 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
. T! K8 j* w0 U: @Scan saved at 16:55:24, on 2006-5-6
% f9 \" V/ \* h1 q7 Y( k g4 `Platform: Windows XP SP2 (WinNT 5.01.2600)
* B6 a" u. m/ u2 I4 d" ?& K4 ZMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
- W+ a" [' y, B; E# c" {" Y1 Q& N9 _- E3 V1 @9 H8 m" L2 a
Running processes:- P/ S. i, B! F6 @( c" ^
C:\WINDOWS\System32\smss.exe
4 @& x& m% ? \; h6 [; ]* `# }C:\WINDOWS\system32\winlogon.exe
1 U% q0 ?8 ^2 k# `8 ]; h. RC:\WINDOWS\system32\services.exe& b* Z: Y0 \; |
C:\WINDOWS\system32\lsass.exe
( K' C/ Q) I% L, D' J7 N* IC:\Program Files\Common Files\Virtual Token\vtserver.exe
/ N' N6 Z$ P" m& R( v* \$ JC:\WINDOWS\system32\ibmpmsvc.exe5 t/ k f+ I$ W! M/ n) R( M6 ^
C:\WINDOWS\system32\svchost.exe. L5 W0 e$ H. O
C:\WINDOWS\System32\svchost.exe
* O, C) _; x( h9 FC:\Program Files\Intel\Wireless\Bin\EvtEng.exe! j0 \/ e8 p* a, G
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
/ ]: m6 X! B' e2 |% ]C:\WINDOWS\system32\spoolsv.exe! m' j. {2 L/ p8 N$ i3 Z
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
, s& O0 T( H. m d0 @- o4 F! yC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
" L; c" r) g3 vC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe, X% N B# r* j; c! d+ H
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
) Q( r& q& f3 ^5 N* L2 qC:\Program Files\F-Secure\Common\FSMA32.EXE- n! b2 C7 l' R$ ~# K6 D1 c
C:\Program Files\F-Secure\Common\FSMB32.EXE8 U- H' @ C ]4 Q! F
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe$ \/ ` Y Z; t# y; r
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe6 V9 }3 }* d( @9 u; K+ M& i$ W0 }
C:\WINDOWS\System32\QCONSVC.EXE9 O& f6 I5 B( {8 n
C:\Program Files\F-Secure\Common\FCH32.EXE6 z Q! l, f, l* d2 r# B9 V/ M" [ k7 _
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
$ W2 E4 j4 I; M$ s9 j+ ]C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
( o# b# x8 r# t1 z- v* |' |, O/ @C:\WINDOWS\System32\TPHDEXLG.EXE7 o) p0 C6 U! Z+ w, l1 K5 L
C:\Program Files\F-Secure\Common\FAMEH32.EXE* q( c, Z( I2 }; b
C:\WINDOWS\system32\TpKmpSVC.exe
( O) Z$ p) J$ E6 b/ g& m" l @+ N( oC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
: S$ U& F/ P0 {7 a+ xC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
6 p: Q: Z5 Y; e6 w3 u8 n" KC:\Program Files\F-Secure\Common\FNRB32.EXE
; n1 v1 ]) F4 I+ o) D; S3 k) mC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
0 H1 O# Q r* X1 y9 O1 n4 y# m3 BC:\Program Files\F-Secure\Common\FIH32.EXE3 l( [+ S* A; Z8 e
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
1 u8 ?7 t* s/ r m( K" ~& y4 NC:\WINDOWS\Explorer.EXE
& ~$ f( l8 L: U6 Q5 k4 r6 ?C:\Program Files\Synaptics\SynTP\SynTPLpr.exe E( {5 q6 W/ s2 ]/ J: V
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
) u# R2 f/ S" L0 ]1 i) M+ O* |C:\WINDOWS\system32\hkcmd.exe
7 R+ w! j5 s( m+ i, c+ E8 b+ HC:\WINDOWS\system32\TpShocks.exe
' s7 J4 o2 [% z9 x3 c" P% pC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
& F4 L% b9 X5 q; @& S5 a6 L4 }- O, _2 hC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
9 X/ b% m( u) F$ nC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
7 k3 G: U3 ?( UC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
* T7 D5 w8 e( ^/ B# `3 w% r4 e/ eC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
T9 C* W( Y1 f8 f( `+ S% w0 }& b6 yC:\WINDOWS\system32\dla\tfswctrl.exe
5 ^# C0 i+ w8 |9 E$ sC:\Program Files\IBM\Messages By IBM\ibmmessages.exe$ L, f' B/ _( |! `' G) H
C:\IBMTOOLS\UTILS\ibmprc.exe
- V& j5 h* X" T' ~( G( J+ XC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE2 |1 o% ?1 \4 B. y+ o% A
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
/ u c/ z$ G; Y0 z. |! t- g7 G4 iC:\WINDOWS\System32\svchost.exe
! D) q/ H2 _+ Z1 \4 zC:\WINDOWS\system32\rundll32.exe# n' K: s4 V1 P6 {
C:\Program Files\F-Secure\Common\FSM32.EXE
1 ?7 W: y+ ]. l/ B0 e' {/ RC:\WINDOWS\system32\CTFMON.EXE
6 {; ?: X; n4 J* Z7 RC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
: g Y* N5 U. f" t5 M" ZC:\Program Files\Digital Line Detect\DLG.exe
- Y) W% N1 a# S, B; d; dC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
" w5 k6 a: F9 h% ~3 Q) x6 m* JC:\Program Files\F-Secure\FSGUI\fsguidll.exe
* s6 l' E0 V; j; q( PC:\Program Files\Messenger\msmsgs.exe
2 }$ I1 k+ T$ I5 C* N" VC:\Program Files\Internet Explorer\iexplore.exe( ~6 \& D+ O- _1 c
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe; Q9 q3 U$ w C& {
8 Y8 R& ^6 m( n# BO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll* X* r6 F' i8 Q) n
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe5 h% ?4 R {/ |* Y
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
7 ` [. ]6 w) A( rO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe, f4 i, k4 B8 L( I R
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
