 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1* \* Z2 d" M4 x1 s) b" r6 ] ~# A
Scan saved at 16:55:24, on 2006-5-6# U/ f& r0 ]$ L: Q4 A
Platform: Windows XP SP2 (WinNT 5.01.2600)
; H4 P/ n- a+ z% H2 s; OMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180), `4 p$ j# b- J% C
# c# z9 \8 E1 r/ @' e' X
Running processes:, r; W/ u, |. k3 [' {" r# c% C
C:\WINDOWS\System32\smss.exe
1 |' u9 p. M* U1 Y, t& E6 P. j3 }C:\WINDOWS\system32\winlogon.exe
p, ~1 U! s) M, _% e3 S+ HC:\WINDOWS\system32\services.exe
; [) T9 y9 t* U# R1 i4 p. q TC:\WINDOWS\system32\lsass.exe# G9 w1 O* q5 v7 G# B; h7 F
C:\Program Files\Common Files\Virtual Token\vtserver.exe
7 ^& S L) @- i$ t6 Q1 h: X$ B: sC:\WINDOWS\system32\ibmpmsvc.exe
$ ?$ ]& h( ~4 {0 @ JC:\WINDOWS\system32\svchost.exe
~2 c8 e9 F: `% F' mC:\WINDOWS\System32\svchost.exe
, o% I- V) B- Y, k" IC:\Program Files\Intel\Wireless\Bin\EvtEng.exe5 B2 g: Q: g' e' f3 n
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe3 b& G* L" E6 b! ?% \. k
C:\WINDOWS\system32\spoolsv.exe
+ @% N1 ~0 A6 T% V4 }% wC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
+ W4 j _# M/ |8 D2 M( p4 WC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe, G5 t+ L# z3 _4 a! h1 _2 I0 i7 G
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe" t5 j6 y3 Q6 e5 G8 N/ I
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE$ Z* ~% G* e% L' D5 S/ ?$ z
C:\Program Files\F-Secure\Common\FSMA32.EXE
4 N5 }4 [' @* C7 H. r' yC:\Program Files\F-Secure\Common\FSMB32.EXE* O- c) z: t# K/ T4 V6 ]/ @% X
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe+ ^8 H; W$ b) A% n0 l, p, v
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
4 o2 ]- |$ p8 H" { N4 dC:\WINDOWS\System32\QCONSVC.EXE0 }4 W) W* I% w |1 `8 x: w, A
C:\Program Files\F-Secure\Common\FCH32.EXE7 m$ K* b& j* z, k& k* Q* q3 g3 S6 R
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe& x/ ~8 W) a, [' v
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe+ F C H0 D7 `5 u# m
C:\WINDOWS\System32\TPHDEXLG.EXE
; a! {: i4 L. V1 KC:\Program Files\F-Secure\Common\FAMEH32.EXE
2 P! O/ X7 P- DC:\WINDOWS\system32\TpKmpSVC.exe. x) @& t. L* R. O0 r- p9 c
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
+ q3 e* F4 t" s- @, RC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
3 P6 f- K: l# Y, x, xC:\Program Files\F-Secure\Common\FNRB32.EXE6 c' F1 E4 s) k
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
' L6 O a" D2 a- S& j5 d$ oC:\Program Files\F-Secure\Common\FIH32.EXE( ~! `- A4 N+ T9 U9 m
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe8 j/ E0 W( l" W
C:\WINDOWS\Explorer.EXE [" j0 a. h. {* _
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" b; }8 l+ D$ I4 u
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
9 S4 ^$ Q0 Y: O4 F8 O- B& a! ^C:\WINDOWS\system32\hkcmd.exe* L$ w) ^# k) y1 r* K4 W
C:\WINDOWS\system32\TpShocks.exe
8 g* a" T. f+ AC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
! p9 h: ^5 a0 R$ M y, u: \1 `" t0 UC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
; p4 m! N+ L$ k. j) q/ KC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
6 E% d6 U+ Z0 E0 c/ Q* zC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe# k9 ?7 W5 R4 j9 f0 q
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
2 c3 |/ U% Q5 \( V6 p, nC:\WINDOWS\system32\dla\tfswctrl.exe
0 L1 m$ F0 v. [! R5 V8 o& lC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
\- u# F/ l0 ]3 U. d# q9 q5 i9 v! Z. xC:\IBMTOOLS\UTILS\ibmprc.exe
% {& @/ d5 B AC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
8 e; L# K# P1 [( }( e6 mC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
$ C) C6 M. }7 X( z' N$ x7 G% G, zC:\WINDOWS\System32\svchost.exe
6 c1 O; S. l7 _( d3 F Y2 _, NC:\WINDOWS\system32\rundll32.exe
: x/ }3 p8 L- JC:\Program Files\F-Secure\Common\FSM32.EXE$ q; H8 ~5 O9 A- {5 h, i
C:\WINDOWS\system32\CTFMON.EXE
+ a8 e3 o4 c; w! Y5 }/ U/ lC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
/ [. N7 \* ?- F$ w3 PC:\Program Files\Digital Line Detect\DLG.exe
: @1 U* [: B1 k: YC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
! s! W0 X5 N# K3 h% q4 W) lC:\Program Files\F-Secure\FSGUI\fsguidll.exe
% \8 s1 g" t uC:\Program Files\Messenger\msmsgs.exe$ n4 a% j1 ^5 s$ `$ |3 n+ ?2 h
C:\Program Files\Internet Explorer\iexplore.exe
1 ?4 L; Z& E3 v9 o$ A( pC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
{/ k! v( k R( i e$ N
- p: o* @) p5 `2 UO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
/ F' R+ U( t) [& O2 Z: z ]O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
' v2 p4 f0 ]; `; c9 k% O& RO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe; O" s2 _) o1 p8 O$ m$ p
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
. \5 _, D! u( ^/ A( H- YO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
