鲜花( 1) 鸡蛋( 0)
|
楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
3 c( e- g! g: |6 P* S( Y! z1 C3 oScan saved at 16:55:24, on 2006-5-6: I- @# G: a0 i( F# z# z: Q9 V
Platform: Windows XP SP2 (WinNT 5.01.2600) c: I$ q- l. [
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)$ _# A; O6 g/ O3 G& w" o: D! C
% K7 b6 ~+ N2 a& H
Running processes:; V7 r5 s! ]8 A. }6 k: W+ ]; X6 V
C:\WINDOWS\System32\smss.exe( K j% e) C; F; y/ l2 `* n3 D
C:\WINDOWS\system32\winlogon.exe
! r5 h b4 d" r; H$ LC:\WINDOWS\system32\services.exe* O+ B( ~' w! \" ]9 i+ K5 ~7 b
C:\WINDOWS\system32\lsass.exe
1 Z7 J) \. K3 d, w; fC:\Program Files\Common Files\Virtual Token\vtserver.exe
9 P' }7 j5 X' t8 ^& z7 {C:\WINDOWS\system32\ibmpmsvc.exe5 i o; f W+ n( ^7 F* j( ?
C:\WINDOWS\system32\svchost.exe
8 @9 c, Z% F' i. `9 ]C:\WINDOWS\System32\svchost.exe! K0 x/ n+ H* ]
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
1 b! P# b6 n, E0 G- ^, pC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
/ @% j5 v$ V+ LC:\WINDOWS\system32\spoolsv.exe3 k" J* c4 n: ]& c' R) ]6 t
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE. {1 e; q% W8 ~' N( B5 n/ A/ g
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe3 C; P8 q# f! Q+ j' `
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe q5 Q) p& i. E& s6 f+ a
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE8 ?. R$ u7 T" Z0 w7 O6 X. ^
C:\Program Files\F-Secure\Common\FSMA32.EXE& a3 T0 ^8 _3 y9 f+ b
C:\Program Files\F-Secure\Common\FSMB32.EXE; h* t( l$ v8 [3 @/ I4 _$ v
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
9 f5 d, p5 z& H' vC:\Program Files\F-Secure\Anti-Virus\fssm32.exe
+ K: X7 j' G7 {C:\WINDOWS\System32\QCONSVC.EXE" }8 \7 I+ i8 Y ]: G
C:\Program Files\F-Secure\Common\FCH32.EXE/ X$ N! `* _4 K+ _7 b1 f
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
. D* O3 I4 ]* f" O* B0 OC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe6 t/ g! S2 }, O) u) ]
C:\WINDOWS\System32\TPHDEXLG.EXE
$ E6 S& I9 L! f; I, j' CC:\Program Files\F-Secure\Common\FAMEH32.EXE
- S& d7 z# J5 [( VC:\WINDOWS\system32\TpKmpSVC.exe
1 q2 `0 a1 [0 |1 U: c# @) dC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
: h0 |) a0 S9 U! iC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
8 \* |9 K3 E3 e" I0 ~$ P( Y/ z/ sC:\Program Files\F-Secure\Common\FNRB32.EXE
: S- l$ y. @& x6 g- YC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
( t: s( ~1 U+ `0 WC:\Program Files\F-Secure\Common\FIH32.EXE8 S% ^# H! n$ b' t, c
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe9 E9 [6 _2 e; t: |
C:\WINDOWS\Explorer.EXE! O' h( C9 V" {& g
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe5 t2 z" Z4 s0 x: {+ N3 H& c
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
! Y& i" O! H. @+ V( bC:\WINDOWS\system32\hkcmd.exe, ?& N- z' {& P6 W$ S
C:\WINDOWS\system32\TpShocks.exe# \5 e7 m" y3 x
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
# l% F) \9 a) X% H0 h8 ^+ FC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe& |1 M/ Y1 [+ ?2 O
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe7 t( z& G2 o% y
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
& T$ ] }& A. \0 v7 KC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe0 Y. z) n, l) [
C:\WINDOWS\system32\dla\tfswctrl.exe7 j# y' G1 l* t" K R/ F! t
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
( t+ a- X% T# U/ v+ ^C:\IBMTOOLS\UTILS\ibmprc.exe$ h; F; h, L/ y4 s P/ d, T
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE2 z" O: N: K$ p+ i: f
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE' j& M1 t* Y- n. a
C:\WINDOWS\System32\svchost.exe/ ^- R4 S! o7 Q, z+ W, R
C:\WINDOWS\system32\rundll32.exe
$ k5 s- A% h2 c; o3 b% ]/ bC:\Program Files\F-Secure\Common\FSM32.EXE
: V9 I3 Y9 X2 Z# @6 lC:\WINDOWS\system32\CTFMON.EXE- E9 P. U# u4 G# u( }8 x
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
8 d* u4 }' v+ _; dC:\Program Files\Digital Line Detect\DLG.exe5 ^2 I* G% F! @7 c9 ]& T
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe+ _7 ^& p$ I, e: ^! z: P$ l- q3 {
C:\Program Files\F-Secure\FSGUI\fsguidll.exe& ?3 Q; [) F2 A# @( c
C:\Program Files\Messenger\msmsgs.exe
' k$ [9 J5 J7 p# MC:\Program Files\Internet Explorer\iexplore.exe3 ~# f. r" J' t# q2 a7 V: P$ M
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe+ H: f6 g* ?, A3 B4 h3 f
: p4 G0 A$ `% @4 t1 `
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll1 s- l/ ~ W, J* Q4 H# @
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
S/ @4 I. j. {' R% L* eO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2 T3 Y7 C) o$ u5 E0 yO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe' X4 O3 N9 F9 N: d9 c0 T6 p
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe {7 \* z1 l F' }5 K+ [
