鲜花( 1) 鸡蛋( 0)
|
楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
/ J" Y5 Z: U% M0 Y. h' ?Scan saved at 16:55:24, on 2006-5-6
( J1 Q5 X' c9 ~4 dPlatform: Windows XP SP2 (WinNT 5.01.2600)4 k1 {5 E2 ~+ |
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
" T* {( m' {$ m* d1 q
C0 {$ e$ |, k4 b+ J' hRunning processes:
& M6 `. p$ o& L$ d3 b# n bC:\WINDOWS\System32\smss.exe& v& b! n% R: q8 y- P/ S z: x1 y
C:\WINDOWS\system32\winlogon.exe0 o4 W5 s/ E% I! ~9 {
C:\WINDOWS\system32\services.exe- `6 d! ^2 F2 c' ^5 L) ?, Y
C:\WINDOWS\system32\lsass.exe* T! k' h1 A1 m/ y! a+ L- F' d
C:\Program Files\Common Files\Virtual Token\vtserver.exe
3 N$ V1 x X& \# M3 P8 {C:\WINDOWS\system32\ibmpmsvc.exe% C. k; t1 X3 Y+ g: k
C:\WINDOWS\system32\svchost.exe: t1 c' Q. f* Z u
C:\WINDOWS\System32\svchost.exe
" K7 a3 _/ N. V0 L) AC:\Program Files\Intel\Wireless\Bin\EvtEng.exe6 F; I/ b, p& R: T- `/ U
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe6 l+ c" c c' ~7 s
C:\WINDOWS\system32\spoolsv.exe3 J9 \% Y: l) v5 \$ f! a
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE9 B- A+ L3 C6 s" j
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
+ z! G+ Q% G9 U3 x) I5 y/ CC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
3 i' c7 a9 N' \C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE8 k# ~1 M6 ^8 |. H( _- m# C' A1 Q
C:\Program Files\F-Secure\Common\FSMA32.EXE
~* C) ]: T0 j0 m! o2 ~C:\Program Files\F-Secure\Common\FSMB32.EXE
6 _1 l8 [1 i% WC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe/ {: a _6 i% o- G7 \
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
- J4 P8 L* |! [; E7 |$ m8 n2 t7 pC:\WINDOWS\System32\QCONSVC.EXE
# Y) z7 h# J7 z2 d( _C:\Program Files\F-Secure\Common\FCH32.EXE/ W. N. r' c8 U; e
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe' F/ F- S! r% m
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
! m8 q3 S! o( i9 E) kC:\WINDOWS\System32\TPHDEXLG.EXE
# g4 U8 c, G- W0 C6 `6 w* AC:\Program Files\F-Secure\Common\FAMEH32.EXE
& m1 a+ a4 t+ [* i" z! o& iC:\WINDOWS\system32\TpKmpSVC.exe
s8 d6 I5 M& o6 Y& gC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
0 X. Z# s0 k1 T, dC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
& r' Z5 Q/ Z2 {. u- E! {C:\Program Files\F-Secure\Common\FNRB32.EXE
# C( g5 D1 \1 z' Q" MC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
( j; i, N2 a1 e& ]$ XC:\Program Files\F-Secure\Common\FIH32.EXE+ [; a& U6 q$ i7 V6 H
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe2 [$ Q) B0 F3 D. n9 i
C:\WINDOWS\Explorer.EXE% }# m- {7 M; p- K; `) X" X
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe( N, M# W) O% o! |
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" s3 \( X% O& ?* g9 p" H' o
C:\WINDOWS\system32\hkcmd.exe
) i1 ~5 `; f4 |$ y3 WC:\WINDOWS\system32\TpShocks.exe/ e1 x; K3 @0 @' k: s3 o! F5 n
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
) z: c, @$ H/ K) hC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
9 h6 D3 u; x# M' WC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe& S9 h; }+ ~* }: n% P8 g
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe8 D' X5 o* S: H! h
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
. U% D* U0 {5 I2 c0 JC:\WINDOWS\system32\dla\tfswctrl.exe
: g7 E+ b" S$ T4 G0 GC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
) E! B$ x3 Q! e& {! zC:\IBMTOOLS\UTILS\ibmprc.exe0 i' [, w: `% G9 k4 m
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
' c6 g d4 g: O* _( F% i/ H+ wC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE k8 C" u" E3 w: [
C:\WINDOWS\System32\svchost.exe* D0 c5 T8 V T/ F# n( Y; f
C:\WINDOWS\system32\rundll32.exe
% k* i1 e5 A. n+ ^7 }; T" q0 A5 oC:\Program Files\F-Secure\Common\FSM32.EXE1 P0 M; j9 p) Z- v' h5 H% t/ ?- W/ T
C:\WINDOWS\system32\CTFMON.EXE8 V6 G- o- J; K0 y
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe/ r7 J1 h0 ~* q4 H
C:\Program Files\Digital Line Detect\DLG.exe
9 j, k( w) y( o t% r8 M7 @. CC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe8 Y9 }' \, K8 e( Z' w' `- `
C:\Program Files\F-Secure\FSGUI\fsguidll.exe
5 k7 K1 [% W0 S' @C:\Program Files\Messenger\msmsgs.exe
, w( F; B! A% s( w1 F4 {4 kC:\Program Files\Internet Explorer\iexplore.exe# q8 P4 B) M# r4 I$ t' H* h
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
7 g! C# c% E% u3 @1 {. ]' v
6 s/ I+ I O, x, K. Q O; g1 nO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll8 N* f6 r% b* [5 i
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe( D, I) y S; T) K
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
0 w& ]& m, v' |# H/ N) h% ~O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
4 Z7 d5 d6 i5 Q% n6 `7 D1 w kO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
