 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
" ?. \$ M, w- U- E$ M/ bScan saved at 16:55:24, on 2006-5-6
8 q: X7 W, S) i$ b/ }+ T8 yPlatform: Windows XP SP2 (WinNT 5.01.2600)1 {3 C. |# n$ {/ H
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
( `+ u% l0 J# p- `3 h2 w r
) I3 R$ C* r G, k' sRunning processes: e. w5 Y2 t7 e; C& B% @% ]
C:\WINDOWS\System32\smss.exe* ^0 J5 \3 @6 l" [; C! W/ G
C:\WINDOWS\system32\winlogon.exe" z, z, E2 h2 F
C:\WINDOWS\system32\services.exe! z: n5 c6 v" B* z4 ?6 ~) h
C:\WINDOWS\system32\lsass.exe; G7 g/ s* P6 V* o7 F
C:\Program Files\Common Files\Virtual Token\vtserver.exe2 u+ K) m; T) s
C:\WINDOWS\system32\ibmpmsvc.exe* ]' Q9 I: _. R0 y6 W$ J7 Q7 I3 w
C:\WINDOWS\system32\svchost.exe
- n7 ~$ R! i* o8 B) M z" y8 }# hC:\WINDOWS\System32\svchost.exe
0 F9 f" I, M ?: p9 r5 K0 yC:\Program Files\Intel\Wireless\Bin\EvtEng.exe, Q1 L7 q0 n* O" b
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
' _& s1 f# J) NC:\WINDOWS\system32\spoolsv.exe
* a' A. \1 q, m- d# [: _C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
9 U# v" M. V E3 D' K/ p9 [5 hC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe6 ~, @% ?0 a- h; t) {9 S$ T0 s p- f
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe/ z* N) b# c7 T% M0 `0 ~* L1 C
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
( @1 [$ a4 x/ I' p tC:\Program Files\F-Secure\Common\FSMA32.EXE2 O+ |. h. Y$ y: j* @
C:\Program Files\F-Secure\Common\FSMB32.EXE/ c% Y( k, {) Z7 [9 v" O2 {8 Z
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
7 d1 h; X- z( p7 D7 ?# PC:\Program Files\F-Secure\Anti-Virus\fssm32.exe6 ^" w' j* f& f) K, }8 Z& l9 N
C:\WINDOWS\System32\QCONSVC.EXE0 B0 Z, ~ p2 T- t0 j; K
C:\Program Files\F-Secure\Common\FCH32.EXE5 C$ K0 |, ]! N2 X+ o
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe. \/ i" ]6 g/ X$ x
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
" D/ m* C" Z3 L8 b" k0 RC:\WINDOWS\System32\TPHDEXLG.EXE
, x2 H8 }; M$ T# Y2 U( \C:\Program Files\F-Secure\Common\FAMEH32.EXE
7 |" s, h q. |2 t( G$ eC:\WINDOWS\system32\TpKmpSVC.exe4 H9 w$ Z1 ?* k( [
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
! e0 e: _ r$ S6 W% q% [C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
, Q. Q: K _0 G4 K' CC:\Program Files\F-Secure\Common\FNRB32.EXE
& a+ g e6 j' @C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
6 Y: h6 n6 U0 r% ?2 OC:\Program Files\F-Secure\Common\FIH32.EXE0 |8 Y9 v# R' o: M/ x( M9 Y
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
. n7 m1 a& A& P" s) DC:\WINDOWS\Explorer.EXE9 Z- s0 o- _7 P/ E2 }
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
- r1 D* q9 k6 ^7 _* V- K2 E2 {C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
7 b: _2 a0 w. {, c8 J' c: CC:\WINDOWS\system32\hkcmd.exe
0 p" o4 V/ }* d$ _; HC:\WINDOWS\system32\TpShocks.exe
; C& d+ o! v' n. U0 SC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe- W; y. y( G$ _. s; r. s
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
0 O1 M* b5 h2 w) n& aC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
1 u& H$ z/ {- K7 r" YC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe* f* _# d( Z/ R& z8 ^
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe+ e, o: C4 v8 @) z
C:\WINDOWS\system32\dla\tfswctrl.exe+ H; |; x) G" l' v
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
( L( C9 ?# J" R. Y! eC:\IBMTOOLS\UTILS\ibmprc.exe
, T b' S5 S+ SC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE0 y) f+ u$ n' X! L
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
% G. c' O% y; I7 f5 bC:\WINDOWS\System32\svchost.exe4 N; |) [- e! y. K
C:\WINDOWS\system32\rundll32.exe
, h. [8 i' o- e% lC:\Program Files\F-Secure\Common\FSM32.EXE
6 @" L, N$ n1 T! D/ O$ [, FC:\WINDOWS\system32\CTFMON.EXE, B. N* o$ B4 i" ^2 C, G
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe+ W" H( @8 w% G& O# Q* A6 U
C:\Program Files\Digital Line Detect\DLG.exe
! Y0 n. X& k+ H: GC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
. C, J0 J$ _4 j: t' M3 n; f2 HC:\Program Files\F-Secure\FSGUI\fsguidll.exe
' a' _0 Z. t6 A+ ?# ?C:\Program Files\Messenger\msmsgs.exe
8 I, v. ?, {9 E! V+ HC:\Program Files\Internet Explorer\iexplore.exe. T+ k% C& o6 u7 }6 ~
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
- ]) g! v: [2 c4 {$ H! v
) P' M6 L' F6 F8 H+ b) xO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll$ j$ F6 ~) s$ c: O
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe+ @- k, }1 |4 y( j" W, q
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe/ n5 n! O' t2 E/ N
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe0 l8 |6 ]4 E9 _ l' s+ g% H/ {! v
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
