桌面上出现一批处理文件
angelskydel.bat
文件内容如下
:try
del "C:\DOCUME~1\uersname\LOCALS~1\Temp\18991230093336.exe"
if exist "C:\DOCUME~1\username\LOCALS~1\Temp\18991230093336.exe" goto try
del %0
经查看C:\DOCUME~1\username\LOCALS~1\Temp\目录下存在18991230093336.exe
手工删除该文件和桌面上的bat文件,重新启动后,防火强提示C:\DOCUME~1\wangtie\LOCALS~1\Temp\18991230093336.exe试图访问网络,查看后C:\DOCUME~1\wangtie\LOCALS~1\Temp\目录下自动生成18991230093336.exe文件,桌面bat文件也已经生成。拒绝该exe文件的网络要求后,temp目录下的exe文件自动删除,桌面上的bat文件存在。
目前发现招商银行的专业版无法输入密码,其它的现象还没有发现。
系统使用卡巴斯基—+ZA+ewido保护
Hijackthis
StartupList report, 2006-8-28, 上午 10:01:53
StartupList version: 1.52
Started from : C:\Documents and Settings\username\桌面\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
F:\APMServ\APMServASP.exe
C:\PROGRA~1\ESRI\LICENSE\arcgis9x\lmgrd.exe
C:\Program Files\Leica Geosystems\Shared\bin\ntx86\lmgrd.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\PROGRA~1\ESRI\LICENSE\arcgis9x\ARCGIS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Leica Geosystems\Shared\bin\ntx86\ERDAS.EXE
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\eMule\emule.exe
C:\WINDOWS\system32\Flurry.scr
C:\Program Files\Maxthon\Max.exe
C:\Documents and Settings\wangtie\桌面\HijackThis.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\wangtie\「开始」菜单\程序\启动]
Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Shell folders Common Startup:
[C:\Documents and Settings\All Users\「开始」菜单\程序\启动]
服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
KAVPersonal50 = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
Zone Labs Client = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
StormCodec_Helper = "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
LVCOMSX = C:\WINDOWS\system32\LVCOMSX.EXE
MSConfig = C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
bgswitch = C:\WINDOWS\system32\bgswitch.exe
H/PC Connection Agent = "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
msnmsgr = "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
eMuleAutoStart = C:\Program Files\eMule\emule.exe -AutoStart
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=EXPLORER.EXE,SystemSaveFile.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\logon.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper
Objects:
(no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\PROGRA~1\FLASHGET\jccatch.dll - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7}
ThunderBHO - C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll - {889D2FEB-5411-4565-8998-1DD2C5261283}
--------------------------------------------------
Enumerating Download Program Files:
[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://update.microsoft.com/micr ... e.cab?1156206556062
[Shockwave Flash
Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx
CODEBASE = http://download.macromedia.com/p ... s/flash/swflash.cab
--------------------------------------------------
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\DOCUME~1\wangtie\LOCALS~1\Temp\nsbD.tmp\System.dll||C:\DOCUME~1\wangtie\LOCALS~1\Temp\nsbD.tmp\
--------------------------------------------------
Enumerating ShellService
ObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\st
object.dll
--------------------------------------------------
End of report, 6,248 bytes
Report generated in 0.078 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only