真是越来越心寒啊。。。。
望高手指点。。。。。。。谢谢了~~~
后来用卡巴似乎扫到很多...
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ kav Kaspersky Anti-Virus Kaspersky Lab e:\program files\kaspersky lab\kaspersky anti-virus 6.0\avp.exe
+ RavTask RavTimer Beijing Rising Technology Co., Ltd. e:\program files\rising\rav\ravtask.exe
+ RfwMain Rising Personal FireWall Main Program Beijing Rising Technology Co., Ltd. e:\program files\rising\rfw\rfwmain.exe
C:\Documents and Settings\wejfxh3kj fh34\「开始」菜单\程序\启动
+ 腾讯QQ.lnk QQ TENCENT e:\program files\tencent\qq\qq.exe
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load
+ C:\WINDOWS\rundl132.exe c:\windows\rundl132.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
+ Alexa 找不到文件:C:\WINDOWS\system32\qproecss.exe
+ Ver 找不到文件:2006.07.20
HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components
+ 0 找不到文件:
About:Home
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ Rising Execute File Exts hook Rising Shell Ext Module Beijing Rising Technology Co., Ltd. c:\windows\system32\ravext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Display Panning CPL Extension 找不到文件:deskpan.dll
+ HyperTerminal Icon Ext HyperTerminal Applet Library Hilgraeve, Inc. c:\windows\system32\hticons.dll
+ RISING Rising Shell Ext Module Beijing Rising Technology Co., Ltd. c:\windows\system32\ravext.dll
+ Shell Extensions for RealOne Player RealOne Player Shell Extensions RealNetworks c:\program files\real\realone player\rpshellext.dll
+ Web反病毒保护 Script Monitor Internet Explorer plugin Kaspersky Lab e:\program files\kaspersky lab\kaspersky anti-virus 6.0\scieplugin.dll
+ WinRAR shell extension e:\program files\winrar\rarext.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ kakatool.dll Beijing Rising Technology Co., Ltd. c:\windows\system32\kakatool.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ 启动迅雷 e:\program files\thunder network\thunder\thunder.exe
+ 腾讯QQ QQ TENCENT e:\program files\tencent\qq\qq.exe
HKLM\System\CurrentControlSet\Services
+ AVP 保护计算机远离病毒和间谍软件的威胁。 Kaspersky Lab e:\program files\kaspersky lab\kaspersky anti-virus 6.0\avp.exe
+ ewido anti-spyware 4.0 guard ewido anti-spyware guard Anti-Malware Development a.s. e:\program files\ewido anti-spyware 4.0\guard.exe
+ RfwService Rising Personal Firewall Service Beijing Rising Technology Co., Ltd. e:\program files\rising\rfw\rfwsrv.exe
+ RsCCenter CCenter Beijing Rising Technology Co., Ltd. e:\program files\rising\rav\ccenter.exe
+ RsRavMon RavMond Beijing Rising Technology Co., Ltd. e:\program files\rising\rav\ravmond.exe
+ SoundMAX Agent Service (default) SoundMAX service agent component Analog Devices, Inc. c:\program files\analog devices\soundmax\smagent.exe
HKLM\System\CurrentControlSet\Services
+ aeaudio Andrea Audio Stub Driver Andrea Electronics Corporation c:\windows\system32\drivers\aeaudio.sys
+ BaseTDI basetdi Beijing Rising Technology Co., Ltd. c:\windows\system32\drivers\basetdi.sys
+ dump_wmimmc 找不到文件:C:\WINDOWS\system32\drivers\dump_wmimmc.sys
+ ewido anti-spyware 4.0 driver e:\program files\ewido anti-spyware 4.0\guard.sys
+ ExpScaner ExpScan.sys e:\program files\rising\rav\expscan.sys
+ FETNDIS NDIS 5.0 miniport driver VIA Technologies, Inc. c:\windows\system32\drivers\fetnd5.sys
+ FETNDISB NDIS 5.0 miniport driver VIA Technologies, Inc. c:\windows\system32\drivers\fetnd5b.sys
+ HookCont TDI HOOK Driver Rising tech Co. ltd e:\program files\rising\rav\hookcont.sys
+ HookReg e:\program files\rising\rav\hookreg.sys
+ HookSys Hooksys Rising e:\program files\rising\rav\hooksys.sys
+ HookUrl HookUrl Beijing Rising Technology Co., Ltd. e:\program files\rising\rfw\hookurl.sys
+ kl1 Kaspersky Unified Driver Kaspersky Lab c:\windows\system32\drivers\kl1.sys
+ klif spuper-ptor Kaspersky Lab c:\windows\system32\drivers\klif.sys
+ kmsinput c:\windows\system32\drivers\kmsinput.sys
+ MEMSCAN MemScan Driver 瑞星软件有限公司 e:\program files\rising\rav\memscan.sys
+ mProcRs Rising Personal FireWall mprocrs.sys Beijing Rising Technology Co., Ltd. e:\program files\rising\rfw\mprocrs.sys
+ npkcrypt nProtect KeyCrypt Driver INCA Internet Co., Ltd. e:\program files\tencent\qq\npkcrypt.sys
+ npkycryp 找不到文件:E:\Program Files\Tencent\QQ\npkycryp.sys
+ NPPTNT2 nProtect NPSC Kernel Mode Driver for NT INCA Internet Co., Ltd. c:\windows\system32\npptnt2.sys
+ NTSIM Network Device Monitor Utility VIA Technologies, Inc. c:\windows\system32\ntsim.sys
+ nv NVIDIA Compatible Windows 2000 Miniport Driver, Version 56.73 NVIDIA Corporation c:\windows\system32\drivers\nv4_mini.sys
+ nvcap 找不到文件:system32\DRIVERS\nvcap.sys
+ Ptilink Direct Parallel Link Driver Parallel Technologies, Inc. c:\windows\system32\drivers\ptilink.sys
+ RsFwDrv nt_fwdrv Beijing Rising Technology Co., Ltd. e:\program files\rising\rfw\rsfwdrv.sys
+ Secdrv SafeDisc driver c:\windows\system32\drivers\secdrv.sys
+ smwdm SoundMAX Integrated Digital Audio Analog Devices, Inc. c:\windows\system32\drivers\smwdm.sys
+ TSP spuper-ptor Kaspersky Lab c:\windows\system32\drivers\klif.sys
+ viaagp1 VIA NT AGP Filter VIA Technologies, Inc. c:\windows\system32\drivers\viaagp1.sys
+ viasraid VIA SATA RAID DRIVER FOR WINXP VIA Technologies inc,.ltd c:\windows\system32\drivers\viasraid.sys
+ vulfnths VIA USB Host Controller Lower Filter Driver VIA Technologies, Inc. c:\windows\system32\drivers\vulfnth.sys
+ vulfntrs VIA USB Roothub Lower Filter Driver VIA Technologies, Inc. c:\windows\system32\drivers\vulfntr.sys
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ klogon Logon Visualizer Kaspersky Lab c:\windows\system32\klogon.dll