1.是不是解压后杀毒?病毒的路径呢?
2.可疑文件
自己测下
C:\windos\Tasks\hackshen.vbs
http://www.virscan.org/http://www.virustotal.com/zh-cn/操作方法见我的签名
删除启动文件夹
[test]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\test.exe --> [File is missing]><N>
删除驱动及对应文件
[KSysCall / KSysCall][Stopped/System Start]
<\??\C:\DOCUME~1\wangbin\LOCALS~1\Temp\Rar$EX00.750\KvDetect\KSysCall.sys><N/A>
[dhqmgmsd / dhqmgmsd][Running/Boot Start]
<C:\windos\System32\DRIVERS\dhqmgmsd.sys><Yahoo! China Corporation>
[KSysCall / KSysCall][Stopped/System Start]
<\??\C:\DOCUME~1\wangbin\LOCALS~1\Temp\Rar$EX00.750\KvDetect\KSysCall.sys><N/A>
[yaskp / yaskp][Running/Boot Start]
<C\windos\system32\drivers\yaskp.sys><Copyright (C) yahoo Corporation>
删除浏览器加载项
[Yahoo!Photo]
{33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, yahoo! china>
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, yahoo! china>
[yFlashDl Class]
{F166BC04-3C84-44cc-A6E9-2315EC4844B9} <C:\Program Files\Yahoo!\Assistant\Assist\yflashdl.dll, Yahoo! China>
[assist]
{FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll, Yahoo! China>
[雅虎助手]
{5D73EE86-05F1-49ed-B850-E423120EC338} <
http://cn.zs.yahoo.com/start.htm?source=yzs_icon&btn=yassistnew, N/A>
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, yahoo! china>
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, yahoo! china>
[]
{45A87252-1326-4C5B-B08A-5D159D57D9D3} <C:\WINDOWS\system32\dmkagalibhzjt.dll, N/A>
[Yahoo!Live]
{57421194-58FB-49AE-9B4F-FD48869B9AD4} <C:\Program Files\Yahoo!\Assistant\yaLive.dll, yahoo! china>
[DragSearch BHO]
{62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, yahoo! china>
[yFlashDl Class]
{F166BC04-3C84-44CC-A6E9-2315EC4844B9} <C:\Program Files\Yahoo!\Assistant\Assist\yflashdl.dll, Yahoo! China>