 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1; f i+ z( r. l+ E3 z
Scan saved at 16:55:24, on 2006-5-6% z R! ~, M3 W3 r% f, w4 j6 Y
Platform: Windows XP SP2 (WinNT 5.01.2600) q" ]' A5 B+ L9 e9 K
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
% I7 J8 r3 j# |5 g6 }; U0 C
: r$ Y# ]; w% `1 \7 QRunning processes:1 j7 U" S+ [- a6 y" w1 \; |
C:\WINDOWS\System32\smss.exe
- G+ U* A# d) J1 [# s/ o R$ UC:\WINDOWS\system32\winlogon.exe
: d% }8 L' @/ x9 L$ ]; B/ [9 jC:\WINDOWS\system32\services.exe2 r! j2 L$ Z; z9 S
C:\WINDOWS\system32\lsass.exe4 _; n8 N E8 t; w% m, j/ _. P) k
C:\Program Files\Common Files\Virtual Token\vtserver.exe
% {3 o% P! P: V$ SC:\WINDOWS\system32\ibmpmsvc.exe4 P) Y. Q& r1 F; V$ f+ U
C:\WINDOWS\system32\svchost.exe
6 ^+ }- K6 H) e; }C:\WINDOWS\System32\svchost.exe! |8 c+ V: U& C) y
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
9 i$ l6 F0 d1 gC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
* U6 y8 K; \' m" |. H) q8 g, WC:\WINDOWS\system32\spoolsv.exe
* G6 W5 i2 o4 ~4 b, i, h' WC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
' R) n* [. k7 _7 d, \C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe+ P4 x( {9 C) p9 Q b) l$ M
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe' u! u( {" z( a6 X
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
* q6 e* b; B. X( U1 r6 wC:\Program Files\F-Secure\Common\FSMA32.EXE& N+ \- G' C0 J" t2 `& C
C:\Program Files\F-Secure\Common\FSMB32.EXE8 F& L3 n, Z" g. O
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe8 ?; G: `. o. M8 b8 k" I9 i
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe7 f7 Q Q: L Z9 b
C:\WINDOWS\System32\QCONSVC.EXE
! K% B$ s" K7 O& w0 o% O9 ~& eC:\Program Files\F-Secure\Common\FCH32.EXE
, e" _- @/ h8 H- Y: HC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe, m7 G5 i# x& c: v
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
! d% V. c7 Q, v& m/ T- `; eC:\WINDOWS\System32\TPHDEXLG.EXE
% T/ R0 j& J! ?* w$ N; QC:\Program Files\F-Secure\Common\FAMEH32.EXE
2 y+ n; M$ v7 lC:\WINDOWS\system32\TpKmpSVC.exe1 Q% f8 h$ j6 a1 e* E4 x
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe! R! z% N) X1 Y7 x( {% K; s
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe$ _. T1 ]1 E5 U) \1 @7 Z/ A% l8 r, h
C:\Program Files\F-Secure\Common\FNRB32.EXE
0 }+ C: b0 D' dC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
2 E: q# b) P7 b/ {C:\Program Files\F-Secure\Common\FIH32.EXE
" i' Y& L! K: CC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
2 {6 b3 g2 S J) }+ B% HC:\WINDOWS\Explorer.EXE# y% i# F: V6 }% z7 m0 r, Q, `
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe, t4 z5 h! I' y$ }' i9 b, q
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" M+ V# X; J1 m
C:\WINDOWS\system32\hkcmd.exe; x1 ^1 f# R1 M4 @
C:\WINDOWS\system32\TpShocks.exe2 o7 y/ b# \/ {0 O9 i
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
3 T! j+ t; x: j; _C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe& P9 a' G7 o- I1 ?+ S
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe% i; d5 Y6 ]+ f: P1 T; Q- [- R& v2 a
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe" D* G; i$ z, O9 {- b
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
5 g" K! o4 K/ F0 G) V" r% jC:\WINDOWS\system32\dla\tfswctrl.exe7 h, Q1 K+ Y4 C' U6 }7 l6 y
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
8 z& Y/ S" L" p7 u$ aC:\IBMTOOLS\UTILS\ibmprc.exe
2 I8 V ~3 L- u' T4 ?C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
0 R+ B0 h) x6 X' `C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE8 |# ~* U( H- f
C:\WINDOWS\System32\svchost.exe. T* |" w& P8 ]" [; i; Q& H* _
C:\WINDOWS\system32\rundll32.exe6 u: I! G, j) ?8 `: D
C:\Program Files\F-Secure\Common\FSM32.EXE
7 u; P1 T$ [+ @% LC:\WINDOWS\system32\CTFMON.EXE
" J8 P- |$ }1 zC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
0 m+ M2 K- x. N i- w1 n& r/ _C:\Program Files\Digital Line Detect\DLG.exe* @) X7 ?! ] I5 E( R
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
) K# ~/ k; ~5 U/ K' Y; IC:\Program Files\F-Secure\FSGUI\fsguidll.exe
/ s% {, {5 g6 y0 |, V; hC:\Program Files\Messenger\msmsgs.exe
- g2 v2 ]$ |* a8 u) i1 [" Z( rC:\Program Files\Internet Explorer\iexplore.exe3 U0 c T6 U7 I
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe; k8 D8 S% K% [' x
3 J+ x- f7 S7 u) A2 O7 i' H
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
6 g/ u. ~# A9 Y& o" t H- ]O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
9 g( j5 z' D% `2 [6 b$ I* FO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
4 W! _5 M8 C g: E: IO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
! a2 M3 ?" @, w9 ^4 |7 u0 T& xO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
