 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
" b' q4 Q1 \) y5 XScan saved at 16:55:24, on 2006-5-64 R9 e; Y3 S; Q3 f* ]* I
Platform: Windows XP SP2 (WinNT 5.01.2600)
% q8 ~! S# S: ]. L' t" PMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)3 z1 `* @# M3 J! }1 K
6 Q$ X V3 t7 t# sRunning processes:
* f F8 X; [: d+ X. fC:\WINDOWS\System32\smss.exe+ P: D& R/ T; }2 q9 |. r! o; y
C:\WINDOWS\system32\winlogon.exe
; e$ U' }, x8 D* cC:\WINDOWS\system32\services.exe
8 c$ [8 f: \9 }7 [5 |3 BC:\WINDOWS\system32\lsass.exe
- l) @ N6 P, e s0 Q2 n- {C:\Program Files\Common Files\Virtual Token\vtserver.exe! C! M' j( n. M0 I! E: _, |
C:\WINDOWS\system32\ibmpmsvc.exe
6 k& s" W0 u, @) lC:\WINDOWS\system32\svchost.exe
, Q+ x1 C: Y5 R3 T" S# OC:\WINDOWS\System32\svchost.exe$ K+ T7 g, E/ Y
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe1 s3 |4 g9 [' M3 E; z
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
. F& @0 w6 H8 {1 G9 iC:\WINDOWS\system32\spoolsv.exe
3 \) V. h; ]# ~/ g. KC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE, J" g9 t: P# l! m- `! p
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe' ]- f% M4 w" I- z" l$ I
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
" i$ j$ W% g9 E7 iC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE7 S/ x. r8 g! `* v7 K: H, ~
C:\Program Files\F-Secure\Common\FSMA32.EXE; C: i4 f6 W6 g% a# Z
C:\Program Files\F-Secure\Common\FSMB32.EXE' j8 g& d+ H1 W6 z, g1 e2 [
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe# _' e0 c* T- m1 C
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe p" T6 f8 R- a" g1 q1 U. m
C:\WINDOWS\System32\QCONSVC.EXE
# [3 T+ G5 ]( a% CC:\Program Files\F-Secure\Common\FCH32.EXE
9 E, ^- _- n' z% F0 UC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe& ?1 m1 m, W* `+ n1 x% c4 Q- r
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
. C% z. }4 w0 c7 ]' y) eC:\WINDOWS\System32\TPHDEXLG.EXE
7 C% J' ?! h2 d$ m0 xC:\Program Files\F-Secure\Common\FAMEH32.EXE; [& r h. P! _- s( X2 I& F/ C
C:\WINDOWS\system32\TpKmpSVC.exe
1 R7 q7 w" y+ EC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
. }! K# ]! m! U5 _5 O: PC:\Program Files\F-Secure\Anti-Virus\fsrw.exe1 F! p5 i K1 H8 }
C:\Program Files\F-Secure\Common\FNRB32.EXE
3 N8 P% b! ~* x. `, l' bC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe6 y/ ^; B$ Y$ z
C:\Program Files\F-Secure\Common\FIH32.EXE- g3 L) N$ ?& G, X! S- x' y
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe' i/ t! F F6 `4 P4 }) \; C4 S/ f
C:\WINDOWS\Explorer.EXE
0 h1 f& e$ }1 Q2 Q) C; E8 SC:\Program Files\Synaptics\SynTP\SynTPLpr.exe6 I0 A$ ?# \6 S, q& P+ J. G# n% J
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe/ K0 V4 v4 E% f7 n
C:\WINDOWS\system32\hkcmd.exe
9 M# Y* o4 ^0 k, Q& R/ U: WC:\WINDOWS\system32\TpShocks.exe ~+ n9 ?) @. k Z- J* n" A
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
; G- M3 G" {# q% f2 ?C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe) `0 W7 s; R% K( t q& a, o
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
7 w$ D; F1 d% q: D! t* AC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe2 j. H9 s6 r5 R8 j3 x
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
5 d; u1 Y) E& l' R: S- m! k' EC:\WINDOWS\system32\dla\tfswctrl.exe! H5 k# p5 M. f" A7 N1 t9 I: x
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
. L5 P0 E3 U+ g' lC:\IBMTOOLS\UTILS\ibmprc.exe9 Y" Z1 }$ `1 ?1 n
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
& W/ j4 ~) Y# cC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
6 W7 w, N2 T; j/ i; r a% cC:\WINDOWS\System32\svchost.exe+ g- _6 f m1 [; U, D6 t6 k
C:\WINDOWS\system32\rundll32.exe
% I! [+ F+ R& g7 Z# HC:\Program Files\F-Secure\Common\FSM32.EXE% \& I+ Z+ g% c% I; Y
C:\WINDOWS\system32\CTFMON.EXE& G ~, K- {$ X1 ]. I( g
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
2 R' w! y$ \3 X0 m8 S# SC:\Program Files\Digital Line Detect\DLG.exe4 v- L) {0 w; ?: c
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe* ?4 N6 z; H9 @/ f' e9 z
C:\Program Files\F-Secure\FSGUI\fsguidll.exe4 V1 a {+ @& n2 D: E. n% R
C:\Program Files\Messenger\msmsgs.exe
( S; [% U3 C! BC:\Program Files\Internet Explorer\iexplore.exe
1 o- r! Q# b2 \C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe# K r" K5 F+ b, z. `. p7 z
5 m" V z( q8 O
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll; S0 k. G4 |+ ?9 \
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe/ U4 g8 c/ {7 ?; q
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe/ A" ?$ j( S. [( z0 R
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
" R' y: [3 W! N% y8 HO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe/ T8 X! y" |; P% a, T, g
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
