 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
0 M! m. _2 f& u) ?2 @Scan saved at 16:55:24, on 2006-5-6
1 X1 J$ x4 ]& X3 Y7 I. S bPlatform: Windows XP SP2 (WinNT 5.01.2600)# ]2 H( P6 o a0 O1 x3 [
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180). S8 E/ q ]5 I* u1 o* ] i) A
* p# ]+ t8 f% L& O- V }) a' qRunning processes:& [6 J! S+ a( T: d4 D
C:\WINDOWS\System32\smss.exe& L$ a1 x6 B* R0 N7 [
C:\WINDOWS\system32\winlogon.exe2 h* y6 m& N. y7 c' R) \1 Y
C:\WINDOWS\system32\services.exe
8 U! Q# T3 v. M0 Z, D: V9 R4 GC:\WINDOWS\system32\lsass.exe
* \" Y/ h9 f2 ~1 jC:\Program Files\Common Files\Virtual Token\vtserver.exe
$ c* A7 T1 n2 IC:\WINDOWS\system32\ibmpmsvc.exe
- f' i5 y9 |! C/ yC:\WINDOWS\system32\svchost.exe
0 `, z- p$ _2 B/ f$ [: n/ f. I; L+ F9 \C:\WINDOWS\System32\svchost.exe2 a( Y( V. q3 a `& P! Y
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
8 A" a/ K' T; s! e) n0 H( RC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
$ y m1 Z# V$ s( _, \9 gC:\WINDOWS\system32\spoolsv.exe
4 A1 A' f& ^, S0 Q+ z, PC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE9 ?& u3 v+ ^" m! q1 m9 |8 _
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe9 M, F: d* X4 T* _ d$ l
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
% H- Y4 {9 C8 Q! D- ?0 AC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
) J) E+ @" w2 M: UC:\Program Files\F-Secure\Common\FSMA32.EXE
% @. n3 s8 C9 g3 K- k8 tC:\Program Files\F-Secure\Common\FSMB32.EXE
' x' p6 ^: ]& `2 ?C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
* U0 Q! U1 e2 S/ ]1 h1 PC:\Program Files\F-Secure\Anti-Virus\fssm32.exe+ \/ ]4 j4 K" u. \
C:\WINDOWS\System32\QCONSVC.EXE
! F! x- }7 T- @/ B* n) ]! s/ }C:\Program Files\F-Secure\Common\FCH32.EXE
2 F1 X6 E- o4 O2 x2 PC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
' A6 F) q0 |4 [, a* rC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
' e) r1 T: y. s8 H" H/ DC:\WINDOWS\System32\TPHDEXLG.EXE# ~ Z; I5 m: ?( M b' z" v% X& w& y
C:\Program Files\F-Secure\Common\FAMEH32.EXE
+ s; z( r7 L. ~: S: O2 ?C:\WINDOWS\system32\TpKmpSVC.exe: q, s7 Z9 v9 y1 W3 _. H
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe+ U0 Q& S: j" j0 h3 U/ t
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
' R5 O2 ]2 ?* k4 X) I& d$ l# \C:\Program Files\F-Secure\Common\FNRB32.EXE
2 a: B- w" x4 f/ p) m3 Q$ i& lC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
9 w9 n" I" I8 ^* g* q+ WC:\Program Files\F-Secure\Common\FIH32.EXE1 q# K5 M6 W- C7 j
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
* P2 {8 _5 d/ ^! Y7 K. a! y9 eC:\WINDOWS\Explorer.EXE) g; D3 c. Y. P7 ]! u
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
# M2 B/ k" c( [6 u6 q ~7 ZC:\Program Files\Synaptics\SynTP\SynTPEnh.exe8 d0 G l1 L: A; p
C:\WINDOWS\system32\hkcmd.exe
" L, v" ]$ C. ^ `) y1 w+ JC:\WINDOWS\system32\TpShocks.exe
5 J& D0 Z1 t o" Z9 s7 Q* o4 XC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
( y2 U4 h0 N: D; g7 b: W, E" gC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
. u3 c! C* f" z4 o1 YC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe, Y& U2 g w0 P! c
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe5 I+ T6 F: [' Y1 Z
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
) E" {* n! ]# m1 {# M9 y. YC:\WINDOWS\system32\dla\tfswctrl.exe
0 n# ^! b6 i! P6 B4 rC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
. N2 q# H2 ^- _$ ?C:\IBMTOOLS\UTILS\ibmprc.exe0 [& y( W- y0 E% v
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE! J8 w- R0 Q" z+ S1 _
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE, C8 N' I' S' o$ n/ y
C:\WINDOWS\System32\svchost.exe+ c5 P6 g+ O6 d) a1 h1 D
C:\WINDOWS\system32\rundll32.exe
9 r: F% r9 o1 x% r" f# z& wC:\Program Files\F-Secure\Common\FSM32.EXE
8 }; X/ N( X/ }. JC:\WINDOWS\system32\CTFMON.EXE/ O$ ~* Z( @' _6 N
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
0 H2 [! \1 t( SC:\Program Files\Digital Line Detect\DLG.exe
+ g' b7 S; q- |. E5 E0 X( jC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
( |2 f' @1 H9 B, h" r4 n4 `C:\Program Files\F-Secure\FSGUI\fsguidll.exe% Q; N4 @/ c3 T1 N5 E7 Z/ U% ^' o
C:\Program Files\Messenger\msmsgs.exe
! w, r& U( i0 \2 P% w3 jC:\Program Files\Internet Explorer\iexplore.exe, h7 y9 F0 k% ~; }+ q" |3 e/ @" k0 ?% F
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe" A1 N8 Y& e; v1 n
# }, y- N% X1 i A
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
; {5 ~! k! @9 n" p3 i0 c. mO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe1 Z8 U" o! ]3 m& K3 N( A& F
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe. P( W' h+ S3 C ~% \
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
* @! ~) I, u: r" H9 N) A# i" jO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe$ Y2 j' H$ h( o. n! ]1 h
