 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
# b! h L* c1 r( OScan saved at 16:55:24, on 2006-5-6
4 F" k! n K1 L/ @# i9 |5 K, nPlatform: Windows XP SP2 (WinNT 5.01.2600)+ j3 h8 m' O, v/ w! j
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
2 ^5 g* y @- ?6 _# |" U( m/ M% t0 b. g! e0 G
Running processes:
6 j) d. n7 q$ Y7 B" H2 W0 dC:\WINDOWS\System32\smss.exe
s2 _9 Q% p' DC:\WINDOWS\system32\winlogon.exe
. _8 l$ M9 ?5 I% H& ?6 qC:\WINDOWS\system32\services.exe
2 [7 n! s, E* P3 N. j# aC:\WINDOWS\system32\lsass.exe% T6 j, Z+ y, G/ u2 ~. f+ h, y
C:\Program Files\Common Files\Virtual Token\vtserver.exe+ Q( Y& ^+ q5 o4 z; E. n. t
C:\WINDOWS\system32\ibmpmsvc.exe4 z' U8 N! } t9 g1 T
C:\WINDOWS\system32\svchost.exe% P' _1 m1 S7 ?8 W$ @- W
C:\WINDOWS\System32\svchost.exe
; ]. c+ M/ ~+ yC:\Program Files\Intel\Wireless\Bin\EvtEng.exe! z/ P9 @1 u6 J( c1 A2 e; J% A3 a
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
& l0 }0 [# Q @! |C:\WINDOWS\system32\spoolsv.exe t9 f0 A1 H- V: t
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
% Z& l, N3 y- R' |; mC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
7 M. v/ C8 [+ J7 M" C5 R* z5 z) ~C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe2 k0 u& N$ _. c2 w3 ~0 Y
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
/ i' m, C) K& S' Q2 b& a% nC:\Program Files\F-Secure\Common\FSMA32.EXE
) ]; V+ O1 s7 b) D) `C:\Program Files\F-Secure\Common\FSMB32.EXE" f1 h l4 R# m0 _/ T. n! w& a
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe+ X6 U; u4 T. b
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
5 d& y5 c: d. u& F9 G% I! eC:\WINDOWS\System32\QCONSVC.EXE
4 H( c3 p# c6 D1 Y% L) {C:\Program Files\F-Secure\Common\FCH32.EXE
2 h/ w2 J* ?" A' TC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
. X1 y7 s- T+ A* a( o$ KC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe; t# w5 F$ b& I8 t* n! E( f/ b, N
C:\WINDOWS\System32\TPHDEXLG.EXE
0 g* h0 A! R; I( i; |: r( J$ a1 _C:\Program Files\F-Secure\Common\FAMEH32.EXE
" k5 U5 }9 n+ X) G8 RC:\WINDOWS\system32\TpKmpSVC.exe
( Q4 {/ X- {- rC:\Program Files\F-Secure\Anti-Virus\fsqh.exe5 b2 b" S& o8 A
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
6 f2 A' M7 H6 t) R. X! T' {0 ?. L3 [C:\Program Files\F-Secure\Common\FNRB32.EXE' s G3 ~5 m3 j, i
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe$ Q7 V0 K! B$ O- G, s. Y' X5 F3 ]9 R
C:\Program Files\F-Secure\Common\FIH32.EXE
' c4 b4 R8 f7 T/ D4 [' UC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
# B% p; Y: V- h* N4 i! R4 O7 j- xC:\WINDOWS\Explorer.EXE
' Z1 `4 S( D& o" H: ~$ A b* B! h4 \C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
- a8 o2 W) f" d" B/ cC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
4 T+ H3 a2 o8 T, n+ o" d LC:\WINDOWS\system32\hkcmd.exe5 ]- u. O. v8 O. V6 X/ S1 T7 ~
C:\WINDOWS\system32\TpShocks.exe3 d( L4 }% L: ?! q S
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
+ \# z0 z% |; `6 O: V, t e- nC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
; p% M/ r# i; G& l9 P; l+ FC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe' U( Q9 F& t! Q1 a# N
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
9 a5 T+ b/ m" X- j* N/ vC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
. W! M& ] R g. j1 ^! yC:\WINDOWS\system32\dla\tfswctrl.exe+ y1 R- f2 J# J/ Y d! n* x2 A0 M
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe. }6 n* E* |# |8 V$ K
C:\IBMTOOLS\UTILS\ibmprc.exe, t. {" s. ?$ @, j
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
+ t$ V% L0 v+ ~) H" CC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE5 x% Z% f* F1 R% h
C:\WINDOWS\System32\svchost.exe& L4 D9 E: f" `' K
C:\WINDOWS\system32\rundll32.exe
# z0 o% V2 K7 l. K: o1 EC:\Program Files\F-Secure\Common\FSM32.EXE
- v1 `& {" v4 xC:\WINDOWS\system32\CTFMON.EXE
+ ]7 `7 v5 s" h0 s! _! LC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe" z3 I: e: x! |8 d$ ~* J) Y
C:\Program Files\Digital Line Detect\DLG.exe7 T! d: J6 s+ Z) a# T, G7 V
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
4 g% G9 G4 V2 o. A3 L8 ?C:\Program Files\F-Secure\FSGUI\fsguidll.exe# Y* c/ i1 e4 V1 F
C:\Program Files\Messenger\msmsgs.exe
9 j, A1 D( n" Z) L. l. IC:\Program Files\Internet Explorer\iexplore.exe
7 |2 i, \$ X2 ]2 J6 z1 hC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe5 i" c; |6 ^% d1 m# O" q/ l+ R
4 x0 `3 `" v9 O; @, V
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
1 e2 Q0 S2 p; L6 W! ~- p9 ?O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe0 @6 N9 Y! a6 L+ u, `5 d7 w$ o
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe2 _+ c d6 f6 E6 K
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe- R7 H* @. l6 S2 F+ T2 X% w" d
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
