 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
) V! ^: w9 Z9 ?7 yScan saved at 16:55:24, on 2006-5-62 V9 Z J2 Y7 `% h7 X3 b; u8 b
Platform: Windows XP SP2 (WinNT 5.01.2600)
1 R0 u) {3 I/ |, l1 L B& h2 OMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)3 Q3 F) K0 o3 H
! r K0 y7 `2 |" a
Running processes:
0 e2 E! L, ]% o% V7 XC:\WINDOWS\System32\smss.exe9 { l' T" `) m3 k1 s
C:\WINDOWS\system32\winlogon.exe
2 j/ f/ m: W) n2 g" l7 ]C:\WINDOWS\system32\services.exe
3 ^4 m! T' l3 p. J/ bC:\WINDOWS\system32\lsass.exe
|" l. d( }3 r5 K7 U% `9 g- XC:\Program Files\Common Files\Virtual Token\vtserver.exe. S# |& }+ [& R9 U+ ~8 [
C:\WINDOWS\system32\ibmpmsvc.exe
5 X% X4 V, Z8 ]6 g* \! Z( SC:\WINDOWS\system32\svchost.exe6 J' Z" B/ N0 k" V2 q
C:\WINDOWS\System32\svchost.exe* w# b" e! Q' \3 t; r) M' N
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
2 K2 b. \% S6 h; R0 U4 `& t0 lC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe7 R9 a+ w" B5 X) V6 |4 a
C:\WINDOWS\system32\spoolsv.exe
4 O2 }& F8 g, sC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE c8 @- X! r% d6 e, R4 q, W
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe7 p$ `/ h9 z8 Z7 u! v
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
- A5 j# m8 _% \: t% v" FC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE4 Q; Z/ d8 a. ^4 j e
C:\Program Files\F-Secure\Common\FSMA32.EXE/ e4 Y$ Q# O; [
C:\Program Files\F-Secure\Common\FSMB32.EXE n7 f8 g8 J. H6 K
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe* G! K, u) `3 ^9 }( u2 [
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
9 c2 M5 p3 R, n/ `! YC:\WINDOWS\System32\QCONSVC.EXE; b& q7 n* n# N0 D) n" W
C:\Program Files\F-Secure\Common\FCH32.EXE
" M( ]. o6 H) Q' E8 ^9 \C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe0 K2 m' A; U6 s6 o8 ~- O- A1 V
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe% A" I5 I$ E! V% Q9 A( @: j7 J
C:\WINDOWS\System32\TPHDEXLG.EXE
+ v _6 ]) ^9 w$ P2 uC:\Program Files\F-Secure\Common\FAMEH32.EXE) a4 r; \8 i9 {8 K9 e+ G0 c) F
C:\WINDOWS\system32\TpKmpSVC.exe& s( M) ?1 }. Q. i+ ?
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
$ e* s) U# s1 v9 x7 W1 |C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
( r; Y1 ]0 j) n# j) ?C:\Program Files\F-Secure\Common\FNRB32.EXE
9 F Q* i, B! u' _7 _- c! HC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe @5 T$ M7 q4 t2 N8 Z4 `, {$ m
C:\Program Files\F-Secure\Common\FIH32.EXE3 x6 E: L/ B+ F$ l" ^& k& R! Z
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
2 c- {4 l+ S O7 MC:\WINDOWS\Explorer.EXE
) T* S8 J [( z/ @C:\Program Files\Synaptics\SynTP\SynTPLpr.exe9 C1 {+ n0 ^! L1 ~/ `; W* n3 a; F' V
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe4 f* } A' P/ I
C:\WINDOWS\system32\hkcmd.exe& o& ^1 x% `3 W1 \; r% K
C:\WINDOWS\system32\TpShocks.exe
$ L/ i4 l; e' Y9 }0 z" X! ]C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
, W% ^' z: U, v; s* Y! QC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe) F5 G0 ?0 n) k5 T; r
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
) b) g' e+ `3 V$ \C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe$ _( g3 o$ P) v# W0 x
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
4 U+ _3 k, Q5 y4 Q% N: x0 l0 {C:\WINDOWS\system32\dla\tfswctrl.exe
$ d1 K* U* B3 @! |$ N5 L+ {C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
; ?* o0 e! s! M8 eC:\IBMTOOLS\UTILS\ibmprc.exe
( R$ h3 l4 o9 D: t& ^C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
5 O3 X, }0 g5 A( r5 WC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
. X% Z; R7 c& jC:\WINDOWS\System32\svchost.exe$ g! D$ v( m: | x2 { w
C:\WINDOWS\system32\rundll32.exe# B* P3 u' d. S% c% s% A/ l
C:\Program Files\F-Secure\Common\FSM32.EXE# p2 F* x2 i6 A! f) Q# c# r" L* j
C:\WINDOWS\system32\CTFMON.EXE9 x2 y9 w: c% \6 r9 N7 g
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
$ j' T4 q. g8 w3 }C:\Program Files\Digital Line Detect\DLG.exe
# k+ Q$ j- ~1 O( l) HC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe; w K0 z% B0 K: {) R+ R5 u
C:\Program Files\F-Secure\FSGUI\fsguidll.exe
# k, H' |4 f; y* AC:\Program Files\Messenger\msmsgs.exe
0 J! h& ?" t) z( F7 e* ~! X4 P H( rC:\Program Files\Internet Explorer\iexplore.exe
# H/ V7 C# A3 U0 h" b, I) |C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
) L" |4 U3 C% ?# S' v
$ l% W: i1 q5 vO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll. O5 W2 k# n) O0 K& J/ e5 p/ |4 [: a
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
9 D7 X# m/ J; I. Z. A5 AO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
L' [( W7 u1 I4 k2 L6 D# b+ zO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe$ m3 B0 H" @5 n- W' o
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
