 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
4 ~1 H6 \4 y6 xScan saved at 16:55:24, on 2006-5-6
1 k, I" {2 \' d% }Platform: Windows XP SP2 (WinNT 5.01.2600)/ C! G6 B5 t6 k+ ^3 g4 X; a
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
9 `" U3 F3 s/ T t o; l& }4 @2 E* N, K/ a( \. \/ Y3 p+ o
Running processes:
7 ^% o& v' a6 e/ a4 E$ ZC:\WINDOWS\System32\smss.exe+ Y' E4 C5 v7 u% b: o$ B) R; B
C:\WINDOWS\system32\winlogon.exe d; n3 {3 s0 b0 }
C:\WINDOWS\system32\services.exe( W; O* ~% \1 x" i+ a) \* a) R
C:\WINDOWS\system32\lsass.exe
, I; u( A0 o, | tC:\Program Files\Common Files\Virtual Token\vtserver.exe
' v8 P9 j' x. T$ s1 QC:\WINDOWS\system32\ibmpmsvc.exe; O1 O X e# h- u; L
C:\WINDOWS\system32\svchost.exe ^9 H& Z3 [- r# F
C:\WINDOWS\System32\svchost.exe+ e# @! J. b8 F; n D# f
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
9 n" t( E& e( l4 ]C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe y0 d+ Y, G& G) j& @
C:\WINDOWS\system32\spoolsv.exe
* a' c' }" D" X' O+ GC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
$ x- D+ `* w# T* a |: M3 u& bC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe7 |: H! r, s5 c& F, D% }
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
( e, |' Q0 z8 S+ V# F0 g9 `+ CC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
- v9 |8 x% u1 T" FC:\Program Files\F-Secure\Common\FSMA32.EXE9 q9 N) p l' U( W7 l' x
C:\Program Files\F-Secure\Common\FSMB32.EXE- K5 ~6 J+ L2 l' O
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
3 b8 ~8 z8 {9 y9 V) H" S3 GC:\Program Files\F-Secure\Anti-Virus\fssm32.exe) [8 y' P, |& y9 l$ m
C:\WINDOWS\System32\QCONSVC.EXE1 ]. [1 V% m2 N2 ]! t
C:\Program Files\F-Secure\Common\FCH32.EXE0 V; Q2 N! f: M8 w% ~: a
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
' y$ o! E3 ?4 T; @5 oC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe8 b! i6 T: h4 ?4 X) Y2 c9 C+ O, i& {
C:\WINDOWS\System32\TPHDEXLG.EXE
/ S2 f# Z# K- s: F jC:\Program Files\F-Secure\Common\FAMEH32.EXE
7 s7 n0 k: p" u( g1 D8 v, s% i/ O4 C& [; WC:\WINDOWS\system32\TpKmpSVC.exe# u' j/ c$ B( ~, x
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
( G, F( n3 t3 T. X. o) d' L5 DC:\Program Files\F-Secure\Anti-Virus\fsrw.exe! i7 t- @) F& G) ]
C:\Program Files\F-Secure\Common\FNRB32.EXE" `) k. y x2 V/ O& N; E
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
# O `4 I+ ^* l n+ P& IC:\Program Files\F-Secure\Common\FIH32.EXE
: g! ^- i3 T* P# M- ZC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
9 [9 ^8 S: E) J! P9 j2 Q( ~C:\WINDOWS\Explorer.EXE: B6 S/ q L( W3 |/ F: j! M
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
+ q$ o" {* `; O3 w* }# AC:\Program Files\Synaptics\SynTP\SynTPEnh.exe1 }4 k5 d) b4 q. d
C:\WINDOWS\system32\hkcmd.exe2 Z- }% d$ o+ s" @
C:\WINDOWS\system32\TpShocks.exe
Y4 J+ P8 ]- M. f. m% U/ N+ tC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe- @4 v1 u' p. X q
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe# S! j8 ?. V9 [6 W8 j. K
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe3 Z# }, {$ h$ f. ]0 q- M
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
5 \' t& U/ o: u d: o0 FC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
3 X# v, e1 T& h8 T7 Y, U4 V. s" cC:\WINDOWS\system32\dla\tfswctrl.exe! A4 ?7 b$ w0 r3 \0 n, s+ N4 m
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe5 G& r2 A' @1 J6 ^( |5 r% [# g( a# m
C:\IBMTOOLS\UTILS\ibmprc.exe
$ B, M. f% j$ q+ u$ u, y dC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE5 Q. g4 H3 R- _4 r3 D4 _
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE& O9 d& h5 {, s5 l6 G) [
C:\WINDOWS\System32\svchost.exe
! l {+ v9 t/ h& \! p! ^C:\WINDOWS\system32\rundll32.exe1 |) A Z; d0 Y8 z
C:\Program Files\F-Secure\Common\FSM32.EXE
0 m$ L# _, N3 SC:\WINDOWS\system32\CTFMON.EXE/ S9 @. D1 ~- T2 ^ W3 p$ B h
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
0 ~% Q6 {- ^" e% tC:\Program Files\Digital Line Detect\DLG.exe4 V( M5 L* J1 V# \* B4 w( z
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe' r/ Y8 W" @7 x- i
C:\Program Files\F-Secure\FSGUI\fsguidll.exe
+ @& u) T7 E6 ~$ k6 k- Y! BC:\Program Files\Messenger\msmsgs.exe" [' R! ^ Y/ q
C:\Program Files\Internet Explorer\iexplore.exe% ^! B2 {: b* ]
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
( ]- y' ?. t U$ X. z' F2 I2 }/ U* i( ^
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
5 ~ t3 `4 i. B; _0 p, cO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe- U4 S2 o4 b- M j- H7 [5 P
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ~: m1 T; S, Y3 V9 t
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
: d {4 S& \! XO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
" b1 P8 K0 R5 }O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
