买的网络版瑞星,最近又两台服务器启动瑞星杀毒时只要选择“内存扫描”,瑞星才扫到第5个文件“csrss.exe”时系统就重起,但是如果不选“内存扫描”就可以正常扫描,但是查杀不出由什么病毒。瑞星重装了好几回也还是一样的,也没有发现什么明显的异常进程,以下是hijackthis扫描的日志。
Logfile of HijackThis v1.99.1
Scan saved at 11:19:20, on 2007-7-6
Platform: Windows 2003 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Netscape\Server4\bin\admin\ns-admin.exe
C:\Program Files\Cognos\cer4\bin\amserver.exe
C:\WINDOWS\system32\serverappliance\appmgr.exe
C:\Program Files\Cognos\cer4\bin\ppserver.exe
C:\Program Files\Cognos\cer4\bin\UpfrontAdministration.exe
C:\Program Files\Cognos\cer4\bin\upfdbsrv.exe
C:\Program Files\Cognos\cer4\bin\rds.exe
C:\Program Files\Cognos\cer4\bin\UpfDispatcherService.exe
C:\WINDOWS\system32\serverappliance\elementmgr.exe
C:\Program Files\Cognos\cer4\bin\UpfFMServer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Cognos\cer4\bin\UpfFMServer.exe
C:\WINDOWS\system32\IBMHPASV.EXE
C:\WINDOWS\system32\ibmspsvc.exe
C:\Program Files\Cognos\cer4\bin\UpfEventServer.exe
C:\WINDOWS\system32\ibmsprem.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\ibmsprem.exe
C:\Program Files\Cognos\cer4\bin\UpfServer.exe
C:\Program Files\Rising\Rav\RavService.exe
C:\Netscape\Server4\bin\slapd\server\ns-slapd.exe
C:\Program Files\Cognos\cer4\bin\UpfSearchEngine.exe
C:\Netscape\Server4\bin\slapd\server\ns-slapd.exe
C:\WINDOWS\system32\serverappliance\srvcsurg.exe
C:\Program Files\Cognos\cer4\bin\UpfServer.exe
C:\WINDOWS\Explorer.EXE
C:\Netscape\Server4\bin\slapd\server\slapd.exe
C:\Netscape\Server4\bin\slapd\server\slapd.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Acronis\TrueImageEnterprise\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Rising\Rav\RavTray.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
G:\ha_hijackthis_1991\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [TrueImageMonitor.exe] D:\Program Files\Acronis\TrueImageEnterprise\TrueImageMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [RavTray] "C:\Program Files\Rising\Rav\RavTray.exe"
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: AmarsoftDataWindowP - http://192.168.12.63:7001/amarbank6/Resources/1/Support/AmarDWP.CAB
O16 - DPF: AmarsoftDataWindowX - http://192.168.12.63:7001/BudgetAndPlan/Resources/1/Support/AmarDWX.CAB
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - http://192.168.12.63:7777/console
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = xacb.com
O17 - HKLM\Software\..\Telephony: DomainName = xacb.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = xacb.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = xacb.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = xacb.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = xacb.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = xacb.com
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Netscape Administration Server 4.2 (admin42-serv) - Netscape Communications Corporation - C:\Netscape\Server4\bin\admin\ns-admin.exe
O23 - Service: Cognos Access Manager Server (cer4) (amserver_cer4) - Cognos Inc - C:\Program Files\Cognos\cer4\bin\amserver.exe
O23 - Service: Cognos PowerPlay Enterprise Server (cer4) - Cognos Incorporated - C:\Program Files\Cognos\cer4\bin\ppserver.exe
O23 - Service: Cognos Upfront Administration Service (cer4) (Cognos UpfrontAdministration (cer4)) - Cognos Incorporated - C:\Program Files\Cognos\cer4\bin\UpfrontAdministration.exe
O23 - Service: Cognos Upfront Data Store (cer4) (Cognos UpfrontDataStore (cer4)) - Cognos Incorporated - C:\Program Files\Cognos\cer4\bin\upfdbsrv.exe
O23 - Service: Cognos Upfront Dispatcher (cer4) (Cognos UpfrontDispatcher (cer4)) - Cognos Incorporated - C:\Program Files\Cognos\cer4\bin\UpfDispatcherService.exe
O23 - Service: IBM Active PCI Alert Service (IBMHPS) - IBM Corporation - C:\WINDOWS\system32\IBMHPASV.EXE
O23 - Service: IBM Remote Supervisor Adapter II (ibmspsvc) - Unknown owner - C:\WINDOWS\system32\ibmspsvc.exe
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Netscape Directory Server 4.1 (Directory) (slapd-Directory) - Unknown owner - C:\Netscape\Server4/bin/slapd/server/ns-slapd.exe
O23 - Service: Netscape Directory Server 4.1 (Directory1) (slapd-Directory1) - Unknown owner - C:\Netscape\Server4/bin/slapd/server/ns-slapd.exe