联想万全的服务器,windows2003系统,企业版瑞星,最近服务器运行速度明显的变的很慢,看了一下进程发现有四五十个cmd.exe.是不是不正常啊?中毒了吗?每天都用瑞星查毒都没有查出来啊....这是所有的进程
System
smss.exe
csrss.exe
winlogon.exe
services.exe
lsass.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
CCenter.exe
spoolsv.exe
msdtc.exe
svchost.exe
sqlservr.exe
mysqld-nt.exe
Apache.exe
RavAgent.exe
RavAlert.exe
RavUpdate.exe
svchost.exe
RNReport.exe
dfssvc.exe
IEXPLORE.EXE
Apache.exe
explorer.exe
RavTray.exe
RavTask.exe
ctfmon.exe
sqlmangr.exe
Monitor.exe
wmiprvse.exe
cmd.exe
ftp.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
ftp.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
RsAgent.exe
agentsvr.exe
conime.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
explorer.exe
RavMonD.exe
RavMon.exe
RavStub.exe
RavService.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
cmd.exe
WinRAR.exe
prockiller.exe
----共导出进程103个
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 10:45:28, 日期 2006-9-20
操作系统: Windows 2003 (WinNT 5.02.3790)
浏览器: Internet Explorer v6.00 (6.00.3790.0000)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
D:\MYOA\mysql\bin\mysqld-nt.exe
D:\MYOA\bin\apache.exe
C:\Program Files\Rising\Rav\RavAgent.exe
C:\Program Files\Rising\Rav\RavAlert.exe
C:\Program Files\Rising\Rav\RavUpdate.exe
C:\Program Files\Rising\Rav\RNReport.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\MYOA\bin\apache.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rising\Rav\RavTray.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\MYOA\bin\Monitor.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\Program Files\Rising\Rav\RAVMON.EXE
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Rising\Rav\RavService.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.641\HijackThis1991zww.exe
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} - C:\WINDOWS\system32\AlxTB1.dll
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - IE工具栏增项: Alexa - {3CEFF6CD-6F08-4e4d-BCCD-FF7415288C3B} - C:\WINDOWS\system32\SHDOCVW.DLL
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [RavTray] "C:\Program Files\Rising\Rav\RavTray.exe"
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [ShutdownEventCheck] %systemroot%\system32\dumprep 0 -s
O4 - 启动项HKLM\\Run: [MSConfig] "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
O4 - 启动项HKLM\\RunServices: [MSDN for Windows with NT's] msdn-nt.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RuunServices:[MSDN for Windows with NT's] msdn-nt.exe
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: 通达应用服务监视器.lnk = D:\MYOA\bin\Monitor.exe
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7FA99B91-BD25-4250-8C20-88E71FA0B174}: NameServer = 202.99.8.1
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - NT 服务: IMA_Server - Unknown owner - D:\MYOA\IMA\IMAServer.exe
O23 - NT 服务: MeChat - Unknown owner - D:\MYOA\MeChat\MeChat.exe
O23 - NT 服务: MySQL_OA - Unknown owner - D:\MYOA\mysql\bin\mysqld-nt.exe
O23 - NT 服务: Office_Anywhere - Unknown owner - D:\MYOA\bin\apache.exe" -k runservice (file missing)
O23 - NT 服务: Rav Net Agent (RavAgent) - 北京瑞星科技股份有限公司 - C:\Program Files\Rising\Rav\RavAgent.exe
O23 - NT 服务: Rav Net Alert (RavAlert) - 瑞星科技股份发展有限公司 - C:\Program Files\Rising\Rav\RavAlert.exe
O23 - NT 服务: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - NT 服务: RavUpdate - Unknown owner - C:\Program Files\Rising\Rav\RavUpdate.exe" (file missing)
O23 - NT 服务: RNReport - 瑞星科技股份发展有限公司 - C:\Program Files\Rising\Rav\RNReport.exe
O23 - NT 服务: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
ap\Á1}æ8Ãbbs.ikaka.comZ0pÕ~É5´1