谢谢老大
Autoruns 日志
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe
+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwmain.exe
+ Windows木马防火墙File not found: C:\Program Files\ftctry\Trojanwall.exe
C:\Documents and Settings\gaohao.LEGEND-B47A48B3\「开始」菜单\程序\启动
+ ADSL超频奇兵 V4.3.lnkADSL 加速软件奇兵软件 Worldfax.netc:\program files\worldfax\adsl超频奇兵 v4.3\adslx2.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Display Panning CPL ExtensionFile not found: deskpan.dll
+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll
+ TuneUp 碎纸机TuneUp Shredder Shell ExtensionTuneUp Software GmbHc:\program files\tuneup utilities 2006\sdshelex.dll
+ WinRAR shell extensionc:\program files\winrar\rarext.dll
+ 好看123上网精灵超级兔子上网精灵超级兔子c:\program files\super rabbit\magicset\haokanbar.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ ThunderIEHelper ClassXunLei BHOThunder Networking Technologies,LTDc:\windows\system32\xunleibho_v14.dll
+ 超级兔子上网精灵超级兔子上网精灵超级兔子c:\program files\super rabbit\magicset\haokanbar.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ bitcometbar0.3.dllBitComet Toolbar for IEd:\bitcomet\bitcometbar\bitcometbar0.3.dll
+ 超级兔子上网精灵超级兔子上网精灵超级兔子c:\program files\super rabbit\magicset\haokanbar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ 浩方对战平台浩方对战平台上海浩方在线信息技术有限公司c:\program files\浩方对战平台\gameclient.exe
+ 网址大全File not found: http://www.coc.cc
HKLM\System\CurrentControlSet\Services
+ PDSchedPDSched ModuleRaxco Software, Inc.c:\program files\raxco\perfectdisk\pdsched.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
+ svosh媒体播放c:\windows\svosh.exe
HKLM\System\CurrentControlSet\Services
+ ac97intcIntel(r) Integrated Controller Hub Audio DriverIntel Corporationc:\windows\system32\drivers\ac97intc.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys
+ CKG005File not found: C:\WINDOWS\TEMP\5m9hv.sysce5ub74.sys
+ COK568File not found: C:\WINDOWS\TEMP\b.sys
+ EagleNTFile not found: C:\WINDOWS\system32\drivers\EagleNT.sys
+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys
+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys
+ HookRegc:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys
+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\hookurl.sys
+ kmsinputc:\windows\system32\drivers\kmsinput.sys
+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys
+ mProcRsRising Personal FireWall mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys
+ NPPTNT2nProtect NPSC Kernel Mode Driver for NTINCA Internet Co., Ltd.c:\windows\system32\npptnt2.sys
+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 56.73 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ PxHelp20Px Engine Device Driver for Windows 2000/XPSonic Solutionsc:\windows\system32\drivers\pxhelp20.sys
+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rsfwdrv.sys
+ rtl8139Realtek RTL8139 NDIS 5.0 DriverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8139.sys
+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
+ SecFileFile not found: C:\Program Files\SecFile\secfile.sys
+ ser2plUSB-to-Serial Cable DriverProlific Technology Inc.c:\windows\system32\drivers\ser2pl.sys
+ USBW685Universal Serial Bus Camera DriverWinbond Electronics Crop.c:\windows\system32\drivers\2kw685.sys
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
+ PDBoot.exePerfectDisk Boot Time DefragmentationRaxco Software, Inc.c:\windows\system32\pdboot.exe
HKCU\Control Panel\Desktop\Scrnsave.exe
+ C:\WINDOWS\system32\屏保.scrFlurry screen saver for WindowsMatt Ginztonc:\windows\system32\屏保.scr