M/ {, r# u; H* }' CO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper% y4 z, [/ R, t Z+ s
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe5 H# u: w0 p, I; D) z0 I4 }
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
. W. L# n" o& [( sO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
2 W( I" x% s) XO4 - HKLM\..\Run: [TP4EX] tp4ex.exe' @) \& M" N8 {; H9 _" I
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
. E$ r+ d# Y# ~- l. B) B. _2 ^O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe% n" s4 w/ ?8 ^2 [3 G* G9 J+ O
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray) n7 R# S1 o1 m- M% `5 f
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r" s" E' Z4 N; y7 T1 c% U0 H8 B
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
9 ? {; \6 s# f3 e, f- q* ?O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe7 D3 x1 `( |1 t# _+ r
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
! M5 X4 M K, A' L3 Z w h7 r/ nO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE# [" P" m# N. L9 {3 c% `4 {; r
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE2 [& H" \" d: I& M+ ^) h, t
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor8 U5 v% ? j+ @: D
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog6 L9 X: `) b0 o# ^; O9 f" `
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration327 a# N7 r- y5 @' d5 _
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
3 }5 K& ]+ C0 _( Q# nO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
% ~2 Y1 L& ?- O4 _8 YO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
; V& F5 w! V' q4 d0 RO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName2 k: _ P8 l3 n; j+ N7 M2 {: r. R
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
& d+ k' Q! ]* |O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW: a6 ~6 e0 U+ r
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe& K( D: V S: f+ ~ X a3 v
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
+ i* x# E. L3 P- J+ TO4 - Global Startup: Digital Line Detect.lnk = ?
( Q5 ^5 W v9 r1 b% n8 XO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
$ K0 Y2 M& A1 B9 HO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
, B9 b" |, s0 x. P& O% H+ nO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
" Y* w) r5 @; g7 _& aO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll* {: P9 h. L: u; n' m! V/ f
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll) k2 T+ f, J c2 H
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll' t8 c) {8 K+ }4 \" s) w
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
- P, U2 x& b) I5 yO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
- s! z8 ?% N& L! C) A3 CO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe# Y i. T& |' i8 S
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll s: I; O3 {2 @1 w6 e8 Y1 V% g
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
5 ?0 ?8 l1 L& _2 h& hO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
- Y0 f* }6 T! t, d' `O11 - Options group: [JAVA_IBM] Java (IBM)
9 p: T0 s4 j: w) w# |O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll5 ]6 @: h2 I. F# o
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll; Q( s4 i" k8 ]- V+ `
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll# T j- z9 |- O) z+ }
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll/ k/ Z( _/ \. d% T( n# S! j
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE4 Z) m% W' L& W' U
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe# }, y6 ?+ @8 B% v- j
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
( R) ~- F+ W6 ?O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE! |1 r; i" ]: W1 l0 ^
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe/ z1 r& u4 E# R5 Y% F! ?
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
' l5 B2 K* T( W iO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE1 E, J" _* i( ^6 V1 \
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe. t9 @/ {; r3 Z6 f0 O) {; t" l
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
' C \5 N- h8 h+ g0 L! \$ m8 S/ PO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe! E! H" Y& v/ U9 ?7 U
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
) X6 Q) ^' P: \6 S- ~O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE( q9 q7 l/ W$ j: {) F1 v2 N4 k/ y
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
2 t: H {4 A: k1 A5 k5 K. cO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe- d) k( d6 y% x. T% M
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe/ r* D9 V9 F3 r% { K p8 ?
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
3 N* q7 w5 A# Y" X% j" }4 i4 i9 WO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe) \. a4 n3 R$ h4 P
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|