 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1* h7 b2 o& s0 G2 m; f2 j
Scan saved at 16:55:24, on 2006-5-60 b9 y' N3 n" n$ ]. {& w: c
Platform: Windows XP SP2 (WinNT 5.01.2600)
: e$ w0 W% m f2 E. q; `MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
0 D* g' B- L: b( F& r' e, i4 l& H1 R4 Q& Z& v1 I
Running processes:
9 s/ o r% ~& _% ^* ^1 w+ c6 aC:\WINDOWS\System32\smss.exe
- @# m' r" |. Y% _% L& tC:\WINDOWS\system32\winlogon.exe
4 X* b: w; K+ g$ o! KC:\WINDOWS\system32\services.exe
7 B+ C- t9 N b# X4 N" m. }0 FC:\WINDOWS\system32\lsass.exe& q% i* W1 J0 _4 i
C:\Program Files\Common Files\Virtual Token\vtserver.exe# a. `% M+ T- l
C:\WINDOWS\system32\ibmpmsvc.exe
8 b& }2 D3 c- j, b3 s) I, J1 |! MC:\WINDOWS\system32\svchost.exe
8 Q9 S F2 s0 dC:\WINDOWS\System32\svchost.exe
# F- b, \0 e4 M I* H$ YC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
' U3 q, N ^. U% k* pC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe) i7 k Y7 t9 \
C:\WINDOWS\system32\spoolsv.exe7 I- [. n6 s9 x7 y3 k! R
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE! b2 m8 o# G2 S
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe ?& q& d O5 S; J) \6 @( Q9 b
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe# j1 w& F3 D4 B7 m# X
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE' @! @8 b) [. N9 C
C:\Program Files\F-Secure\Common\FSMA32.EXE
2 H5 y) N+ k- v( I8 K# n3 AC:\Program Files\F-Secure\Common\FSMB32.EXE. T- H" @& |) q5 B( f4 Z$ j! e( D
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
4 ?) G9 P( [2 wC:\Program Files\F-Secure\Anti-Virus\fssm32.exe
# a% w! X$ P6 m2 m$ HC:\WINDOWS\System32\QCONSVC.EXE
& I, w, G! E0 V5 {C:\Program Files\F-Secure\Common\FCH32.EXE3 o( Z& \" @# V6 I8 Y* M
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
/ E9 k* m+ E/ ~( X8 N9 R5 dC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
! m3 `% O5 z2 c a" M% j4 ? vC:\WINDOWS\System32\TPHDEXLG.EXE
* |$ H4 t' B8 q6 \' I4 A$ z8 e. `C:\Program Files\F-Secure\Common\FAMEH32.EXE, U# |! D- K m3 Q' C
C:\WINDOWS\system32\TpKmpSVC.exe
$ Q: N U3 c" q; lC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
^. D5 X0 |7 ~4 L% x; o Q- @C:\Program Files\F-Secure\Anti-Virus\fsrw.exe) a' c# X9 Z8 \3 _2 U0 M# R' I
C:\Program Files\F-Secure\Common\FNRB32.EXE' |( @( P- x) r* L$ S
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
* n1 L5 ?# d6 [ P) DC:\Program Files\F-Secure\Common\FIH32.EXE
5 n) m# I" t) T# D1 N( ~0 vC:\Program Files\F-Secure\Anti-Virus\fsav32.exe {3 C7 ^5 g N. A- l b( D6 c
C:\WINDOWS\Explorer.EXE6 \! [9 r7 ]8 G1 v) x, v q# c
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe Y" n6 @9 n2 f
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
9 e3 i4 N2 P# ^3 jC:\WINDOWS\system32\hkcmd.exe0 @% ]! z s( S5 Y' D
C:\WINDOWS\system32\TpShocks.exe
1 Z" t; l& c/ t1 _# M* ZC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
% X" j1 E7 K5 FC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe. V+ P( w+ ?! H ^ v9 e8 ?# r* m
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe8 q. M& n2 R7 G& }
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe3 z3 c6 o3 `+ V! W" _2 J, g
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe$ J2 b0 f+ G5 {
C:\WINDOWS\system32\dla\tfswctrl.exe
' R- Q* m' r8 t2 wC:\Program Files\IBM\Messages By IBM\ibmmessages.exe3 V! H9 ^& {1 Q+ m/ k
C:\IBMTOOLS\UTILS\ibmprc.exe4 w0 d: V( C; x6 O
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE3 U' ?* s" S R2 x* b
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
/ l* R9 ~# w" T+ V. qC:\WINDOWS\System32\svchost.exe" ?5 @8 J1 c: x* Z1 F
C:\WINDOWS\system32\rundll32.exe" G( ], u: `9 s# _& t; O
C:\Program Files\F-Secure\Common\FSM32.EXE
! G6 U9 ?% m1 \' J4 E9 c+ |# cC:\WINDOWS\system32\CTFMON.EXE2 t8 w; n, ]) [
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
1 q' V2 v1 S% u l; w! I7 BC:\Program Files\Digital Line Detect\DLG.exe- N# ~ H: t% _8 J: }6 Y" t3 m
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
% c' w8 G9 z, kC:\Program Files\F-Secure\FSGUI\fsguidll.exe. y% C4 }! c* ?+ h5 ^. S z
C:\Program Files\Messenger\msmsgs.exe
8 h' W3 A$ \2 d2 cC:\Program Files\Internet Explorer\iexplore.exe/ P6 C5 l5 W) n+ L6 v; `7 `
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
5 J9 z: f* N3 @# c2 f/ R7 m& y* j# L$ p; {
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll4 s: R' Q" p! q9 q3 M% _. x
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
! b/ z5 T5 p, g. N; e0 BO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
" M: I& U/ N% R# jO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe9 _% [- A. U2 m2 u9 @+ B! t: {
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
