having some troian experience (long time ago `cause today sucks with all that script kiddies) program will launch from these points
/windows/win.ini -edit it with notpad
[windows]
load=
run= ----here can be placed something like c:\program.exe
/windows/system.ini
[boot]
oemfonts.fon=vgaoem.fon
shell=Explorer.exe ----if you put somenthig after that it will lunch it too.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ,run once
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ,run once ,run service
if it is a msdos based program it can be launched from autoexec.bat too
there is another trick
install some soft for the process manager.i use efprocessmanager
with this program.you can see the files that are working on your comp and also TAKE A LOOK FROM WHERE they are launched.then delete the folder from where they are launched,reboot and then windows tell you you have an invalind link in the registry and point you to thet link.type then regedit in the run from the taskbar,delete the link and bingo you fu*** their F**** spam.