; c: K( X, D' x RO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper8 K% B2 C% d) s/ N: }' \# ]
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe- T; X/ i; D) |7 l# t7 S
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe- G0 d) H: U, E1 A% j2 N8 [
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
0 \# q; _2 a+ K: ~+ `+ XO4 - HKLM\..\Run: [TP4EX] tp4ex.exe0 M% Y7 t- o8 X/ q
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe: y+ r" n" n/ E: x
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe; Q5 D. T& L% [2 M# U) u5 R- L
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
; G( }0 b J; o* N4 g* u. UO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
/ Q; }5 Z! b% ^. xO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe( C4 c, ?4 u6 d( f5 `$ Z" e
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe7 v- j0 z: m. }# ~+ h
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe5 Z U# u; T! l; z
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE2 j a$ e% G1 G$ Q. L* {" m
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE4 h$ y, H; O4 C" S
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
- p2 U9 r/ Q! gO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
, w; `. Y% y) {$ A$ x1 AO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32* h9 J* K- R. x' Y" x$ a
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE+ Q8 P+ G9 C" v
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
: M3 f9 T% h- c1 p! K8 SO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
+ t" c% ~5 p, j0 w3 ?) n [. BO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName3 j/ B6 ^; p+ F5 ^) n
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash8 o3 \. I7 M3 j" Y6 }
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
# A3 P) ~* ?/ H, n; L, YO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe; ~( `* c* g7 D, x! _/ j2 }
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
; [* e) t9 Y9 E* e$ v$ w' h- jO4 - Global Startup: Digital Line Detect.lnk = ?& a0 u$ o4 v' x) [5 o
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe! G- q: c1 D2 j5 w, ^
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm h) H9 R; J7 J% D
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll) A, }) c1 D* n
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
4 e* h% }* j$ Q' }% l3 [. A, l2 tO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll8 z c6 ?& y% m) B% N' Q2 ~
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll* ~2 q! I5 p. t
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
, [% u! F8 |0 K6 o. X% |O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe: R9 r- R5 W' S9 I( m t
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
) l: u7 `. g0 G/ k) m8 r+ `6 e OO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll4 p! m& `2 I" B, s
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll/ ]9 i7 X7 ]& a0 q
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
$ j; p4 Q8 d2 A3 d i7 `O11 - Options group: [JAVA_IBM] Java (IBM)# a o7 W+ ?% I: r$ A s3 ?1 @7 E
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll# I" { g& X* R' B$ @1 V$ H
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
$ k( N$ j* Y% [ g! O7 Y7 I) QO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll u$ Z$ v$ G/ ~: |3 a0 `" F1 ~
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
: ], }( E: }7 h0 C. J7 c- IO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
6 U! r" s4 C7 h& [# Q/ N& iO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
+ W0 p q* C q" o( `2 ^O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe% @' J2 V$ H. J2 L4 u( q/ x% x
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE: f% K" _( l- `
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe1 j0 M% O2 j; m$ V4 m; j! }
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
, s" [ t8 o5 h. `( z) H# [( IO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE0 z5 u3 p i) A* y+ N y" c
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe* s" t% W; p$ M5 s
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe" ^' c' `7 Z% b( m1 e% v" _+ Z& T; A
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
! \% v/ J- u U& T' mO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)% D0 K5 k& Y) \1 l( c( `. G
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE ~2 q& O( t) a
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe* O+ {1 v8 [" q1 w8 N1 `
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe- d4 Q8 p& V5 B& @2 X
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
' s, T( n' p, M* O2 \O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE( ~+ u h( K+ N. O
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
' ?3 u8 M3 u7 t. @! T" [) k- c% nO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|