 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
6 o( W4 Q% U9 M1 M# NScan saved at 16:55:24, on 2006-5-6$ J1 x1 b# I: d7 T( H
Platform: Windows XP SP2 (WinNT 5.01.2600)0 o6 n }9 G8 M2 |8 k r m1 @
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180). M8 ~- {; _8 f
8 r$ M" E. H' Y/ z) C. gRunning processes:
" W! Y3 M7 ?5 V3 Z2 xC:\WINDOWS\System32\smss.exe
& b' x( A2 o* a* GC:\WINDOWS\system32\winlogon.exe
( M" r) g$ z3 SC:\WINDOWS\system32\services.exe( J9 r. C0 @+ ]; g. V4 t
C:\WINDOWS\system32\lsass.exe
0 w& \1 z$ ?* r% [. TC:\Program Files\Common Files\Virtual Token\vtserver.exe
; T. S# a0 \" k0 Q2 }C:\WINDOWS\system32\ibmpmsvc.exe0 G$ N. |9 \( ^- |7 H
C:\WINDOWS\system32\svchost.exe! i) ]' i! K2 B2 h
C:\WINDOWS\System32\svchost.exe
) u$ e- b0 s8 F) y+ IC:\Program Files\Intel\Wireless\Bin\EvtEng.exe0 }4 D5 u7 e+ d
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe/ I1 j' \5 t- A
C:\WINDOWS\system32\spoolsv.exe
* h6 C& A; O! L, U: {C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE4 W0 g4 N2 g! |. o2 ]/ V% k
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
+ ~8 n \( Z4 i5 \5 Z2 F+ P oC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe. l4 G6 K/ |$ u! q
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
9 N% F4 q/ T7 _2 n yC:\Program Files\F-Secure\Common\FSMA32.EXE
5 ~6 h3 i {+ aC:\Program Files\F-Secure\Common\FSMB32.EXE
9 L7 @' U8 h% m8 L. L+ P- U3 oC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe, U2 M5 v/ b4 E2 U" J
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
0 v& J; y1 h7 x- Y, N+ k* t+ SC:\WINDOWS\System32\QCONSVC.EXE
l0 b4 X& W: vC:\Program Files\F-Secure\Common\FCH32.EXE
; j$ a6 H: }$ U8 e" xC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe% o3 n% [" N6 _0 h; X* [
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe/ X1 c* s/ f7 M* {+ q
C:\WINDOWS\System32\TPHDEXLG.EXE5 h; \( L% ~5 g, P+ G. x
C:\Program Files\F-Secure\Common\FAMEH32.EXE V& u9 q0 S% b) n7 g; S
C:\WINDOWS\system32\TpKmpSVC.exe
" }+ `9 N, F( L: ]5 D# i( n8 F/ BC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
" q8 x- w& F2 f, l( h) _# TC:\Program Files\F-Secure\Anti-Virus\fsrw.exe; J+ a( ~; g$ c! e( |2 K3 j
C:\Program Files\F-Secure\Common\FNRB32.EXE7 k* T1 x: C; O F' n8 Y9 y
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe! b2 G/ F( I. ]" V4 f F
C:\Program Files\F-Secure\Common\FIH32.EXE5 Y0 i$ J; Z8 C; e6 J
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe' R4 C, j5 \7 d$ U$ F
C:\WINDOWS\Explorer.EXE
& g! z) A8 C6 m p& d% F( A* ZC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
* a& S" C& \$ e9 v9 CC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
! E! ~. u& Y- K/ AC:\WINDOWS\system32\hkcmd.exe
8 q; e0 j/ A/ v/ s. EC:\WINDOWS\system32\TpShocks.exe0 P5 \! A' l9 C U( i- N
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
" g) l& l& e" P: H/ h% O" E0 i0 b# JC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe. [0 Y' d/ ]* k3 ]9 E
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
9 f, Y! }1 X: P, kC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
, U: n1 p: B5 L+ |9 W( UC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe3 C1 _4 _/ w" R5 D+ J, Q
C:\WINDOWS\system32\dla\tfswctrl.exe
& D) O$ b. i" K! i& M% x hC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
+ A8 h, \/ z. g; X+ g' C+ {$ mC:\IBMTOOLS\UTILS\ibmprc.exe3 Y- t- \" t" o
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE+ H* O# m7 T/ R o- E- y
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
2 n' e2 j4 b3 mC:\WINDOWS\System32\svchost.exe
: W/ e7 i9 o% ?3 xC:\WINDOWS\system32\rundll32.exe) P7 z3 n. I3 U9 N$ y
C:\Program Files\F-Secure\Common\FSM32.EXE+ W# k' A3 F1 m1 [6 b
C:\WINDOWS\system32\CTFMON.EXE
" Q* B2 Q0 g& s; PC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe8 f1 r' [( F# f7 q/ i" X5 V
C:\Program Files\Digital Line Detect\DLG.exe
9 H) s/ i" T/ D4 x4 [C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe- G1 C; d) T0 n3 a# E
C:\Program Files\F-Secure\FSGUI\fsguidll.exe7 o, |( N4 j1 U3 S& ~
C:\Program Files\Messenger\msmsgs.exe
+ e# Q/ m3 P; L+ V O2 hC:\Program Files\Internet Explorer\iexplore.exe
# c+ Y% w$ W/ _, P4 N. b5 xC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
: |6 O; S& ]5 H9 n Y3 |7 }* U8 Y
9 H9 K3 K3 `3 {: X! C) U. H$ M; jO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
! m9 C/ P! I- F+ F/ RO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe0 e) F5 b8 A* S: q
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
6 K" u& M7 l. p: l# `" g eO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe3 k1 o3 O6 n( Z/ H$ }
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe! H+ o" z6 h4 p( {1 P0 b6 _
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
