 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
5 z) [ v5 q2 ?' F. MScan saved at 16:55:24, on 2006-5-6* x& {" I- _' o2 W, Q8 _
Platform: Windows XP SP2 (WinNT 5.01.2600)$ b0 }6 c1 Z# T3 b/ j4 {& g4 C5 r d
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) C) \; B( }# Z/ u& [( e, K
- A+ H* B9 z) SRunning processes:. v. j" S) l) p' Y
C:\WINDOWS\System32\smss.exe; C0 j! i+ e2 j) h- A
C:\WINDOWS\system32\winlogon.exe: f3 ]' _% N L5 a
C:\WINDOWS\system32\services.exe
: R" e+ N& v7 J3 u; xC:\WINDOWS\system32\lsass.exe
& C7 C! D' o4 J9 JC:\Program Files\Common Files\Virtual Token\vtserver.exe+ Q e9 M2 h& E1 ]
C:\WINDOWS\system32\ibmpmsvc.exe, n+ k$ K+ s' ]/ l5 O' d$ W
C:\WINDOWS\system32\svchost.exe
3 |- p6 `$ W% P; _/ X% NC:\WINDOWS\System32\svchost.exe4 ^* R/ s* Q% l1 \( i
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe2 G$ t' O5 e+ B# s6 i `. u. I1 n
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
2 E) o& ?0 U9 G& @' zC:\WINDOWS\system32\spoolsv.exe b& H+ |, i0 @* b4 m# v
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE$ s- ?8 v, _ |0 _/ N3 |# T+ X
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
! m% V5 ?7 T# E0 lC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
) U9 z7 g( W. R$ `C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE9 O8 ?5 W3 Z+ G; z( K% k
C:\Program Files\F-Secure\Common\FSMA32.EXE
8 \1 [' \/ A1 t' ] M5 C7 XC:\Program Files\F-Secure\Common\FSMB32.EXE
4 H: h2 D' J4 m. [5 e( O0 e! ^6 `' GC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
; E, K/ T u" z3 ]9 S+ IC:\Program Files\F-Secure\Anti-Virus\fssm32.exe
% i3 f5 \" b- W; y& H1 eC:\WINDOWS\System32\QCONSVC.EXE5 X1 g# \0 P! U8 M' M3 q7 |
C:\Program Files\F-Secure\Common\FCH32.EXE
8 j+ M. E& K; e3 u* a8 HC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe/ j' K: o% D# [- w) q
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
1 [1 }* v# J+ KC:\WINDOWS\System32\TPHDEXLG.EXE( ?+ f4 U7 z7 o5 ^1 [/ [- S
C:\Program Files\F-Secure\Common\FAMEH32.EXE
8 U4 G# r+ p9 cC:\WINDOWS\system32\TpKmpSVC.exe
. }& N5 N0 u8 y, d# KC:\Program Files\F-Secure\Anti-Virus\fsqh.exe3 x4 Y& H2 o" h- I* c- ~8 C
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
4 B1 n7 N8 S' u; f, b" qC:\Program Files\F-Secure\Common\FNRB32.EXE; [2 [' |; @% I/ f1 h/ |* W- B
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
: h& r3 W' q- q* vC:\Program Files\F-Secure\Common\FIH32.EXE6 x- T d8 _( E; r& M9 z3 f" }$ s
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe0 H& Q+ d C9 E
C:\WINDOWS\Explorer.EXE4 _# f- c; D1 G
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
* H* {" j" m; ]% [7 ?0 ?C:\Program Files\Synaptics\SynTP\SynTPEnh.exe4 C) u! a- _4 f. @5 d _2 {% N' E
C:\WINDOWS\system32\hkcmd.exe, h5 h* S9 G# u; E! ~
C:\WINDOWS\system32\TpShocks.exe. p2 r6 d6 Z: q% v6 x
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe% [# q. [0 z& S( t3 w, p( c- K
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
8 W0 S1 t B. P( G% O8 |C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe6 J0 m1 J( A) u2 }2 t% y
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
6 ]9 y' }4 g# C t, D' CC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe; Z. k5 m5 s6 t) _; B' K
C:\WINDOWS\system32\dla\tfswctrl.exe! Q0 Q$ s' l Q s/ C6 f
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
3 Z1 R6 t. {( v- c2 @% t8 |: GC:\IBMTOOLS\UTILS\ibmprc.exe
3 M+ ?# P7 }8 Q* _# I IC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
. o# _8 {/ S8 zC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE l/ j4 C8 n9 D$ L
C:\WINDOWS\System32\svchost.exe
8 W" I/ w+ l* u; xC:\WINDOWS\system32\rundll32.exe
, M" c* W. `" D6 jC:\Program Files\F-Secure\Common\FSM32.EXE
* `$ {: d6 j* @. bC:\WINDOWS\system32\CTFMON.EXE% ~0 n& x4 B, L! t+ W* \
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
# @. H, ?- T! G: W H. HC:\Program Files\Digital Line Detect\DLG.exe d: j' N' C3 P2 ]
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe w( {" M, v- G4 @; q, ]3 P8 \
C:\Program Files\F-Secure\FSGUI\fsguidll.exe
3 A( f% l, F1 k4 V, h# iC:\Program Files\Messenger\msmsgs.exe
1 M3 Q U. X* W5 oC:\Program Files\Internet Explorer\iexplore.exe
2 ^- n! N' T4 B1 H4 ]1 k; e: CC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe! j: \7 f- A, F# M+ g
* S! r: m/ L9 x, R3 r/ uO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll* [, f; d. i; @* J2 c/ q( q; G
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
: e. X* V: s5 B* r, fO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe( Z9 s0 U- i' `" U% q, h
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe8 E6 n- q8 P4 m0 n% h& g' t5 Q7 }
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe0 p" j+ k+ M( M- |$ f$ H9 l
