 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
0 B- R: k' N8 k& r; v9 D5 mScan saved at 16:55:24, on 2006-5-61 F, k& C5 f' B
Platform: Windows XP SP2 (WinNT 5.01.2600)
3 i/ T6 n: ^9 P: |MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)6 ]8 ^; j/ d3 @) G
3 {* r6 m( Y6 G" e& E; l' G% JRunning processes:
$ T) a% o* ~0 Z/ B2 d* SC:\WINDOWS\System32\smss.exe
, a4 ~# O9 M* \, a+ t0 {* L' GC:\WINDOWS\system32\winlogon.exe% M+ c% U8 G# [% a# u+ K
C:\WINDOWS\system32\services.exe8 u3 C3 ~* \% U# r6 K D
C:\WINDOWS\system32\lsass.exe/ y' Z% ^; E$ L- j
C:\Program Files\Common Files\Virtual Token\vtserver.exe
7 q" J/ t7 z$ l. F/ x+ a# v IC:\WINDOWS\system32\ibmpmsvc.exe
! t/ L. u: l7 S3 m) WC:\WINDOWS\system32\svchost.exe6 p5 k; H, `2 T! n3 f
C:\WINDOWS\System32\svchost.exe
# |+ h8 g6 ~$ k8 S" `& A- sC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
& \9 @1 a, r& j# zC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
) L0 W: Q7 A/ R( TC:\WINDOWS\system32\spoolsv.exe. Q( R, C3 B8 @: h0 k( V1 M
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE6 G5 d' V# o9 z- Q) D
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe8 V2 V: F& F2 N
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe$ e& B$ B; F" j) k% b6 _6 L! O9 L. Z
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
/ |% K) J2 H4 v2 E" p' N! w' }C:\Program Files\F-Secure\Common\FSMA32.EXE
" Y% T/ r5 V3 UC:\Program Files\F-Secure\Common\FSMB32.EXE
% w% D/ W' J- T4 ~0 qC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
0 O" k, O2 m" r _C:\Program Files\F-Secure\Anti-Virus\fssm32.exe) f, h! k6 g1 e y5 Z/ k
C:\WINDOWS\System32\QCONSVC.EXE
8 m& z8 D) k0 \9 h/ t" XC:\Program Files\F-Secure\Common\FCH32.EXE- I3 S4 J! u" n5 w: o
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe' }0 h4 v5 x. Q$ E# U3 C
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
7 w0 E) Q( j' FC:\WINDOWS\System32\TPHDEXLG.EXE7 j% W. p1 z* X$ E
C:\Program Files\F-Secure\Common\FAMEH32.EXE- [, q3 |! ~# |8 C: ^
C:\WINDOWS\system32\TpKmpSVC.exe
+ o3 S+ N" t8 v Y; ` H. x5 hC:\Program Files\F-Secure\Anti-Virus\fsqh.exe3 m7 T9 F$ j: A0 D/ E
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
+ y2 d# V: { F& [2 t5 P/ }C:\Program Files\F-Secure\Common\FNRB32.EXE
9 u% d, {# v7 l3 O9 FC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
& X, j/ R" {2 H0 MC:\Program Files\F-Secure\Common\FIH32.EXE
( m* U; Z ?: X( Z$ B2 {7 \) qC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
' }/ O+ A) |+ a7 hC:\WINDOWS\Explorer.EXE
( w i [. I# @( e8 u8 w% CC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
5 c0 k+ D' n: @* N$ {4 o3 V8 h. jC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
- C. Y( b- v- kC:\WINDOWS\system32\hkcmd.exe
4 |0 n- R) B3 eC:\WINDOWS\system32\TpShocks.exe& U7 L' d9 S9 L. h. \% S
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe) F1 |5 T- g( q( Q7 N
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
4 H" r" }8 w cC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe" o- q0 a8 L) v1 G+ a) Z0 L
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
% ^% W k9 x9 j% A; F: gC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe# R( g3 ^# N5 h
C:\WINDOWS\system32\dla\tfswctrl.exe
) M% b# ^, c) h( p) F& g* r% bC:\Program Files\IBM\Messages By IBM\ibmmessages.exe& V5 y5 K6 I; d4 f8 _; J
C:\IBMTOOLS\UTILS\ibmprc.exe- Q2 n4 [1 w6 y% y, E
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
% B9 g! m; e$ r9 d" w6 L) UC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE1 A( \" I8 \# g) @( v2 U3 U
C:\WINDOWS\System32\svchost.exe
2 _4 \6 x) F+ r) G3 j4 s0 T, |6 G3 iC:\WINDOWS\system32\rundll32.exe
# F8 V1 K6 y# MC:\Program Files\F-Secure\Common\FSM32.EXE& _; ^, I' j2 M5 _: H
C:\WINDOWS\system32\CTFMON.EXE
8 ~ d2 F8 P8 z9 P. U6 |6 nC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
% O# {- |( m& sC:\Program Files\Digital Line Detect\DLG.exe
0 Z) U- n, G; A+ wC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
: s6 K4 F4 q/ V/ @# d+ A$ TC:\Program Files\F-Secure\FSGUI\fsguidll.exe! i( ?6 u6 s! ^: }$ K
C:\Program Files\Messenger\msmsgs.exe4 ^8 ^' z- T: Y7 y+ P
C:\Program Files\Internet Explorer\iexplore.exe
M8 I9 L: B. Q* N& T. sC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
6 j" p8 Z1 e" {7 [' v7 g, g) r4 ]3 I+ w7 O* }# W, E4 t
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
, C, ?# X$ X7 \2 |O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
0 X$ x7 ^# U8 f3 LO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe5 @5 e7 Q. k0 g: L7 \
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
9 I% m I1 w$ T( p$ y: BO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe4 [+ a' T) S I2 D, |" Y. L, o
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
