 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
9 O `9 x8 l' r/ MScan saved at 16:55:24, on 2006-5-64 u& e, j% h8 i1 Q
Platform: Windows XP SP2 (WinNT 5.01.2600)
6 S, K7 G, A3 s2 N* S& |, z BMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180), Z- T, f0 I& M0 M; `8 ]. z- h
. y. W. Z) h: L5 CRunning processes:$ W$ b# h3 v! h- s& g. v" }
C:\WINDOWS\System32\smss.exe( W q5 g& D' V, F Y n
C:\WINDOWS\system32\winlogon.exe
6 _7 J' N; @' E" O& CC:\WINDOWS\system32\services.exe1 o3 K" B6 P+ \& p6 g8 l, i
C:\WINDOWS\system32\lsass.exe' ]: t: \! f1 s G3 Y! j
C:\Program Files\Common Files\Virtual Token\vtserver.exe% y `/ _0 |. L$ r- G
C:\WINDOWS\system32\ibmpmsvc.exe* c! t" M) ?8 ?3 T
C:\WINDOWS\system32\svchost.exe
; U' p1 g& \- E4 P, eC:\WINDOWS\System32\svchost.exe' T0 }2 m+ C+ M" }3 L
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe: J* o8 p7 j% C; K( N
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe/ y7 J) Z( ^: |% H- C
C:\WINDOWS\system32\spoolsv.exe% l/ z5 t( k& E. H! t5 t' h& y: v
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE }2 ^) P Q1 e: E6 O Y M' }
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
/ e8 B& T/ T9 p2 F; m) RC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe& O7 N. i3 n- {& ~' }6 t m
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
4 ]2 }* \+ V+ d% i; ]0 EC:\Program Files\F-Secure\Common\FSMA32.EXE
& u+ n3 e; ^5 E3 Q7 V. n. o! ?# p- A+ PC:\Program Files\F-Secure\Common\FSMB32.EXE' |0 g" _# T: x
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
8 u7 p" H; S, C/ S- yC:\Program Files\F-Secure\Anti-Virus\fssm32.exe* ~0 _+ ~9 G' T- O
C:\WINDOWS\System32\QCONSVC.EXE
8 b3 F# a& m/ s/ Z7 cC:\Program Files\F-Secure\Common\FCH32.EXE; m7 C& q+ k! u( z
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
' g) s* y. ]3 }+ u1 b! {C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
2 C' c- l8 |: K8 n) r$ J9 x8 TC:\WINDOWS\System32\TPHDEXLG.EXE
4 e Y, {3 S9 T5 D0 Y. l s# uC:\Program Files\F-Secure\Common\FAMEH32.EXE1 \4 E" ^+ ?) Y9 V
C:\WINDOWS\system32\TpKmpSVC.exe- `+ B' J" ?6 D" K% c; R9 T
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
. U7 h: D$ I0 |5 p/ @+ rC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
/ @9 t. i& v; B& JC:\Program Files\F-Secure\Common\FNRB32.EXE
' ^1 _3 ]" v( g+ xC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe* [1 n$ U) w3 r6 K$ \
C:\Program Files\F-Secure\Common\FIH32.EXE& e# Y# W( k$ E# l, v I
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
+ R6 y4 O! ]! {2 }/ e* D: i% W5 s- tC:\WINDOWS\Explorer.EXE
8 ~* G9 ]. o# ~* J! `: Z7 \C:\Program Files\Synaptics\SynTP\SynTPLpr.exe, S$ o6 I, {) R, U
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
6 b, @4 a8 S: l9 f1 p! IC:\WINDOWS\system32\hkcmd.exe
) e. \& ^, Y- X- [C:\WINDOWS\system32\TpShocks.exe
6 s! P1 N9 |- j9 J$ m K( r; QC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe1 S6 _* o* z& m8 M1 o
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
" o3 f; M* B1 h* aC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
" }. _! X) O8 ]1 R( u: oC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
' X, J$ r$ R, [/ IC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe7 e# w, j% ]3 s' _4 h& S% ~! H
C:\WINDOWS\system32\dla\tfswctrl.exe/ C$ r5 I* G: m1 O) ^
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
, l$ G2 n, g# X: B$ h+ IC:\IBMTOOLS\UTILS\ibmprc.exe
& g' [- K) Q+ {1 L+ I0 vC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
& J0 B% Z/ n8 v$ K* DC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
0 P' E% L" ~% C0 I- {( u* zC:\WINDOWS\System32\svchost.exe+ P* v2 E* {1 d4 z
C:\WINDOWS\system32\rundll32.exe7 m% d. j4 R$ G: X
C:\Program Files\F-Secure\Common\FSM32.EXE; z7 o% @6 T- _5 O2 O2 a8 I
C:\WINDOWS\system32\CTFMON.EXE
9 [$ O3 V% f% o6 p5 ~2 H8 G, T$ PC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe! a4 w' h) K/ B3 _& ~
C:\Program Files\Digital Line Detect\DLG.exe! j) G( ?/ r1 A4 _ A2 w
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
. A" A. r# z* [C:\Program Files\F-Secure\FSGUI\fsguidll.exe$ z% G8 l& u% L8 L. m2 W- L/ }
C:\Program Files\Messenger\msmsgs.exe
& S" r% @' u! a, r+ RC:\Program Files\Internet Explorer\iexplore.exe
" t) R1 A7 i, _3 vC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe3 l( q) T& q) p! C. {
3 M$ G+ b& n0 s9 X7 R. S% @& C; p
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
/ P @, ?4 P9 E0 @$ Y1 EO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe/ |& w2 T9 F) N! m8 X; i c* R0 c
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
6 m+ R5 S8 } C/ C0 {- rO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe: s1 r3 v4 c9 T1 c+ B7 r& A
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
7 h& a" R" n9 FO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper* `8 _( o$ q! R T