, \: w( x2 |# YO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
' y- b4 P r* TO4 - HKLM\..\Run: [TpShocks] TpShocks.exe. g4 k7 B) X/ b, k
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
4 k+ a( ]* H1 D; ZO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
; b9 U0 D8 N) V2 M/ V8 @O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
- g+ O5 S- V- o7 j* A' I, ^) j: vO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
8 ~ f1 D) T4 t2 A$ aO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
5 X5 W! c4 x% j6 M( d1 |4 @& MO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
" i7 s* M& m1 \) F7 @, x8 W( ZO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
% X' S7 d& J# @. w5 |7 _O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
! p: Y4 R4 [/ u( ~O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe: t7 u( V" f% W9 G# {' N( Z
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe4 F; t3 Q2 F6 x5 z
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE/ y/ t3 D, H8 z
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
6 J$ P# i& `, F/ hO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor' ]0 S6 H Q* ^8 c1 X0 J
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog( ^9 m# {5 Z0 |' a6 V
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration320 T5 |) r% Z+ K4 R9 T8 H7 J
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE+ s; f/ p: s1 H. K8 ~( h& M
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
% I, a+ x/ o& j8 _- N3 e6 p K" rO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC b( Z! b4 {, I% t+ s0 g* h" ]
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
" Z, w, ]# ?# [; ?5 @O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
* s6 M+ |# l- C- z* Y% a' a7 kO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
) ]" M$ e3 M* d! M4 f6 |& W8 k3 @O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe |8 E( W4 f+ f
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
. Y( a8 p6 O% q8 }4 jO4 - Global Startup: Digital Line Detect.lnk = ?
' l; f2 w! g$ p( ]2 [- H! sO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
4 v A5 `% {. U( UO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm/ a: `! ?$ R! ^) L
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll- w- [. \& G' M
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll/ n% p+ R2 }: b( T! r- i
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll; ]8 G" F8 j1 t3 v
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll6 R& j0 n) b: U% T' N$ ?
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe8 P4 N! u( s+ `" |
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
3 e7 @% Y2 d7 @7 t; {" a# fO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
& L& q8 d) j E& E8 ^) `7 `O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll% F: T+ f/ s! B" ^& j# N. e o
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
+ ^8 J4 [" \4 m5 HO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll9 R6 b* Y( x% D; p* Z
O11 - Options group: [JAVA_IBM] Java (IBM)
3 Q6 E* ~6 o2 [, i" W# `O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll: x+ T7 y$ K1 q4 S; f) l8 O
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll1 I# r( U* z" N7 ^) X
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll2 F; C5 @( P; X. W# w6 Q
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll/ _) r' R3 P9 J2 Y+ L4 Y
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE8 F- Z0 d# Z6 L8 M9 W
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
- o G) F! }1 m; O6 q& }O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
3 ^9 H- }3 c2 I' o! NO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
4 Y9 P( M% _5 V* }O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
! H7 t$ Y4 c3 j2 pO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe8 v% L# d0 M/ J" @" X; ]
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE2 n! C7 Y: Q% P7 @1 |. c# N
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe# j$ w% q6 e" Q- K% J
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe5 _7 z$ I, c t- |7 U# V" D
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
- X. H0 k8 k7 TO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
- x3 y. B# e, ~/ d4 Y+ q* n* ?O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE9 \2 i6 A0 S3 |" V6 \( r; U( L. E
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
& [8 q% |' f QO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
0 R" T4 J5 p1 nO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
! f1 P5 \ l+ b% G. k- o1 }, t, ^0 GO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
$ ^$ k, d3 i$ E) T1 E8 g* eO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe6 `# N/ B, G' S) s' Z4 \2 |1 n
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|