 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1* I" f, b" Z) _7 C+ x: F
Scan saved at 16:55:24, on 2006-5-6! E4 i0 i9 h, O" k" f2 u
Platform: Windows XP SP2 (WinNT 5.01.2600)
/ t) p& r4 L' j$ {MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)* K/ @) Q1 ]* ]' k- f
0 s0 c6 X3 m/ B2 F
Running processes:
4 D6 i1 l' }/ y M% o. X+ ?C:\WINDOWS\System32\smss.exe
1 ?8 w; N* |" k! oC:\WINDOWS\system32\winlogon.exe$ i/ j9 g4 E4 p4 K3 X0 r
C:\WINDOWS\system32\services.exe
7 f7 L9 C6 W$ x: C4 A& kC:\WINDOWS\system32\lsass.exe
* _$ j! m# m5 d; `* r- L9 {+ d* ?0 SC:\Program Files\Common Files\Virtual Token\vtserver.exe
( X4 \, w1 h% F- m5 m' O1 ~5 oC:\WINDOWS\system32\ibmpmsvc.exe% Y; |2 C) _7 U* {# W/ _0 w
C:\WINDOWS\system32\svchost.exe
$ M. F( x" s$ w( X: X. CC:\WINDOWS\System32\svchost.exe- B" Y* A9 s' R' {8 m0 S9 N
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe/ R/ H' z y# n- A* @8 [$ ~
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
" y, }" o* n, h2 Y' P) g$ YC:\WINDOWS\system32\spoolsv.exe
5 u9 k/ G% }6 W& p/ PC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE6 t- `: c) |# |# V
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
% D3 P& u" m7 S1 ~. JC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe1 U$ H9 o4 y: M2 _2 D
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE0 s; C- @' x1 X. r4 M6 u( w
C:\Program Files\F-Secure\Common\FSMA32.EXE
( b6 c7 g0 `3 ?6 B$ lC:\Program Files\F-Secure\Common\FSMB32.EXE! k+ F% ]% Y' ^5 W" s" b
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe" ^6 W0 \% @6 n' V1 H/ ^
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
- b! o, |! ` W2 D$ P' T' OC:\WINDOWS\System32\QCONSVC.EXE
* _ D* r7 H8 L+ Z9 hC:\Program Files\F-Secure\Common\FCH32.EXE8 N& e- |- n$ J+ _; R: y
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe1 F. d5 f( U3 ~) Z/ ?3 B. d; a
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
3 s+ m2 m; p. W$ ]) e5 vC:\WINDOWS\System32\TPHDEXLG.EXE+ q2 v- {' ^' _/ w4 z- C) A! k
C:\Program Files\F-Secure\Common\FAMEH32.EXE
, O$ l9 W' g$ U, f% h1 IC:\WINDOWS\system32\TpKmpSVC.exe
# {& q6 B! g7 t& X% f; k0 m$ q8 QC:\Program Files\F-Secure\Anti-Virus\fsqh.exe: Y: ^4 D; L/ o0 d o( I
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe/ g/ Q* ?% X* d! C7 K% |! d2 `
C:\Program Files\F-Secure\Common\FNRB32.EXE; x/ A; i" y, V3 O
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
. M, `) j* ]# @4 m' I; c, qC:\Program Files\F-Secure\Common\FIH32.EXE8 O' m6 y6 _) m9 A; o
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe: E; S+ X" {" A& q8 y
C:\WINDOWS\Explorer.EXE
, w5 o8 f/ i* s; m1 TC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
3 o+ b2 y1 M( O+ S5 k; kC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
' {2 ^* _% G% k8 _8 U0 ]C:\WINDOWS\system32\hkcmd.exe
2 c+ D: Q) Y! y K2 fC:\WINDOWS\system32\TpShocks.exe
( `6 {% p' n8 s3 j# x r) Y6 ZC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
5 \$ B, a& v: z& e- X. bC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe1 L: ~. U4 V6 d' j; S* {$ z
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe7 ~* ?; T8 M s2 [# z% ]
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe+ N3 {2 Z1 b+ T. g$ s+ M( H
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
! K6 F' z$ W, H( o' iC:\WINDOWS\system32\dla\tfswctrl.exe4 E) N' n3 j2 t5 `- i! }
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
$ R* d# i9 x4 G7 {6 LC:\IBMTOOLS\UTILS\ibmprc.exe2 _$ S+ o- y7 }
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE, h+ q }, X$ m6 \
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
0 }6 [( Y0 E0 JC:\WINDOWS\System32\svchost.exe- V' [* M" ^1 E4 o) x- H
C:\WINDOWS\system32\rundll32.exe
f3 |& t% P- e* WC:\Program Files\F-Secure\Common\FSM32.EXE8 t2 ]3 H h# X$ c7 q3 U
C:\WINDOWS\system32\CTFMON.EXE
r. d \3 @. d$ c' O H7 @C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
, a& w% }# P: F) Z2 }3 Y: M7 k3 q; C& pC:\Program Files\Digital Line Detect\DLG.exe
/ r, A% V& H! q8 l: CC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
- K5 O2 [: y/ X$ w+ b& c+ \C:\Program Files\F-Secure\FSGUI\fsguidll.exe# {2 q: e+ W& Y0 \ I/ A# V
C:\Program Files\Messenger\msmsgs.exe
+ B! n k. G3 i4 I3 gC:\Program Files\Internet Explorer\iexplore.exe5 U! M$ l/ F% s" N; i# u/ s; x
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
5 ^1 D& f/ T% J# K1 S5 ~- q! H+ a5 _7 a% ~: C, J2 }
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
% M( u) p/ h$ S7 B' lO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
, ~) _: L- ]7 D; o) H. G9 U( zO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe7 c m+ ^; ^6 H9 Z7 R6 |
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe) Z, |! ?: X) l0 w h% \( S9 ~
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe: B* M( \) `0 H) n& j; ^