2 E! @1 E/ j: A, k3 vO4 - HKLM\..\Run: [TpShocks] TpShocks.exe# U: x4 B9 h0 W- ?; t& D
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
! m' N& q( T, }' Z$ VO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup. H. k1 C: M1 j+ Z* f
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
y7 q3 p7 g0 z" CO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
0 a% L1 J# {/ z8 Y6 c; X3 UO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
( y& k4 B$ w& ZO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
( M8 Z% f# U6 b; lO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r) A% g' I: i) Y( Q& V# ~9 [
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
; L+ E8 K, N. M; d5 L5 }O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe" U4 t' ^& p8 W! ], l
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
% b/ |4 I1 h6 q) NO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE7 N& ]% h$ {0 y# f
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
3 [2 n+ Z: `3 r) ?- i3 a( dO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
, r- t9 m: r$ }; Z7 H3 PO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
/ S3 R8 |- p# V5 S2 dO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32" B# H# H. Q! j4 Z D0 N
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE( e" t0 J) l. l8 Y9 {
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
) a$ t9 p8 T+ e6 j% @O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC7 N5 T% S. I7 P0 R1 ]+ E) m7 L
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
- f! m+ K5 A& u7 o; r& ~) n9 NO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash% k+ t2 \* V, b( F2 F
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
' T9 X) n5 C" Y0 R9 b7 B) Q- kO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
9 Y+ r5 z5 V2 N7 B+ mO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe' Z! m0 e3 F# m( k' T4 C$ c
O4 - Global Startup: Digital Line Detect.lnk = ?% _* W- Y1 v9 R" G& k9 A
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe- G% k6 L+ [6 l7 Q# \' E8 B4 G% ]
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
& _5 W' V% P/ D* L7 ]O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll8 w, Z2 H. ~( e9 i# R5 _9 e* Z
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll5 s9 y2 }: R( s: f- E
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll: g4 p) N: [% v' ]1 ] K* v
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll; ^- t L( V7 L& s# ^0 S& i
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
* `9 }9 P- H+ T" Y0 X) }# |6 OO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe& ?% R$ m3 L, Q% ~' e( c
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
' _* e( i) a! I4 n CO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll% d& Z% @3 r d3 r R
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll5 e+ r s8 [# a# m: I
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
% V1 u/ ?' Y5 xO11 - Options group: [JAVA_IBM] Java (IBM)7 _1 {" i& c' c6 k3 e/ R4 F5 y
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
4 d' k0 ], o+ r' f4 i% jO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll% z4 ^1 V' R1 h: [% V% p9 L- y
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll9 ?* z0 X6 s. q
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll. x: d% H) R# i* } z
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
3 y% V5 D9 `3 d! RO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe& R* @7 N. C0 g5 J& f
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe4 k+ Y: m1 p! S, R& n
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
- ^, `/ E8 B {/ i% ]) h4 @O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe6 Q. ] T% [8 g3 H0 s8 q6 h
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe# A4 {; Y: T* U' Q3 R* A$ N
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
7 G: W3 X+ n; P$ l6 hO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
" p& Y7 l5 [' V0 s1 B% t$ l. @O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
; @3 G. X! r' ^2 \3 IO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe$ P9 m3 b# z+ w0 |2 C8 E# r) j3 `
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
7 x0 }* f* N7 E: E+ A# I6 X: N( H1 xO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE7 o+ k: q* F* N6 {. E2 `$ V
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe0 c" w/ U, I. _7 T7 J
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe! ?; v' q4 R3 I3 D9 Z7 f9 }
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe8 ]: E7 y8 W1 ?; L# W3 v
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
1 d' q8 I! o+ YO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe- N# _' |6 ?3 b4 W" W9 j m
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|