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
?* [$ |) J+ J5 I% VO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
( K& M+ I$ V2 L& x3 aO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe( n2 c: O" [- E# L9 p7 c, \8 t
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup( p7 I6 q- M4 U# p3 J5 G
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe" D& E+ [# X2 ~% J/ n5 A0 f
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe1 h1 e4 u: j1 R; N$ e; w S7 P
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
, [5 T9 r, \2 TO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray6 t; n8 @$ }- e* Z) f
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r, i/ x, G- [3 k& h
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
# R/ X9 G' W; O3 c* @O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe, \5 S' I/ x* q2 M
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
! y4 |: z8 _" Y, `; W5 m# J4 lO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE' ]# X: B2 q8 h
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE* m) ]8 ~: S3 |! ]3 g/ b
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
! U! Q6 m, `0 iO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
8 U% @; A! D" pO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32" f4 k- ~! e; {6 G' N0 Q7 U M
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE/ G" A$ ^; u) m1 D) c) G u
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC% W g5 N' g7 u1 Q g3 p
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC. _6 B5 u% i8 g" X% {6 C8 w9 \
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName0 s4 d- U$ x+ W* }2 Q
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
* T4 d! ]% V5 D; P$ m7 @O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
- e% R2 i. D' z& _O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
( ^/ A+ D" H( S* Q. k2 QO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe! y/ G2 D8 M7 Y% U8 l; j t5 E
O4 - Global Startup: Digital Line Detect.lnk = ?
& e% [7 O: }) @O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
, R- V; E9 _; ]# h, v OO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
7 T; h J3 _- y+ ^# L* C; mO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll# } }1 c8 B( U" {: `
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
( I+ m4 k" a" @% F' y0 W' |; XO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll* T' x1 W+ g2 z: ~* ]2 S J
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
& P+ ]+ {( E' f5 [/ v% k/ cO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
" \/ u4 ]! [3 ? Q6 zO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
5 C, N0 P* H8 Q ^( h% ~; |: eO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
8 c6 I t; j! _* s% c3 o' e) c& dO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
- C, r& V3 ?) a6 r K! g$ ?O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
& \! |+ u- t/ U9 b; W, ZO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll( L& S! M, {7 @. c q
O11 - Options group: [JAVA_IBM] Java (IBM)* }7 k2 Y) {$ y, y- J2 }. I3 i
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
( d1 E7 ]: p9 I$ s7 |9 bO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
# ~( q+ W7 @7 [: n" _( B& cO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll+ p- C' m/ H7 U% U4 q& c
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
6 B5 B8 T0 J2 Y7 B0 [ JO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
- o( J S* d9 oO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe9 h. Z8 R7 Y b _1 O- H N
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
3 K/ c$ c/ p, s5 x: M( E; TO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
q* \/ R- N9 P6 X* CO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
' W1 z2 o, j. ]3 m3 \5 |O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe# P" a. P( d* r5 f* O1 }# `
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
4 V4 C/ V" q5 b0 B A! d: TO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe" }( W' y( k5 t! o/ R
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe: Z4 {( H7 L3 ]# v
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
! R+ m& v0 p( [" C7 F9 p# XO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
! _6 H8 d% v/ o8 c: T3 OO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE" M+ a3 [9 K7 q+ o6 y
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
% }9 ]! J( q2 x- ?" v. DO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe# T i& H# |* g4 O$ S3 h$ ]
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
) a ]" z7 b# {9 D7 _; [# WO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE1 b$ ~% v2 [! d; i% m& p" r
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe4 H8 E4 f/ ]+ S1 H
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|