 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1, V% Y' f. U' Y; z( W
Scan saved at 16:55:24, on 2006-5-6
1 `$ ]) ?" X) Y. T0 xPlatform: Windows XP SP2 (WinNT 5.01.2600)) Y; J4 I7 @+ Q0 j+ M
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
' @7 I$ c/ w: U7 O* K1 w, q) t& o6 N% p
Running processes:5 l# m3 J0 _9 m' h
C:\WINDOWS\System32\smss.exe
# d6 ^5 E/ n+ j( k. L) {5 k8 V, ]C:\WINDOWS\system32\winlogon.exe- e/ `: S. `3 C$ Q" Q1 E; `
C:\WINDOWS\system32\services.exe
) D# R7 n3 E7 p8 q: G6 S* h: EC:\WINDOWS\system32\lsass.exe! S- \ i0 @& O4 Q
C:\Program Files\Common Files\Virtual Token\vtserver.exe3 {- {# f% |7 ]5 M. x# T
C:\WINDOWS\system32\ibmpmsvc.exe% R# \% E$ L/ n% k4 l& j7 |4 h4 L8 D
C:\WINDOWS\system32\svchost.exe+ `5 |1 @: A$ M% {
C:\WINDOWS\System32\svchost.exe7 G8 q9 ]" J6 _) K! _& w$ Z
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
+ ^2 ` A6 _' d* A) KC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe$ L$ G, e2 ?- e' ^5 J
C:\WINDOWS\system32\spoolsv.exe
% G0 a- @2 }# b) E# M1 J4 JC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE- u1 _0 y4 u- v( |" J% p, l8 v
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
1 `0 k0 [) ]" }9 `# yC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe3 X& \; b" L1 U4 w+ X
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE% P8 o3 ^% j" D
C:\Program Files\F-Secure\Common\FSMA32.EXE
: R7 ]( \: t( c5 cC:\Program Files\F-Secure\Common\FSMB32.EXE5 y) V+ F9 C w9 C3 b$ ~8 h5 o
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe- |# e7 y; N; s. g, g5 D. H6 X' B6 j
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
0 J- ~$ |% j# U# @% X1 ^, QC:\WINDOWS\System32\QCONSVC.EXE! `& ]) H+ ?1 _8 p$ J w
C:\Program Files\F-Secure\Common\FCH32.EXE
( E, v& _2 P+ l% wC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
}7 }, O: G4 f% U& ] @C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
, x w2 J. w8 q) W$ wC:\WINDOWS\System32\TPHDEXLG.EXE& p8 ]3 N& b+ @ i" {) x. `! ?
C:\Program Files\F-Secure\Common\FAMEH32.EXE
" g5 K/ R* p. [4 RC:\WINDOWS\system32\TpKmpSVC.exe; U4 ?# z: ]9 I" L
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe/ Z7 Q! ], e' s: }( M+ D
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
+ q" ?3 z4 Z" f. M i0 p2 O. O y9 bC:\Program Files\F-Secure\Common\FNRB32.EXE4 @8 U& ]% J# b7 e% K& b* B. q* y5 X
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe; Z, s; Z3 ^/ k Q; V; D# `, g3 I
C:\Program Files\F-Secure\Common\FIH32.EXE
6 b0 R5 C5 Z$ s5 WC:\Program Files\F-Secure\Anti-Virus\fsav32.exe) p6 Y) j2 C9 J8 ^4 @$ g
C:\WINDOWS\Explorer.EXE
3 D" {" B, i- [9 Y) {% AC:\Program Files\Synaptics\SynTP\SynTPLpr.exe9 r5 |9 w8 s* j3 X6 V; v; t& V
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe& Z& c% `$ z2 A" B$ F
C:\WINDOWS\system32\hkcmd.exe0 T! S! N0 a+ ~, t
C:\WINDOWS\system32\TpShocks.exe
* v9 o3 S8 s$ q- ?. VC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe8 {% G, b4 W0 S' p+ [- y
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" w2 B" X/ a( h2 S" e( }$ h
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
3 v4 L0 o6 l4 s4 R" x1 t* {0 yC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe8 ?: X* s9 E( s1 h
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe: _: l) F1 J3 ]/ u( U# `
C:\WINDOWS\system32\dla\tfswctrl.exe- f9 q: ~+ Q3 U/ f( y/ ^5 E
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe- n$ R+ Y( b! {6 T U! C
C:\IBMTOOLS\UTILS\ibmprc.exe
8 l# y) n# j+ u1 U% j+ {+ _9 A0 yC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE8 u. c+ C7 S" s% D. N9 L/ n; Y
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE& O! S( z' B- h. {0 j& W l
C:\WINDOWS\System32\svchost.exe
& M$ [, S4 R" L6 ZC:\WINDOWS\system32\rundll32.exe; G5 y2 m8 r! x: K3 X6 P9 y
C:\Program Files\F-Secure\Common\FSM32.EXE
+ k* \) H; |" X+ ^" ZC:\WINDOWS\system32\CTFMON.EXE# {& q2 z; T3 I6 T# ?, I
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
, N" B7 E. g4 o+ A( \7 ~' ]C:\Program Files\Digital Line Detect\DLG.exe
, T9 r; @' }0 I- o; e5 G( [C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
. V: E! A6 M' s ?* m qC:\Program Files\F-Secure\FSGUI\fsguidll.exe
) V( d$ k' ] A9 s7 Y' @2 B, tC:\Program Files\Messenger\msmsgs.exe
7 s7 J4 `. i* {C:\Program Files\Internet Explorer\iexplore.exe
3 \8 p7 j1 C0 e7 q6 P9 wC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
: B: F+ W5 }: i
0 e4 x& @8 q4 \O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll7 S9 g2 ~" h5 y1 Q8 d& }
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe2 c0 G; V! J# p4 h; Q
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
) {. {" C# Q6 HO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe: c2 S3 q6 U1 f# t
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
