</font><br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run<blockquote>PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br>PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME<br>nwiz = NWIZ.EXE /INSTALL<br>SpeedTouch USB Diagnostics = "C:\PROGRAM FILES\ALCATEL\SPEEDTOUCH USB\DRAGDIAG.EXE" /ICON<br>RavTask = "E:\瑞星\RISING\RAV\RAVTASK.EXE" -SYSTEM<br>RfwMain = "C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP<br>NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVCPL.DLL,NVSTARTUP<br></blockquote>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices<blockquote>MS Windows System Alert = MSWSA32.EXE<br></blockquote><br><font size=5 color="#ff0000">AppInit_DLLs</font><br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows<blockquote>AppInit_DLLs = <br></blockquote><br><font size=5 color="#ff0000">系统文件关联</font><br>.exe ==> exefile = "%1" %*<br>.com ==> comfile = "%1" %*<br>.cmd ==> cmdfile = "%1" %*<br>.bat ==> batfile = "%1" %*<br>.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1<br>.scr ==> scrfile = "%1" /S<br>.reg ==> regfile = regedit.exe "%1"<br>.doc ==> WordPad.Document.1 = "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"<br><br><font size=5 color="#ff0000">其它启动项</font><br>WIN.INI<blockquote>无信息<br></blockquote>SYSTEM.INI<blockquote>SHELL = EXPLORER.EXE<br></blockquote><br><font size=5 color="#ff0000">Winlogon 启动项</font><br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify<blockquote>crypt32chain = CRYPT32.DLL<br>cryptnet = CRYPTNET.DLL<br>cscdll = CSCDLL.DLL<br>ScCertProp = WLNOTIFY.DLL<br>Schedule = WLNOTIFY.DLL<br>sclgntfy = SCLGNTFY.DLL<br>SensLogn = WLNOTIFY.DLL<br>termsrv = WLNOTIFY.DLL<br>wlballoon = WLNOTIFY.DLL<br></blockquote>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon<blockquote>Userinit = "C:\WINDOWS\SYSTEM32\USERINIT.EXE,"<br>shell = EXPLORER.EXE<br></blockquote><br><font size=5 color="#ff0000">IE - BHO</font><br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects<blockquote>{54EBD53A-9BC1-480B-966A-843A333CA162} = D:\QQ2006\QQIEHelper.dll<br>{889D2FEB-5411-4565-8998-1DD2C5261283} = D:\迅雷5\ComDlls\XunLeiBHO_002.dll<br></blockquote><br><font size=5 color="#ff0000">Winsock SPI</font><br>MSAFD Tcpip [TCP/IP] = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD Tcpip [UDP/IP] = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD Tcpip [RAW/IP] = C:\windows\SYSTEM32\MSWSOCK.DLL<br>RSVP UDP Service Provider = C:\windows\SYSTEM32\RSVPSP.DLL<br>RSVP TCP Service Provider = C:\windows\SYSTEM32\RSVPSP.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{77F05A38-FAE6-42AB-93CF-B25A96023110}] SEQPACKET 3 = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{77F05A38-FAE6-42AB-93CF-B25A96023110}] DATAGRAM 3 = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{3B638374-D4DF-4F0C-BC27-E1A1B62C8790}] SEQPACKET 0 = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{3B638374-D4DF-4F0C-BC27-E1A1B62C8790}] DATAGRAM 0 = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{8813B67C-6EDD-42B0-B560-45286D4B79FF}] SEQPACKET 1 = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{8813B67C-6EDD-42B0-B560-45286D4B79FF}] DATAGRAM 1 = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{12FA444C-42D3-4ED7-A260-FA4D3368C704}] SEQPACKET 2 = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{12FA444C-42D3-4ED7-A260-FA4D3368C704}] DATAGRAM 2 = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{B4425B74-7BE7-476E-85F8-5BBBDCA5097F}] SEQPACKET 4 = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{B4425B74-7BE7-476E-85F8-5BBBDCA5097F}] DATAGRAM 4 = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{FA03788C-9E99-4237-8042-04B131F08224}] SEQPACKET 5 = C:\windows\SYSTEM32\MSWSOCK.DLL<br>MSAFD NetBIOS [\Device\NetBT_Tcpip_{FA03788C-9E99-4237-8042-04B131F08224}] DATAGRAM 5 = C:\windows\SYSTEM32\MSWSOCK.DLL<br><br><font size=5 color="#ff0000">系统服务项</font><br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services<blockquote>Alerter = C:\windows\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE<br>ALG = C:\windows\SYSTEM32\ALG.EXE<br>AppMgmt = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br>AudioSrv = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br>BITS = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br><font color="#f0f0f0">BlueSoleil Hid Service = C:\PROGRAM FILES\IVT CORPORATION\BLUESOLEIL\BTNTSERVICE.EXE</font><br>Browser = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br>CiSvc = C:\windows\SYSTEM32\CISVC.EXE<br>ClipSrv = C:\windows\SYSTEM32\CLIPSRV.EXE<br>COMSysApp = C:\WINDOWS\SYSTEM32\DLLHOST.EXE /PROCESSID:{02D4B3F1-FD88-11D1-960D-00805FC79235}<br>CryptSvc = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br>Dhcp = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br>dmadmin = C:\windows\SYSTEM32\DMADMIN.EXE /COM<br>dmserver = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br>Dnscache = C:\windows\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE<br>ERSvc = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br>Eventlog = C:\windows\SYSTEM32\SERVICES.EXE<br>EventSystem = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS<br>FastUserSwitchingCompatibility = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br>HidServ = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br><font color="#f0f0f0">IDriverT = C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\DRIVER\11\INTEL 32\IDRIVERT.EXE</font><br>ImapiService = C:\WINDOWS\SYSTEM32\IMAPI.EXE<br>lanmanserver = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br>lanmanworkstation = C:\windows\SYSTEM32\SVCHOST.EXE -K NETSVCS<br>LmHosts = C:\windows\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE<br>Messenger =