 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
# I1 l# p( m# _; s; ?Scan saved at 16:55:24, on 2006-5-69 Q9 U% ^1 w0 Q& Q3 u; a3 W8 Q# I) Q* Q
Platform: Windows XP SP2 (WinNT 5.01.2600) r6 a2 W7 ~ D G
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
5 e1 U! O7 m; ]9 V6 T2 H. g7 ?
6 C q9 k7 W9 J8 `Running processes:
) J$ r3 {; p% m: E3 q; Z5 JC:\WINDOWS\System32\smss.exe# h/ R, _) e# b
C:\WINDOWS\system32\winlogon.exe0 |4 @. h# b4 ]" z9 a
C:\WINDOWS\system32\services.exe! G: ?% M2 d$ a5 u: L* p& X
C:\WINDOWS\system32\lsass.exe5 I9 T& Z9 P* h
C:\Program Files\Common Files\Virtual Token\vtserver.exe. T) s7 \6 K) P$ k O8 j9 G+ @2 ~
C:\WINDOWS\system32\ibmpmsvc.exe
- m: L! M# a2 m2 v) \C:\WINDOWS\system32\svchost.exe
0 J$ w. `. X DC:\WINDOWS\System32\svchost.exe% W: P7 O" H$ k; r
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
; X2 }+ h) O( h t+ ^1 J( |C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe- g$ ?4 l \7 y5 Z
C:\WINDOWS\system32\spoolsv.exe
. g: U L' V" B1 h* ]6 |C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
7 ~3 J1 K9 j1 A0 @( ]' C6 ~C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
0 V y9 B$ u, @# m$ MC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe; R7 ?# a- K: T; s/ W
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
3 a) C# d) N/ l3 OC:\Program Files\F-Secure\Common\FSMA32.EXE
* D4 r; C# S4 P: R& q! t' h% pC:\Program Files\F-Secure\Common\FSMB32.EXE4 T2 a5 X U8 }+ `8 S
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
) N4 m1 J5 ]# N' r& g0 yC:\Program Files\F-Secure\Anti-Virus\fssm32.exe9 q) P9 ~3 { f" W# |
C:\WINDOWS\System32\QCONSVC.EXE2 }" w3 @# y$ @5 ]+ k$ g
C:\Program Files\F-Secure\Common\FCH32.EXE( V$ Z+ w: F4 z- r8 z+ |; K' \- C) t
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe4 o( Q: ]% K/ a4 M+ U
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
% ?" N( ]% ^# Z% v7 |C:\WINDOWS\System32\TPHDEXLG.EXE
/ ?* Z& w: d s) H: g. g& TC:\Program Files\F-Secure\Common\FAMEH32.EXE# P0 q4 S( v; T3 s8 Y; Y) C
C:\WINDOWS\system32\TpKmpSVC.exe* C" |8 B! N d
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe3 ~1 I- E! y# |) o/ P
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe" l2 M' a$ { J4 R
C:\Program Files\F-Secure\Common\FNRB32.EXE
- D! V" H1 z$ |/ W- o+ B; xC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
( f% ^3 K! p' Y6 ~; |' O: WC:\Program Files\F-Secure\Common\FIH32.EXE4 k! E% B/ N9 z
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
. {4 I) U& R: h7 v5 FC:\WINDOWS\Explorer.EXE
) X, e) e4 k9 ]4 q' m! RC:\Program Files\Synaptics\SynTP\SynTPLpr.exe8 \$ ?2 y3 h- e5 a7 G
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe, F" V; t9 I0 D+ J% B/ l% M
C:\WINDOWS\system32\hkcmd.exe
" r( ?3 A6 Z9 NC:\WINDOWS\system32\TpShocks.exe b9 V9 b. o" d% _" I% g
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe( r. Z3 ~9 u; K
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
1 ^ G# U. ~' sC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe$ G% [3 w) @+ \. x( ]
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
4 g ^5 f! \7 Z [" d7 T3 ^C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
. |$ A3 p M4 ]! s$ {3 M$ mC:\WINDOWS\system32\dla\tfswctrl.exe/ p+ M x1 x- O# ^2 \8 U/ z# }
