我用AUTORUN扫描的 看看可以么
HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
+ rdpclipRDP Clip MonitorMicrosoft Corporationc:\windows\system32\rdpclip.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
+ C:\WINDOWS\system32\Userinit.exeUserinit Logon ApplicationMicrosoft Corporationc:\windows\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exeWindows ExplorerMicrosoft Corporationc:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ CnsM.dllCnsM北京三七二一科技有限公司c:\program files\3721\cnsm.dll
+ CnsMin3721北京三七二一科技有限公司c:\windows\downloaded program files\cnsmin.dll
+ helper.dllRun a DLL as an AppMicrosoft Corporationc:\windows\system32\rundll32.exe
+ IMJPMIG8.1未找到文件: C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE
+ IMSCMIG40W微软拼音输入法安装工具Microsoft Corporationc:\program files\common files\microsoft shared\ime\imsc40w\imscmig.exe
+ mhsa未找到文件: C:\DOCUME~1\V9000\LOCALS~1\Temp\mhso.exe
+ PHIME2002A微軟新注音輸入法 2002aMicrosoft Corporationc:\windows\system32\ime\tintlgnt\tintsetp.exe
+ PHIME2002ASync微軟新注音輸入法 2002aMicrosoft Corporationc:\windows\system32\ime\tintlgnt\tintsetp.exe
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe
+ runeipRising AntiSpyware MonitorBeijing Rising Technology Co., Ltd.c:\program files\rising\kakatoolbar\runiep.exe
+ SoundManAvance Sound ManagerAvance Logic, Inc.c:\windows\soundman.exe
+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe
+ tlsa未找到文件: C:\DOCUME~1\V9000\LOCALS~1\Temp\tlso.exe
+ wdsa未找到文件: C:\DOCUME~1\V9000\LOCALS~1\Temp\wdso.exe
+ wmsa未找到文件: C:\DOCUME~1\V9000\LOCALS~1\Temp\wmso.exe
+ YLive.exeYLiveYahoo! Chinac:\program files\yahoo!\assistant\ylive.exe
C:\Documents and Settings\All Users\「开始」菜单\程序\启动
+ 木马杀客2007.Lnkd:\木马杀客\木马杀客\mmsk.exe
C:\Documents and Settings\V9000\「开始」菜单\程序\启动
+ QQ游戏启动加速程序.lnkQQ游戏深圳市腾讯计算机系统有限公司c:\program files\tencent\qqgame\accel.exe
+ 迅雷4.lnk迅雷4深圳市三代科技开发有限公司c:\program files\sandai technologies inc\thunder\thunder.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ ctfmon.exeCTF LoaderMicrosoft Corporationc:\windows\system32\ctfmon.exe
+ ravshell未找到文件: C:\Progra~1\Eset\1explore.exe
HKLM\SOFTWARE\Classes\Protocols\Filter
+ Class Install HandlerOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ deflateOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ gzipOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ lzdhtmlOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ text/webviewhtmlWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ text/xmlMicrosoft Office XML MIME FilterMicrosoft Corporationc:\program files\common files\microsoft shared\office11\msoxmlmf.dll