 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
4 Q% e7 F! F' H. UScan saved at 16:55:24, on 2006-5-6! N, @9 A( }/ u+ V
Platform: Windows XP SP2 (WinNT 5.01.2600)+ H+ o5 V4 C8 n- l P
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)- B! g% j8 u, F: X& J6 m
: S" J! ?( |& s' I2 `Running processes:
- ~7 g; j8 a/ p2 Y0 T8 D& M qC:\WINDOWS\System32\smss.exe
8 t6 |8 A1 z: q9 l) ^C:\WINDOWS\system32\winlogon.exe7 p& m; k) j) \2 k/ }1 Z
C:\WINDOWS\system32\services.exe
9 L' h0 ^ e* W: B+ |. G/ KC:\WINDOWS\system32\lsass.exe
6 W( [3 y! n/ t0 WC:\Program Files\Common Files\Virtual Token\vtserver.exe
2 ~# _0 P. I2 t! k9 _% LC:\WINDOWS\system32\ibmpmsvc.exe1 `4 R$ n _5 s$ |8 ?- c E( K
C:\WINDOWS\system32\svchost.exe
$ ^3 v4 O; V Z( L' RC:\WINDOWS\System32\svchost.exe1 h. F U% P8 W6 d; ]
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
; s- f& R) y# T9 k! o ^# `4 RC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe/ M C; U; C0 U0 y
C:\WINDOWS\system32\spoolsv.exe" K6 N2 i8 c% Z. L$ t3 _" w
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE+ X6 Q( c; [6 d- @
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe5 v$ g+ u R: P
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe' b+ h' X& `: g+ ]4 H) Y
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
1 J* q( w3 s hC:\Program Files\F-Secure\Common\FSMA32.EXE
/ X" n; @9 P5 E; I) Q+ f; UC:\Program Files\F-Secure\Common\FSMB32.EXE
% b! w- m; l- x( }$ g' S3 jC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe" }& |3 j$ x( W2 P& r' t/ {" l
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
y9 A. u! q4 E! E1 }C:\WINDOWS\System32\QCONSVC.EXE+ Z' |0 y* P8 @& H( c
C:\Program Files\F-Secure\Common\FCH32.EXE- r/ \7 i4 |) ?2 M' h2 L
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
: E4 b d; A. F; g% n. GC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe* H+ V, Y' B. J# C. U. j7 ^, T
C:\WINDOWS\System32\TPHDEXLG.EXE
1 n0 z) ?+ g9 F1 E3 t! [% {C:\Program Files\F-Secure\Common\FAMEH32.EXE
F' |' R$ Q9 U6 gC:\WINDOWS\system32\TpKmpSVC.exe
+ R, ^$ D1 j, G' S) \C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
- V6 Z# C w0 aC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
8 p7 g# p% M' |8 u E( E, ?* lC:\Program Files\F-Secure\Common\FNRB32.EXE
& `) N1 Y S# C$ I: BC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe+ D+ `5 }3 h+ D7 E' H' i
C:\Program Files\F-Secure\Common\FIH32.EXE
' i6 X/ ] W# n* p# N4 e( ~C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
8 A l$ d3 |0 E: jC:\WINDOWS\Explorer.EXE
4 D- N$ r5 b. ^C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
) i& ~; Z9 ~) ?7 { I1 u0 g* j mC:\Program Files\Synaptics\SynTP\SynTPEnh.exe1 ~" j, ]# |" s7 @
C:\WINDOWS\system32\hkcmd.exe
/ N" ~: d; i) H* w5 X; A( B: [C:\WINDOWS\system32\TpShocks.exe
/ I- ]1 ~( q4 x! a/ m- eC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
}) w) i" q0 r7 O7 J( \' d; ^C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe6 a k1 ^! N+ w5 Z3 C7 i/ d4 y
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe7 \% W2 s0 X6 l& J. h- G9 @2 _. ~
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
7 e6 Z m1 ]/ b- |, q5 _5 h% C+ gC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe. b6 ]2 c7 C4 {8 R, p
C:\WINDOWS\system32\dla\tfswctrl.exe
' ^, B$ f/ s. m* X! CC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
* ?6 q' _7 x1 gC:\IBMTOOLS\UTILS\ibmprc.exe
; }6 N' Z# Y8 T2 P5 r9 h! oC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE9 @$ n7 |( v7 p+ b7 d& L1 U
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE3 R. ] P8 C; B
C:\WINDOWS\System32\svchost.exe
3 R# S0 K6 U' D: M" V5 UC:\WINDOWS\system32\rundll32.exe
! _. C6 r6 G$ r3 N; J6 P( GC:\Program Files\F-Secure\Common\FSM32.EXE
7 ^9 ?8 N, F0 W1 KC:\WINDOWS\system32\CTFMON.EXE
. b4 E2 m* W1 f5 MC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe2 Z6 K% [/ m8 |. a! N5 S2 B# U
C:\Program Files\Digital Line Detect\DLG.exe
7 d1 ?; ]8 q! i$ ^ GC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe$ T) Z& Z; Y7 O9 f- c3 G
C:\Program Files\F-Secure\FSGUI\fsguidll.exe
; N8 S: |5 X( i& vC:\Program Files\Messenger\msmsgs.exe
) H1 V u" k# SC:\Program Files\Internet Explorer\iexplore.exe
0 `" C0 x. c+ F5 _6 c( @C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
+ ~4 u4 z5 a& @
; A$ h$ }+ n1 z+ g z0 }O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll3 k( c6 e O, K! Q% r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
. U$ ]+ G6 P; p: BO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
* z. [# ~6 q, W: t. k& R1 PO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe' L5 e" u6 M# m9 M$ ~
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
5 x7 K$ l* B. g5 S& m# EO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper+ E2 O1 K9 q% i0 u" B& \
