 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1" S! j' ^: ^. U- C" v, w, J
Scan saved at 16:55:24, on 2006-5-6% a! N1 |$ U; v& m, Y8 T/ O
Platform: Windows XP SP2 (WinNT 5.01.2600)
. k' f% w) N$ K; v& NMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
3 c& l3 A# r$ y1 _) `- L; r; r
& ?! U8 b1 J) w( bRunning processes:9 H% G( }% h" Z j# }
C:\WINDOWS\System32\smss.exe/ u0 p4 ?2 m- x: {) I# N
C:\WINDOWS\system32\winlogon.exe
% O, o; H8 G" C" S4 aC:\WINDOWS\system32\services.exe. s% j5 H2 L9 I* T
C:\WINDOWS\system32\lsass.exe
( f8 e" @* i: S; j. `$ P, P3 VC:\Program Files\Common Files\Virtual Token\vtserver.exe8 R% m1 {* x1 i& w1 n# g
C:\WINDOWS\system32\ibmpmsvc.exe2 U: u/ m/ ?+ @: z# ?1 J o
C:\WINDOWS\system32\svchost.exe% z: h9 n6 V# t% O+ V
C:\WINDOWS\System32\svchost.exe
7 V1 B5 o; H$ ]C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
Q4 A8 o9 i- x2 N/ nC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe- A! o# e; H% t8 {" n& g( s3 `
C:\WINDOWS\system32\spoolsv.exe- A* }2 } z' ]# M
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
1 o2 b! i2 k2 t9 C gC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
* I+ F' ^0 V- X; ]C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
7 C6 i. E1 g5 E1 g. o& uC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE5 ~' C( l3 A0 L3 g" z7 H
C:\Program Files\F-Secure\Common\FSMA32.EXE
5 g& e; ]( D* L* q! b5 _1 R) hC:\Program Files\F-Secure\Common\FSMB32.EXE7 Q# ?! }7 B/ ^. d: [1 m+ a) [8 t
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
% n; h% O# Y( M) s2 c9 ~C:\Program Files\F-Secure\Anti-Virus\fssm32.exe- z1 C8 h& Z1 M4 X. Z+ k5 N) N; @
C:\WINDOWS\System32\QCONSVC.EXE
. U! d# `& W9 r5 ^* PC:\Program Files\F-Secure\Common\FCH32.EXE
2 {8 o1 k5 ~# Y/ S; M' d4 V( ~, vC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe' v2 u) X+ d8 d2 S
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe- _( c8 b- Z8 l/ O, u2 ^# A1 I* G
C:\WINDOWS\System32\TPHDEXLG.EXE
7 ?. I: T5 t9 X8 j" F+ w5 LC:\Program Files\F-Secure\Common\FAMEH32.EXE$ J ]; C }3 M- b$ H9 Q" m
C:\WINDOWS\system32\TpKmpSVC.exe
; V: a$ T( \. Z9 U; L, w2 c6 a. RC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
1 a8 M1 E2 S) y+ H% j0 j- |C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
- _$ k6 N1 w1 y5 {6 mC:\Program Files\F-Secure\Common\FNRB32.EXE( M* d1 a; }1 o) y, G9 w
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
" l( ^& u2 ^. y$ yC:\Program Files\F-Secure\Common\FIH32.EXE
- K \4 V9 l6 Z NC:\Program Files\F-Secure\Anti-Virus\fsav32.exe8 ^9 S2 L# k5 V
C:\WINDOWS\Explorer.EXE2 O: t6 V# C/ J3 \
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
) U& g" g; w4 `: [C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
5 x1 p3 ~, u1 p) j+ FC:\WINDOWS\system32\hkcmd.exe7 b8 }" ~9 f; l% ?* v
C:\WINDOWS\system32\TpShocks.exe, k" T* s- S& ]; O
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
6 v" U5 Z; Y0 C& i% N6 |% X9 c4 b# hC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe% t# I- f/ b/ w$ m* `. d
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe6 ^. z% M$ s, J' |' w
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe. {) W0 I# O$ q+ I1 R# P/ ]
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe- e" z% T& d7 r+ y1 g0 @5 _
C:\WINDOWS\system32\dla\tfswctrl.exe
/ X* D* v& Q# H' k4 S) x8 j+ |; yC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
. z* L* k Z$ m; p; [C:\IBMTOOLS\UTILS\ibmprc.exe
. I: t+ z3 j2 R( w- {C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
; i0 B2 d5 |& O3 F B& f& r3 o6 z% |C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE4 L- p7 d" x0 ?% n/ {5 N
C:\WINDOWS\System32\svchost.exe7 s0 l' P( C# a5 ~& _" ^% M
C:\WINDOWS\system32\rundll32.exe& P/ l) y" z, A, W
C:\Program Files\F-Secure\Common\FSM32.EXE
/ G/ X% j" s8 ` t: n7 O7 h( U# WC:\WINDOWS\system32\CTFMON.EXE9 Z7 O9 G- ~& W6 ]
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe3 _/ t& h4 ?% \3 }! N! \
C:\Program Files\Digital Line Detect\DLG.exe; L6 Y5 p% p) R; h2 f: q
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe) Y! m; N8 w4 w2 L
C:\Program Files\F-Secure\FSGUI\fsguidll.exe# S8 c& Y! v$ y8 u
C:\Program Files\Messenger\msmsgs.exe
9 R4 f m) D, t4 Q% AC:\Program Files\Internet Explorer\iexplore.exe
0 L. j# v2 }! l5 V" P, cC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe% l7 Z9 j+ g) _5 n
0 t4 B9 {- h" M/ h/ X& AO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
3 {& E ~ L j( D/ A( @O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
. L; |5 j% i- r- cO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe' z3 ^ e0 s) b" t
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe9 Y8 W7 X/ W/ s
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe5 f1 l, G* A: `- n! P
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
