1-24 7:34:52
13_FileVersion=1.0.1.6
13_FileCompanyName=Beijing Rising Technology Co., Ltd.
14_HKey=HKEY_LOCAL_MACHINE
14_Key=Software\Microsoft\Windows\CurrentVersion\Run
14_Name=KernelFaultCheck
14_Value=%systemroot%\system32\dumprep 0 -k
15_HKey=HKEY_LOCAL_MACHINE
15_Key=Software\Microsoft\Windows\CurrentVersion\Run
15_Name=Super Rabbit SafeEdit
15_Value=c:\program files\super rabbit\magicset\srfc.exe /load
15_FileSize=43520
15_FileDate=2004-12-5 19:31:32
15_FileVersion=2.20.0.0
15_FileCompanyName=Super Rabbit Soft
16_HKey=HKEY_LOCAL_MACHINE
16_Key=Software\Microsoft\Windows\CurrentVersion\Run
16_Name=TuoTu
16_Value=c:\program files\tuotu\tuotu.exe /m
16_FileSize=3465216
16_FileDate=2007-1-12 16:39:16
16_FileVersion=2.1.0.63
16_FileCompanyName=Tuotu.com
17_HKey=HKEY_LOCAL_MACHINE
17_Key=Software\Microsoft\Windows\CurrentVersion\RunOnce
17_Name=KKDelay
17_Value=c:\program files\rising\antispyware\runonce.exe
17_FileSize=61440
17_FileDate=2007-1-22 6:38:54
17_FileVersion=19.0.0.2
17_FileCompanyName=Beijing Rising Technology Co., Ltd.
18_HKey=HKEY_LOCAL_MACHINE
18_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
18_Name=load
18_Value=
19_HKey=HKEY_CURRENT_USER
19_Key=Software\Microsoft\Windows\CurrentVersion\Run
19_Name=ctfmon.exe
19_Value=c:\windows\system32\ctfmon.exe
19_FileSize=15360
19_FileDate=2004-8-7
19_FileVersion=5.1.2600.2180
19_FileCompanyName=Microsoft Corporation
20_HKey=HKEY_CURRENT_USER
20_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
20_Name=load
20_Value=
Max=20