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
$ K+ C7 z: ^% p, J: J( G3 _; AO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe7 |! D& {# z9 ]& P8 K% u6 z
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
1 ?3 F: y, N! Z# N0 @O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
: q& s2 R0 A e( ?! C" IO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
9 \1 l- z4 H3 aO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe$ M5 {% e% u" \! S( m
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
& T9 G4 B0 M$ a) t: eO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r9 B" T9 r& n4 B* o2 b4 z* E
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
# H- N' P. ?* A2 l* L( UO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
5 W' I( `3 ~& l2 t( fO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe6 f) Z4 ?9 J+ p1 u$ i# U5 ]0 r
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE/ K2 Z1 ? B8 |. v
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
& W0 k5 G% N' jO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor* @- P) N; \7 Y/ z; \0 N& m
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog- ~3 n! x- _: |: I- Z0 X
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration326 H- ]) [+ r/ l/ n( G* T
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE2 m9 q4 B3 s1 b
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC! ~0 z5 t) j/ c, x# z
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC; u- t; a( ?/ }; ^) ?5 m# y' m' R5 m
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
4 {1 g5 n l* IO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
* _- V/ R9 `( l4 S( P' q$ CO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
c) _5 s2 w$ O! `7 y# QO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
* N1 J, S- ]$ M8 W n* k I; oO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe3 `5 M6 I( u1 a7 o
O4 - Global Startup: Digital Line Detect.lnk = ?! Q& D. X4 ~" j c% ?" M/ z
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
+ a$ E: M2 q/ s( A' |0 dO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm a7 P- b7 {% J* q. o
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
4 ]' V& F4 U% P6 @* D& iO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
8 V: n. f% ^, q; V/ u& d' |# J- dO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll3 V4 E5 Q& a; X5 J
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll j) h8 W3 K0 d" ]) w& s/ O3 Z/ n
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe8 `9 \/ U, O) C$ T# {
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
6 Z% m! {1 H+ h) W& T4 hO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
* @. M F' R. p! _* e5 pO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll$ O3 c: \' x& j: L, g! U) _
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
( q- ~) L" [" y$ v, y0 f3 w* UO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll# p& H1 _% \% V! ~2 j; V3 f
O11 - Options group: [JAVA_IBM] Java (IBM)
" x* J: n' _2 _5 MO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll! _2 j j+ p' ^6 |# w
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
2 t. s$ }* W: n( [7 {O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll% P( c3 d* D6 a
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
1 U: X# |9 l. GO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
( ~, C! ~' u! u, U: ]* N2 bO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe' Y1 _: ^( M; L/ @, Z: T
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
/ G" U7 v$ {0 P# N8 E# @O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE# ?% [) w; O( I" f
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
V& [+ @; B0 f, q6 @O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe5 u0 u' n! t' E9 {
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
) ^% G+ [- w& X- x' Y+ N' {O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
( W& b2 G% t |$ K2 d4 R. _O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
) Y2 T r* K) y; O! _1 t! p: TO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe- l+ D: |! z! F
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)/ B: q I$ l) |0 {$ y$ B O' M
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE. \0 M5 J0 B) ?/ q
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
# A: Q; U: L! I) C( P4 x7 XO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
+ l. B' B) `& gO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
8 ^' X6 A+ b E5 y. @: nO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE1 v$ r' a2 N& j, A9 ~4 c7 V
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe8 S! X. [1 H4 ~ H) r1 R, l3 y- |
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|