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper2 H2 @4 U# c0 j! x' W/ L2 A
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe' t7 g6 G- r6 U
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe* v. R/ ?5 t% I" x7 k5 J; k
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
- \" a$ `0 d5 E2 d6 T8 A3 EO4 - HKLM\..\Run: [TP4EX] tp4ex.exe
. @3 l" E5 O# @/ rO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
1 u- r- h8 V( E4 w6 b0 RO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe, Y$ _' m- H- |4 r4 v$ {0 f. c
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray, e9 U5 I: y6 l& H
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
# E: C {* _- W* O( EO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe0 M8 G5 `3 m( a6 x$ c# ]
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe+ t+ `7 [1 g- X: y
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
$ m# ?$ n' S* f! W; F- k* tO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
! G0 @& l, m% p. ^1 Q f% j: g+ @O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
) H1 u" P+ p4 Q# m' x5 E3 j3 ?O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor( |6 B d. s# e# P* Q
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
% O9 ?: e' B! K4 YO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32; O5 v! P+ a# k/ T0 r8 c+ w
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
, m/ m! @* M/ D+ \. ^O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
; Z: V v' F. i$ D/ z$ p+ GO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC: F# U. D0 a8 m* B9 z+ J2 [
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName8 Z6 V9 }+ D+ U v
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash, m% V V2 e* m; g5 {
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
- ^) b! Y6 }5 B: h4 a- EO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
; k* Q2 b' p7 y% H7 x6 e( k3 R: YO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
7 s3 h! k5 A+ P1 lO4 - Global Startup: Digital Line Detect.lnk = ?( ^( }; X6 ?( d; y
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe* j. N7 Y0 V5 a8 w: C
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
2 k: X6 K/ U1 b# f# f6 gO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
$ P3 Z1 P. N2 f" j* s" R: GO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll. m4 k$ i/ t2 D5 p$ v1 G
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll g, Y% U0 }0 v8 k" G2 r; {# \
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll2 I7 O" h }; s. l. c: S l* p/ {& V
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
8 f3 s; W q! [: }O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
1 X: b3 G" R3 u9 Q; Y% mO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
( r* W2 x6 F7 T3 h& RO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
0 t) a+ R6 E8 H9 W3 Y0 c% bO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll# Q- k8 |% v ]/ y! M2 O; x
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll9 }! o9 C% J4 x: K: J* x2 Z/ F
O11 - Options group: [JAVA_IBM] Java (IBM)3 ] M! T# P; L5 l$ C( m# v$ \! q
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
% ^' f4 h8 k) f8 Q& aO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll0 f; @8 O% }# y
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
2 X# K* h1 O7 y: i* tO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll) G( k; V. X9 q
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
! }- A, i2 k& ]3 z [5 k( xO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe7 M* }* H# K; d
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe- Q& i4 x- ]8 w9 z
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE$ z. n6 f- |7 }8 Z. _# q" k0 K
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
8 f7 D+ t4 x" @5 Y5 B6 UO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
& e- b+ P; y# q& ~( VO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE: I* t: |+ U4 u- O7 Z# H
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
; X+ n: s; v2 i; G WO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
, J6 i3 U3 B$ u5 D% W2 V3 \9 }O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
g, }, R2 d, x$ V `' t3 Z; @5 VO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)/ C1 X" M# ^# w* x3 Y2 z7 U
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
& d S" P& i2 `" qO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
" _; N. L+ R. z" VO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe3 y8 z! L- W3 v( W! t8 E# P& c- k
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
( A6 G9 h; T* I; `5 cO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
# S1 _, w7 O2 Z8 wO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe' Y4 g7 b8 b- q- E9 |5 h
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|