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
7 K9 `" x7 w( |" _2 p& {. OO4 - HKLM\..\Run: [TpShocks] TpShocks.exe: z6 f! P% N/ }$ g! E# E% O
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
1 j( U3 X/ y6 {/ ^O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup- N, C/ |+ ?# a( O
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
# v p4 q8 V8 \6 J1 ~2 q, ~0 EO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
+ i7 Q" f6 Q( ^; j6 m$ Y- mO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
! M3 x& I6 b5 s1 J, j7 ^O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray9 z/ Z; u* b( n! o' p* o9 o" W
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
( P# L0 C& A3 IO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe: @5 U. T6 p3 [2 z+ L- ?+ ^' M
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
& T6 U4 z9 F) {2 a! q8 F/ HO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe# m% w! x/ D3 s
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
; r, H! z5 G2 p# n ?3 w0 {O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
; u8 @/ Q% h0 L9 X, K, jO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
! r. a) s& z9 t. g% j; p: g tO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog$ @! g$ O1 c# w/ X, y
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
$ |2 v3 N/ W) VO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
7 a$ ~8 x9 m+ ~' C/ m( z8 j, @O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
3 N9 R3 C: h/ xO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
% K; Y# E) w, c* MO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
1 Q$ ~5 C2 {! Y1 M# \ T6 CO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
/ g2 y& p' W J- u, vO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW0 e" q% Q. Y7 t/ E+ c5 b
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
6 p. N$ s5 o- K+ \' g* sO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe9 W8 m! t. X: w
O4 - Global Startup: Digital Line Detect.lnk = ?
( B" m. E; M8 d9 B2 y! vO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe+ L# S4 s+ ^* M+ Q
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
0 J! t& d8 ]( K/ P, RO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll0 {- B H' n8 F. O. N2 v7 I
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll1 o `) R) S+ o; `. _
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll, o- K8 A- e0 v; b" g
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
5 ?% o+ Y: k7 h# ?' _2 YO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe9 d& h. C6 {8 \1 }4 d, _1 G9 i
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
0 G% ]" M% q) U" l& _O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
/ u, L# r- o, K: Z; Z3 S* qO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll, [3 {* B D5 o3 P
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
& p+ e$ U8 ~: KO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
, C7 t/ ^6 Z2 j7 c* j1 `! SO11 - Options group: [JAVA_IBM] Java (IBM)2 b" a8 Q8 k$ [4 z2 U& R- `
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
3 B% O" x' d( K& `: M. U% BO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll: |; o( [' x- r4 V; I
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
* ~* |5 H4 i# b8 Q! cO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll# [, C4 ^4 [3 j# k/ ?! l
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE7 a2 c$ C- R, \" [( _# ^# F0 H' j) I
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
/ F8 V7 X! L5 ^4 b5 |O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe0 I5 T- f/ N. D8 y
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE" W3 W1 s8 t# h) i. k
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
$ D" ^0 J* t" g4 VO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
3 ^) g( s7 Q3 [" kO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE4 |$ a" q# Y9 h* @! O
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
" _+ f: ^ {- G+ L% x( K% d4 ^1 uO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe+ K4 L4 G! |: y- E) t* B& h% K% `% R
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
( }0 g$ j$ B: n7 J' d! G# wO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
2 Y$ E C# G7 V4 ^O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
- u3 Z8 x! @5 s9 s C% VO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
" f5 L& N# Q/ g( r1 k0 JO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe5 c4 c9 F: i: l+ `
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
6 j2 a1 N2 d% f$ |0 j8 SO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE: x7 _: U% g& Z& r$ ]+ t
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe. B; S- @" d, ]! ~1 }+ [: B6 ?0 K
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|