 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
4 R& e F" u3 s5 H$ B* NScan saved at 16:55:24, on 2006-5-6
$ w9 J2 X2 T2 o- M- YPlatform: Windows XP SP2 (WinNT 5.01.2600)
/ X4 w7 {3 v0 vMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
2 H& D! h1 ^5 f# ?) |' |, R7 ~" V, K' X8 d
Running processes:6 S8 O" l1 ]: ]3 s8 n1 H
C:\WINDOWS\System32\smss.exe+ ?4 F, l+ A) y% f9 ~
C:\WINDOWS\system32\winlogon.exe
: `6 K. E# |2 b3 O+ q1 |C:\WINDOWS\system32\services.exe7 j- k' s: ~$ _) v& B
C:\WINDOWS\system32\lsass.exe
( v8 Z0 X! x. Z; S5 [8 ^C:\Program Files\Common Files\Virtual Token\vtserver.exe
4 X% P/ L) _( \ R# t: ]C:\WINDOWS\system32\ibmpmsvc.exe
! X; a: A+ s4 P3 [& v$ `C:\WINDOWS\system32\svchost.exe0 X8 B" F- a0 a% n
C:\WINDOWS\System32\svchost.exe* g3 f6 ~$ Z+ F$ w4 s6 d" k
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe+ s, d$ P! v- r8 Q3 d
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
1 Z8 B' a; a) e6 KC:\WINDOWS\system32\spoolsv.exe
3 m% v- U) }/ ^6 GC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE# b8 E6 l6 ~, A- u
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
: J$ ~) b$ y& q. q% pC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe) D# k4 `$ a' |
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE4 k3 `) c% _0 r: @3 j
C:\Program Files\F-Secure\Common\FSMA32.EXE6 W S: ~4 M' J) `$ q0 w6 B
C:\Program Files\F-Secure\Common\FSMB32.EXE
) R' |' E; {" I9 i3 @0 lC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe: F. p% A, g8 d) ?/ h: [, u
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
, C9 N7 G) l1 Z4 KC:\WINDOWS\System32\QCONSVC.EXE& w v& }7 @0 ~# _+ e$ s
C:\Program Files\F-Secure\Common\FCH32.EXE
! e5 h N( G4 q$ ?, B; IC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe) f6 x( ^" T. j4 f
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
% o8 l2 ?, h! n) ~C:\WINDOWS\System32\TPHDEXLG.EXE
" q9 @, l' Z4 R# b7 x) DC:\Program Files\F-Secure\Common\FAMEH32.EXE
. E- r( O3 {2 k& VC:\WINDOWS\system32\TpKmpSVC.exe6 m! ^" j4 i2 t& r
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
0 E+ a0 C b8 R6 X* s! [C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
$ l5 d- \! _; Z9 M( IC:\Program Files\F-Secure\Common\FNRB32.EXE
# c2 e3 Z s( t) i9 C4 SC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
7 p3 v: |& T! N1 DC:\Program Files\F-Secure\Common\FIH32.EXE
' v/ d) f: K* q6 U8 S4 lC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
1 |, ] b9 ]% n0 h0 oC:\WINDOWS\Explorer.EXE
& _; S6 A3 ~6 i$ nC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
5 y8 B$ D2 Q* |3 P- L1 hC:\Program Files\Synaptics\SynTP\SynTPEnh.exe4 |& e0 v) J! W, @
C:\WINDOWS\system32\hkcmd.exe! X+ L) M' z/ M1 Y* C4 d+ q8 ~
C:\WINDOWS\system32\TpShocks.exe
; ?$ m6 s! w dC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe6 i$ K+ K! {# C6 j5 O
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
& v1 n; C2 r k$ B3 r" @, o9 nC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
/ M+ S8 m+ G. Y4 L( l' d1 g4 B, ]# cC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
7 R% @' k! x3 C7 D7 o& C+ \. O; ^5 bC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
2 s5 N, s5 \, H1 _+ hC:\WINDOWS\system32\dla\tfswctrl.exe# F- W6 K: l7 z0 G2 R6 E. }8 e
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe6 {4 @( h3 k* }! f" j
C:\IBMTOOLS\UTILS\ibmprc.exe
- I2 b: s; p8 e' B: O) c- ~& gC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE4 w* v8 Z; ]& O/ y
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE8 [% ?6 L$ v# [5 V; B/ t
C:\WINDOWS\System32\svchost.exe1 `0 f' y) S5 l: ~ J7 V
C:\WINDOWS\system32\rundll32.exe; m* S) }: p: U- W
C:\Program Files\F-Secure\Common\FSM32.EXE
* q B) P' O) ?4 d" nC:\WINDOWS\system32\CTFMON.EXE
6 T6 r |/ o- E. a0 ^: ZC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
" y: P5 e- X! ?C:\Program Files\Digital Line Detect\DLG.exe* s! I, _8 r% P2 M2 U
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
) Q! N8 ?- {% cC:\Program Files\F-Secure\FSGUI\fsguidll.exe
2 q4 A8 ]4 }4 W6 X1 b# Y7 v- `# YC:\Program Files\Messenger\msmsgs.exe4 B6 r; C% ^/ l/ h
C:\Program Files\Internet Explorer\iexplore.exe
+ L; m4 F6 e/ |( {: FC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe! r7 \% K% T% ]; U4 Z) e" E$ s
, I2 `2 ]8 d& f( ]
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
* l4 R; x3 ~: N8 sO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
" H5 o/ d' b& r) N9 IO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
; ]0 q& G7 P. J; C8 r$ V/ O$ WO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe5 U2 m3 a( y4 U& n' W2 z9 i# k3 V
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
