 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1/ n0 W+ K! F; J! c
Scan saved at 16:55:24, on 2006-5-60 o- g* X6 o; q
Platform: Windows XP SP2 (WinNT 5.01.2600)
) G. j1 S1 l& F/ Z2 O! ZMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
! P6 h) \% r( m$ e8 ?
) I% U; p, h+ M' ?Running processes:
' _7 `2 `7 v0 G6 g7 r0 H& EC:\WINDOWS\System32\smss.exe9 u5 }, L$ K- k0 `( o$ h
C:\WINDOWS\system32\winlogon.exe; Q& \! @$ O/ ^: ^
C:\WINDOWS\system32\services.exe
& T7 S9 Y) S$ G$ J" b4 p4 {, g. m7 }, GC:\WINDOWS\system32\lsass.exe
& I0 @( @1 N+ Z7 iC:\Program Files\Common Files\Virtual Token\vtserver.exe7 ^& G9 B5 m# z5 l5 Q4 M5 @% B. s( _
C:\WINDOWS\system32\ibmpmsvc.exe
" t) @5 I* G. x, ~1 S* MC:\WINDOWS\system32\svchost.exe
; ?5 v; w6 v* c7 a9 b3 E* QC:\WINDOWS\System32\svchost.exe
0 K' X; a1 P! F0 r: `/ J. QC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
% c6 V/ T- c1 Q0 o' B% f: d9 kC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe0 j7 F, `: k L7 ^& N
C:\WINDOWS\system32\spoolsv.exe
; }& F R" e' C+ y+ X |6 }$ S- OC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
8 N, H% r( P5 B( d$ {/ hC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
$ w g' I( J0 _+ [/ n% d- i4 ^. C4 jC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
. O1 F9 n- O/ X* a) a( P. yC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
. v, _/ {& G' }, \C:\Program Files\F-Secure\Common\FSMA32.EXE6 K* {# R) ]7 n, E- |$ e( T% W/ ~9 g
C:\Program Files\F-Secure\Common\FSMB32.EXE5 N1 ?& r. j2 L) {9 E" H
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe! ~; o. U) X# ?# f9 d( f' O& B$ i1 g
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
1 n$ k. }0 U* K( U* @5 _C:\WINDOWS\System32\QCONSVC.EXE
+ L; j" f# Q7 ?# j* j7 _4 e# lC:\Program Files\F-Secure\Common\FCH32.EXE
( f7 x- T+ k- b' P8 Y; AC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
' P$ ~1 k, n% @! g3 OC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
+ y; Q# Z1 M! tC:\WINDOWS\System32\TPHDEXLG.EXE( v! v& a p C5 C7 V8 M4 T7 u! [
C:\Program Files\F-Secure\Common\FAMEH32.EXE5 D& M- I4 i& j" f* O4 O0 }
C:\WINDOWS\system32\TpKmpSVC.exe
4 G. j8 R. Y7 M0 Q7 wC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
5 X) W' q1 }1 H7 f8 fC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
2 K9 Q: w6 x. M: vC:\Program Files\F-Secure\Common\FNRB32.EXE
" o I% M$ A9 f- B, f5 ~( C; UC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe+ N) r0 }% J1 ]6 W) J/ z
C:\Program Files\F-Secure\Common\FIH32.EXE
/ f7 `( h5 I: B/ s C% A$ qC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
9 t( d- b6 U H" hC:\WINDOWS\Explorer.EXE
9 h, m- `+ h9 X& N% U) F+ ?C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
! z" N4 ~4 z3 R8 C8 Y! Q [5 G: d8 Y- cC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
) h$ L: @! b( V3 p$ L& KC:\WINDOWS\system32\hkcmd.exe
L0 r5 ]5 C. T5 DC:\WINDOWS\system32\TpShocks.exe
6 v0 K3 P: ^7 M+ J, z ^C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe d' p0 E/ ^/ a. |: S( r$ B$ e
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
7 v* i4 r1 Q7 @" T& GC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe) `% A( c2 S* |6 M8 k
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
9 r# K) V4 j& w3 b6 o6 ~C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
) w" c# {6 O. f* D& ?/ \! yC:\WINDOWS\system32\dla\tfswctrl.exe! e/ D3 M' x( h5 T( Q1 O: H4 ?- K2 P
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe( U Y2 l* \3 q) X$ x8 L
C:\IBMTOOLS\UTILS\ibmprc.exe
+ Y3 w- ], M9 X) nC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
8 l* J U# u: d4 ~2 C' k9 ZC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE [. s/ s/ H- ^4 ]
C:\WINDOWS\System32\svchost.exe
8 n/ T J' c; S, ^" W: E. ~C:\WINDOWS\system32\rundll32.exe
2 J, a! s0 ~% L7 I8 t9 T% LC:\Program Files\F-Secure\Common\FSM32.EXE# E5 l( t! h4 }
C:\WINDOWS\system32\CTFMON.EXE
7 X! s/ q: k) V1 k% C$ b9 O& \C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe5 I# V+ J' M( P, J6 Z* q
C:\Program Files\Digital Line Detect\DLG.exe
8 m9 \7 ~: l9 Q2 t) Y7 b- EC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
. E5 X& p& S8 u+ z _C:\Program Files\F-Secure\FSGUI\fsguidll.exe
& N- b. C5 ^0 M2 M8 I! r3 xC:\Program Files\Messenger\msmsgs.exe
( k; a0 J2 a! l4 u) F- I1 W* IC:\Program Files\Internet Explorer\iexplore.exe
5 ?5 x b3 U, t. w" e7 H' k& |3 @C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe/ t8 R; D+ V& P; v" C4 J$ ~" Q
6 g2 B2 s- p7 p1 D6 ^O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
; H' P8 E8 F; j: K% sO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
: d: z- e9 o$ F/ f! a# aO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
( {/ A0 T" x- z; oO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe4 U/ ]7 [7 i: {. d: @+ _
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
