3.还有服务器也中了,郁闷。
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 19:03:46 上午, on 2007-6-18
Platform: Windows 2003 SP1 (WinNT 5.02.3790)
Boot mode: Normal
Running processes:
C:\Documents and Settings\Administrator\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\trcboot.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\System32\dns.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
e:\Program Files\Magic Winmail\server\MailServer7.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
d:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe
D:\Software\动态域名\winpip\winpip.exe
e:\Program Files\Magic Winmail\server\http\Apache.exe
e:\Program Files\Magic Winmail\server\http\Apache.exe
D:\Program Files\Serv-U\ServUDaemon.exe
C:\WINDOWS\system32\tcpsvcs.exe
e:\Program Files\Magic Winmail\server\http\Apache.exe
C:\WINDOWS\system32\lserver.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Drivers\ldlcserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
e:\Program Files\Magic Winmail\server\MailCtrl.exe
C:\Program Files\360safe\safemon\360tray.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Serv-U\ServUTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\Lotus\Domino\nserver.exe
D:\Lotus\Domino\nfileret.EXE
D:\Lotus\Domino\nsrvwrap.exe
e:\Program Files\Magic Winmail\server\http\Apache.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
e:\Program Files\Magic Winmail\server\MailCtrl.exe
C:\Program Files\360safe\safemon\360tray.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Serv-U\ServUTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\Lotus\Domino\nserver.exe
D:\Java\jdk1.5.0_04\bin\java.exe
D:\Lotus\Domino\nsrvwrap.exe
D:\Lotus\Domino\nevent.EXE
D:\Lotus\Domino\nUpdate.EXE
D:\Lotus\Domino\nReplica.EXE
D:\Lotus\Domino\nRouter.EXE
D:\Lotus\Domino\nAMgr.EXE
D:\Lotus\Domino\nAdminP.EXE
D:\Lotus\Domino\nCalConn.EXE
D:\Lotus\Domino\nSched.EXE
D:\Lotus\Domino\nHTTP.EXE
D:\Lotus\Domino\nIMAP.EXE
D:\Lotus\Domino\nLDAP.EXE
D:\Lotus\Domino\nPOP3.EXE
D:\Lotus\Domino\nSMTP.EXE
D:\Lotus\Domino\namgr.EXE
G:\服务器共享\杀毒防火墙\HiJackThis_v2.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: NavigatMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - C:\Program Files\360safe\safemon\safemon.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [Magic Winmail] e:\Program Files\Magic Winmail\server\MailCtrl.exe
O4 - HKLM\..\Run: [360Safetray] C:\Program Files\360safe\safemon\360tray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ServUTrayIcon] D:\Program Files\Serv-U\ServUTray.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: 快捷方式 到 nserver.exe.lnk = D:\Lotus\Domino\nserver.exe
O4 - Startup: 快捷方式 到 startup.bat.lnk = D:\tomcat5.5.17\apache-tomcat-5.5.17\bin\startup.bat
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O10 - Broken Internet access because of LSP provider 'c:\documents and settings\administrator\windows\system32\mswsock.dll' missing
O15 - ESC Trusted Zone: http://down6.zol.com.cn
O15 - ESC Trusted Zone: http://download.pcstars.com.cn
O15 - ESC Trusted Zone: http://www.standardsoft.com.cn
O15 - ESC Trusted Zone: http://www.sures.com.cn
O15 - ESC Trusted Zone: http://www.dilongcn.com
O15 - ESC Trusted Zone: http://www.magicwinmail.com
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O15 - ESC Trusted Zone: http://*.windowsupdate.microsoft.com
O15 - ESC Trusted Zone: http://connect.microsoft.com
O15 - ESC Trusted Zone: http://oca.microsoft.com
O15 - ESC Trusted Zone: http://update.microsoft.com
O15 - ESC Trusted Zone: http://windowsupdate.microsoft.com
O15 - ESC Trusted Zone: http://www.mylove520.com
O15 - ESC Trusted Zone: http://*.server
O15 - ESC Trusted Zone: http://map.sogou.com
O15 - ESC Trusted Zone: http://www.standardsoft.cn
O15 - ESC Trusted Zone: http://auction1.taobao.com
O15 - ESC Trusted Zone: http://*.windowsupdate.com
O15 - ESC Trusted Zone: http://soft3.xn163.com
O15 - ESC Trusted Zone: http://www.yzykj.cn
O15 - ESC Trusted Zone: http://*.update.microsoft.com (HKLM)
O15 - ESC Trusted Zone: http://*.windowsupdate.microsoft.com (HKLM)
O15 - ESC Trusted Zone: http://go.microsoft.com (HKLM)
O15 - ESC Trusted Zone: http://msdn.microsoft.com (HKLM)
O15 - ESC Trusted Zone: http://oca.microsoft.com (HKLM)
O15 - ESC Trusted Zone: http://support.microsoft.com (HKLM)
O15 - ESC Trusted Zone: http://technet.microsoft.com (HKLM)
O15 - ESC Trusted Zone: http://windowsupdate.microsoft.com (HKLM)
O15 - ESC Trusted Zone: http://www.microsoft.com (HKLM)
O15 - ESC Trusted Zone: http://*.windowsupdate.com (HKLM)
O15 - ESC Trusted IP range: http://192.168.0.2
O15 - ESC Trusted IP range: http://218.241.133.18
O15 - ESC Trusted IP range: http://192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = standardsoft.com.cn
O17 - HKLM\Software\..\Telephony: DomainName = standardsoft.com.cn
O17 - HKLM\System\CCS\Services\Tcpip\..\{87229191-0E2D-40AF-9BC3-DB1DE326F47C}: NameServer = 202.106.0.20 202.106.46.151
O17 - HKLM\System\CCS\Services\Tcpip\..\{9FF883C2-C603-4CA9-A9DE-CC2FC59854EA}: NameServer = 202.106.0.20
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = standardsoft.com.cn
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O22 - SharedTaskScheduler: Browseui 预加载程序 - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\Documents and Settings\Administrator\WINDOWS\system32\browseui.dll (file missing)
O22 - SharedTaskScheduler: 组件类别缓存程序 - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Documents and Settings\Administrator\WINDOWS\system32\browseui.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: 卡巴斯基互联网安全套装 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
O23 - Service: ldlcserv - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe
O23 - Service: Lotus Domino Server (LotusDominoData) - IBM Corp - d:\Lotus\Domino\nservice.exe
O23 - Service: Winmail Mail Server (MagicWinmailServer) - AMAX Information Technologies Inc. - e:\Program Files\Magic Winmail\server\MailServer7.exe
O23 - Service: COMEXE PIPClient (PIPClient) - Unknown owner - D:\Software\动态域名\winpip\winpip.exe
O23 - Service: Serv-U FTP 服务器 (Serv-U) - Cat Soft - D:\Program Files\Serv-U\ServUDaemon.exe
O23 - Service: TrcBoot - IBM Corporation - C:\WINDOWS\system32\drivers\trcboot.exe
--
End of file - 9159 bytes