 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
1 _( P/ J( u0 rScan saved at 16:55:24, on 2006-5-6/ v# W _ O$ k# |; ?$ l( X2 f
Platform: Windows XP SP2 (WinNT 5.01.2600)
. Z" v7 {+ b. }1 n$ }) S! `MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
9 @, \7 l# o0 M+ x, j) Z" m7 a. z0 G- B' B" d Y, x* w0 T8 @% Q
Running processes:
5 \+ U3 d1 l; Q- p! `) mC:\WINDOWS\System32\smss.exe
! \: s; \; Z: V. }$ H, B, cC:\WINDOWS\system32\winlogon.exe
" q( |3 h% a* k& m L; ]$ DC:\WINDOWS\system32\services.exe9 R: ]0 f6 U0 |+ B- I) o e& I
C:\WINDOWS\system32\lsass.exe2 b, V, \4 J/ }1 O5 i4 p
C:\Program Files\Common Files\Virtual Token\vtserver.exe( _4 a1 e/ L3 R% E( w5 {
C:\WINDOWS\system32\ibmpmsvc.exe9 q+ A, X+ ~6 o# A6 E
C:\WINDOWS\system32\svchost.exe
/ k& o$ s2 S% K E# X& J \$ |" nC:\WINDOWS\System32\svchost.exe
7 j0 ^/ E5 C, T4 n' C1 yC:\Program Files\Intel\Wireless\Bin\EvtEng.exe* y8 m/ [5 ~& J
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
; E1 @4 Z' {0 l! ^7 IC:\WINDOWS\system32\spoolsv.exe8 @/ s# A; b1 k- f
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
2 S* n$ F8 F2 a) FC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
8 R8 v9 M* Q8 W+ H5 a8 Y3 u7 HC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe( ^" m+ t2 \* L- r
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE+ {. \$ ]- r% M0 Y; ]( m% h
C:\Program Files\F-Secure\Common\FSMA32.EXE
; ]6 h6 N0 q0 U2 C. o h# [+ ZC:\Program Files\F-Secure\Common\FSMB32.EXE5 A& e( i7 Q L3 }; j
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
9 C$ R, L6 ^0 e1 QC:\Program Files\F-Secure\Anti-Virus\fssm32.exe
& P; T* m- M. V, iC:\WINDOWS\System32\QCONSVC.EXE' m; D7 L' @5 ^2 ]0 c4 m) `8 [
C:\Program Files\F-Secure\Common\FCH32.EXE
8 s: \+ Y. N) T1 o) pC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
( k. N- Y9 A7 f! o# m" PC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe8 ]: k3 X* W0 C# W( R
C:\WINDOWS\System32\TPHDEXLG.EXE) i! d2 n. E N3 T& T
C:\Program Files\F-Secure\Common\FAMEH32.EXE
: R# C3 y! y) [) X6 i& r& C5 cC:\WINDOWS\system32\TpKmpSVC.exe$ l7 N, O3 C' @ ^ X
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe# t" O: f, k/ W
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe- p+ d+ p" z$ g9 J% g7 @5 \
C:\Program Files\F-Secure\Common\FNRB32.EXE: u3 y; \2 y; \2 k y7 a) Z- D
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe& q. `4 v) k9 i- A' ^
C:\Program Files\F-Secure\Common\FIH32.EXE
/ z n) u' q# ZC:\Program Files\F-Secure\Anti-Virus\fsav32.exe; A2 }7 h; E) m) g3 @% l
C:\WINDOWS\Explorer.EXE
) `* X7 s' |- b' ^% G) m& JC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
7 _* R) h2 ^+ ~, n/ v" oC:\Program Files\Synaptics\SynTP\SynTPEnh.exe' Q$ S2 t: \, P5 u
C:\WINDOWS\system32\hkcmd.exe
9 y5 `, ]( B9 ]' |+ T5 NC:\WINDOWS\system32\TpShocks.exe2 q% K! q! o/ w
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe( X: u k! A6 a# R1 \( g: B, B! I
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe4 {* j2 e8 Q# P. h. _* g, B
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
+ `: _5 z1 ~! b+ K1 k, a0 rC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
1 J, c, K& T) ^( E1 ?C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
, K; F$ H4 z$ e5 `! |C:\WINDOWS\system32\dla\tfswctrl.exe/ T' k* S f# M! Y% f
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe' i# X; t* ^7 N# g6 e& }( g' b
C:\IBMTOOLS\UTILS\ibmprc.exe
+ }( M- a9 W% q' ?: ~5 h) Y2 H8 ^# jC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE0 G2 [1 @9 I, p. h9 R0 V: w" e
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
: z3 q: ?9 q) f) b; YC:\WINDOWS\System32\svchost.exe9 p$ Q. y4 @ Q
C:\WINDOWS\system32\rundll32.exe/ }: W; o6 { d3 A+ d
C:\Program Files\F-Secure\Common\FSM32.EXE
) C. f3 k+ e7 h. ?* n+ CC:\WINDOWS\system32\CTFMON.EXE& b: @, O% ~! C. H. \
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
9 j1 p* h: A; _; wC:\Program Files\Digital Line Detect\DLG.exe2 ^3 N V% x8 G4 r# @1 j- P" b# X
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
# K6 `. c4 i: @2 S% M$ d9 FC:\Program Files\F-Secure\FSGUI\fsguidll.exe
6 U! Q" t/ ^8 P7 yC:\Program Files\Messenger\msmsgs.exe
' P" c2 D3 X! KC:\Program Files\Internet Explorer\iexplore.exe2 h0 w5 _: s0 y$ W2 {
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
. O# H, W5 u# s- H/ L. H' x# g+ b$ L9 O
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll8 O) N6 q4 ^4 T: d
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
8 ^, I( u- ]% Y$ L5 Y; K& i( p9 U# R! lO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
% `/ Y" k0 k4 r( I6 c- K& c1 [O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
. q2 |( a2 [( z/ ?6 U( aO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
