 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
7 p9 R- L' h! ]/ u+ h' tScan saved at 16:55:24, on 2006-5-6
, S2 `4 q2 M2 o! VPlatform: Windows XP SP2 (WinNT 5.01.2600)
3 {5 ?) ?+ K0 L6 \& xMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)# M- o, d) c( T. W
" |5 [: i M! Z% {+ d I# z6 WRunning processes:8 L8 O% b F( \: X8 \ X ] q
C:\WINDOWS\System32\smss.exe
# ?4 h1 M. ~2 M4 u t& qC:\WINDOWS\system32\winlogon.exe! u3 h; z+ G* h( A- o- O7 }
C:\WINDOWS\system32\services.exe
0 p# M- a; l8 l9 q; PC:\WINDOWS\system32\lsass.exe. E7 O" u, v/ f4 ^- W
C:\Program Files\Common Files\Virtual Token\vtserver.exe
% u J* d5 O# B2 Q, V# O$ r* Z% {C:\WINDOWS\system32\ibmpmsvc.exe
# \5 P" n1 W W+ [) hC:\WINDOWS\system32\svchost.exe [; q8 q* ]& X% n9 E; @
C:\WINDOWS\System32\svchost.exe
6 W- `* N* K- M" z" c' b3 t: R5 |C:\Program Files\Intel\Wireless\Bin\EvtEng.exe, C/ d! i: n6 C: u6 t; G9 C
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
* s- a- [9 e( rC:\WINDOWS\system32\spoolsv.exe* i1 U/ {9 f1 b
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE! ^/ u# O( s6 R, b, v! ?+ L
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe- \0 {& K" e. o* i* O' {- v# \# J
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe5 ~. Y3 k7 d, G8 \& H' H0 t
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE$ w# \9 j/ L0 V4 d- M* J
C:\Program Files\F-Secure\Common\FSMA32.EXE
/ k0 L2 y2 L* o: F5 DC:\Program Files\F-Secure\Common\FSMB32.EXE8 T- Z6 _7 z; U) _! r& I/ d k
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe* Q$ ~4 O% ?. v: o- A$ u
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe% n7 X- ], `1 ?7 g$ T! K
C:\WINDOWS\System32\QCONSVC.EXE
2 A4 E3 x* {: h. E8 fC:\Program Files\F-Secure\Common\FCH32.EXE
$ {" [3 Z! G+ B: \) u4 P& Y. I# UC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe3 ?- h1 Z9 L& X) n9 `
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe! h* G/ C! U+ l, \" ?4 s3 Q
C:\WINDOWS\System32\TPHDEXLG.EXE$ [1 O& T3 v' A: S7 j
C:\Program Files\F-Secure\Common\FAMEH32.EXE
6 T A# l. Z) m% |8 CC:\WINDOWS\system32\TpKmpSVC.exe
) ~& S# }6 @! `, d& D" }3 Y( e0 h7 FC:\Program Files\F-Secure\Anti-Virus\fsqh.exe d( H1 E, V/ ?' @- |
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe" ]+ }- c* n) x& I* p* H
C:\Program Files\F-Secure\Common\FNRB32.EXE$ y) ]) s5 f- u1 J4 y7 q( F
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
6 Q% y: T% }# ]2 FC:\Program Files\F-Secure\Common\FIH32.EXE" C. V# \4 V6 z" O0 @% A, E
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
" i3 i' S J6 y6 K0 S1 |# uC:\WINDOWS\Explorer.EXE N; ~5 T6 n2 L# H3 P4 W
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
( x4 c$ h5 ^6 S6 }: ~0 QC:\Program Files\Synaptics\SynTP\SynTPEnh.exe% y7 l0 b, D5 b F. j( C
C:\WINDOWS\system32\hkcmd.exe
0 Y: Y8 [6 J0 _C:\WINDOWS\system32\TpShocks.exe) f+ m- F w+ K
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe9 J. R( D S: \: H
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe3 @( Q$ q( X* {' y4 B0 ^8 w) ~% b! t
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
2 R( L2 ?4 Z$ S# U9 _: A+ y! VC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe3 |. {! B; ^( i. o# z
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
, `/ Z0 Z1 y( x' O4 H3 n& a, w% ?, q4 zC:\WINDOWS\system32\dla\tfswctrl.exe" ~- v$ |, J* @6 K g
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
8 x9 \0 C2 ^2 S' Q) f) R2 CC:\IBMTOOLS\UTILS\ibmprc.exe8 {/ R6 E4 V+ h' |) Y
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
! Y% |5 B' U: w# H4 rC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE9 o$ F- i# Z4 G! l$ i0 V' e
C:\WINDOWS\System32\svchost.exe
, C4 N- u" w7 PC:\WINDOWS\system32\rundll32.exe% L" c) O+ T1 `$ @2 V( v) r
C:\Program Files\F-Secure\Common\FSM32.EXE
3 g4 }9 O$ R' d9 |$ d5 O5 E: N' @C:\WINDOWS\system32\CTFMON.EXE w6 q9 n1 ]9 T# b
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe% j% `& y8 B; e' d5 E$ ^" I( z
C:\Program Files\Digital Line Detect\DLG.exe- }2 P, V9 ]0 P! _$ B
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe) l; B# B' ]6 C6 ]
C:\Program Files\F-Secure\FSGUI\fsguidll.exe! P# ?3 m2 |) `0 U
C:\Program Files\Messenger\msmsgs.exe
9 s; W. s) ]7 d6 y. w' WC:\Program Files\Internet Explorer\iexplore.exe
" q6 L3 p6 B- A2 h5 hC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe( k$ e8 ^% w4 N% h
9 D3 S( f1 U% d( e! I2 RO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
2 j8 p# c* K+ u% t. NO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
& S. e+ \; K E$ SO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe- z# u% R, F5 L% O* F
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
- c% }) P* Q: A z# i; o( aO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe$ X. q6 k9 ^" [! [; v" o: ~' G