4 t4 s1 u: k) Z+ ~' r7 eO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper7 z" b" e( o2 C& D" w( M
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
?8 [4 k- I& w- O! _' _7 [O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe- q/ P* r# C" e+ ?/ y
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
) v# p- @7 Z' n9 C: [O4 - HKLM\..\Run: [TP4EX] tp4ex.exe" e) \2 @6 t1 k0 \, U* O7 @
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe6 K- X0 }) j2 ^: @% Q+ r2 }6 }
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe# }1 q: A7 U4 ]( S
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
$ H4 ]# v: u5 U. `! ^O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
# x5 u, M* d: X+ n& e7 q1 w* }0 t7 kO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
# @! C, {7 z9 I% b8 ~6 ]O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
: D0 @) ?6 |( a( hO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
5 f$ g) \. ?. s' h' M% \O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
: S9 y" w6 T8 m5 H+ f( _O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE5 y- V* |: t* |3 H+ t! v3 _% |
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor( H6 V/ \* q1 p$ C
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog/ i8 M% H# Q n7 n" e) @4 W& o: A0 `3 g2 X
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
h" e( @3 M5 m' HO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" \1 j& q& _- U" k1 i ?
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC8 d9 f! r* ] k/ U C4 q! H
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
0 `$ P8 r0 [; S4 VO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName7 _" J* N& D1 H. g" I* r: U# P
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
; y, P. ?4 D& k/ J! l! ^O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW. K0 x% a& p! c5 ~9 I
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe3 p- U4 m# J8 P- M9 L2 x
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
! s* s1 ?# i% p' HO4 - Global Startup: Digital Line Detect.lnk = ?
) Y1 x# c# ^6 E9 U& e( sO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe& l: V* j1 p" x
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm, ]6 k. A, E& [
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
9 ~1 a! @* ?3 J7 y* |+ z) p9 cO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll) b5 X1 C+ \5 D# e7 E P! E" c
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll) f+ [4 @- n; U5 o/ s
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
9 r% _! K7 Y# f) ZO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe) F/ @4 L/ a2 Y$ k1 h! _
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe1 t* S& f0 i7 Y3 k" e2 c
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe9 ]* b9 D6 j& U- i( y) r, X9 s
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll n5 a# T3 @8 a [% B E
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
5 _6 Q" ]8 _0 E7 {/ O1 _O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
" R k: C: [' }$ u" F0 }+ MO11 - Options group: [JAVA_IBM] Java (IBM)
& ?8 S9 y. ^" PO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll: v% ]! @4 g- B u" y2 B
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
+ H5 q5 l9 z& t$ W/ G5 \, U* fO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
+ H) L$ f6 ]' _% cO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
* J$ T' x, Z' m0 UO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
3 \/ `. u* c/ o4 d. C( ?O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe3 |% h/ ~. N, @8 B# j& a, M( S
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
/ r' A/ W- K4 Q$ vO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
4 p; @7 {# t, dO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
1 p' o% Q' G: gO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe" j: ?' u) I- m9 f2 }! b/ W
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE( m1 I y1 e/ h" V
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe% R; \4 V4 ^: m6 e% y! e' Y9 b
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe2 D: Q" _& t* d1 }# u) E5 f
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe/ F+ K7 K; b( `5 |4 A. O" \
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)2 A* F* d& {% V5 D3 H# z
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE q9 n; }- u, X$ G V, Z
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe7 b8 L# Y& k- K- C
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe' P8 w4 t( B, X2 S; t
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
1 }2 y( W( \ c- Z+ ^2 UO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE0 u' T/ l% A& u: O
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
# V* E4 u: b& h& r2 {7 PO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|