 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
8 }1 C& D, H7 j" ~( aScan saved at 16:55:24, on 2006-5-6, S0 z0 Z* {& x9 t L. S6 d
Platform: Windows XP SP2 (WinNT 5.01.2600)) \, _! f; _+ ]6 a6 L% |$ L% V
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)" B( n( K1 L o. i7 o4 A
: _/ u3 F) ?2 | w2 G8 [3 X
Running processes:) u" p* U) d9 I; T* z
C:\WINDOWS\System32\smss.exe {; {2 L9 C& }' V7 u) r
C:\WINDOWS\system32\winlogon.exe
- V: V9 C4 |2 \! h) B" h7 JC:\WINDOWS\system32\services.exe
! ^+ g3 Y! J; J! T' O# D# PC:\WINDOWS\system32\lsass.exe* [8 l3 r. U) X& n+ X9 C
C:\Program Files\Common Files\Virtual Token\vtserver.exe2 x( B1 N0 W% l) R/ ^
C:\WINDOWS\system32\ibmpmsvc.exe/ ^$ a( s1 n3 c& A
C:\WINDOWS\system32\svchost.exe
1 @2 F+ ~( E* P) D# Z9 HC:\WINDOWS\System32\svchost.exe. J2 R3 `5 u% ~% }5 ?+ S0 L
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe* a' r3 R9 t3 @2 Z
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe; v* [% P$ ~# a
C:\WINDOWS\system32\spoolsv.exe
! E8 M" M- N0 ~C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
; x4 m2 j4 I0 f# E+ l& EC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
; v: ~& f1 E. dC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe+ {' ^& e- }+ }: p, R, t
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
* N3 |% [+ P& }) OC:\Program Files\F-Secure\Common\FSMA32.EXE
7 k. [' {3 p7 N N+ Z/ m4 B5 T9 wC:\Program Files\F-Secure\Common\FSMB32.EXE
/ P" Q- _2 y! }! N& e3 hC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
6 g5 g0 v/ u2 Z; P* l4 dC:\Program Files\F-Secure\Anti-Virus\fssm32.exe7 J' ?/ [& I" y2 l
C:\WINDOWS\System32\QCONSVC.EXE
5 H% n2 o6 E) f- ^6 tC:\Program Files\F-Secure\Common\FCH32.EXE
& ~' b6 R, D! j9 D& zC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe9 c( Z& R) s; F* N4 @# B1 e/ a. }
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
9 V0 [9 ?1 M) aC:\WINDOWS\System32\TPHDEXLG.EXE
1 k j4 ? [# U3 n3 ?9 }C:\Program Files\F-Secure\Common\FAMEH32.EXE
* s8 \9 e% E2 X `8 B7 \0 jC:\WINDOWS\system32\TpKmpSVC.exe
# `3 j% V) M" d' hC:\Program Files\F-Secure\Anti-Virus\fsqh.exe/ p% s; p; _4 v* O1 M
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe2 i; u8 N- D- U% v" V6 a- Q
C:\Program Files\F-Secure\Common\FNRB32.EXE
9 X% |$ b3 ]0 Y# T8 e1 FC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe# d- q8 e; j4 h9 g3 C* I0 Q
C:\Program Files\F-Secure\Common\FIH32.EXE& j/ y( h4 ^( J8 t' ^
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
b6 l1 W/ S. l s3 ?+ H: p, rC:\WINDOWS\Explorer.EXE' Q' P! I- M: X7 a. Y3 ]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
1 D- ^4 h' n; L( _C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
, ] i6 c; Q5 K bC:\WINDOWS\system32\hkcmd.exe
* `6 b S0 }7 z' G! TC:\WINDOWS\system32\TpShocks.exe
9 Z9 h3 W/ c, x8 q9 X8 e/ D, z4 HC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
( X* e) Q: F/ ^# B% H4 v9 AC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
1 A. i$ ^' U5 x& s. zC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
/ G3 u; A, J+ wC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe7 n& B; l6 a. A# p
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
' N% o0 ?2 ^! z7 e# C6 AC:\WINDOWS\system32\dla\tfswctrl.exe
9 ~- t$ ]. s9 ]. I D6 N( [C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
* W2 _4 |" c0 D3 E* `; O6 ^' a( \C:\IBMTOOLS\UTILS\ibmprc.exe" t) P, ^! o4 `' a; ~- V% d$ ^3 C& h
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
/ k8 t: \ o' S8 h0 Q; @$ f: WC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE6 f2 S' I, x6 o4 L- Q0 Y0 _
C:\WINDOWS\System32\svchost.exe
# h4 d L' i xC:\WINDOWS\system32\rundll32.exe
5 _1 C+ c, `3 h O$ yC:\Program Files\F-Secure\Common\FSM32.EXE
( C* j- J$ a3 N- K- b5 k+ kC:\WINDOWS\system32\CTFMON.EXE
1 |& g& ]$ W; I/ _% YC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
1 b* o; Y; ]- y/ T. y0 CC:\Program Files\Digital Line Detect\DLG.exe
) H9 b' Z; h# FC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe9 Y3 _5 r1 I: |0 F+ O
C:\Program Files\F-Secure\FSGUI\fsguidll.exe
0 A* ?/ F, J% s; hC:\Program Files\Messenger\msmsgs.exe
- A4 {8 G$ _" q# R/ P& S" tC:\Program Files\Internet Explorer\iexplore.exe* f* q5 l% D8 t! f4 C% t4 I
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
% v% Z+ c {8 D, ~. D( ^( ]& B; {. m' e( y( v0 x* v- p9 ]
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
: R% _& T/ G; Y& |* N& fO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe9 H$ d8 r$ [) B* C, ]1 F
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe, b: S2 V* g/ z& }. b
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
- a" e9 M, U9 ^, @O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe" c5 h8 y1 h: D3 ]& W1 k