8 b4 }" z. h+ ZO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper2 l$ n( x7 q4 b4 y# d
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
/ U& W2 G: C& IO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe4 ~. r2 Q" \. ~: i3 |
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup d5 \2 z; s& ^: ?6 @. @+ g
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe% f3 a. X7 U( g+ |. |8 N2 G
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe Y7 B* W$ V' n
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
* \! [1 i, K4 ] \O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
6 I6 `% U0 X) B' |1 kO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
- `9 n( ^" m- o- u1 ?' QO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
8 g8 x X( d& f6 f, rO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
% Q7 A2 _! u1 y; AO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
; }: M) H4 V3 ZO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
! {% w8 H6 z2 Q( N- zO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE0 ]" ?1 m$ K' f, C: b% y
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor* c" j+ T- ~$ q4 W7 j# a+ F
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
: N! @ I6 W3 fO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32( O: m/ X, ?7 h( N- ~6 O4 z* {
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE% ~, M n' D4 \2 c* }6 w/ a1 W
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
* H: }+ b' |& {9 C9 F- v! B" fO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
9 Y- B$ |3 D" [; AO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName6 B% f2 G# w9 w- h9 O+ N
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
j6 O" u: \+ |* L8 x$ PO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW+ Z/ N8 Y4 a/ T5 u; c, l ?
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe5 f" c9 q m' m9 n! G: @! q% G
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe3 b4 P+ ^6 F, z+ M. a+ Z2 ` I
O4 - Global Startup: Digital Line Detect.lnk = ?
+ i8 D. ~: r7 rO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
. c4 o8 t7 F7 J- {& h% Q3 }; MO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
% Z) G o5 i$ {! W- ]( r/ D4 a# @O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
; W2 B% G2 ^. r/ T9 O: |* |O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll' m: m/ {; C' X3 x/ i9 q7 m
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll+ w% v% f |3 J. k% g) `
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll/ J5 c) C/ ~( Q. F
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
# g; Q5 C. X( QO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe( L$ P3 H" I, n, a
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
% w) M3 C& G/ C1 \' v4 A: uO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
2 P$ |" Y3 D' s! bO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
- \: u$ A% U( Z" f4 r) A' S* H0 RO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll C8 P8 s* a P5 s w, e
O11 - Options group: [JAVA_IBM] Java (IBM)3 _ r3 X( `" O7 r( {* J
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll6 _0 d. w2 J8 _% K+ c" r( K3 A
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll2 b- S( j2 n0 I0 [! |* @
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
K8 |' z1 M: v' k" K" yO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
1 Z) l0 E/ U4 Z; A( gO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
1 d! z* s/ F" [O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe5 w) {* A3 G' p# D4 q0 L
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe2 A( G; E, O) [) k' S
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
* ]! U. p, a; c2 t E: M, t. U9 v7 vO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
" I3 O& e6 d4 n( P1 gO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
8 d* I; m% V- a6 AO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
# |6 i1 s2 G- b: p1 uO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe. B; [1 v. v4 \% [4 O6 s
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
3 B/ X* y& i+ P& m( MO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe/ C3 C5 K9 d5 M! P; n9 Y8 W. X
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
6 p; G& M$ d. n9 I/ Y0 {! @4 e! d& d% kO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE2 ]7 l) j" e& K- f+ t
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe/ M0 |- R( d n8 W7 A
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
g( Y$ Q# l5 m3 C9 Z- KO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe4 D. B( p. q: _( ~' F) W* [
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE, E5 f* b) o) R9 }. L
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe/ n+ x5 F$ S: p, d8 Q
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|