 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
3 j) d/ d( [8 ]Scan saved at 16:55:24, on 2006-5-6$ w4 b3 F- b6 B6 d4 Q: }5 U
Platform: Windows XP SP2 (WinNT 5.01.2600)
5 O( N2 A3 h& P* z f/ K, cMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180), h I9 n' C/ g( Z" X! Q! V
+ L$ U q) \- K2 P4 bRunning processes:2 G& u3 A$ g/ l$ O1 E2 e
C:\WINDOWS\System32\smss.exe
5 w8 M, }+ d/ X. T2 Y2 o) XC:\WINDOWS\system32\winlogon.exe
4 F" v8 O: e9 gC:\WINDOWS\system32\services.exe
- t& g/ f9 ~& _" J: m: L$ e, dC:\WINDOWS\system32\lsass.exe) r. Y2 ?- u, I) T" s- c1 Y# D1 A) g ^8 f
C:\Program Files\Common Files\Virtual Token\vtserver.exe
0 {6 X+ n# f% m7 Z& Q0 j2 JC:\WINDOWS\system32\ibmpmsvc.exe9 y* v8 |/ P6 M4 j4 p) F
C:\WINDOWS\system32\svchost.exe$ v! |0 Y, F) K+ y
C:\WINDOWS\System32\svchost.exe. I+ C- l7 {# a' x
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe- y! B! W G; a5 E9 c. [
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe y) w1 H! ?* B- y! J
C:\WINDOWS\system32\spoolsv.exe
@" q' s! L+ d+ O) W* TC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
0 z0 _: R. v, l* h- vC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
; T1 H0 l% b( S+ ~2 [5 WC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
9 n. |6 r( C: o- G Z. l2 N' rC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE/ a4 u. ?2 Z* o K% E4 N
C:\Program Files\F-Secure\Common\FSMA32.EXE5 W. C _1 @/ ?* I( v
C:\Program Files\F-Secure\Common\FSMB32.EXE
4 N5 {9 \0 v1 i% xC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe5 w/ B& r+ m% m8 ?( Y. g8 C
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe/ y% U- L; C h( j7 b+ D
C:\WINDOWS\System32\QCONSVC.EXE
( h6 {* g% j4 E2 \) _% oC:\Program Files\F-Secure\Common\FCH32.EXE( i1 G! h8 x; b5 c/ M
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
$ p* \9 t8 e; _; H% y# [C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe ^7 X: g0 |, i1 t& K4 }
C:\WINDOWS\System32\TPHDEXLG.EXE
2 v+ i p$ s5 J9 v! mC:\Program Files\F-Secure\Common\FAMEH32.EXE7 F Z" K8 C# L* @: `5 N1 {
C:\WINDOWS\system32\TpKmpSVC.exe
" Z" e7 {/ {' e. c) N* D0 n1 FC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
" S* j' `' {3 s0 A6 `C:\Program Files\F-Secure\Anti-Virus\fsrw.exe& x6 Q" r$ C! m
C:\Program Files\F-Secure\Common\FNRB32.EXE4 y0 n5 y) Y. m) R
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
( T1 G9 r0 p2 X. ^1 [; v) c( OC:\Program Files\F-Secure\Common\FIH32.EXE
; |- {/ h$ b2 H4 N# v9 ZC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
* z6 z3 k+ _# t( K2 }6 |' a) K1 IC:\WINDOWS\Explorer.EXE
$ W; ]6 n- |3 x' n' M5 ]% WC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
. [& @6 b9 n. Z# V1 F6 j$ F& vC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3 c4 e, j, Y. N- K- E6 EC:\WINDOWS\system32\hkcmd.exe
" T6 e% o3 q) ^& S6 v2 FC:\WINDOWS\system32\TpShocks.exe# ^0 N! I' K9 N" V9 @
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
+ ]" r. H5 z2 V/ M6 U* g; p* EC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe7 { V' Q+ p+ N
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe+ ~6 l \2 S2 K
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
g1 g( n( ~ F. o; KC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
4 c$ ?; y5 T0 N( ~; x! ZC:\WINDOWS\system32\dla\tfswctrl.exe
^& Q9 J" K n O, _C:\Program Files\IBM\Messages By IBM\ibmmessages.exe7 k, N: t: o% E- o
C:\IBMTOOLS\UTILS\ibmprc.exe6 A' V/ q$ [' N# z
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
& G* e: W4 g+ |$ d, bC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
3 l% u9 k: A) QC:\WINDOWS\System32\svchost.exe6 k0 R. `0 u- [0 s0 _
C:\WINDOWS\system32\rundll32.exe
( \/ e; q" j) p2 aC:\Program Files\F-Secure\Common\FSM32.EXE
& f# r3 j% D& EC:\WINDOWS\system32\CTFMON.EXE* I' d; X) K1 ^7 r$ J# F) \0 H
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
6 E n' `6 ]" H$ a& WC:\Program Files\Digital Line Detect\DLG.exe0 Q; N1 K$ }9 P4 a
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe! {! G, p6 w) @0 O! Z: v' Q
C:\Program Files\F-Secure\FSGUI\fsguidll.exe/ J* t4 g, I/ M1 g
C:\Program Files\Messenger\msmsgs.exe
! }" q% r. I5 O: D4 r, a! v) FC:\Program Files\Internet Explorer\iexplore.exe' K3 K1 W) k' b# E [( b6 z* a4 }
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe/ J* K( c! I ~3 \0 p) S
3 [0 @& W5 w8 Q2 u( e6 {# d: w' KO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll+ v& U- b( m7 K+ x* T
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe5 l) Q) r2 X# E( I
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe1 M* v" Y/ K9 R, |1 n( r) O5 K
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe: ?9 n K, A8 E. r1 ?8 d# @9 {
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