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
% e. z1 P) l4 l9 I4 R7 O% P$ fO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
- U0 } q5 }$ g) ^O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe% n( J* I% N3 h# k. z
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup' h U7 v5 `, Y; ~& j$ Z3 A
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
7 z' q6 D9 u" Q! K; I" BO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe t) M+ u! M& G- @ @
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
+ n5 h7 |) Y+ [3 KO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray' X m. P! w( c: q# r m
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r& ~4 a+ _' r/ k
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
- R+ K* }! C' z" C p) Q+ YO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
4 m5 t! o; i7 x4 ^O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
5 Q! A. B; V9 HO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE2 P: R! D: ~. T
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
0 d, y2 n* ^9 i1 }! @* K( Z. yO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
0 Q n. l$ m! Q# vO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog9 ]3 Q5 F7 K% J) s
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32* B( V, @( e; `, D" Y
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
" j0 |* p6 x& _0 P; tO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC0 S( h" M# K! d
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC3 o; g+ }6 J2 J7 O
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
* ?, E2 {4 L: }8 J0 N% u* `5 S) nO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
4 q0 z6 G" t3 H: Z1 x$ a' O$ [O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW$ j/ g( W; L+ P8 i+ {
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
( z# l1 e. K7 o) ^ LO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
1 a0 K0 M' Y" {7 OO4 - Global Startup: Digital Line Detect.lnk = ?
5 `/ A# u/ e6 I' Y: |8 E3 tO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe, S, Y1 t7 |! x% M% e
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm. }/ c2 S- j. e) z
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
0 w- N( Z6 F- j/ z5 a: AO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll8 O( k0 f3 f/ u! p. L4 H s
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll9 @$ o, n1 }- P# i
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
$ S8 S4 N# o1 r0 e' V ^" [! NO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
& N3 K4 [2 A. K9 ]7 QO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
7 x! N' O* v5 H2 u) N" lO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
& c, B- ?0 @9 a- S0 ]+ aO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll1 N. h/ h6 E1 F% h0 \
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll' n3 Y9 ]$ {4 R
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll+ x9 Q& ^: O [2 J3 s
O11 - Options group: [JAVA_IBM] Java (IBM)
& I3 b! y( l: N8 ?O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
& Z6 o6 {( z& W+ m3 |) NO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll0 y1 r2 G/ J0 {/ A" l
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
/ t+ C+ n6 X o( n8 V. JO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
% ^+ E- s$ `3 H& X x& Z" U h, |O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE/ x/ Y5 I: q8 z; Q; C
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
* `9 ]9 g- g3 A3 x4 g; rO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
# }1 A5 o l% T0 `9 m1 hO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
& I ]7 w, }; D) V7 C$ bO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
0 m4 s' e# h. ^/ w3 O) YO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
$ u' j$ K) J5 zO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
3 h2 ]: f7 U+ J1 \: qO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe( P/ G3 A( h( l; i% c
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
: c0 a* E; ]6 q3 p4 ?: G4 IO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
! L6 B0 O( ?2 i' [+ w4 G7 }O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
: j) L2 O" \( e9 d$ G) \+ q9 YO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
8 S) p$ j/ W7 [% ~4 m- H1 T# VO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
6 M" n3 H- n/ ?1 mO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
! n% o( s8 o3 U; }O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
7 {. d+ t6 @8 t, O! K. Q, _O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
! x( n; ^! [$ O! {, q }O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
- u4 ]# T' I8 `) ZO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|