 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
+ Q7 `8 j# ]& o0 s! t0 \% d7 x) AScan saved at 16:55:24, on 2006-5-60 }( z, M- Q* h& T1 D, x- U- Y$ B" A
Platform: Windows XP SP2 (WinNT 5.01.2600)' V2 J+ N& ]$ X
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)$ Y: f* M& D, V) o+ p( s; @
( f/ C4 R2 U7 A8 c- u8 ]8 T) X& E3 T4 X
Running processes:) D2 r* g8 k8 R5 _1 o( w+ F
C:\WINDOWS\System32\smss.exe
. y, z6 U1 O. [7 ~% F& V1 q% O( Z UC:\WINDOWS\system32\winlogon.exe
1 p/ I( h+ h2 q; l$ UC:\WINDOWS\system32\services.exe- R8 o& l3 Q ^) |! R" b C
C:\WINDOWS\system32\lsass.exe
+ D. M/ }, f7 N6 t1 _2 dC:\Program Files\Common Files\Virtual Token\vtserver.exe8 {/ S$ ]. x, O* [% {
C:\WINDOWS\system32\ibmpmsvc.exe
/ {3 w" t$ L, z1 G( J+ I1 m8 ]C:\WINDOWS\system32\svchost.exe; V' ]& q8 T+ w3 X
C:\WINDOWS\System32\svchost.exe: {0 W1 ]+ [' }: t( O( c
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe& W9 ]) {9 d1 F& Q& N7 K: p, |
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
0 R7 u: |4 z8 l3 E0 ~C:\WINDOWS\system32\spoolsv.exe1 o9 d% F' K; L, L$ ]7 U2 b
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE7 I9 ]' [, W+ C% Z2 K) k
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
0 D: U' |9 N3 P4 [, bC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
/ D: y6 U* z7 bC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE/ O, e! p: r' i+ |( L
C:\Program Files\F-Secure\Common\FSMA32.EXE
8 `- i. N! t& }5 b, A- J3 }C:\Program Files\F-Secure\Common\FSMB32.EXE
X; q3 P6 h9 P8 F# U& ]3 y) {C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
8 T! k7 C7 E( O* A* DC:\Program Files\F-Secure\Anti-Virus\fssm32.exe$ Q0 w. i0 X* A& y7 N; P0 k
C:\WINDOWS\System32\QCONSVC.EXE
% K8 d1 M6 w' i/ l9 c$ Q/ ?" NC:\Program Files\F-Secure\Common\FCH32.EXE
5 i9 }2 p. O) l; o* ^C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe9 a" x% J" i: S; h% X
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
8 ?4 S# \. ^# r$ eC:\WINDOWS\System32\TPHDEXLG.EXE% I7 Y8 F; {6 k' P8 w8 n {
C:\Program Files\F-Secure\Common\FAMEH32.EXE: p6 g0 G. q1 T3 t6 p* U
C:\WINDOWS\system32\TpKmpSVC.exe
$ L o8 [' K7 ^6 {C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
$ k k# `3 b+ U" |$ XC:\Program Files\F-Secure\Anti-Virus\fsrw.exe* v# x* Q3 C8 G5 g! _( i3 F
C:\Program Files\F-Secure\Common\FNRB32.EXE
" Y& @6 c1 C- M! S0 O5 W; Q* N1 bC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe7 t s, B8 c {: o- E T/ R
C:\Program Files\F-Secure\Common\FIH32.EXE
& Q; C Z# A4 j V0 _0 J% i% a1 ~8 j( C3 AC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
) V5 _; f" F& H& q+ mC:\WINDOWS\Explorer.EXE H0 } t% U' t6 F) A# q* Q
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
: Q8 ^# J- X/ n. T5 J1 u7 CC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
9 l" a- f( J$ D2 w5 E: O" X- I! cC:\WINDOWS\system32\hkcmd.exe, ~6 ]9 Z9 u7 w( k4 o
C:\WINDOWS\system32\TpShocks.exe$ a1 G- ~" [5 y( U- q
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe8 a* P6 b! m, N. f* ^
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
' x* \: O1 J8 j/ I( cC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe( S" b- x% {2 ^5 y `
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe( ` }( S, @. V5 @ H
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe. O% B0 x9 N; y, z5 n9 j) C2 I
C:\WINDOWS\system32\dla\tfswctrl.exe8 O+ |9 h6 q9 X8 o" O9 e
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
: U9 q! W- z( \$ \9 hC:\IBMTOOLS\UTILS\ibmprc.exe. k/ p& B% x" G' k+ h+ n" }% ~
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE, W7 M5 w1 S) _- p6 C; y# N# J2 m
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE/ P+ F/ v9 l! ~
C:\WINDOWS\System32\svchost.exe
1 d" \5 o" [; |& O3 F3 ?C:\WINDOWS\system32\rundll32.exe
7 u0 I' n( k, J! KC:\Program Files\F-Secure\Common\FSM32.EXE2 x6 h2 s' a% l$ r6 O; K& j7 x
C:\WINDOWS\system32\CTFMON.EXE
. k4 Q6 r8 d* ^+ r5 w9 XC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe) N& ] z) b; C7 F% K- l
C:\Program Files\Digital Line Detect\DLG.exe6 g2 E2 ?) _4 g( {0 j
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe1 {' |0 ?7 Q# ], }# F
C:\Program Files\F-Secure\FSGUI\fsguidll.exe& f$ k" S$ u+ j j1 y
C:\Program Files\Messenger\msmsgs.exe
6 L' d( ^; C+ u& M p1 DC:\Program Files\Internet Explorer\iexplore.exe
& N& f- Q$ ]5 p, ]C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe+ ^. f: n# m$ \$ U
) A C6 K; f6 r# Q& T, O, {8 O
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
5 L' P9 } q/ ~: w$ tO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe/ E7 {5 _' T& J) \3 e, r
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe% M+ [" Z+ _* r8 d
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe' x: s- F1 Y( M
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe( J& H2 y5 \8 M% U _+ V4 y
