 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
& e4 a: Z- v- j+ n+ wScan saved at 16:55:24, on 2006-5-63 \! o# K& T5 J$ L
Platform: Windows XP SP2 (WinNT 5.01.2600)
B6 l+ B: G7 Q% @MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)0 b E" c: \8 y$ F/ u" g! y
1 n* b, x2 G; _6 @
Running processes:' u8 i4 ]2 A$ l, _2 a; O
C:\WINDOWS\System32\smss.exe
* B7 W; C" ~+ I8 ]$ a' }C:\WINDOWS\system32\winlogon.exe
6 X: j; o* B; m6 S8 z1 ^1 b+ _C:\WINDOWS\system32\services.exe
" u; _; c6 H U. K# s9 ]: Q1 tC:\WINDOWS\system32\lsass.exe
: G* ]4 p4 v1 c( \; n1 DC:\Program Files\Common Files\Virtual Token\vtserver.exe r& N$ n8 g) l+ o( Q
C:\WINDOWS\system32\ibmpmsvc.exe7 c7 |' W) e% d* @2 O* d
C:\WINDOWS\system32\svchost.exe* ]$ o+ n+ X4 H
C:\WINDOWS\System32\svchost.exe& U6 O7 D. d, z8 ^0 ]
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
9 g: J9 K7 n4 G( j7 ~; z: nC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe8 @. h0 B, G" w+ W" t Z2 j7 Z& e
C:\WINDOWS\system32\spoolsv.exe
/ Y5 v) x% z$ S2 w( h5 y9 [C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
$ g4 d# \/ k2 `$ O( [+ [C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe$ p" n$ P' y; l1 w, ?: y
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe7 n! Y2 t1 F" k* [0 P
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
& `; w: D l+ s$ i4 G. OC:\Program Files\F-Secure\Common\FSMA32.EXE
$ R' [' L1 ^: {+ |6 u. I/ iC:\Program Files\F-Secure\Common\FSMB32.EXE
7 D w/ ~" ~$ `* b0 w. K8 S* RC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe* x2 N* l) h+ g! }% z$ \ ^
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
% o) `, B* [ I% q; ^C:\WINDOWS\System32\QCONSVC.EXE
' f) e! @% o9 b3 s! o6 ]2 CC:\Program Files\F-Secure\Common\FCH32.EXE; r7 j" m# Y% c( y
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe/ @& ~ T4 C4 u
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe* E) j4 H% S8 l5 s* \5 G: e
C:\WINDOWS\System32\TPHDEXLG.EXE
8 ^4 ^1 r6 B) O# S1 w( K: CC:\Program Files\F-Secure\Common\FAMEH32.EXE% L' Y# a2 P: ~8 c; g+ ^8 @: b
C:\WINDOWS\system32\TpKmpSVC.exe
' m* Z ?: [( T" K3 K, EC:\Program Files\F-Secure\Anti-Virus\fsqh.exe* [& j! K K5 O6 S, w
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
" u" o9 Q* Z/ f6 x3 k, g% k5 v0 EC:\Program Files\F-Secure\Common\FNRB32.EXE; ]+ A& f9 M& }
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
! ~. O; T2 _( q+ rC:\Program Files\F-Secure\Common\FIH32.EXE& c; r% \5 R, i
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
3 o" [# H/ {! N, V- K4 G* [C:\WINDOWS\Explorer.EXE! c+ r/ D2 `( X0 Y8 N
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe( j, r, x. q$ o8 b. P6 }2 b; ^$ g) R
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe0 ?+ E, ^* F9 _: m, e, p* z1 p8 _
C:\WINDOWS\system32\hkcmd.exe
% {: ^/ `4 g! B: k% vC:\WINDOWS\system32\TpShocks.exe2 S1 i9 ]- M o8 k, ^8 z$ m
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe0 r/ ^* b! h1 D7 M! R! u* R7 p3 K
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe6 z1 ~, s q- o4 S& q- @/ W
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
3 P% B& i1 f# L- o h6 }+ pC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
$ ]2 m- m0 _6 s h$ NC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe% v( d! S# i' x; @; s
C:\WINDOWS\system32\dla\tfswctrl.exe
! j5 s9 A% D$ T8 _* p( ?4 I8 H: j" O' JC:\Program Files\IBM\Messages By IBM\ibmmessages.exe% Z: W2 v2 ]: \! ^
C:\IBMTOOLS\UTILS\ibmprc.exe& ^/ K/ A6 V9 W9 t% [- g
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
3 I' H/ B4 K, S! CC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
! H0 V' ?. y5 _) `C:\WINDOWS\System32\svchost.exe+ _' D0 K" W" B1 U" O0 C8 w
C:\WINDOWS\system32\rundll32.exe' m6 \4 r* r" j2 F* Q
C:\Program Files\F-Secure\Common\FSM32.EXE u' ]# ?' O* \ b
C:\WINDOWS\system32\CTFMON.EXE: M! d2 P" d7 k4 L; o
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
& N: E" k" d% U$ o3 _" \' `C:\Program Files\Digital Line Detect\DLG.exe
z9 H3 g0 S+ M9 B" f1 F& O# X4 l+ ~C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
' ?5 Z$ n- N, V# qC:\Program Files\F-Secure\FSGUI\fsguidll.exe
3 O+ r r* t: v7 bC:\Program Files\Messenger\msmsgs.exe+ c& R% v: o8 F; e) y
C:\Program Files\Internet Explorer\iexplore.exe6 C& ]: W: e7 q
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
5 i& d# I. x5 r$ M; {4 t5 [* U) U8 a9 i$ S, Q
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
5 F! i1 t+ O2 F6 Y" C9 Y, B8 Q2 W% zO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
2 l1 C$ _% [3 Z/ j- ZO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
# }% s" ^! W$ t5 `7 m% \: S DO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
, a( o. y% K, ^2 b$ o Z4 M7 {O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
