 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.17 ?5 R& ~* g! |# [
Scan saved at 16:55:24, on 2006-5-6; o1 \) l; o+ B& U& f
Platform: Windows XP SP2 (WinNT 5.01.2600)
2 l$ B# Z5 p5 L2 q1 Z0 }' cMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)- {$ I/ r z; v" @
' g2 w3 J/ |& n" a. _Running processes:
, H$ Y4 u$ T/ Y8 l* [C:\WINDOWS\System32\smss.exe- h, z4 s* c* Q$ H" A; N/ k7 q
C:\WINDOWS\system32\winlogon.exe# a4 w1 U5 p" P7 N9 n
C:\WINDOWS\system32\services.exe% K. ? }7 e7 `; G/ q& |5 c
C:\WINDOWS\system32\lsass.exe2 Q0 o; ], I; t& t
C:\Program Files\Common Files\Virtual Token\vtserver.exe
7 W4 T2 } {! g% R7 v$ y: a! Z2 @0 VC:\WINDOWS\system32\ibmpmsvc.exe k, F# p! b( s! q5 p$ u
C:\WINDOWS\system32\svchost.exe9 ?" e! e, G. w- z! q% d
C:\WINDOWS\System32\svchost.exe
D8 T. u p+ W5 x, q5 d, AC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
6 n% ]6 B$ @ O5 GC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
) R) ^6 y: p/ I( z* R, y" CC:\WINDOWS\system32\spoolsv.exe/ Z! s+ H! b& J# d6 f C
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE; u! Y4 J, Q% Z
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe( d" j0 ~" ~, w6 a
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
7 z. Q6 A/ B% q/ G& H7 `C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE3 c0 [$ R+ o1 V2 }) N
C:\Program Files\F-Secure\Common\FSMA32.EXE. E* ?3 B9 U% [' O- W1 K- \
C:\Program Files\F-Secure\Common\FSMB32.EXE
* V `' Y7 }% y3 e" S2 x; VC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
, |) W' D* H! s6 YC:\Program Files\F-Secure\Anti-Virus\fssm32.exe1 M+ `$ p! P, \ e# c( `
C:\WINDOWS\System32\QCONSVC.EXE
$ T' d2 O7 i" oC:\Program Files\F-Secure\Common\FCH32.EXE
: F0 s t6 |3 ` I+ dC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
1 p* P) i$ V( I0 E$ W/ }C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe& @& o! _! _ G/ G+ g
C:\WINDOWS\System32\TPHDEXLG.EXE
- @5 `$ y5 }+ F5 sC:\Program Files\F-Secure\Common\FAMEH32.EXE
2 C# u5 Y4 U6 I! O# P+ S3 d5 sC:\WINDOWS\system32\TpKmpSVC.exe
: }# C2 x& E3 ^3 t& V3 Z2 O9 IC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
! a3 l+ X. e0 |# t, wC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
* v0 q6 {3 s7 L0 bC:\Program Files\F-Secure\Common\FNRB32.EXE
; X4 {% D% a9 Y& R0 r' T( U) xC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
5 ]0 W! h5 a- m# L0 {: oC:\Program Files\F-Secure\Common\FIH32.EXE; w; [: h5 P. x! p+ c ~. Z* B
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe1 x" b# t$ ?& t
C:\WINDOWS\Explorer.EXE0 {4 u" W1 x: t7 G, N2 o
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
k4 {) }2 ?" O- OC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
* q4 |, I/ r5 w7 |. z1 YC:\WINDOWS\system32\hkcmd.exe. p A" M' \2 [
C:\WINDOWS\system32\TpShocks.exe U# h% g9 \4 |1 F5 f
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
4 `/ ~! O$ j% E; T! a3 J* AC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe: P( m3 @' X |- T5 s2 Y* F+ e; B
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
; x. {( p; o c0 M. a. cC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
/ I! j% T, z4 z$ x! k3 }C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe% e7 G: t' s; X2 l% p) \
C:\WINDOWS\system32\dla\tfswctrl.exe
6 L% K$ @( R- K9 EC:\Program Files\IBM\Messages By IBM\ibmmessages.exe" k+ B, m8 z4 ?; O8 U6 J* i P O
C:\IBMTOOLS\UTILS\ibmprc.exe. R* R* Q+ X7 P8 k: H( Z ]+ g; L
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
3 t& H8 O* y: q1 fC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
. k0 R9 _* e* d% n: b- e( ]$ \C:\WINDOWS\System32\svchost.exe
) l% K2 ? D% O- v, bC:\WINDOWS\system32\rundll32.exe* L9 ~$ d' y# u( S! L1 E2 L
C:\Program Files\F-Secure\Common\FSM32.EXE
# O4 [9 ]( M( S4 C5 p. dC:\WINDOWS\system32\CTFMON.EXE' M& d G! n8 O& [9 p+ x
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe( ~4 ~/ m" A$ R
C:\Program Files\Digital Line Detect\DLG.exe* n# i0 ~+ C% u+ {! e4 _4 H5 g
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
$ q1 n3 h8 f& r3 U" M) c# cC:\Program Files\F-Secure\FSGUI\fsguidll.exe
5 {& a$ X: N/ u) V' H; E/ O6 _1 vC:\Program Files\Messenger\msmsgs.exe
/ M" l1 p# o" W( Y9 K! CC:\Program Files\Internet Explorer\iexplore.exe
; P& S0 W! c' N$ G; wC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
" p& `; ~3 Y7 U2 `3 z4 x, @6 Q6 G6 W- L y3 w
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll1 }% l: F# T' F0 K4 ^ V
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe+ m K, t( E9 _& w# q+ E
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe0 R0 u+ U6 g% h c, U2 x& E
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
% g, T) \2 R. L0 U: x$ _O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
