谢谢楼上的高手,日志如下:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe
+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe
+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwmain.exe
+ Thunderc:\program files\thunder network\thunder\thundershell.exe
C:\Documents and Settings\sky\「开始」菜单\程序\启动
+ 腾讯QQ.lnkQQTENCENTc:\tencent\qq\qq.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ DesktopSpriteSnowFox Studio.c:\program files\snowfox\desktopsprite2\desktopsprite.exe
HKLM\System\CurrentControlSet\Services
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe
+ RsCCenterCCenterrisingc:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ bho Class万能五笔接口程序深圳世强软件开发部c:\program files\common files\wnwb\wnwbio.dll
+ NTIECatcher ClassNet Transport IE Helper ModuleXid:\program files\xi\nettransport 2\ntiehelper.dll
+ QQBrowserHelper
Object ClassQQIEHelper Module深圳市腾讯计算机系统有限公司c:\tencent\qq\qqiehelper.dll
+ 超级兔子上网精灵超级兔子上网精灵超级兔子d:\program files\super rabbit\magicset\haokanbar.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ update万能五笔接口程序深圳世强软件开发部c:\program files\common files\wnwb\wnwbio.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ FlashGet Bar\
+ 超级兔子上网精灵超级兔子上网精灵超级兔子d:\program files\super rabbit\magicset\haokanbar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ kele8File not found: http://www.kele8.com/
+ 腾讯QQQQTENCENTc:\tencent\qq\qq.exe
+ 易趣购物File not found: http://click2.ad4all.net/url2/urlmanage/url.asp?id=5