! t$ g* k) k* D) h$ |O4 - HKLM\..\Run: [TpShocks] TpShocks.exe8 n8 q* T# z) w2 O! g. D, U
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe) S m, d6 Z! f4 I, N, Z/ O
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup0 P6 F n* {, m& V8 `" `: m
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe; Y4 Z+ j3 b8 N z
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe/ Y- H6 Z3 n: ^/ p5 [' U# K) u$ A
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe! F& y0 A0 [1 |' R5 x2 ?" i# d
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
2 k* V, F/ J. ~. ZO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r; I% X4 B+ k& A) l3 i- m
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe; E% a3 _! U5 ?8 ^8 k
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe+ _6 r F2 U& D0 ^; F- o
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe. H( Y) L3 x3 W# S4 `. }
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
3 g' Q$ R+ } ?0 R9 r* l- ^O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
# U) h% l, \' {* N6 iO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
- l/ c7 i2 t+ k9 DO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
! v: f" W% S! e* OO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32' k( m. u# r, A/ J; s
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE& `$ u( P0 Y8 a" e
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC4 K7 M5 U4 {1 Y
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC Y2 G6 o- P( n3 ]2 p
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
& d8 ^4 T6 `: l4 `+ h$ X! }O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
' e: ?6 C. A: o8 |+ s/ B6 UO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW' @4 g* h G( h$ @) C: b; `3 Y* B
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
# O2 f- h9 r" j7 Z6 B8 J1 J8 w0 BO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe1 e: Y9 T) f" a! n0 I8 [0 @
O4 - Global Startup: Digital Line Detect.lnk = ?
) M" g2 `" I( _7 tO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
. ~* B& U1 v; S; g0 M/ F. G6 [O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
' y/ w o# N5 R5 H" IO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll& f6 q. \% ^. k0 I& Y9 ~# n
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
* m7 B! p7 m: R: f4 z' @O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll2 u* k5 ]' }- ?, s1 p" z& r. T
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
& Q% f6 b5 v+ K( [; ^: `O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
1 P3 ]' w/ H+ e' Z8 w- u9 eO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe D0 y+ \! m$ I1 p6 d
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
3 Z; ~7 M, G- Q& }3 s$ C1 I' E, ^O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
2 f& L# ^" e4 R! s) c7 C9 j! W% w( VO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
! ]# W f9 o1 mO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
8 k5 D. T: |' `2 LO11 - Options group: [JAVA_IBM] Java (IBM), b% K: l Z$ W; n
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll6 L8 ?; l t! D
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll: o/ h6 T# Y/ n6 T" D9 _
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
( e) j4 I m6 ~" F7 rO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll8 a2 }( w2 f% G$ e, h* |- W9 ~
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE: l9 Q( g" o) r6 q+ l$ y
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe( t1 ?, }5 |/ c3 C) j, Y
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
& Q4 @$ x z! g2 t) D4 o" s: r" {O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE0 Y. P0 K5 V- a ^% C
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
" s9 A* R* N# f9 jO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe% X$ ~# I& S% u4 p. B& z
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
# {9 V" n1 J! R* W, w) Y4 ZO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
6 b6 E5 A; J. ^/ h, vO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe. h$ i3 A5 S2 C9 q, X
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe% c0 ~/ _7 B! L2 {' d( d3 g2 D W3 e9 d
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)* Q! P6 J+ g( j2 I
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
# V& c% w, x0 t# j- {O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe9 f- v( g1 x0 @* g" n1 i" h
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe0 ?6 I& ?+ }" [8 S
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe& U1 V- u( Y( p. U4 T& a
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
7 L7 `8 [6 [2 S$ f/ k. D* `O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
% r4 Z( B4 t3 P( @O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|