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
) p" z- i% H" F! ^C:\IBMTOOLS\UTILS\ibmprc.exe4 b8 w! s: I% A4 _( \' }
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
( I' M& Y6 b' p ^' zC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
8 N+ ]# r! o: E# ~( o3 O; }: DC:\WINDOWS\System32\svchost.exe- S* Z: e5 X0 `( s) ?
C:\WINDOWS\system32\rundll32.exe
3 |) j2 J( @1 K! j& E; \C:\Program Files\F-Secure\Common\FSM32.EXE W0 {( _8 D; z6 k0 y2 |1 f
C:\WINDOWS\system32\CTFMON.EXE3 _4 v# v2 n: c; r2 g
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
7 z E+ f1 k! _4 T8 W" tC:\Program Files\Digital Line Detect\DLG.exe; T. U0 k$ j& m& ~
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
0 {1 n6 N o4 w2 y, D, AC:\Program Files\F-Secure\FSGUI\fsguidll.exe" L$ ?7 w K" O: q; r
C:\Program Files\Messenger\msmsgs.exe
S( |4 j% y" X* v2 m1 ^, ^C:\Program Files\Internet Explorer\iexplore.exe
1 j- v2 o$ ]$ b- |/ vC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
% q) ?: b$ S# k: s! P' k
0 X' S" A6 y2 x3 _6 p/ \% L7 v( zO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll% ~1 P: c( f( q( j; c
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe- B) ?, I8 r1 O9 J5 X: x
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe7 W3 i9 k! e; G- u1 D
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe- w2 Z X) \. v" C6 y
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe2 E( O9 u N0 P1 t
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
+ B5 L0 C+ Z, i% G' F, H2 s* WO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
3 a8 R! A7 E* V* x) dO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
0 H- G0 N4 g2 `. t5 eO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
[, V1 L+ ^% `/ i2 R; L, ~O4 - HKLM\..\Run: [TP4EX] tp4ex.exe# W2 [) F& b7 F
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
6 {7 I; a0 X' S* {O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe. p& ~& Y+ z, ]( Z6 Y# g' j
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray0 x# I) C$ C |
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r% t# s3 z- d9 p/ [2 W
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe& R& O) w8 {2 u4 G: ^+ D& {
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe$ [7 s* ^$ x9 k2 C* x' x6 u
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
! [5 l0 [" D0 C, B7 zO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE' h4 G, F% U. f" @6 k
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
- h1 p1 O1 R5 }7 ~! F% X kO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
1 T0 O% V b6 }7 c9 H( W) SO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
A3 i; K; A2 j1 `" j" OO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
3 R( ? H; |2 x' D$ `O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
8 q0 `) a9 L- a! Y6 m# E4 lO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC$ e& V+ w5 p1 \
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC; G+ ]) q, N4 O
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
# K" ^ }' D" Y+ m2 M; b" _O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
' Z) Z _0 s6 ?% ?+ H* FO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
1 e+ l& p& W/ ?/ D0 X4 ZO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe8 u* N8 ]4 G1 Z- E+ l. {+ t
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe9 b% O5 F" r* p( P
O4 - Global Startup: Digital Line Detect.lnk = ?
8 t/ D3 W" {+ c7 yO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe) ~% J1 v N# ~5 f, i* u; T' M
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm1 c4 [6 m$ F! s) P0 q5 M
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
+ y, h% B! a* gO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll2 }& \. ^1 s. V
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll- v& Q, ~, W+ a( I! c8 i( p
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll3 Y' \1 j. F0 c
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
. k- }( w! u* p. U, y, n8 zO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
& y. n- I3 n8 d9 QO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe) k/ [2 f0 u) V3 G1 ~, J
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll1 w+ u# L5 I# x/ a' P
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll4 P1 X. L, k& P" {- `
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll7 q6 T5 o0 I3 K$ E& L1 m& U
O11 - Options group: [JAVA_IBM] Java (IBM)0 h+ b" P4 O! Q2 E6 u
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll5 ?9 u2 K1 V: v' g: ^4 n3 B4 K; j( ]* N
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
$ Z& X4 F9 R8 L7 R* [; WO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
# _6 e; {& V* ?: L1 C2 qO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
$ l+ \0 V0 M* D: u( [ JO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE: H5 i) U5 q: Q7 M; p+ O7 o
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe" i) q3 f" {, i. v, F, o
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe$ A6 k" S0 k3 m2 c
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE4 l4 ^1 r% N" C7 z8 n% _
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe+ e; c3 i- r& L. m t' ^) i
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe: b0 G6 f6 k4 w+ A! N8 T0 o# a
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
1 l( U% t. ^1 F7 t( u: @4 |O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
7 v& [$ y, v" S; h* UO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
' l7 v$ J y" t/ a- f0 rO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe+ D3 i9 w$ w# H0 G
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)* v# o, b. R) O: n9 @: Y
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
3 e' }* \- L' o% ] }/ BO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
. W. f0 t, @, e" x1 \; Y& z/ pO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
0 p6 r8 }; g8 c" eO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe8 M' B( D( m+ } d& W, Y
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE5 a* f$ ~0 r: s2 [) A9 u5 N3 v
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
% a( b }) d9 fO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|