}
Performance Logs and Alerts [SysmonLog ] <Stopped>, Binpath = C:\WINDOWS\system32\smlogsvc.exe
Telephony [TapiSrv ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Terminal Services [TermService ] <Running>, Binpath = C:\WINDOWS\System32\svchost -k DComLaunch
Themes [Themes ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
Distributed Link Tracking Client [TrkWks ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Universal Plug and Play Device Host [upnphost ] <Stopped>, Binpath = C:\WINDOWS\System32\svchost.exe -k LocalService
Uninterruptible Power Supply [UPS ] <Stopped>, Binpath = C:\WINDOWS\System32\ups.exe
Volume Shadow Copy [VSS ] <Stopped>, Binpath = C:\WINDOWS\System32\vssvc.exe
Windows Time [W32Time ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
WebClient [WebClient ] <Running>, Binpath = C:\WINDOWS\System32\svchost.exe -k LocalService
Windows Management Instrumentation [winmgmt ] <Running>, Binpath = C:\WINDOWS\system32\svchost.exe -k netsvcs
Portable Media Serial Number Service [WmdmPmSN ] <Stopped>, Binpath = C:\WINDOWS\System32\svchost.exe -k netsvcs
WMI Performance Adapter [WmiApSrv ] <Stopped>, Binpath = C:\WINDOWS\System32\wbem\wmiapsrv.exe
*****************************************************************
IE BHOs
*****************************************************************
{0005A87D-D626-4B3A-84F9-1D9571695F55} Xunleibho.ThunderIEHelper.1 C:\WINDOWS\system32\xunleibho_v5.dll
{54EBD53A-9BC1-480B-966A-843A333CA162} QQIEHelper.QQBrowserHelper
Object.1 C:\Program Files\Tencent\QQ\QQIEHelper.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} QQIEHelper.QQBrowserHelper
Object.1 c:\program files\google\googletoolbar.dll
{BB936323-19FA-4521-BA29-ECA6A121BC78} CoolBar.CoolBarObj.1 C:\Program Files\3721\Assist\asbar.dll
{D157330A-9EF3-49F8-9A67-4141AC41ADD4} CnsMinHK.CnsHook.1 C:\WINDOWS\DOWNLO~1\CnsHook.dll
{EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} BhoObj.AxObj.1 C:\PROGRA~1\yisou\yisoub.dll
*****************************************************************
Boot items in Registry
*****************************************************************
------------------------------------------------------------
0:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
------------------------------------------------------------
ctfmon.exe……C:\WINDOWS\system32\ctfmon.exe
MSMSGS……"C:\Program Files\Messenger\msmsgs.exe" /background
------------------------------------------------------------
1:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
------------------------------------------------------------
------------------------------------------------------------
2:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
------------------------------------------------------------
------------------------------------------------------------
3:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices
------------------------------------------------------------
------------------------------------------------------------
4:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
------------------------------------------------------------
------------------------------------------------------------
5:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows 键值名称:load
------------------------------------------------------------
load……
------------------------------------------------------------
6:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows 键值名称:run
------------------------------------------------------------
------------------------------------------------------------
7:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System 键值名称:Shell
------------------------------------------------------------
------------------------------------------------------------
8:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
------------------------------------------------------------
------------------------------------------------------------
9:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
------------------------------------------------------------
IMJPMIG8.1……C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
PHIME2002ASync……C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A……C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
LHotkey……LHotkey.exe
Lcc……C:\Program Files\Lenovo\联想键盘驱动\LCC.exe
VTTimer……VTTimer.exe
SoundMan……SOUNDMAN.EXE
TkBellExe……"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
RfwMain……"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
WinampAgent……"C:\Program Files\Winamp\Winampa.exe"
MS-4011 Memory Patch……D:\RavSasser.exe -Patch
RavTimer……C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
RavMon……C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
MINI_MINIPP……C:\Program Files\MINIPP\MINIPP.exe
helper.dll……C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
CnsMin……Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
ADShow……C:\WINDOWS\system32\bcsysnote.ex
BCUpdate……C:\WINDOWS\system32\BCUP.exe
assistse……"C:\PROGRA~1\3721\assistse.exe"
SysExplr……C:\Herosoft\HeroV8\SysExplr.EXE
------------------------------------------------------------
10:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
------------------------------------------------------------
------------------------------------------------------------
11:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
------------------------------------------------------------
------------------------------------------------------------
12:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunService
------------------------------------------------------------
------------------------------------------------------------
13:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
------------------------------------------------------------
------------------------------------------------------------
14:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
------------------------------------------------------------
------------------------------------------------------------
15:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon 键值名称:Shell
------------------------------------------------------------
Shell……Explorer.exe
------------------------------------------------------------
16:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon 键值名称:Userinit
------------------------------------------------------------
Userinit……C:\WINDOWS\system32\userinit.exe,
------------------------------------------------------------
17:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows 键值名称:AppInit_DLLs
------------------------------------------------------------
AppInit_DLLs……