没人帮忙吗?再提供一点线索,kk里有几个奇怪注册表信息
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AppSetup
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Startup
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Logon
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Logon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Shell
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ RTHDCPL Realtek HD Audio Control Panel Realtek Semiconductor Corp. C:\WINDOWS\RTHDCPL.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
C:\Documents and Settings\All Users\「开始」菜单\程序\启动
C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
+ QQ游戏启动加速程序.lnk 提升游戏大厅启动速度,极速畅游QQ游戏世界 深圳市腾讯计算机系统有限公司 C:\PROGRA~1\TENCENT\QQGAME\ACCEL.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
C:\WINDOWS\WIN.INI
C:\WINDOWS\SYSTEM.INI
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Protocols\Filter
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Protocols\Handler
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components
+ 0 ABOUT:HOME.EXE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ 显示摇曳 CPL 扩展 DESKPAN.DLL
+ Shell Scrap DataHandler Shell scrap object handler Microsoft Corporation C:\WINDOWS\SYSTEM32\SHSCRAP.DLL
+ Directory Query UI Directory Service Find Microsoft Corporation C:\WINDOWS\SYSTEM32\DSQUERY.DLL
+ Shell properties for a DS object Directory Service Find Microsoft Corporation C:\WINDOWS\SYSTEM32\DSQUERY.DLL
+ Directory Object Find Directory Service Find Microsoft Corporation C:\WINDOWS\SYSTEM32\DSQUERY.DLL
+ Directory Start/Search Find Directory Service Find Microsoft Corporation C:\WINDOWS\SYSTEM32\DSQUERY.DLL
+ Cab 文件 Cabinet File Viewer Shell Extension Microsoft Corporation C:\WINDOWS\SYSTEM32\CABVIEW.DLL
+ WinRAR C:\PROGRAM FILES\WINRAR\RAREXT.DLL
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Shellex\ColumnHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ IcbcBho Class 中国工商银行IE工具栏 中国工商银行 C:\PROGRAM FILES\中国工商银行\工行IE浏览器安全插件\ICBCTOOLBAR.DLL
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\UrlSearchHooks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
+ 工行工具栏 中国工商银行IE工具栏 中国工商银行 C:\PROGRAM FILES\中国工商银行\工行IE浏览器安全插件\ICBCTOOLBAR.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions
+ 启动迅雷5 Thunder Networking Technologies,LTD C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\THUNDER.EXE
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions
+
HTTP://WWW.YLMF.COM/INDEX.HTM 计划任务
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services(Drivers) + IntcAzAudAddService Realtek(r) High Definition Audio Function Driver Realtek Semiconductor Corp. C:\WINDOWS\SYSTEM32\DRIVERS\RTKHDAUD.SYS
+ JGOGO SCSI Port upper filter driver JMicron C:\WINDOWS\SYSTEM32\DRIVERS\JGOGO.SYS
+ nv NVIDIA Compatible Windows 2000 Miniport Driver, Version 163.75 NVIDIA Corporation C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS
+ nvrd32 NVIDIA? nForce(TM) RAID Driver NVIDIA Corporation C:\WINDOWS\SYSTEM32\DRIVERS\NVRD32.SYS
+ presafe C:\WINDOWS\SYSTEM32\DRIVERS\PRESAFE.SYS + Tcpip TCP/IP Protocol Driver Microsoft Corporation C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\BootExecute
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UIHost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GinaDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman
HKEY_CURRENT_USER\Control Panel\Desktop\SCRNSAVE.EXE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BootVerificationProgram\ImageName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\Authentication Packages