<svc><C:\WINDOWS\svchost.exe> []
<pbmini><C:\Program Files\pcast\PodcastbarMini\PodcastBar.exe -hide> []
<sysmini><C:\WINDOWS\system32\sysmini.exe> []
<spoolsv><C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer> [广州傲讯信息科技有限公司]
<ourmini><C:\WINDOWS\System\svchost.exe> [MicroSoft Corporation]
<defender><c:\\dfndrff_12.exe> [ewjiruweru8tu389uu54389refju8eu]
<keyboard><c:\\kybrdff_12.exe> [*&&*#&$*#RU*#Y&*#YR&Y#&RY#R]
<newname><c:\\nwnmff_12.exe> [04399289e8uwhru243y5r78f73yh3t7y3]
<><C:\WINDOWS\system32\intenat.exe> []
<SoundMam><C:\WINDOWS\system32\SVOHOST.exe> []
<RichMedia><C:\WINDOWS\system32\Rundll32.exe "C:\PROGRA~1\pcast\hbcast.dll",WaitWindows> [Shanghai Henbang Technology Co., Ltd]
<ToP><C:\WINDOWS\LSASS.exe> [nYVmLJNNBoK0PT1Uvl2f]
<TProgram><C:\WINDOWS\SMSS.EXE> [Xs5kzBEUMw1vRVHCJxSh]
<Torjan Program><C:\WINDOWS\WINLOGON.EXE> [nYVmKIMNAnJPS1Tul2fq]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<uninsrest><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<SoundMix><rundll32.exe C:\WINDOWS\system32\soundmix.dll,Load> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\hhkgkah.exe> []