% I" r! A" s, T6 M' Z1 J* RO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper4 v1 O. y C7 U0 C! P
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
2 p9 y+ r) J6 u$ J" ]O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe) U1 P3 U# O( `: [8 C9 N* `3 a
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup/ B# K0 w+ r) @8 M- Q
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe2 D2 v/ L7 R; Z! s) n6 e& v/ ^
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe2 L) c/ t! m. D! w1 Q- v) L
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" c* [5 ]1 X* q3 s
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
! M3 F! x1 t+ ^' H. l- gO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r7 D5 D% I8 I m( }* I* r. X( _5 ^
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
" h' r8 g1 `8 B0 Z9 \O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe4 G7 e8 m* V) E* N
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe' \$ O5 a/ |3 _# Q/ l( `
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
( y* }5 s/ U3 \% _# \8 K, oO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE9 D+ P; Y: V1 G8 n- M6 h2 w
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor: M! D! u) ^0 S( d5 L2 [
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
N) m& I7 u6 W, ~$ y, w# |6 yO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
' F/ P. G r6 ~5 K* d# q8 I; _3 IO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
$ J/ c, `5 D2 x8 TO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
0 @; q5 L% u+ B. q4 j: cO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
0 |4 m8 v) B8 p2 `* i! KO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
* Y+ l s3 d/ EO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash( j% _8 Q8 Z3 Y8 b- F/ _6 f5 |
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW5 p3 c( G" X& x; N
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
) Q5 P% J, \1 _2 uO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
N8 A( l9 p1 ?" _; ~$ {/ @% ZO4 - Global Startup: Digital Line Detect.lnk = ?
( M, S! W ~' DO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
/ ]! ?$ I5 k4 i7 D) E6 nO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
: K. v' \# ?: BO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
9 y0 U) x' N- I7 @( ZO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll) R3 [6 I4 x3 S Q( y" }
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
P, D/ k1 c0 {' AO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
* R! j& V& f, U! [9 PO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe1 I$ T- h9 l* Z
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe# ^# m/ }3 Z. _
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe/ k) _1 v2 X! f! ?% B
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
; m( |2 M1 I" }4 IO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll+ R/ y7 d9 h5 X+ G, h" C* o4 |( q% t
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
! ^' E3 a4 S+ j o' B/ tO11 - Options group: [JAVA_IBM] Java (IBM)$ Q z4 c" P1 k3 k3 m7 z9 D! h) l
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll2 E( ?+ f6 k2 H. n( u
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll0 s k4 p) c9 D6 H. P0 S' I. l
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll! K! F: t% g% @& D1 ^7 t
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
) _' T' O" J4 h' Q9 B$ A0 kO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
# D5 ?7 |' C4 A! j' m5 x8 ^( A& YO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe) [8 A" ?, e: O
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
v/ `7 d, t. E: @6 _) c9 P9 tO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE9 W/ b. b/ | _5 ^* m! b/ c
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
/ r' q. d1 m, L! }1 y% h, WO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
8 b; U+ f: ]# i. B3 l& \O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
# l2 u( b) g' CO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe9 P' B5 h0 N) u# y6 z1 M0 j0 @
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe& K' ^- {- Z' _ G/ R7 e/ z6 k
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe J( P- Q6 o" ~7 p) P9 E
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)$ s% \1 x( J! y
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
9 E6 {) i+ A ]4 x7 TO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
! b0 W! P) ^) Y; [. x* r# l8 _. IO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe8 U0 L- R: W; P. @" y- q$ v# D
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe6 B# K2 C2 R/ }7 W& c `
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
* ?. D5 m; y- H" F SO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
4 }, ]( w$ X$ D, B c1 b7 j! ZO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|