好,我这就删
Autoruns日志:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
+ C:\WINNT\system32\userinit.exeUserinit Logon ApplicationMicrosoft Corporationc:\winnt\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exeWindows ExplorerMicrosoft Corporationc:\winnt\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ NvCplDaemonNVIDIA Display Properties ExtensionNVIDIA Corporationc:\winnt\system32\nvcpl.dll
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe
+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwmain.exe
+ Synchronization ManagerMicrosoft Synchronization ManagerMicrosoft Corporationc:\winnt\system32\mobsync.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ ctfmon.exeCicero LoaderMicrosoft Corporationc:\winnt\system32\ctfmon.exe
+ SystemSafetyMonitorMaster ModuleSystem Safetyd:\program files\system safety monitor\syssafe.exe
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ Address Book 5Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ CRLUpdateUPDCRLMicrosoft Corporationc:\winnt\system32\updcrl.exe
+ EnableRevocationMicrosoft(C) Register ServerMicrosoft Corporationc:\winnt\system32\regsvr32.exe
+ Internet Explorer 6IE 5.0 Per-User Install UtilityMicrosoft Corporationc:\winnt\system32\ie4uinit.exe
+ Internet Explorer 访问Windows NT User Data Migration ToolMicrosoft Corporationc:\winnt\system32\shmgrate.exe
+ Microsoft Outlook Express 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ Microsoft Windows Media Player 6.4ADVPACKMicrosoft Corporationc:\winnt\system32\advpack.dll
+ NetMeeting 3.01ADVPACKMicrosoft Corporationc:\winnt\system32\advpack.dll
+ Outlook Express 访问Windows NT User Data Migration ToolMicrosoft Corporationc:\winnt\system32\shmgrate.exe
+ Windows 桌面更新Microsoft(C) Register ServerMicrosoft Corporationc:\winnt\system32\regsvr32.exe
+ 自定义浏览器Microsoft Internet Explorer Customization DLLMicrosoft Corporationc:\winnt\system32\iedkcs32.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
+ Browseui 预加载程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 组件类别缓存程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
+ Network.ConnectionTrayNetwork Connections ShellMicrosoft Corporationc:\winnt\system32\netshell.dll
+ SysTraySystray shell service
objectMicrosoft Corporationc:\winnt\system32\st
object.dll
+ WebCheckWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
+ shell32.dllWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ AlcoholShellExAXShlEx.dllAlcohol Soft Development Teamd:\program files\alcohol soft\alcohol 120\axshlex.dll
+ AutoCAD 数字签名图标覆盖处理程序AcSignIcon ModuleAutodeskc:\winnt\system32\acsignicon.dll
+ Autodesk Drawing PreviewAcThumbnail ModuleAutodeskc:\program files\common files\autodesk shared\thumbnail\acthumbnail16.dll
+ Desktop ExplorerNVIDIA Desktop Explorer, Version 66.93 NVIDIA Corporationc:\winnt\system32\nvshell.dll
+ Desktop Explorer MenuNVIDIA Desktop Explorer, Version 66.93 NVIDIA Corporationc:\winnt\system32\nvshell.dll
+ Microsoft Office HTML Icon HandlerMicrosoft Office 2003 componentMicrosoft Corporationd:\program files\microsoft office\office11\msohev.dll
+ nView Desktop Context MenuNVIDIA Desktop Explorer, Version 66.93 NVIDIA Corporationc:\winnt\system32\nvshell.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
+ Shell Extensions for RealOne PlayerRealOne Player Shell ExtensionsRealNetworksc:\program files\real\realone player\rpshellext.dll
+ Web FoldersMicrosoft Web FoldersMicrosoft Corporationc:\program files\common files\microsoft shared\web folders\msonsext.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ Fax Tiff Data Column ProviderFax Tiff Data Column ProviderMicrosoft Corporationc:\winnt\system32\faxshell.dll
+ ShAVColumnProvider classDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll
