 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
8 w# }9 P$ S+ c& u; \# z/ AScan saved at 16:55:24, on 2006-5-6 ?, x J2 [* I% |7 Z1 Z
Platform: Windows XP SP2 (WinNT 5.01.2600)6 |2 T- k5 a% [# Z
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)+ f. `5 w" o; j% ?; j2 L* T
6 G. s# i7 A9 A. D
Running processes:
, g9 V5 f! R# a$ `) L! JC:\WINDOWS\System32\smss.exe( |; k K! C: k9 o
C:\WINDOWS\system32\winlogon.exe
. t9 E2 C5 n' n: @C:\WINDOWS\system32\services.exe4 f! J0 p+ m. Q+ `
C:\WINDOWS\system32\lsass.exe
k2 N, l2 B; bC:\Program Files\Common Files\Virtual Token\vtserver.exe x1 u. ~4 Z" Q# x; E1 k
C:\WINDOWS\system32\ibmpmsvc.exe
$ j9 A: p: r% ]3 UC:\WINDOWS\system32\svchost.exe
/ ~. }7 h2 [) J, A5 z7 R' J9 F8 jC:\WINDOWS\System32\svchost.exe
9 y0 C p! _$ D9 D1 wC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
8 @! A9 \4 @# Q4 l& n* H7 n8 E4 [5 y. ZC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe' o9 T* i& b: \5 f; |. i
C:\WINDOWS\system32\spoolsv.exe
0 G7 r8 [8 b; y. y- P& e/ R4 bC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE/ p9 F" z4 t9 z0 L
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe) l0 L8 A) D" V4 h7 A# W
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
7 i/ B/ x" x. T3 X+ FC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
* j1 K6 z* u7 S7 wC:\Program Files\F-Secure\Common\FSMA32.EXE1 d- k# u) ?% A& f" I# N
C:\Program Files\F-Secure\Common\FSMB32.EXE! t/ Z& h* ?* d* n/ R3 Q: i3 {' L! N
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
& N7 T" |% A8 m8 RC:\Program Files\F-Secure\Anti-Virus\fssm32.exe8 Y) A9 B. b. Y0 x+ s
C:\WINDOWS\System32\QCONSVC.EXE
5 R2 L$ `3 [7 d7 jC:\Program Files\F-Secure\Common\FCH32.EXE
f ]/ @ O% H5 R0 hC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
5 E! |5 D" f3 y( W3 x, [C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
8 x) s9 Q# U& O: i) A* [. ZC:\WINDOWS\System32\TPHDEXLG.EXE8 [1 a( B% t/ r& n6 T% o6 E
C:\Program Files\F-Secure\Common\FAMEH32.EXE
" K/ O6 O4 `; H0 eC:\WINDOWS\system32\TpKmpSVC.exe
7 k7 O V3 h, |1 Q# e3 qC:\Program Files\F-Secure\Anti-Virus\fsqh.exe3 P3 w6 w3 k& X: ]
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
9 {- \$ ]5 i) k6 q0 pC:\Program Files\F-Secure\Common\FNRB32.EXE( T3 B d& a4 Y2 K" B1 [- h
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe y# G# ]4 ^! ?( h* T3 A5 C, T
C:\Program Files\F-Secure\Common\FIH32.EXE7 ]9 X# A2 h' d3 k( S9 a5 A
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
5 i+ `1 X4 r' [$ qC:\WINDOWS\Explorer.EXE' b9 b8 C4 B: |: ?0 {0 E( \& C, ?9 g
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
; _5 W a' ~! Q- L$ n: T3 nC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
5 N( e8 L& X/ e3 l/ M& \0 O+ c9 CC:\WINDOWS\system32\hkcmd.exe
. h9 N! s+ E$ k WC:\WINDOWS\system32\TpShocks.exe
3 Z- g* M/ V4 _7 f; ^3 DC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe) z3 d& h0 r% o* m9 j3 y3 u9 o5 J6 ?
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
; u# B h* ]& d3 ]C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe* h8 H Z) g" e0 l0 B1 q% |
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
- g& Q, W6 o# H( J' {" y! aC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe3 R$ K7 g( d2 S1 ~2 l0 p& n# ^
C:\WINDOWS\system32\dla\tfswctrl.exe! e/ \& Y" v: B0 i+ _( z, C/ ~+ I1 P7 q
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
4 p# K6 t$ o0 K% }) p9 e- P/ ^C:\IBMTOOLS\UTILS\ibmprc.exe
' V m3 k8 d; c ~% N7 K+ Z: B" pC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE4 r: w: C6 W- ?
