I'll get to the rest later. Busy with other stuff right now...
Trusted Zone -- Control Panel->Internet Options->Security tab->Trusted->View
sites. The information you see there, as well as under the other three zones, is
stored in the registry under {HKLM|HKCU}\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap. Sites in this zone are granted more access to your computer.
AppInit_DLLs -- Specifies a list of .dll files to load into every process.
It is under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows.
Winlogon\Notify -- Each subkey of HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify specifies a DLL to load into the WinLogon.exe process
(a critical system process). When certain events occur, such as logon and logoff,
a function in the DLL may be called.
ShellDelayLoad objects -- COM objects loaded by explorer.exe some time
after boot. Under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad.
The value in brackets is a CLSID, which you can look up under HKEY_CLASSES_ROOT\CLSID
UserInit -- Manages Windows startup. The value controlling this is under
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. It specifies
a comma-separated list of programs to run. By default, the value should be