( `2 A1 _3 z: p% lO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper5 R A. Y' _' S6 \% S( K: D7 r/ E
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
/ I6 F) M% H( O7 A2 iO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
9 K; Q4 Q' ^0 T9 JO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup. ?, e1 W. n& i+ ?2 C" F
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe" }; H. U" Y& ~, |- G" f% y! p. N
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe- [/ \0 ^8 b" E+ [1 \
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe* E/ t2 F/ V O7 ~" v+ ^6 T5 \% [
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
4 T. v1 h8 m, `' N* t! A( W8 w* ^' xO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
c; C! r" w8 D* }$ A. t0 xO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe0 u4 k; ]8 U2 j: y
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
1 {/ l+ |0 z4 T7 ~( w5 o+ IO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe( k, }: K) F! u
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE8 o" q5 X" n# D5 N: O/ |! H
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
4 e5 i! T4 K- _, d# S0 w' }O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor9 S5 C9 Q( T$ x) W x S6 q
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
4 g- q4 o7 i) a8 NO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
+ Y! r3 o4 H2 w2 r2 q# I. A0 WO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE' E+ q" H# c [3 f; _) n& I
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
7 _/ S9 [9 G; u, B+ [8 K% f" m6 W9 yO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
3 H) E& ~. x9 l) mO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
! w8 h; [% @' \: B9 v8 QO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash" x' R$ X( F3 k0 d/ L
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
! x. F$ k2 h3 i: J/ B$ l9 dO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
5 e" D i, x+ K; ^! r6 [O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe5 h' W5 }# s [3 u: @. ?1 T; G
O4 - Global Startup: Digital Line Detect.lnk = ?
) Y" ^2 e5 W5 g* m5 HO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
0 R# }1 _4 K6 pO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm8 f; N4 [+ a7 ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
! H' f" N' F& P* a: |O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
: K; g. y, g; ?( e; l0 h5 S" p* OO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
+ `. `% A; U, K& T9 x) D3 ]O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
& X/ c% o+ D0 n7 bO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe0 \: h- s; w- _9 Z* o
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
- J% b8 h( O& v* }0 A) `. ~O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe% c7 T) q3 r" C8 s! ~ J
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
$ C9 I9 ^- `9 J1 E* O6 W' _O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll# s# l$ Z+ M# _( g# m+ V S
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
6 Z" b. r1 U5 V# I7 R# zO11 - Options group: [JAVA_IBM] Java (IBM)0 F9 S5 H) U$ }: b' U% W
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll. m+ `, W) v$ Y3 Z
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
6 R, c! v* l( `' WO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll D Q7 y; V/ Q3 w: J U& q' D
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
# `5 r1 L5 R; a8 Q mO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
; b/ [/ T2 _" U+ V" _8 c" f/ TO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe* N) j, k- c' m+ Y) B9 p$ K5 N
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
! ?7 B$ {' I% t" |! XO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE1 P! B/ Y8 z" z$ \9 k' C
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
" X. W/ w$ B# c. b C( QO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
# I: e( o; o1 x, T1 }$ a% IO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE& Z) ?. W& s+ i8 r
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe; e( y2 {, k" ~- ]
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe1 O; f8 l" a) s
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
; m2 L0 D* f" j3 w% L, s9 \O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)) d: v( c5 t. N% `( @* |5 X$ f
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
- @, _0 K+ F' d' \8 Q+ A+ XO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
" g0 _1 z- |% H4 oO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
i* P, S% o4 h$ l' R9 V! pO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe& x3 e8 y' B; \% \* w$ @
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
5 O, s! q1 k* B) OO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
3 [8 C# n0 `4 n; zO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|