6 u: o2 `7 [6 L$ \4 YO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper$ a7 b$ C( n9 J8 q4 o
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
$ A, Y0 ~4 J0 D# R |# cO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
! c& X% @2 _/ O" P$ x0 |2 y% R6 CO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup+ Z% t! E9 Z" }8 t' Y, a
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
" c3 O" q& d: \5 K! r3 @. H7 R4 A% kO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
; z; L i+ f j6 `* EO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
" `/ |9 K. f* oO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
8 s0 D' y, R8 fO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r3 N, X) G. g9 I7 D, _; n
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe* M1 x+ Q% E6 t; J) N D6 w
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe1 B6 [) c) _8 X9 A0 c8 I
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
3 ]' Q4 P8 e8 ^- W) EO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
5 I( i, c( D$ R8 _8 q5 sO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
+ c! q( `- V9 `. ?O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
% E" |; m4 f& y' L* VO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog5 e- d2 a' f; V1 w Q3 a a
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
- ?% w( p% J& n& p X% J3 }0 C. |O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE- _) I) \ A* H& ]
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC T$ u7 ?, E u! w+ m3 \4 I
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC8 M8 n+ d) J" a* G$ A7 ^
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
4 W9 X# ~4 [1 pO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
0 e# [$ }* o2 M8 n0 sO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
- N1 A5 b! s0 ~O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
9 Z9 N! X A4 B) r) |* ]O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe4 r* L2 l( [. f0 }
O4 - Global Startup: Digital Line Detect.lnk = ?6 _2 b; o9 h6 r% \
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
) d& J/ Z5 ?4 U% v, v) l- uO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm0 A% q/ _) T# m; `: p: Y
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
8 z$ c- q5 v. f1 r* [& ~% t% PO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll0 |* B; ]) {; t! d& `/ u
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
7 M+ O6 B6 ~( l; J' IO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll/ R4 K6 Z7 u- W9 u3 V
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe- s* q$ d: p) E% z7 e, O
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
1 I, n. Y, j) ]1 C: Q9 \O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe7 Z$ Z' l4 [' V/ e8 G
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
" q+ y6 K- Y, Z: [; Y2 HO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
9 K* b. `% [( z& g' UO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
) x" m0 E+ \( YO11 - Options group: [JAVA_IBM] Java (IBM)& ~/ l- Q6 i% C: V7 {1 y( F
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
" _4 N0 |0 y& B6 {% Z2 pO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
, N, d+ P+ R/ f, E* I8 a2 R( zO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll4 S+ I7 y( V0 Z7 D! t+ w6 q
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
8 Y; q8 m/ {) m* {/ {O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
$ U' K$ w) L' o( CO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe2 U* G6 |. |! N
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
k) u- `" K, `7 `O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE, Z% y$ b6 G! g. a
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe4 Z" t/ \- f: M/ H4 ?
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe9 o1 P! {( w, w" `2 y- n
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
8 P9 R: n7 M3 @* d" T9 vO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
5 ?7 i/ u `; U# `6 dO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe. q7 w& f, k& A9 I0 Q+ D) g
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
/ u) Q7 K) v; mO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)8 l2 I2 E2 K; ^3 R
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
4 b& ]( k8 W% X4 N$ h8 gO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe# z: F) X/ W: G/ h1 V1 _
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
w& t- @- t* N C HO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe% w7 `" o& R& c9 ]) N7 k) w+ z
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE! \2 L4 x: v# D$ Q% K
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe2 h) C% @1 \8 ?# R4 c* o
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|