9 f! }' ^8 \- ^7 m* R' @O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper( z* M y" O7 ~3 ~: C3 c! k
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
; Y4 \7 S0 b7 ~! c7 F2 JO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
% H# c2 G% \7 z) o( ^- l+ D8 C! Q$ YO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
. @ z) ?# n% |2 j9 q- bO4 - HKLM\..\Run: [TP4EX] tp4ex.exe
7 h6 j- J ?; A: _) ]5 z uO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
3 F) }) X6 e) [2 S) I: Z) Q0 C! J% ?& ZO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
1 F4 F4 K8 P9 i) z5 N' r* ^) zO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray7 H" L8 Z% o7 x! O* e5 L
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r4 c" Q( w2 q- H; H J* \; ~
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
+ j. o' R T y! D( wO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe' A/ S$ J# b" e% ]
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe; K, N/ F" |% R- G4 H
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE( B6 y" L9 K" |: X0 _
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE- o+ H) _ y4 j+ o- n* U! y. @* Y
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor, \0 F& n2 \& K# S2 ^3 k
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
( {$ m" g/ Q$ t; i4 o( z3 OO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration322 p3 z3 i5 Y3 P2 a: I
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE9 d4 b% U7 [ G
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
3 q* x* N5 M# Q$ Y/ ^O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC" }" k. P5 [1 N1 l
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
* t( J/ w* I& w. tO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
& {) }8 i* v% n" HO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW7 g1 N5 A2 q4 u+ c
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
`. f( ~/ w2 fO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe# x2 R2 b3 i6 t
O4 - Global Startup: Digital Line Detect.lnk = ?
) K- C" z! w1 R) B' C- vO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe( ]; U Q; l' A& _ `. y
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
/ Q) J2 D5 C0 S+ v# [! d" l8 bO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
6 }: A7 A( ^2 J: N; ^* FO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
: W" B9 N+ d, I4 s" w# KO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll9 S/ |2 U+ E+ s1 ]/ M( e
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll$ J) g( { ~% ?& y
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
8 A+ v9 m: _/ [" g6 \4 cO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
, G, ]9 W. W, Y! D% o& `O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe* j* k( N6 ^7 h& k
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll' @" h6 C9 D1 g/ \' w9 L; X/ U
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
+ @8 m; F8 R/ HO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
, ^2 N% |# N Z- k/ G6 V; ]O11 - Options group: [JAVA_IBM] Java (IBM)8 H r7 q6 ^7 K% t& o8 b* W) n
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
4 k9 d8 D- J9 CO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
! z P/ M5 x& w2 t; B) z9 f# FO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll1 S* L0 d) H/ L' Y) s! a( Z8 \
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
& m" _% ~; ?+ v$ ^O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
* }1 M5 b4 Z" h1 R3 \. b9 [+ PO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
" E% {+ R: {! F' _* xO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
" P" S. u. V/ R7 @; lO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
7 X* w4 ~( p0 B# H: x0 T/ ]) KO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe H- E8 w$ J4 f; g8 X7 | |- I
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
! B/ \6 ^$ r) W. }% UO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE1 A+ U, n' p f" L: W8 C) J T
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
+ u+ [+ t4 b) qO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe+ S6 F# ?9 ?& ]
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe5 N5 c G5 o9 B h
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
, a3 Z( {; q. wO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE" j) Y7 r2 ]- n+ `" H
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
/ s' Q7 w1 g$ T8 c" r4 wO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
; x7 b) g- h* j8 j) q3 `1 ]& F! b5 A# ]O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe/ P* h! Q* V0 g. } ~5 b* n9 z; a
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE/ \" ]7 Y! d5 R% Y& W7 w" E; \
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe8 ]! g' C# R/ h
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|