$ I5 I7 ^( P: O9 eO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
- U+ m' C# C) c3 A3 D" `$ {O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
" k- |, x. s8 w7 cO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
* z4 G$ x2 e" U" gO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
4 ^) Z7 E0 b K* HO4 - HKLM\..\Run: [TP4EX] tp4ex.exe6 t6 H5 L; i7 H& E, G/ \* }* d1 N7 ]
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe# p, F' Q( n p: B# A9 [2 M; i
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
) _+ y; m( P7 I* _3 C( i2 kO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray4 y% P: u7 o( ?. S( |+ N
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r$ r9 D" D+ }) V; _" S
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe# k- D5 w8 P: \, N, l0 Y
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
: _2 B+ h2 u/ Z4 j# c6 ]O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe8 b1 j9 o& d8 Z7 ^
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
' A. P. h9 I; W' qO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
, W6 B" W: |4 C2 j+ g7 y" fO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor1 l. `; b& |- [: w2 K1 u/ y- o
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
5 P1 \/ l9 v/ sO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
+ J2 i. S( h6 AO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE; e: [- b) d6 p1 A1 B! G
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
# R7 l; W( P$ ^2 wO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC0 s/ V6 d# D+ b2 j8 U% f3 S
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
! h/ G$ E; E! r! F/ UO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
% t* s s$ z+ ^9 k; n- TO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
5 v$ \+ I$ r8 B2 iO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
3 z- d( G: J P# {& W" T( KO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
* r- j) | q9 `O4 - Global Startup: Digital Line Detect.lnk = ?! B5 H0 i) {* y/ }& @1 Q
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe+ L" @' p& J( W+ C8 m
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm& g" ?5 k% B7 D$ J; }( Z1 m
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll$ y1 _7 g; S, d0 m$ z! h
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll3 [' B$ S) ~" C: D0 s1 b0 W
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll) @8 g* _% w/ Q' f& e i" O+ U4 \
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
# t7 d- H6 W# q a; Z* tO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
$ E$ ?2 ]( ]- T V7 NO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
* `1 Z; r$ B: A# T; ]O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe% q; z& o7 ~" b+ L2 L; L* R
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
9 E, f# } L; G# _8 ]8 pO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll- t; i$ M* g0 L3 o* `: M
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
- K5 V$ V3 }! y% p m$ g& TO11 - Options group: [JAVA_IBM] Java (IBM)
& [' q9 {/ Z& QO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll! n" ^4 q& Z' W: B2 _+ M
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
6 P- x# L4 ~0 UO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
3 \. ~3 Z& ]& _( Q& B' fO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll8 c: p3 E2 w/ X6 Z# a" Q4 e1 a
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE4 @; l& p" G* ?( s
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
$ n. z0 V& z# h7 H! UO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe- U: v! K* H9 @" x* k3 p9 a$ f
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
5 X) p$ S6 f. V9 ^% I6 kO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
7 y; I$ V8 I) B: EO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe! ~ x0 h4 z: a% D
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE- F$ k* }- G$ P2 `
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe0 o! J- |% Z# `8 z% p# i
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe, d- D; @" s3 I3 |6 M' K0 L3 M! b# ]
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
. [' L( L$ S. P1 Z `O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)* T& d+ |# X5 `! }! O
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
7 @7 Q' C' u: A6 S+ j" LO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
0 u5 q* }! D: Q- O9 BO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
8 n9 k4 {& y" e2 RO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe( Z9 A1 Z; t- N6 d! u
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE: R% B; d8 S) G/ g
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe1 t s; g$ c! R' i
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|