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE) f0 n5 z [4 ^/ }: }9 g3 }& p
C:\WINDOWS\System32\svchost.exe6 M. M$ G/ M* A. s3 S
C:\WINDOWS\system32\rundll32.exe
' m/ X, h" Y1 b$ {$ r$ u2 VC:\Program Files\F-Secure\Common\FSM32.EXE6 Y. b, t( R2 h- w
C:\WINDOWS\system32\CTFMON.EXE
3 I5 F& m- y& _ LC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe6 c& @+ k1 y& f4 N6 N& |
C:\Program Files\Digital Line Detect\DLG.exe
2 e' L! L: G9 s s/ V$ Z- IC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
+ u. W8 Y, [( |* ZC:\Program Files\F-Secure\FSGUI\fsguidll.exe
3 f8 b. P) Z: M% r. l pC:\Program Files\Messenger\msmsgs.exe4 L& b1 Z, z! V: X6 J* k
C:\Program Files\Internet Explorer\iexplore.exe* i& q: K( F1 k$ `4 [- \9 f
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe+ p+ D: F2 ~3 ^% }& C
( h- t1 V( n% A% S) n( a' L) gO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll. [ u4 s$ g0 l" z
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe: t2 k% J3 {% d' b5 `9 R
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe' o, C# f& l d' |, _) j
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
* [+ M+ X( N. ~% E5 d' |2 c# bO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
/ a1 X2 _& H) z5 B2 Y2 wO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper# A; o. ] z2 F9 W. a9 F/ M
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
' Z* k, v% f7 X8 J0 x# lO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe2 q) @, D& P5 s8 }, W! t) C/ a
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
/ P, z7 @; k8 d. q0 B: \& g6 jO4 - HKLM\..\Run: [TP4EX] tp4ex.exe8 y+ W' s/ ~6 I( h' X+ A, s
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
* F3 M# a1 l9 j' m, FO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe9 _- x$ u& G) ~1 \
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray! U. x$ e6 G8 A6 y
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r) C& R5 Q8 N3 `2 g% N
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
8 v o. j5 k8 r) q5 I( u0 UO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe" c( T& j) _0 h- e7 |6 e
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
$ C$ T- L9 @9 t" v( s% x' XO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE6 \9 e, i1 z: M- ^- N, N# Z
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
4 X7 S" \- H/ {& p! {( }O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor( M/ C7 Y, d: R1 ~' N L
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog- v- K, V5 v+ \# C
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
% Q6 t6 l8 a; C, z. m& MO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
4 c- O E$ P O! U n/ cO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC0 P* ^0 x4 t e! a1 b6 r) G
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
) _# m R7 h' M, @' c. bO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName- K# i4 M) ?) j7 S T8 a+ c ] t/ L* v: C! g
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash. O0 X8 D+ W. v; b3 K- t) m' O
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
" T% h* b7 x7 @( ^1 ?/ F4 |) VO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe3 @7 }# Q3 w: E
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe2 t Z+ U* m$ P& y
O4 - Global Startup: Digital Line Detect.lnk = ?4 ?. J7 L( @; Q& p* i/ L. Q2 S) Z: T
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe* t1 n* ~8 g' D
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
8 `6 Z+ r; a6 T/ \- WO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
W! c5 T# ?, O5 V* \O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
* T& }. j7 \9 n# x5 |O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
- @' L* y, q2 Y, z- Q, m( w9 a8 [O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll! B0 b* M2 v0 L) ]
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
5 i C0 Z' _$ l2 fO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
) x$ E- s! `5 h4 F2 O% Z! G+ @& pO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
* x8 G8 p w/ w$ ]+ o4 f$ `3 xO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
* D$ D! R+ S, {3 I5 lO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
( G; ^; D+ H2 ]O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll( G9 t3 t) W* l9 g% N- ]9 Z! w
O11 - Options group: [JAVA_IBM] Java (IBM)9 ^ L( ]7 c0 y2 P+ w3 d1 B
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll' X6 u- Y7 D& k8 X2 ~0 t- Q8 \ H
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll2 z4 u% X. _* ]6 q& u) \ X
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll5 B; T6 u, m' B: _; m
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll* Y- H6 H" E$ E3 E! }
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
8 P+ T, A# {( ~+ L: d0 MO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe7 H, ^4 @+ ~! x7 r1 c1 @, U8 _
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe2 M( x- t/ _) w- |
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE' a! q8 C4 ~1 x$ y, Q v2 p
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe: y U* C: n0 I, y* |0 u
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
0 C3 J" {9 }8 ?7 DO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
6 z, |0 @9 H5 l: ~: vO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
2 M6 K. k: }# @1 B7 jO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
1 F) E* E' y/ f$ rO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
2 D- y4 m# ^. L, M* @* Y6 ^" b5 GO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing), n4 T+ k, I8 o* M5 ^& l+ O1 K
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
3 l3 E' C1 n- F# L$ F# n9 OO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe3 a* r8 }/ A2 l0 H0 X/ M' Y
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
/ B/ S- N4 I" \2 b! m! EO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
. k0 H/ f' y& c; e. cO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE0 @* R. h2 r' [
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
" W! D& ^ a" r. r: HO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|