还是扫个日志来,让大家帮忙分析分析吧。
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ RavTask RavTimer Beijing Rising Technology Co., Ltd. c:\program files\rising\rav\ravtask.exe
+ RavTray RavNet Tray Rising c:\program files\rising\rav\ravtray.exe
+ TkBellExe RealNetworks Scheduler RealNetworks, Inc. c:\program files\common files\real\update_ob\realsched.exe
C:\WINDOWS\Start Menu\Programs\启动
+ 腾讯通.lnk Tencent c:\program files\tencent\rtx\rtxc.exe
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ Windows 安装 - 链接栏 c:\windows\command\sulfnbk.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ Rising Execute File Exts hook Rising Shell Ext Module Beijing Rising Technology Co., Ltd. c:\windows\system\ravext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ RISING Rising Shell Ext Module Beijing Rising Technology Co., Ltd. c:\windows\system\ravext.dll
+ Shell Extensions for RealOne Player RealPlayer Shell Extensions RealNetworks, Inc. c:\program files\real\realplayer\rpshell.dll
+ Web 文件夹 c:\program files\common files\microsoft shared\web folders\msonsext.dll
+ WinRAR shell extension c:\program files\winrar\rarext.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Web Folders c:\program files\common files\microsoft shared\web folders\msonsext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ IeCatch2 Class jccatch Module Amaze Soft c:\program files\flashget\jccatch.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ FlashGet Bar FlashGet IE Bar Amaze Soft c:\program files\flashget\fgiebar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ &FlashGet FlashGet Amaze Soft c:\program files\flashget\flashget.exe
+ @shdoclc.dll,-864 c:\windows\web\related.htm
+ 超级解霸 c:\herosoft\hero3000\mplayer.exe