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper' q: e5 R' s H* r V7 t
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe% o6 D9 E/ s! A- @ s8 D3 I) _. I
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
9 d. Y6 O/ O) ?2 i( I% yO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup/ u \/ u1 q0 t. ]' N; X! p
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
! ]) G! f9 L/ h. f5 e- dO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
( ?) z3 q8 I* b/ ]. O8 [2 ^$ dO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe2 f2 n7 o+ ^* E7 b+ w- C* e7 g
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
' p* ]3 z( c$ e4 p2 d: x3 cO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r# b! Q0 c5 Q) Z4 b' F: B n
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
2 P* N. {! H$ m! s$ W7 S5 LO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
* ^1 f' Y$ |- fO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
# y+ C2 ^7 w7 B- [) u4 S+ nO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE: P7 [! b6 ^- z! H$ n
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
1 O$ g" G U! h( MO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
- }, D2 P& \3 \: e# e$ CO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
7 ?$ p* y& ~/ f: M$ b, |( ~O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration323 A/ f( [* w) g# q! l
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
F% K8 G% w; Q S: LO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
" I- O1 x) V: y$ C' DO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
/ W5 T# a4 o' C; y' m! {( yO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName) S, C K2 Y3 ]0 a! t
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
, K8 I0 y( M2 H% l2 W. O/ [O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW" l% n& u6 L! X0 o2 ^# k# F& P7 M
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe! F( c0 Q, F/ B A6 c5 d
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
" o m$ `5 i2 [. u* U$ |O4 - Global Startup: Digital Line Detect.lnk = ?& p. N* t# y2 |) x, C
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe$ R# P4 E4 S# L% _& @! V$ d
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm- m5 a+ R8 C9 E0 |1 v0 s A+ s+ v4 C+ @
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
8 d& E5 L# ~1 qO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
0 ^; i/ Y% T( V8 ^& j% l7 a$ {O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
- F! ^# a' f" S. Y+ F E. N* n0 x2 RO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
N0 m& k1 ^8 ~& c6 q$ y. GO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe8 K. D5 z* T7 ]( }% k1 A
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
4 Q7 [5 l6 q% e7 F+ ]5 w# ]O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
1 A t" z( V+ V# F# ]( [O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll% J' L. {1 p; o- L V; R ~) T
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll1 ` C$ P$ a+ ?) p7 j
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll, ^& I: I1 I" v
O11 - Options group: [JAVA_IBM] Java (IBM)
" d# z/ v' @% u4 v5 A# k' jO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll) R4 i5 u7 [0 K
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
7 Z; B) y2 ^/ Q% [O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
8 Q+ \7 M0 Z3 H8 i2 PO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll- ?/ X" H" }+ c5 T
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
( J' F0 D- e( | S; h# rO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe' P' H" d- G2 i3 m: b) i
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
* @. ~ n. K1 f) r0 f, ^O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE$ V6 u9 ?. u" m( ]9 |) o; C( _2 v
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe/ R3 S' D4 |5 a! l+ d
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe( }8 ]8 o3 z: Q# W- \% d
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
( i- K0 @2 E3 v9 z, Y* q# |O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
+ M- I2 H1 F9 ?O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe! f- F$ C4 ~4 T3 S3 _: o, Z, U
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
- d! j/ t* [, }8 e1 n" S5 N1 pO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)9 T. ~2 D1 ~) M Z" p9 z: Y- g- z* z
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE; ~0 d; t0 K; Z2 k
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
1 E- ~9 M- n1 T# a3 V. PO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe4 d _7 u' t! q! E( e& m
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
0 b- Y: i! B$ i. o# Q) K9 HO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
" h5 t V/ [4 |4 B" M) J5 _) u IO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe- _8 f/ r5 H% B, a$ x/ T
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|