) o+ B+ U! l9 VO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
- w& h4 a* C/ e/ t# g& m) W9 g' fO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe- t+ b; { n( O$ G- M J! w \
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup( H( @( ^: |* p& I" n- U3 o
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe8 E3 a, F3 J# a) N; _2 ?1 d
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
. k6 U" O' T' R4 J; W/ a; oO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
4 D; `# K; w7 \: ~* J3 FO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
4 t$ ~5 [$ M5 jO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
" a9 Q" \: U8 @, XO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe# s6 z6 K/ K; K5 r. O# _* Z9 d; M: ^
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe/ y# V, m0 k4 Q' f+ E
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe/ j5 J, G( c2 w1 M- O$ v
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE. Q! r9 l# K" V8 G
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE4 h8 `. E* v y' o1 {& l8 s
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
$ U: I. s# l" V% O2 }: Y9 tO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
: m0 G* M3 Z0 z. wO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32! D2 V2 Q6 Z/ |' t. B" X+ H
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
, [% h4 ]0 @4 l0 E$ U6 yO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
( ~ F0 L/ l: z( N/ s& j2 E, LO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
4 i. `) N8 e1 W/ F. U& I8 W( h- g3 ]) IO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName$ Q9 X* i& J$ M5 T
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
+ I5 p1 P5 [7 F5 C2 O4 OO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW8 X( I: A" n" u; {) X1 f
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
7 U, _% _4 [. ^+ q- A. qO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe4 D8 |6 ]4 U3 }1 v a8 V9 Q5 H y
O4 - Global Startup: Digital Line Detect.lnk = ?5 |7 _/ [. _- s6 o; r7 n- V
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe$ l! l. ]! ?. U; ?8 H; ]
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
) r9 R; E' Z4 f( t6 a2 U9 X7 o" cO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll9 ^# {" V8 C, H& @% K
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
9 p/ h; `. F6 k8 o3 KO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
3 \: F0 H [6 O2 HO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
' |; G2 T' I7 O, \9 O5 p+ SO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
$ b( k$ J# |) ?6 ]) A. U+ zO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe/ W5 \7 \' \3 T" |/ j4 V
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
+ ?2 c. G& F2 z- y* r+ RO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
( u7 ~ \" X) r+ s, NO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll3 x: _1 P( R! U6 o2 W
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll3 R; |7 h& P+ |8 U$ k) r8 P
O11 - Options group: [JAVA_IBM] Java (IBM)2 B/ k! t, ]6 d% V/ m3 g0 q6 ~) f, K2 Y
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll8 Y9 s, d' f: ?
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
. U- [5 s3 }, E' U( U( [: FO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll R/ O7 O* p2 e, k9 y* c1 G* ~
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
K7 c& u6 n& y# QO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
" g4 ~$ ?" _$ }, YO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
1 p* s) s0 b* b0 S% KO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe6 P$ R! q$ m3 y7 w, C2 {, N5 p
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE% u% h. d2 H8 Y* i/ s" h% P
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
6 Z* g/ n. S3 l1 RO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
( J8 y6 [4 s* y* }0 nO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE1 P. d6 \0 s4 [* J( A9 d
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
* {7 V, ]" N4 s' qO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe) q S% g. s; m4 X, |- y* P7 W$ W
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
; H* y$ T% ?/ l ^5 L) dO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
- l9 t N9 C. p* Y4 F& sO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE: \' e6 B! W3 h- w3 K8 ~
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe- w$ { J% t% d4 ?% V V
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe( [" U9 e' f2 n3 z: _3 G. b! Y! L
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
% Y J/ |- L' ?O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
/ F+ P2 [% j5 z( TO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
7 F8 z, }" {5 x( |$ y& ^O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|