; Q1 I4 o, u2 M* l* F7 \# a5 UO4 - HKLM\..\Run: [TpShocks] TpShocks.exe# ?' U6 j- ], J2 J, q! A
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" H! X- J9 L2 R8 G
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup/ {8 p3 V+ `/ Z7 [* X
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
. w& T3 Q* G) I/ l( l" JO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
* y5 |0 u- [" _: F3 }O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe8 N" F: C- y/ k( _0 f" A O
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray4 ~- X( o2 T. v6 z
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
% x" i* Q2 ?6 g4 ^2 v, L' }* ~O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe2 D% j( o6 E" P2 Q! T& R$ v$ n' q
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe9 c+ ]6 [: C1 B: d5 b1 \5 j
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe1 K; j2 A F4 I0 J+ _
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
# Z$ q c+ I% t5 |' A* K% nO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE) u# S! V7 l' ^+ D# e% |
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor4 `( C: f" ]7 s7 x# p
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
6 A# e( @4 i1 m& [/ O, s$ _& KO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
3 [; ~* b9 C4 j6 L$ fO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
' f _8 _0 e) A3 X# D4 C. Z2 oO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC3 s ?) [# S8 D" ?! u, b
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
b2 }% B) \" G& V7 w0 Q; _0 JO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName, E+ d# T0 A; J9 F
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash5 a6 w; J% p- a5 p: s8 |
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW& R) W/ W/ H8 N! c
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
9 @' e4 y9 k- E6 vO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe9 i& j4 L0 \* J [. P
O4 - Global Startup: Digital Line Detect.lnk = ?
0 u" C) k) P( h" V$ W3 t6 }O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe7 x( V8 w& C5 b8 F" n3 i H
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
) s9 a0 S1 u: ?. K! MO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
8 [2 e' r/ h) P7 [1 S8 SO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
5 {7 P" @# u) O8 q/ {2 E qO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
8 a+ `- Q4 w/ \4 n9 aO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll$ _( m" @$ y" i3 J, W- s3 x# i" P0 X
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
9 ?" g+ H7 A- PO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
+ w) S ^' S# W! K5 W3 d# JO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe( b' S/ M) T r0 y& f6 y
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
! ?- T( |5 f' ]/ [# g1 B/ vO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll( |/ J- ]/ l# [% q2 u4 C( B* V
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll" @. p8 x; E4 ?4 f( M, k
O11 - Options group: [JAVA_IBM] Java (IBM)
& D( k, P* S) p6 T$ eO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll. h1 q: u v, W$ N5 b2 E. O/ R, [
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll4 M' t. t8 O- ]9 t( W
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
1 ~; B ?1 E( V, FO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
/ s+ P( L9 C0 ?- F) c* sO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE9 a" Q/ ]& Z/ U
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe1 c7 ?% j" W4 t* m" B
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe" I8 a+ `+ S2 ]! g% Z0 j
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
4 b, ], B! p. B; bO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
6 L8 O$ x8 T2 bO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe ~( S# d* ^% o/ q7 A2 F
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE2 A% Z1 H2 J% I7 L8 `+ l
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
3 T. @2 B1 t) qO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe: |' u' M* ^& B$ B: {0 ^+ M* R
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe8 @' t8 U+ d. E$ }0 [9 `9 i/ z3 D+ y+ u
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
0 h/ @, S. t& K" a* H+ jO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
j' V2 n$ u7 K1 }* zO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe U' \$ W0 W% w
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe: J3 k; w! b0 i3 D
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
' B' h5 x7 w. eO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
5 E. G8 P* ?% F3 _) S; F' aO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe9 V3 L! H- B$ Z o+ o! o
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|