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe8 t0 @& W" x0 K, L
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
/ |5 s+ T2 @# v: L( p5 [O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup/ o% l0 a- z1 z9 M, e
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
3 a5 g6 Q% d2 `# c3 x3 zO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
8 ?2 D. u0 S) n2 `O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe- ]: L1 [' ]: F% o
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
$ S% A9 t4 E5 R5 T& t$ H& sO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r% L/ H+ w& [; K T1 {
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe/ h: W4 O+ |& r: M" N8 D2 z' b* w
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
" B# J& ~' n2 b' J7 \# _O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
% _8 I% ^1 U3 O! J4 T4 t; FO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
: h' C, H& s0 G7 v; s4 xO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
% z+ I# e3 P( G/ v! i; U0 P GO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor) p$ ]5 r4 E+ a5 `. j
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
' m- {1 S; r9 J5 TO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32$ F) _' m: }, [: ?. S. z! O+ g
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE2 X0 p9 O/ m8 P3 [, V* Q% D
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC& u9 f6 O* U, G
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC+ T' I' w& N: c; [/ l9 V
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
* s, ?6 k& N' X* SO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash, o! f$ E0 d3 \* [# s+ F7 i. @
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
) G: l4 h$ ~/ v6 Q1 t) i* t! R+ _O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe! Y3 h2 E8 _. W2 {3 N
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
# ]% x+ ]( v: M8 U; r. WO4 - Global Startup: Digital Line Detect.lnk = ?
. x9 \. v: l* L+ ]' M( Z3 f& YO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe* W! Y+ A% Z# T% I) F7 P
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm6 m+ y% P- W% ^* a4 A' y% R
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll: {( Z5 X& O6 L3 a. d5 p6 Z
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
1 u; Z* t g' d' a+ JO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
0 X) f. N4 z+ A: U! T5 YO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll: j+ l" L6 ^: e9 a
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe# [. J" ?! P, H1 V: P8 D
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
4 j0 |- z& p* E1 wO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
9 n! A3 h, r/ m' a# l$ w& W" R& V! ZO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll$ T2 M5 X4 p. J+ E/ T& {+ L, }- T
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll. p9 W7 R4 J7 T2 }( y
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll+ q: \: F# j/ l& @
O11 - Options group: [JAVA_IBM] Java (IBM); W+ x( F: X- L% [, m
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll# m1 u0 Y. r. {9 q; S& [: t
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
, f [6 e+ U* d5 T1 T% AO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll6 U! D' y% d4 D
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
7 t! t0 K6 L5 S+ j5 kO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE0 y, Y+ V2 o9 i. R8 P Y
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe+ F% H) Q. E9 G3 h( e
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
; d+ [# v/ u% ?! `0 L& mO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE* ^( l, T! o# f$ S4 ^$ b+ E
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe# f9 Y4 L; v% ~2 G" H6 g+ Z2 R4 j
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
; w) M8 z5 j) L' wO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE+ [9 H) {1 E; {0 I' d' ?4 C
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
; y* V0 l" J' XO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
& L. S, R- U- B! N ~( p/ v oO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
2 I6 u4 A' F$ U& U0 A, w6 Q- iO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
8 n9 N& j) G: w& A) v9 a% W( ^O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
5 Y; _& {; x8 f/ ?; CO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe4 A9 t% A4 H5 E2 C6 u0 u; H+ O4 Q8 g
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
2 U4 a" G; Z' e0 b. NO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe3 a6 x% d4 q" j" j6 ^9 `7 z' R
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
$ b9 B; n; X- F% ]O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe8 r4 y( V& }/ `0 a
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|