6 M" g1 m8 h r# wO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
9 W, ^8 j2 Y" }$ O4 |) J _O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
2 m$ S! c6 P2 S4 ?1 Z: f$ N8 bO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
* M: y; m% U+ B: [: G' WO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
- O" P" O: ]7 r" |1 F1 T, oO4 - HKLM\..\Run: [TP4EX] tp4ex.exe
& s6 g# E8 V' XO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe7 v+ L; ]) M8 F2 }3 } C- F0 q
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" V' r C6 B& T. _
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray3 g' v! K$ F1 j: _2 _+ P
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
0 m9 Y7 x! X+ e/ {* A/ V+ JO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
* v2 `& _" j: R. H. M5 FO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe: `( Y& R7 k; a7 s' s4 I7 ]
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
- B b4 x: O1 Z* U# nO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
! k* ?5 j* ^. z2 W6 T3 v, KO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
5 Z9 u2 ?1 i4 n$ I1 X) b% r9 RO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor. a+ E' |# O& G
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
" J* l) E! G& @9 C2 q7 M- n" kO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32$ v" V+ c* ^" b6 Y6 M. N
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
( Z: @4 C& v0 }O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
0 P2 v1 H2 f& g! |, r% MO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC- V% G4 \8 [# N6 X$ }5 n2 P
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
: m% t1 ]1 F0 Q4 D( rO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
\) c8 d( e# D, x8 {3 zO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW5 T5 G; I$ j2 ~ y V5 s8 q
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe5 Q z& V( v( V; ]* c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe" }. j( o y4 x6 ]# v7 j& q
O4 - Global Startup: Digital Line Detect.lnk = ?1 T1 l4 v4 N6 a e, h( X* v
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
: o7 _: h9 k. pO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm' @8 S8 k: W/ K, s/ P
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll0 R6 {. u6 v/ P2 x& S
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
# ]$ a9 a: E' ~ l a( rO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll; z9 c) q0 ]. z) z; N( \
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
# W' ]& K5 I+ RO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
1 M( E# c9 o- C8 k2 w+ B# SO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe0 O. S' k7 e$ V/ L6 [3 F# T
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe0 o( T y) d( E5 ?* @, S0 _4 L9 [
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
) v( Z% H9 p `( P. FO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
& d6 S, V/ J& }# F* c- m7 lO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
$ }/ R8 W3 L1 N9 I2 IO11 - Options group: [JAVA_IBM] Java (IBM)- N: ^2 O) X w. `6 R" ~1 u
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
# O& M! l0 `" \7 X( g5 AO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll4 x! x" _2 n+ F9 [) Y! N: |
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
+ O* b g5 T9 JO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll9 j F6 k5 g( R" j5 u
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE3 y# I4 g3 d7 [- i; A0 R/ b
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
% K V9 c7 O7 E/ }O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
9 |0 K) v: C YO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
7 H5 P0 s) i& G7 IO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
% p% s* R# V6 @O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe7 ~/ ]) q7 R, V! ]( W
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE- }4 [ s$ T; h8 S& Q' V
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
6 N; B }" C& K1 _* v, {( yO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe- L: Y4 `; |# X P# C; S
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
3 x6 V/ L8 }5 B0 Z) O! XO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)- M( I2 f3 ^0 q% S4 ~% \5 d
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
* N6 Y- |* o' z/ v- cO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe' _# v0 T. l/ f* c7 G$ {
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe$ r# t5 `% [$ _ P! s! x
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
8 _7 d" v0 S3 Z& k- S3 w* l kO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE- ~( ^% H# F3 p! y' U. d |
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
' J4 A! \6 _: [! d1 n# q3 x% n' yO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|