5 m9 D x# a6 b8 eO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper( B3 C' c( ?" i- b' v# F( }
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe' q* s$ a- Q) E( h* ?( D0 T
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe4 }% Q& f, T, k' M P! p
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup/ ?+ R1 O+ n* r+ n5 }' y: F
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe. \0 M5 J8 V' m8 k5 n4 z! Y) }# {
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe% y: Q! G( A$ A( u) F! q
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
& O1 P; _4 R) b; | UO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
9 ]$ W3 I: `# f9 U b3 y2 U+ P/ LO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r- F' x6 V7 P7 t; n. h. Y
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe7 X i5 u% i# X$ Z1 `- j3 G
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe; O3 z4 k' ]) T
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe, ?( I9 k8 G& m6 @9 ~
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE0 X8 T4 L& r, R' ^
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE( p; P4 h, B& X% ?1 m0 _2 W d
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
4 X \: Y5 ]% f4 E( e, b6 RO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog0 V. ]2 n1 C+ P- M, e4 u! ?
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration324 y* C+ d1 t7 n4 l. G2 ?; A
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
; ^* w- o, f2 D) wO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC- q. {* O% ~" E0 Y, u5 l$ V, E
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC% p8 b) L- A2 q0 r
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
3 B8 i& Y4 E# vO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash3 V8 J3 E1 |0 A% P, }8 J
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW6 P' ~! ?4 F3 f/ s' i N
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe# Z" I4 o4 @ D1 `( R4 r }/ E( m( D" c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe4 B! h# f7 G; R; {8 g- P) a
O4 - Global Startup: Digital Line Detect.lnk = ?
# Y. X3 i! ]- I3 o6 k0 nO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe# Y) ^- k" l, m. z0 a
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
! a+ v! a7 b. n# e+ |, d, mO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll3 S7 d: B4 A5 `) f) W3 ?: g
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
" g6 l; i/ p. B0 q( ]O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll, s# F3 }% \5 g
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
: y7 g# o$ D2 G$ j7 dO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
: M) Z9 C) R/ p4 CO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe& U2 O- P. T6 u$ P
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
9 L& O8 D$ Z9 |O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll" V* _, E2 i3 U
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll2 g4 Y* G* @; A$ {7 j( |8 l `8 l
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
8 b$ K9 b9 p/ A$ YO11 - Options group: [JAVA_IBM] Java (IBM)
* I' d9 j2 M" d. o: K4 p% JO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
4 V8 w' q c" DO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
% [1 D0 K3 [$ Q# {& ^* w- t1 oO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
; ] S3 Y- I/ R z/ Z' EO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
; C6 O% K& Q; x3 R7 }* XO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE) }3 b8 f- V' o& e7 B
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
8 Q2 [/ e3 v2 o) ~$ [( y6 wO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
& D8 n8 H( e1 \* UO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE$ u6 O- N2 Y1 {& n
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe; n" e" V& ?* I7 n" w, n
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
" y& X1 Z+ W' F. B* `; Q. S9 n: HO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE" r0 i* q! p2 A6 o* H( R0 e
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe* U6 Y& r& |% ]% u6 E% u
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
, O( O& J" ]1 R! m: gO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe' @) [3 o, \/ n# |
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
% Q) z; m7 } a4 Y. RO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE9 ~8 `6 D4 ]4 W3 ]6 U! M: j q
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
8 W0 n2 F0 u: \2 x- GO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe& _- k+ m( y0 g/ u. @
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
9 G% e5 I& I( F4 tO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE; r, C' O0 W( U/ `- }
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe% b& S( z+ k6 J2 C" z
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|