! k! r- T1 K8 `5 W8 b5 w7 ~O4 - HKLM\..\Run: [TpShocks] TpShocks.exe, @6 i! Z0 B9 E! a1 `# C; x0 C$ M9 B+ [
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
; C; n- |% D( X( F( c! K# B- ?O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
3 ~* h# m' ]0 |) _O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
; d. F l" y' b% V! D' ^8 BO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
. d, R4 C# l0 n. \( w& `O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe3 f4 c4 b0 }5 R; } Z+ v
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray& x$ J1 w" w) b1 B5 @
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
- X$ l6 o6 o; B! t6 WO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
) P; B* a6 H) R; eO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
! j# W% ^2 N9 v5 C( E3 [' P# VO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe g+ n5 l' }8 V5 x z2 [1 r h
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE( [& U8 }$ i, G _0 O- p
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
( e( u" A- {; o9 [. y5 H+ ]O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor' |9 |7 [6 `5 ?
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
: [( f* E* p- u3 ^' ~O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration325 q# ?, ?! s g
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
: ~; C7 ~' _, z DO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
# L( w. u& O4 Z+ f6 y2 V% [# `. dO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC% a6 o! ]4 K" E3 j) ~
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName- h7 _5 |" K" L
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash, }) f2 w& S( {( g S( ^8 A4 |" X
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
* E) d% M- u( [: X* y7 y& M; MO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe+ k$ d: I; i8 C1 \
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
0 Z/ m7 X7 W$ W* SO4 - Global Startup: Digital Line Detect.lnk = ?
u: E* x4 g; a5 oO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe3 V& Y7 M! `- P$ Y1 s' u- i
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
2 `( q p& b3 {! g5 R, I$ ?O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
7 q( l- k- z. Z/ x4 f/ xO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll4 h9 [/ w/ _; } m" l0 Y
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll, c4 F0 U. B4 q$ i, ]
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll1 v: a4 j N/ q7 k( K4 f, {9 k
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
. h/ l y/ Y5 R$ ?. r& MO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
- q$ F. h7 T% M8 t+ [1 e1 ?O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe9 w* R G. c5 G5 y
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll% f4 Z+ S2 e, \% C
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll& {5 P; i: K) v1 }! F
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
- r. Y" w; H. q, K$ pO11 - Options group: [JAVA_IBM] Java (IBM)7 o* G* m' J8 v4 L+ P
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
/ _1 R; ~, B8 d: x' aO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll1 z8 C3 A+ X4 X6 @
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
- s) S0 o1 s6 h" x' V# X" g% CO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
# B+ N3 c* }6 o" Z( u8 qO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE% E6 e1 z& V: O4 ^' q9 y7 M
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe6 [0 V+ l' B4 w3 ^" Y
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
4 z' F% r. H* a2 k8 \O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
/ Y! T, W2 a8 p7 S0 d+ m& {- ?. uO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe9 u! \9 }/ j: H( ^
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
+ R# `: H8 g! q# Z$ J$ zO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE/ B/ _4 r4 r/ Y) y u+ D2 U
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe' V. Z. S0 ]0 V5 S! \# {# z# M- o
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
$ q& H' ]- R0 T4 QO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
5 p+ {3 _+ K; q- P2 H/ |; z- bO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
' ~6 S% X' M' m. G" x8 w7 j* zO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE/ }1 {9 ]2 ~5 }: ~5 X m
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe1 I* `+ a$ [) w( G+ k6 \
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe1 B8 B! a4 M5 O' h8 d- d- ]' k
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe* U8 x3 j- x4 U; d: M/ |# p) F1 `) q
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
1 b; w5 I l* C( \4 n. jO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe! e. |9 _2 f0 q* E0 E% `+ R
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|