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper( q( n9 n6 F+ o0 ?5 R: s
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe6 S, ~# @" J( E$ V) R
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
1 k8 x- O) a) IO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
* {9 g9 i5 X' t- b( n9 iO4 - HKLM\..\Run: [TP4EX] tp4ex.exe8 `, f, H, A0 o* x5 ]) s
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
" l+ G" G0 p9 e6 U" ~* ?O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
; F$ X3 b( w6 H2 d G: |/ LO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
[& l- f9 k: [' i9 A `O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
5 l3 J& ]- ?: N6 \O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
# C# e, y5 v2 i) a8 S, nO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
6 G: ~: e- `$ B3 VO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
5 W- o" ]# M7 k& |0 q8 @O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
* W2 A; e+ f4 l1 |. v, G) _O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE* h, D% a H( D; z
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
5 @: ?$ d3 Q( o7 P- q5 ^/ SO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog6 N) ` ~9 B8 W5 d
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32% `/ N4 c: F* E: _) ]: S
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE, C( C" L! A+ ?
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC! h; |( c. z! K
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC q4 h' X! I9 r/ a0 c+ J9 @/ ~
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
; w- `. {/ `; V9 \O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
- C' _+ |5 z# N2 [% FO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
* t' ]$ N9 ]. Z( ?2 ~' l' AO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe8 T) [8 r2 m# ]; j. E+ Q7 E% I0 ?
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe9 q6 Y: p6 l1 u
O4 - Global Startup: Digital Line Detect.lnk = ?
5 y) r8 | g) \O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe& `/ l1 B+ x1 t9 W! K. i5 r( V
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm% j/ {4 _% T) x |" t3 _
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
( Z' V: t* {1 |6 G' a" @' \1 _O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll) c' ]( j/ v) L; b
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll) j+ w! J4 S! b
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll* z# Q0 [- o0 ~; h2 j) F
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
0 O# r) t' z+ C8 ^, \8 zO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
0 q8 l/ ~- Y5 B, @+ V* U. KO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
* z+ F% \# W5 q, Y+ f, u+ g2 l/ zO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
; }9 k) c- Q2 Y( s7 K) o3 rO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll' I/ v$ e' ?; d/ k
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll6 |/ K1 G- H5 ^0 }+ ~
O11 - Options group: [JAVA_IBM] Java (IBM)* @+ X( f2 o& T9 b- F+ G
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll6 N: j" E W U' @8 c
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
& B: X! R' M+ N" k0 `0 gO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll @2 ^1 L+ i' ^$ _
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
* k. b' V$ s& K9 w$ EO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE2 Y8 W5 Z+ b5 ^7 L
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
' k0 }" v C: pO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
' v0 F5 g) \8 P; o8 K/ Z( T' C- zO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE3 g, r$ y5 Q7 l" P
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe! o: B5 N, F, O- I/ C; P3 `: V
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe! C4 T. W4 p7 o
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
; \& y, O8 ?% O# u, DO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe9 n3 m2 F. I6 S4 w3 F' J
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe9 `' m# e* r8 J* M! u+ Z3 }
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
+ F! N! Z0 U: M7 h; a3 L2 tO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)" v3 c, l- S/ y- s. q2 L" B$ ~8 E* q
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE& h. C r( \% M: R
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
. M2 ?, C2 H$ e( G6 AO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe' n; W$ t4 y* l
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe1 b7 ~8 e; t2 O3 y. M
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
8 p* k" W; c3 K7 l( Y& HO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
) m5 i, V3 M5 V' m# DO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|