 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.19 m$ {; u' p* a% f. c
Scan saved at 16:55:24, on 2006-5-6
8 u5 ]; y! G" S3 R3 ] jPlatform: Windows XP SP2 (WinNT 5.01.2600)" s/ l' U: \# X; d6 U4 x( m
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)( X" _6 {4 Q/ C6 O2 `
& @7 C( H$ @% T, G0 p' ^$ c) i+ ^9 VRunning processes:
1 @% v* v8 P6 M, L4 ]C:\WINDOWS\System32\smss.exe
, ]+ _+ A' l' a" v, @. N, q) q! FC:\WINDOWS\system32\winlogon.exe- W7 L O. P! S) H
C:\WINDOWS\system32\services.exe
) ?. }; B( I. p* \& M0 p- q* N' iC:\WINDOWS\system32\lsass.exe3 _: z( |6 O" u" x/ n4 o
C:\Program Files\Common Files\Virtual Token\vtserver.exe; o4 P% I: I1 G/ }) x) z
C:\WINDOWS\system32\ibmpmsvc.exe
0 Z+ I$ C l5 B& NC:\WINDOWS\system32\svchost.exe" l, n$ k( P9 a
C:\WINDOWS\System32\svchost.exe6 R1 E+ u& p1 R! g z( c3 c
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe. H& G" A' x. Y8 z( j% {0 h
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe, X/ u& u: L; H; N, F3 T
C:\WINDOWS\system32\spoolsv.exe
* E, f& _* [2 r1 _C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
3 m4 H3 G h i" @C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
$ |5 O) t4 J. R8 H: K. X2 n g) D1 k3 N" cC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
, ~. q4 Y8 B, ^# i4 }5 S' {/ Q4 _C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
0 N. O% p$ s0 g; c$ kC:\Program Files\F-Secure\Common\FSMA32.EXE
, x- `& X: ^, ^* J2 Q/ P' XC:\Program Files\F-Secure\Common\FSMB32.EXE4 W7 C& H5 b. z2 a
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
! a5 M* j3 M% t4 vC:\Program Files\F-Secure\Anti-Virus\fssm32.exe1 e9 h1 L" H8 ?5 g) @. \1 x$ W
C:\WINDOWS\System32\QCONSVC.EXE$ Q4 v" d0 W# e& N# }+ @! z; T
C:\Program Files\F-Secure\Common\FCH32.EXE
" d/ g' t K6 _9 p* SC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
+ I2 y2 w( u# M" [( SC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe5 @" n- G# I3 i0 o8 a' V ~
C:\WINDOWS\System32\TPHDEXLG.EXE3 I: z h: G, Z$ J8 ]( a# Q
C:\Program Files\F-Secure\Common\FAMEH32.EXE
% g, @0 o! `% D ^ a! B& l2 TC:\WINDOWS\system32\TpKmpSVC.exe
" O. a8 r, D; t l+ VC:\Program Files\F-Secure\Anti-Virus\fsqh.exe% n" g2 D* M& [" J3 Y
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe. i# i5 X! C4 J
C:\Program Files\F-Secure\Common\FNRB32.EXE( I; X1 x# c) r
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe) t; e$ X5 ~* W/ l: J2 ~/ _' @
C:\Program Files\F-Secure\Common\FIH32.EXE
8 ?! s4 D% T* z7 Q3 i! B- tC:\Program Files\F-Secure\Anti-Virus\fsav32.exe9 Z3 {0 E( T3 r) A3 w- H
C:\WINDOWS\Explorer.EXE
% F/ D9 P2 c. rC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
* [, S" j! G3 gC:\Program Files\Synaptics\SynTP\SynTPEnh.exe: c# K3 o# W* }3 |
C:\WINDOWS\system32\hkcmd.exe
2 m: V- G8 V9 q: F) B8 eC:\WINDOWS\system32\TpShocks.exe! N( M& G# L% _3 M
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
( c8 p8 T1 t' i5 A3 R5 [8 ]C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe) Q# H: R& y, q/ [0 G
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
% D# |. N+ @# `, Q7 w) I PC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe) T4 B& Y" K+ |2 f" U2 a
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe5 f5 f! B' D) l3 z. B7 _
C:\WINDOWS\system32\dla\tfswctrl.exe# ^( u' m0 b2 a; k# Y
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
! D6 Q- A( z: A& a; V8 l# cC:\IBMTOOLS\UTILS\ibmprc.exe+ e3 l, ^5 T/ |' v9 ~
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE+ E" ]5 R; |! ^0 `5 ^
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE$ L; b1 v, F* x: e
C:\WINDOWS\System32\svchost.exe
& f; \* @6 _# Q# ]$ xC:\WINDOWS\system32\rundll32.exe" {8 N9 j' l5 Y, {& h+ \# a% c# s
C:\Program Files\F-Secure\Common\FSM32.EXE
3 ~7 v! E; }& L4 f7 y0 I( oC:\WINDOWS\system32\CTFMON.EXE# a; N1 a; X1 C5 b! _/ d
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
. Q7 g$ _) A. _C:\Program Files\Digital Line Detect\DLG.exe
. X6 M" @* }1 U1 u+ ]4 o# LC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
$ Z' M' c0 y8 mC:\Program Files\F-Secure\FSGUI\fsguidll.exe
3 ?+ v4 \7 m# a, |: iC:\Program Files\Messenger\msmsgs.exe( R p) e+ q5 `4 D3 C
C:\Program Files\Internet Explorer\iexplore.exe# t: W* r" [5 a- A v
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
3 g1 G1 w& g. I5 ~ i& B/ r4 |4 Z1 V: M0 Z& a) S$ @
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
. H4 @, G3 \+ X$ zO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe2 t" i8 D+ i$ P
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
( j7 C9 V2 C8 `* q6 X' dO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe$ B _+ p+ K0 _* B
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe. G9 @! N( J8 h% T# }3 | X0 a6 q