4 {* I2 t2 B p) tO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper' _$ v/ t& w' A7 b& ~
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
0 b* @7 w7 ]7 U! {3 {' d% ZO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
8 D( Y5 U8 i* m/ K! K# LO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
]% E0 V5 r( u2 a$ F, _% lO4 - HKLM\..\Run: [TP4EX] tp4ex.exe8 y8 ?4 t, G) ~
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" ^5 G0 e, g A
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
, K; U0 h! @5 }: p$ GO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
" k+ F Z2 `# N) W8 ^9 _O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
0 p1 i) L6 t) t4 kO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
3 p# O9 h# c& v U9 XO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe# E6 a( i/ e) j! z' o ?9 M$ k
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe4 P: O' J( z# J Z+ y' M/ X
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE/ d% o) L0 T+ J$ v6 R$ B6 s
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
4 E8 c: Z" W3 O' O0 |+ N: n. H7 R2 AO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor- |6 D( J& ?3 B) V9 m' T) Q8 D6 p: Z
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
% S+ {& i6 Z) f' B4 v2 S& LO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration324 r, R8 _' d0 g
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
* g. I$ r& ~* FO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
1 m+ o8 V0 ~& X5 NO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC/ ~0 v v4 u6 I) \! N
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
( U/ G# o9 ~7 D8 v* a3 hO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash0 s7 I) D% H1 {8 Q. f! q
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
/ G! G, o t! fO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe7 d4 a! d8 G2 D r
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe0 D( I5 M' }" Q( S
O4 - Global Startup: Digital Line Detect.lnk = ?
4 m' a+ V7 G9 ~' }7 `; ]! {/ k# _O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe. h5 f# f: u' |& ? k6 @
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
, t2 a5 h9 Y% ~( b' i6 ~O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
- t2 |, s( L& ?O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
+ C' | ]1 i: W& j3 Y0 |, w1 _O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
! ], @, W7 j! v6 |. KO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
# }. g8 J' D7 g% D2 XO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
# c# Z- W% E) P2 P* n9 NO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
x3 N, X/ K$ A1 S" f) pO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe6 H& o. x# x7 N
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll+ N: y8 z/ v3 E: ~" o' r3 R
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
7 P; @" s+ o- U) O1 ?% T: z5 HO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll" q8 f$ \* l* y9 V& Z: L1 [
O11 - Options group: [JAVA_IBM] Java (IBM)
8 J. Z" c; x: w# RO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll3 P+ w+ ^4 h; g/ A
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
+ [2 B7 e( V$ R8 D( h4 {O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
" s* f& P! W/ F& V, ]; x5 m* lO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
; x+ u5 {# k/ c0 G _# VO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
9 L+ P3 Q8 J' @$ v& xO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
1 X4 j# W( V) E& q, x" m! ~O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
2 U9 @" t; C8 K# g! f0 ZO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
6 z; ~& O4 M2 u9 b. Z, E l- E FO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
$ |/ _& }! P5 s9 C0 H7 w5 aO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe1 v F- c9 @- Q0 j _& [+ F/ n
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
1 e D. Q: B4 O0 d; Q; ZO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe( d: r, f: |6 u6 o
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe. Y" O5 p0 w" K6 D
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
% f) c$ h8 V% G4 ~6 G7 o+ XO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)7 B3 I' p! B8 Z7 d6 \/ u
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE# X& `" c* N5 S
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe) S" v$ o4 J9 [1 d4 ^, P" y
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
5 S, ~( K. G2 V$ I7 k2 A9 HO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
# r, D V% H. O8 g4 c5 S RO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE \* n ^3 [4 t6 a3 S
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe3 d+ i) z& p; }
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|