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
; {2 P9 J0 |. v8 S3 c- L& T7 Z! gO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
3 B* `" o- z1 C3 u" K4 MO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
2 W8 v1 F( K' H. JO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup9 X' r% h0 c' W) w/ P: ]
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe+ ?( a% F, p- S3 y# G- d" G3 F0 o
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
, ^+ _1 Y3 g3 XO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
0 V$ v0 l J: o* ]3 N1 z- k$ QO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray: [3 p& v4 y% o
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r( P5 @' g/ o( @1 h- d: k4 h0 y2 O1 ~
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
, i6 E B- h6 U0 A( l' x4 vO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe& N) h9 T- v1 [* N2 y
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe9 F1 b) a* A) T8 }4 `! d
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
: ?" l9 s% T$ ?O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
+ x4 b" L; b" B; b' XO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
$ o) N4 Z4 \* e m$ O% s3 WO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
9 h! L& h9 j9 i8 s' `6 \O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration323 m% G: P& |) h. t+ ^5 R
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
, l) ]9 k0 }3 X; XO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC8 s& z2 N" o: O" n4 r
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC) q& c3 t* V- v4 G9 o
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
! R, I/ R& s6 |& `+ jO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
$ d5 H2 K4 m: e) u8 i' XO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
7 Z6 M: W9 _7 C1 z! ^O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
( M& F7 h7 M2 fO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe2 n% k2 y) j- d. s
O4 - Global Startup: Digital Line Detect.lnk = ?
7 F4 s/ _& i* p( E5 eO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe' J# c. m6 u9 S) I
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm7 { y! R8 E7 q# c# W8 W
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll* s* T2 o: s, u& _' E
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
* @7 D/ T& `, ]% w5 X' XO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll1 ]( H5 W" X$ I9 l& B2 L
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
) h* S( m/ t3 b& A) L4 NO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
* {) w5 U _6 ^" {1 y* L* q5 sO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe/ w( B" w6 x! c" Q
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe3 @: X, D" b9 O' M1 _7 C
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
& d5 E; d+ B- a D0 B0 J, MO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll/ }: f+ N2 V3 Q; ]4 A9 F/ W. {
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
: _; P& p- t: {" KO11 - Options group: [JAVA_IBM] Java (IBM)7 ]! T6 ?' Z0 r# `8 x
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll1 q' S' J. A1 o3 G) ^
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll& T/ E: {4 R9 a' g3 D
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
3 n" q5 e6 q4 ~3 |& @5 `% oO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll* S+ R# z8 b k# n% |9 U
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
% o6 S) z7 p% E" B$ C7 X8 p# T- \. B1 nO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
# w$ i1 n4 z% SO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
! Q# s* p1 Q$ l$ Y% j& Z8 D: ]O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
: O! W4 d" Q1 M1 v" iO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe3 p5 k9 K# t( b3 j
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe" O0 g1 r( C( f6 e9 X# R/ ^$ A! s
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE# x& s" n. |, L, E, w! z, _
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe. T; s2 s: S& w" `! \8 |& J
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
- T# Z$ R K/ l: q& K9 YO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe' d3 e. l! i9 ~, D% X
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)" O; B% N/ n& `+ S R" J1 M- e6 X. z
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
: P: R' [/ E- q9 N6 }% tO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
( M, E# F9 L6 R8 F" NO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe/ @0 `6 t8 F2 x% }0 @2 L
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
. \, h( G1 y% a IO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
7 o) i s2 E* k9 eO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
5 V2 R' J5 \' a# f% @8 iO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|