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
# R `* M$ M% SO4 - HKLM\..\Run: [TpShocks] TpShocks.exe Z+ V9 u4 \+ W
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe5 D1 X4 s/ r6 ]
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup- ~: }- @. c. K( F9 u1 U
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe! W8 l& e+ R) W5 m! Y$ w
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe4 C# {. ^+ b, R- g
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
6 E' W% m$ o6 A- C$ ^ @O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
; G# T. Q; P3 S& V, d# }- ~O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
# ^) q/ O9 u7 C0 m4 O, dO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe9 ?0 D3 t" ~0 u) c! m+ v
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
: S7 W5 T) i* e# cO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe1 x4 @0 v/ L8 z. H0 Y9 w2 Q
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
% \1 d( e, e; W. b1 eO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE5 p4 F4 W, ?/ L: \; S
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
% a3 E. [" ?* \3 CO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
: m# b7 B' U4 l9 HO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration325 O& D0 q" _7 s' R4 R2 |6 w
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE3 P5 L1 N5 l J C, {
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
7 ?+ o, J$ T8 J" [O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
4 N( G; h/ o2 \" ]O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName# Q' {* K3 M. X
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
5 S/ \; K' S5 X& C6 C7 y7 Q' IO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW3 z2 _; ]) j" Q4 W% Q
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
3 `2 \; l i0 p* ]$ r3 A% o* ~, L) k6 ~O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe: k7 l/ [9 ~. c) R: }) h8 q
O4 - Global Startup: Digital Line Detect.lnk = ?
G) E1 i; l4 s& d1 TO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe% A& E4 q8 B! T6 ^0 M
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
" t) }& L$ X) j" iO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
8 B. b* B& @: y- E0 QO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll! p- J- h) X# K4 \5 ?% K; J* |9 W( d
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
4 L0 X+ V$ J* eO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll( h! s" |5 \% b! A, D. x5 z
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe3 Q! a9 j. d# N! z
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
8 ?3 S F# J; j, [! tO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
5 ?: |+ U0 _" S0 \. XO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll, J8 H3 g4 p5 @) E, g
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
. v! i: q2 a! t: R) a2 \$ rO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
1 v" s5 m# h1 p+ kO11 - Options group: [JAVA_IBM] Java (IBM)$ K4 [* b; I0 V. T
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll3 r8 u! a- ?( e$ H
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
c) P2 v& h6 n% h4 m3 v( ZO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
2 K1 T% t+ d8 {8 R! l2 N4 ?O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll) F* O* s4 u j5 S3 }
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE( v( j& n0 \2 j! f& F1 l. x$ T
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe% w4 @8 R, P" p H, J2 E
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe j' y9 q2 f: _
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
; x% z$ s* E0 X4 `% J1 HO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
. d6 H; h( J! ^7 P. R/ Q. zO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
4 x1 K, H# B' \' nO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
2 S' U4 u! Z2 T2 g2 k/ s" ~2 KO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
, s! G( ?4 M, g, b( P0 M4 iO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe9 k2 X) H+ U. [
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe8 p# M& j; l6 l2 U% |
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
- Z a4 k$ Z9 ?. \/ q( ~O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
8 T/ a% P6 E4 w9 C/ H, T6 \+ NO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
# r/ A2 X' s8 X9 g, x6 u& zO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
W' V; P8 @" C+ GO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe" J b4 Y7 S5 o8 |. D
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE2 a N! g$ F" @( ]1 O) w% ^
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe6 Q- Y; M3 W5 ^) ~4 k
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|