连用了n个工具,终于搞掂了.机上除了木马外,还有恶意程序.
首先发一发经过上周初步诊断得出的日志
HijackThis_815汉化版扫描日志 V1.99.1
保存于 15:53:29, 日期 2006-02-28
操作系统: Windows XP (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP1 (6.00.2600.0000)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\PROGRA~1\INTERB~1\Bin\IBGuard.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$CXDY3\Binn\sqlservr.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\UNION Technology\优益桌面安全套件 V2.5.04(Siemens版本)\eKeyDaemon.exe
C:\WINDOWS\System32\service.exe
//可疑C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\southtalent\sasweb\量化考核管理服务器.exe
C:\PROGRA~1\INTERB~1\Bin\ibserver.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\SecuritySuite.exe
C:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - 启动项HKLM\\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - 启动项HKLM\\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - 启动项HKLM\\Run: [eKeyDaemon] "C:\Program Files\UNION Technology\优益桌面安全套件 V2.5.04(Siemens版本)\eKeyDaemon.exe"
O4 - 启动项HKLM\\Run: [SwService] service.exe
//可疑O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: 2005新交规驾驶员理论考试系统(全国通用版).lnk = ?
O4 - Global Startup: 启动服务器.lnk = ?
O4 - Global Startup: HP Image Zone 快速启动 .lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O15 - 添加的受信任的 IP 地址范围: http://egat.laho.gov.cn
O15 - 添加的受信任的 IP 地址范围: 172.30.242.62
O15 - 添加的受信任的 IP 地址范围: http://172.30.242.62
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - http://172.30.242.53/officescan/ClientInstall/WinNTChk.cab
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupIniCtrl Class) - http://172.30.242.53/officescan/clientinstall/setupini.cab
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - http://172.30.242.53/officescan/clientinstall/setup.cab
O16 - DPF: {25069B4A-2C99-45DB-BB0E-967C02466656} (SdoFile.FrmControl) - http://172.30.242.62/kwoa/flow/SdoFile.CAB
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) - http://172.30.242.53/officescan/clientinstall/RemoveCtrl.cab
O16 - DPF: {AB10EB91-C2F1-48E9-BD06-8B4987A32A62} (ScanOcrX
Object) - http://172.30.242.62/kwoa/flow/hotocr.cab
O16 - DPF: {B50298C0-84B2-487F-906B-F11714F15AE2} (FSControlX Control) - http://172.30.242.62/kwoa/flow/HttpFS.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{E6BD1E24-16A9-447D-93D6-A8FFBD3E6625}: NameServer = 172.16.22.3,172.16.1.1
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - NT 服务: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - NT 服务: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - NT 服务: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - NT 服务: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - NT 服务: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - NT 服务: InterBase Guardian (InterBaseGuardian) - Inprise Corporation - C:\PROGRA~1\INTERB~1\Bin\IBGuard.EXE
O23 - NT 服务: InterBaseServer - Inprise Corporation - C:\PROGRA~1\INTERB~1\Bin\ibserver.exe
O23 - NT 服务: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - NT 服务: System Internet Service (msinetsvr) - Unknown owner - C:\WINDOWS\System32\inetesvr.exe
//可疑O23 - NT 服务: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - NT 服务: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - NT 服务: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - NT 服务: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
一开始还有个G_server 1.2.exe的启动项,是灰鸽子,被我用专杀工具干掉了.
初步怀疑
1.名为service.exe的启动项,因为正常的系统进程是services.exe
2.名为inetesvr.exe的服务 ,一般上我对注明为Unknown owner 的服务都特别留意,连名字都不敢留,估计不是什么好货色