& e& v0 }3 I# f% h" EO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
( l6 k) M7 u. g; B; h7 VO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
8 V# |+ l; c. X* G2 N8 E$ J( ^+ AO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
% q% x2 q: \; H' cO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup& y2 y) K. g; I
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe( m+ v- I8 e$ ?3 x2 P( Y
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
4 N6 w& d) s& I5 u; h8 OO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
% K4 @3 l K$ C2 X) a) j7 FO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
/ U* A" h( I* |. |6 p6 j. g. CO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
' z$ T# ?# p) U1 d6 `0 i. T: eO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
* Z! Y3 P; m2 Z, z7 T9 ZO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe: D8 [9 Z2 F2 _" o! Y) S
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe5 t8 k; h; W" `9 l- K9 n) A
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE# O( S+ q: A$ @0 B/ m
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
: r9 o- I6 e& L9 V2 A( k# rO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
( V( m9 R0 M# S% UO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog- i: ^) X/ Y, ~5 A& |9 `. f0 p
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32% m' h) F$ A c+ e% Z0 z O
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
}( j, r3 ?9 K8 wO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC6 y5 d+ H& T: m# c* g* s
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC5 E- Y" z* u, v2 b! g5 @
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName/ i- ?. G, F5 n& G; o. U5 h! `6 i
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
5 ?; T/ j: i( J, i3 _0 lO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
3 ]/ t( e1 }( o# }4 ^- W% DO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
0 y6 x6 o+ X$ f( n3 {9 C$ A& ~1 WO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe% v; Q! E% {, g" H( Z1 e; [$ _
O4 - Global Startup: Digital Line Detect.lnk = ?
9 k' }% a" d/ k* PO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe) n$ a+ F- h4 t+ ]1 r, G
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm: m" c; M# v4 m2 E, R8 [
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll9 p; E+ b1 O. U
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
+ G, ^. b2 m+ N+ m5 kO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
- p" S$ r6 f+ p( A- z* V. AO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll" v4 Z( M; Z# d" N, A9 z7 [) M
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
/ q( U3 \3 Q$ G. w- o8 eO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
: s) e" \( n5 \+ M4 S4 o' VO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
0 g- B7 B5 h. p4 i. `8 @O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
+ A9 z- A O& R; B KO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
V; c$ t& C1 A, z5 u( G. tO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll1 x+ C$ c- ]" m7 X
O11 - Options group: [JAVA_IBM] Java (IBM) h# O0 \- W7 ]' p: C3 g0 n' F
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
$ J9 B9 o, J0 k4 E e' FO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
/ w! F/ m& x' X- b! W- g8 |& }1 o; ZO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
7 I( X. Z* T6 D; O" DO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
* t/ E4 r4 b2 W% {, k! }% `# d! O5 sO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE. F# ~' h. ]3 j
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
! D( M, A1 z9 m- fO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe! ^2 c$ D$ Y! q
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE( H8 ?# X0 t3 n% a
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
0 D$ o" n! V2 M0 c$ LO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe h6 w, y- Q* Q+ G5 D% `) S( R
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE9 ^; ~$ X9 {& e4 N$ Y
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe q0 A0 L6 g1 H" \% s- C- o; s
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
. W! I7 N: S; C% r7 [O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe2 b& T/ n, U q$ o
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
8 Y( M: v, N$ v; v# i' dO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
- Z7 _' A$ n! @( CO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe' Y! ?$ A @5 L g
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe% r4 K! D" n0 ^+ A5 M* O' d/ w. j
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe; _) ^. E( f2 S6 _. `% ~: N
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE ~) J7 q6 i3 S# F, Y3 D2 B/ P
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
1 D& \" @- n9 {4 X* I2 ]& j; GO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|