4 T. T q6 O3 i3 D) A0 q% J- f5 SO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper4 p$ C$ C* }) G0 h
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
/ ]4 c- f. U+ y+ Z4 eO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
3 G; _3 y; v; v' {0 H! [# Z) K) q" q; sO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup$ U1 R( y& D# D2 ^0 v
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe+ `/ v; Y0 H- Q6 v: q4 I% J
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe3 _3 ~; v" C1 r
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
/ ~& ?0 D( _% \) n2 FO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
) k: s* y9 D1 j. [# q9 aO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r. Z% i. ]$ a# O- J& ? V3 C
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
8 q/ |, c& S* B" mO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe1 j5 O. Q, p+ O, V: ^& D9 c. {# ~
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe! Q1 c# g- D3 w
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE4 d2 e% Z9 q8 o; e" \; k4 L
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE, ]7 w4 A' V6 `& c2 x
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor' ]% n: E1 x/ i
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
; v& i0 X" E/ P9 n, [5 ~2 fO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32' y3 [3 K( G7 G5 }5 L
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE) f& D. g* Y2 N- f8 v" C" s; O
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
2 m/ m( S8 w" EO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
2 K! D+ Y: z9 r; X8 fO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
/ @0 I: D8 g: B+ z ~O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash' C5 e S* N+ |4 d8 h
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
}' p) K5 o& `2 qO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
* l( U9 s q7 a/ D; hO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe+ q' M% F [+ O7 t( w w
O4 - Global Startup: Digital Line Detect.lnk = ?2 S( ]/ w: q/ m+ C; ]2 } n
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe* Y% k% m- e1 f7 O6 h
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
' |+ Q& v* j' F# d# P* D$ jO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
4 c, t; h" H( R# X b( g7 F! q0 r4 sO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll4 g( h k8 Q \( Y
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
; R0 z D# @/ M# j Q" TO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll4 g0 X& C& K5 O+ B, i; p2 D
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe& R! a$ w+ ]' ]/ ~9 O+ ]; D( }
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
% ?4 s6 ]3 B0 X- FO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe! I* B2 J( f. S
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
& N8 @0 h1 _7 F. bO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll: X5 C! X8 K; F" w
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
/ q) ^& G2 H( S" G- ?2 hO11 - Options group: [JAVA_IBM] Java (IBM)) H- [- r9 r6 ]; O" ~- @
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
, i* J; `+ u( _+ \" L2 n s" J0 DO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll& Y, a' K3 x$ e/ u
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
% C: d* _9 M( ^7 _# P& c, NO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
3 c* ^* {! R0 I, n' m4 DO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE5 C4 c, \$ P# |$ s; z5 C% Q
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe! ]' n; N' i6 e H5 F& P
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
0 P" P- Z1 M$ Y6 V2 `8 C1 @O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE0 v5 f& Q, }; p
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe1 H. [% w, f% j+ E5 t6 S- x
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe/ z3 N* ]* Y3 Z! _
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
: ~/ {! j. u: Z% SO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe; [- M4 C6 O/ z3 s. K N( [
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
! Q) D4 B3 o1 z4 x! j% R) A5 {3 [O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
$ x' \# C( Q4 D, N3 {O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)# i0 |3 b. `6 ~; r6 w# t- z
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
! } ]1 X1 _# w# [$ I8 yO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
( j& t( o9 f# EO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
5 q! M8 v ^- B9 C* IO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
# Y; Q' E8 T3 h& F: }O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
k% V* u; d3 Z" _/ B3 vO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
" k& {2 a4 R0 T- r# Q yO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|