 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
- J" [$ Z- E6 m, X/ t qScan saved at 16:55:24, on 2006-5-6( L& A9 @7 s' X- h6 m( k! t+ n
Platform: Windows XP SP2 (WinNT 5.01.2600)+ n7 V& ]2 p) s. e& I1 }6 u. l
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)1 Y% a5 |- w9 t' b
. Q7 x/ a) Q- @' R8 f L7 ~4 |Running processes:4 Z: ~. s2 M! l1 z: p
C:\WINDOWS\System32\smss.exe
2 I, k; s) i# E" y# `C:\WINDOWS\system32\winlogon.exe
+ f& ^" m3 I0 l( k4 c1 u5 F" ^1 bC:\WINDOWS\system32\services.exe
. d) M" U* g7 ?; BC:\WINDOWS\system32\lsass.exe) b/ J7 _0 ^- l8 p9 U" I
C:\Program Files\Common Files\Virtual Token\vtserver.exe
( J# z$ x s( `$ k3 dC:\WINDOWS\system32\ibmpmsvc.exe
! i3 D5 N2 i: z8 }0 H* `3 {$ d: |C:\WINDOWS\system32\svchost.exe3 O3 T. Y: J7 @/ U4 B4 f
C:\WINDOWS\System32\svchost.exe
! D; b/ x) a9 B% j+ C) R1 |C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
i$ |+ L/ U" ^ H6 |6 Q+ eC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe9 \ M5 h3 a4 i. {) {# b/ d
C:\WINDOWS\system32\spoolsv.exe) j: a3 L' h# H; M s
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE$ H' y' E1 o9 W0 p7 _2 ?! q
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
+ i) s: a9 s5 f$ ]2 m. `! cC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
& n5 D$ I. F& D! R/ Q: ]C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
7 v9 |: ^1 |9 i" Z- TC:\Program Files\F-Secure\Common\FSMA32.EXE
* K# u) z A4 i9 i ^C:\Program Files\F-Secure\Common\FSMB32.EXE7 B( X9 Y$ x" W
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe* b& p0 d- r2 ]# q- t4 I b1 l' ?
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
+ }: B7 c; ]) L7 q& |- VC:\WINDOWS\System32\QCONSVC.EXE. y/ e! Y( U; O; t
C:\Program Files\F-Secure\Common\FCH32.EXE
7 P% d" z- o& MC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe, ]0 ^7 h0 \( i" v4 L& q
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
. F6 x+ i1 {% V4 _% R g' z) r2 A& tC:\WINDOWS\System32\TPHDEXLG.EXE2 W0 o" L0 e% z3 x$ [
C:\Program Files\F-Secure\Common\FAMEH32.EXE7 s' F, q6 L+ ~
C:\WINDOWS\system32\TpKmpSVC.exe- R( m" X$ F3 ?* v5 ?6 M6 x
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
6 ~. E# \' m% [) M$ \2 iC:\Program Files\F-Secure\Anti-Virus\fsrw.exe; M) K2 u Z H m
C:\Program Files\F-Secure\Common\FNRB32.EXE
9 r' T- e# ^$ }' S" ?+ }3 S3 g5 @C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe/ e/ Z7 q4 y' q4 G' p
C:\Program Files\F-Secure\Common\FIH32.EXE R2 U! t5 Y# s9 X
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe8 R3 n- R' t: Q, }) a
C:\WINDOWS\Explorer.EXE4 `( B$ R7 q- u
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe. s6 `! `1 G G# u" U$ z. U
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
4 t" X3 T5 Q$ dC:\WINDOWS\system32\hkcmd.exe
8 f' M& C9 }# {) ^0 ~+ j$ `C:\WINDOWS\system32\TpShocks.exe
! B1 O5 T- Q. N/ I2 w' VC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
* ~: J* U% z7 h4 ?' Y6 V: g: d- IC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
2 \* p: n, u) R& ]2 B' {C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe& ]6 T1 s2 e$ ]$ T
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe( Y* H. j/ b0 ]- j! a1 |6 j4 \
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe% U( B* Y6 L' M
C:\WINDOWS\system32\dla\tfswctrl.exe
/ L; N5 r: H. {( ]% Q6 y+ oC:\Program Files\IBM\Messages By IBM\ibmmessages.exe& S+ W7 K4 j O3 B7 N q
C:\IBMTOOLS\UTILS\ibmprc.exe
, K* ~4 @% v6 _/ S6 g5 C( a- @C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
0 \% g8 b0 F) ~: U5 `1 a2 L7 TC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE7 { H* n2 h# ~2 B; r3 c$ y
C:\WINDOWS\System32\svchost.exe
+ i. c( k1 A% r0 j. p* b0 wC:\WINDOWS\system32\rundll32.exe
: P& @1 K! i9 \C:\Program Files\F-Secure\Common\FSM32.EXE
- F3 x2 a; k1 z8 B3 MC:\WINDOWS\system32\CTFMON.EXE
: W; a. a7 B! h/ }# u5 LC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
M N4 B* K& G a* uC:\Program Files\Digital Line Detect\DLG.exe
0 ^, `9 t/ H- W+ e0 D6 k/ dC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe1 c/ t4 b6 ~' G+ Q9 v
C:\Program Files\F-Secure\FSGUI\fsguidll.exe5 S) h/ ]! K: F V' f8 N
C:\Program Files\Messenger\msmsgs.exe( q& d, h7 c; C( `3 Q/ u1 z9 S* c
C:\Program Files\Internet Explorer\iexplore.exe5 A! |- U- M: o
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe8 L; Y- }6 t/ n! A6 S. V
( S- A1 D& M$ z5 u) o( r) [O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
" N2 @3 z1 ]# ?. W0 g+ EO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe/ ]; I% ~7 p" D
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
( o+ B" p8 n4 G- ]% G/ I( NO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
. L2 h8 \7 h; u: E9 nO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