+ Version Column ProviderDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll
+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ AcroIEHlprObj ClassAdobe Acrobat IE Helper Version 6.0 for ActivieXAdobe Systems Incorporatedd:\program files\adobe\acrobat 6.0\reader\activex\acroiehelper.dll
+ BandIE ClassBaiduBar ModuleBaidu.com, Inc.c:\program files\baidu\bar\baidubar.dll
+ DragSearch BHODragSearchc:\program files\yahoo!\assistant\assist\ydragsearch.dll
+ IeCatch2 Classjccatch ModuleAmaze Softd:\program files\flashget\jccatch.dll
+ stdupFile not found: C:\WINNT\system32\stdup.dll
+ 雅虎助手ToolBarYahoo!c:\program files\yahoo!\assistant\assist\yasbar.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ shdocvw.dllShell Doc
Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ FlashGet BarFlashGet IE BarAmaze Softd:\program files\flashget\fgiebar.dll
+ 雅虎助手ToolBarYahoo!c:\program files\yahoo!\assistant\assist\yasbar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ &FlashGetFlashGetAmaze Softd:\program files\flashget\flashget.exe
+ Yahoo 1G电邮File not found: http://cn.mail.yahoo.com/promo/rd1
+ 豪杰超级解霸V8d:\herosoft\herov8\sthsdvd.exe
+ 清理上网记录File not found: http://assistant.3721.com/clean1.htm?fb=Cns
+ 上网助手File not found: http://assistant.3721.com/index.htm?fb=Cns
+ 手机短信File not found: http://sms.3721.com/ie/index.htm
+ 修复浏览器File not found: http://assistant.3721.com/security1.htm?fb=Cns
+ 寻宝乐趣多File not found: http://cn.rd.yahoo.com/auct/promo/3721/200508/ielogo-wcfashion/*http://cn.promo.auctions.yahoo.com/200507/fashion/index.html?refcode=3721200508ielogo-wcfashion
HKLM\System\CurrentControlSet\Services
+ BITS用闲置网络带宽在后台传输文件。如果此服务被禁用,那么任何依赖于 BITS 的功能,例如 Windows Update 或 MSN Explorer,都将不能自动下载程序和其它信息。Microsoft Corporationc:\winnt\system32\svchost.exe
+ Browser维护网络上计算机的最新列表以及提供这个列表给请求的程序。Microsoft Corporationc:\winnt\system32\services.exe
+ Dhcp通过注册和更改 IP 地址以及 DNS 名称来管理网络配置。Microsoft Corporationc:\winnt\system32\services.exe
+ dmserver逻辑磁盘管理器监视狗服务Microsoft Corporationc:\winnt\system32\services.exe
+ Dnscache解析和缓冲域名系统 (DNS) 名称。Microsoft Corporationc:\winnt\system32\services.exe
+ Eventlog记录程序和 Windows 发送的事件消息。事件日志包含对诊断问题有所帮助的信息。您可以在“事件查看器”中查看报告。Microsoft Corporationc:\winnt\system32\services.exe
+ HidServHID Audio ServiceMicrosoft Corporationc:\winnt\system32\hidserv.exe
+ lanmanserver提供 RPC 支持、文件、打印以及命名管道共享。Microsoft Corporationc:\winnt\system32\services.exe
+ lanmanworkstation提供网络链结和通讯。Microsoft Corporationc:\winnt\system32\services.exe
+ LmHosts允许对“TCP/IP 上 NetBIOS (NetBT)”服务以及 NetBIOS 名称解析的支持。Microsoft Corporationc:\winnt\system32\services.exe
+ NtmsSvc管理可移动媒体、驱动程序和库。Microsoft Corporationc:\winnt\system32\svchost.exe
+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\winnt\system32\nvsvc32.exe
+ PlugPlay管理设备安装以及配置,并且通知程序关于设备更改的情况。Microsoft Corporationc:\winnt\system32\services.exe
+ PolicyAgent管理 IP 安全策略以及启动 ISAKMP/Oakley (IKE) 和 IP 安全驱动程序。Microsoft Corporationc:\winnt\system32\lsass.exe
+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\winnt\system32\services.exe
+ RemoteRegistry允许远程注册表操作。Microsoft Corporationc:\winnt\system32\regsvc.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwsrv.exe
+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\winnt\system32\svchost.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\winnt\system32\lsass.exe
+ Schedule允许程序在指定时间运行。Microsoft Corporationc:\winnt\system32\mstask.exe
+ seclogon在不同凭据下启用启动过程Microsoft Corporationc:\winnt\system32\services.exe
+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\winnt\system32\svchost.exe
+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationc:\winnt\system32\spoolsv.exe
+ StarWindServiceEnables network access to local devices via iSCSI protocol.Rocket Division Softwared:\program files\alcohol soft\alcohol 120\starwind\starwindservice.exe