用瑞星的专杀也查不出病毒啊~~
现在用不了WINRAR来解压HijackThis这个软件,用瑞星听诊器生成的日志也可以吧:
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\PROGRA~1\YAHOO!\ASSIST~1\YLIVE.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\PROGRAM FILES\YAHOO!\ASSISTANT\YNOTIFIER.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\YASSISTSE.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YASSECBLK.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YASMENU.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YIEANGEL.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YMENUINFO.DLL
D:\安装目录\RISING\RFW\RFWMAIN.EXE
D:\安装目录\RISING\RFW\RSGUILIB.DLL
D:\安装目录\RISING\RFW\RSCOMMON.DLL
D:\安装目录\RISING\RFW\PNGDLL.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\SHADOW\SHADOWSERVICE.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\windows\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
D:\安装目录\PERMEO\E-BORDER DRIVER\S5SPI.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5IMPL.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5CRED.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YSCRBLOCK.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\PROGRA~1\BAIDU\BAR\BAIDUBAR.DLL
C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL
C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL
C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YANGLING.DLL
C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
C:\WINDOWS\SYSTEM32\JCCATCH.DLL
D:\安装目录\KUGOO3\KUGOO3DOWNXCONTROL.OCX
C:\PROGRAM FILES\NETTRANSPORT 2\NTIEHELPER.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\安装目录\PERMEO\E-BORDER DRIVER\S5SPI.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5IMPL.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5CRED.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCHPG.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCH_AG.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\FSSYNC.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_RMT.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCCLIENT.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLIPC.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLUTIL.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\RPT.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCIFACE.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRLOADER.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRKERNEL.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRSTRING.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_SRV.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_CLNT.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\TEMPFILE.PPL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8.OCX
C:\WINDOWS\SYSTEM32\NQWBX.IME
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
D:\安装目录\RISING\RFW\RFWSRV.EXE
D:\安装目录\RISING\RFW\RFWRULE.DLL
D:\安装目录\RISING\RFW\RFWLOG.DLL
D:\安装目录\RISING\RFW\RFWDRV.DLL
D:\安装目录\RISING\RFW\PSAPI.DLL
D:\安装目录\RISING\RFW\MONDRV.DLL
D:\安装目录\RISING\RFW\PROCLIB.DLL
D:\安装目录\RISING\RFW\MPORTS.DLL
C:\WINDOWS\EXPLORER.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\PROGRA~1\BAIDU\BAR\BAIDUBAR.DLL
C:\WINDOWS\SYSTEM32\JCCATCH.DLL
C:\WINDOWS\SYSTEM32\PORTABLEDEVICEAPI.DLL
C:\WINDOWS\SYSTEM32\NVSHELL.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL
C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
D:\安装目录\KUGOO3\KUGOO3DOWNXCONTROL.OCX
C:\PROGRAM FILES\NETTRANSPORT 2\NTIEHELPER.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SHELLEX.DLL
C:\WINDOWS\SYSTEM32\NQWBX.IME
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YWIPER.DLL
D:\安装目录\TENCENT\QQ\QDSHM.DLL
D:\安装目录\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\MSN MESSENGER\FSSHEXT.8.0.0792.00.DLL
C:\WINDOWS\SYSTEM32\WPDSHEXT.DLL
C:\WINDOWS\SYSTEM32\AUDIODEV.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5SPI.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5IMPL.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5CRED.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YSCRBLOCK.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\PROGRA~1\BAIDU\BAR\BAIDUBAR.DLL
C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL
C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL
C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YANGLING.DLL
C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
C:\WINDOWS\SYSTEM32\JCCATCH.DLL
D:\安装目录\KUGOO3\KUGOO3DOWNXCONTROL.OCX
C:\PROGRAM FILES\NETTRANSPORT 2\NTIEHELPER.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\NQWBX.IME
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\安装目录\PERMEO\E-BORDER DRIVER\S5SPI.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5IMPL.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5CRED.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCHPG.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCH_AG.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\FSSYNC.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_RMT.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCCLIENT.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLIPC.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLUTIL.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\RPT.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCIFACE.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRLOADER.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRKERNEL.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRSTRING.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_SRV.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_CLNT.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\TEMPFILE.PPL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8.OCX
D:\安装目录\音速启动(VSTART) 5.0\VSTART.EXE
C:\WINDOWS\SYSTEM32\MSVBVM60.DLL
C:\WINDOWS\SYSTEM32\VB6CHS.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\COMCTL32.OCX
D:\安装目录\瑞星专杀软件\RSDETECT.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\SHADOW\SHADOWSETTING.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5SPI.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5IMPL.DLL
D:\安装目录\PERMEO\E-BORDER DRIVER\S5CRED.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCHPG.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCH_AG.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\FSSYNC.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_RMT.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCCLIENT.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLIPC.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLUTIL.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\RPT.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCIFACE.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRLOADER.DLL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRKERNEL.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRSTRING.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_SRV.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_CLNT.PPL
D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\TEMPFILE.PPL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YLive.exe = C:\PROGRA~1\YAHOO!\ASSIST~1\YLIVE.EXE
yassistse = "C:\PROGRA~1\YAHOO!\ASSISTANT\YASSISTSE.EXE"
RunShadowTip = C:\WINDOWS\SYSTEM32\SHADOW\SHADOWTIP.EXE
RfwMain = "D:\安装目录\RISING\RFW\RFWMAIN.EXE" -STARTUP
RavTask = "D:\安装目录\RISING\RAV\RAVTASK.EXE" -SYSTEM
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVCPL.DLL,NVSTARTUP
KAVPersonal50 = "D:\安装目录\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KAV.EXE" /MINIMIZE
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs = C:\WINDOWS\SYSTEM32\CTFMON.EXE
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"