. S* `( j$ @& o/ X* T/ XO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
9 ?' E$ R" g. i( `5 IO4 - HKLM\..\Run: [TpShocks] TpShocks.exe) |% C: i$ j# W. n& w! C& v
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe4 ]5 g+ `' Q9 u7 J( u5 p
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
& L/ Z3 k9 O. y4 r% @1 hO4 - HKLM\..\Run: [TP4EX] tp4ex.exe1 f& G' N: _$ K/ w" _
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe3 w) U" n* `* l- M0 P
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe& [7 g6 f( ~1 @* g' q% X! D
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray1 c9 k% X' x6 j$ X& [
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
0 K3 P( y" R+ U# i6 `" B6 Q/ WO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe- G: h2 x9 W" d, L& |9 L: W+ n5 i5 r
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe4 J4 w0 Y9 a# I: f% m7 b* H
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe% x+ ^8 U+ e& b# ~0 c
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE# ^. I/ P9 L, H7 n0 _
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE; {0 e) k* p9 w# O
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor& B2 ?2 b+ N* d% m
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog7 {7 Y3 Z! J7 t+ I3 B, [* w/ k
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration329 h7 x7 D/ K/ I7 ~6 }8 {
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
; ^2 a$ q1 b) z& L/ |! uO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
. S0 V% F# \. l8 \O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
) X& q5 W% ^- {( [1 b! w; {- oO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
$ ^+ }* h/ H1 _O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
* J( |! P5 r$ ~( H7 s2 E; dO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW5 U0 f9 I$ t, z' m+ j
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
3 _8 j8 T3 c. A- H* u/ qO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
# t' s. v* c) j6 X' X: T8 }& @O4 - Global Startup: Digital Line Detect.lnk = ?
. I7 z6 R7 Z& ^O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
* t( a2 m+ i" V4 ZO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm: Z4 L& C k) Z1 s: T' ~/ u5 B
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
; A+ V B4 S4 }9 u& M4 DO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
' f6 P' B8 D$ h& }' N7 UO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll9 G+ L, \; {9 J3 t2 {
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
7 V: J. Z# _7 l2 _# L& nO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe2 h) `. n2 b+ V% Q
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
C- l8 @* c2 ~: wO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe- K- g$ `7 x. ]3 T% D6 {3 |7 @
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
% M7 l4 O- \* d( s, hO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
' H$ V/ Z: }2 ]5 s7 c$ {4 E$ xO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll3 Z' n1 A, |+ C! e4 L
O11 - Options group: [JAVA_IBM] Java (IBM)
& V, f( ^' O+ r0 mO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll l: b7 }6 G8 E' r) A% l
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll8 e7 E+ S0 o- | ^3 o
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
7 g/ S7 ^% P& Z( TO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
5 n( k/ j7 c! E7 D, j, rO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
( r U z n0 x. y" m5 O8 yO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
: }4 ^6 x/ Z) e# dO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
; L4 {6 n8 Y+ U fO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
6 \+ d' |/ \1 N- OO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe3 v) j; `/ |, P" R
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe, L. k i3 p: S+ [; `0 R0 [* G3 R
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
* J% `, L8 w4 K$ f) |$ \O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
+ f5 f' O9 h# A: ~7 `O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
& }' t6 D* b$ a5 _' ]" SO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
5 C L& J9 N( DO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
( B3 [5 I! Y. ]9 u$ p' sO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
5 b7 a6 e a9 V" Z/ P! f) K$ w) R- aO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
$ B. P- v5 b! _O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
" g0 s* g2 Z+ _2 a5 HO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
9 R8 T, T, r6 i+ eO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
$ f2 @: F; g3 W' BO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
@3 W6 @2 d7 |! g8 F% U7 yO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|