 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1- l& P3 W. W) w, [, F% {% K
Scan saved at 16:55:24, on 2006-5-63 P/ k* o( y- ^! x, s, O: o! X/ @
Platform: Windows XP SP2 (WinNT 5.01.2600)
) j4 M4 M; k9 FMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)' Z2 r# b- I+ x; i
5 a8 [' ^- V* ?6 D; s, d4 a
Running processes:' m/ e& p) y* h0 C/ P" ^7 x, {' K2 _
C:\WINDOWS\System32\smss.exe% J' s. z+ @4 {; S3 y5 t e6 s
C:\WINDOWS\system32\winlogon.exe/ q5 y. G; C3 T* p. Z
C:\WINDOWS\system32\services.exe
! j8 ?+ r6 {1 z- h$ ZC:\WINDOWS\system32\lsass.exe
$ D2 [8 B2 z* f& ]; dC:\Program Files\Common Files\Virtual Token\vtserver.exe8 @* G; \* s3 {. S: l
C:\WINDOWS\system32\ibmpmsvc.exe x3 f. E$ x+ z$ }
C:\WINDOWS\system32\svchost.exe
+ G6 W) J1 i" GC:\WINDOWS\System32\svchost.exe
% u! ?6 X& ^5 A6 sC:\Program Files\Intel\Wireless\Bin\EvtEng.exe1 `8 T! r3 M: I1 g' o, l; B
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe8 r2 U( P; I$ N/ z) P- `7 e3 N
C:\WINDOWS\system32\spoolsv.exe
' K7 V7 }0 ` f5 G5 VC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
$ U, D5 W0 k8 D0 g1 ` G0 wC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe" n6 v- ~0 u$ F6 R3 T
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe9 Y4 o/ ~' h( Z1 e' c
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
+ i2 n/ D8 d& y1 n, e( bC:\Program Files\F-Secure\Common\FSMA32.EXE% L. j; N1 J5 u* a; Y! _1 U
C:\Program Files\F-Secure\Common\FSMB32.EXE1 L. @8 F' ~& j, H9 j/ R/ X
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe& Q, G, }9 f2 E7 W5 |, H+ s
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe( L8 T; B+ Y$ S3 H" Q C
C:\WINDOWS\System32\QCONSVC.EXE' g2 W) X$ _. ]1 f
C:\Program Files\F-Secure\Common\FCH32.EXE
1 P+ R8 J, e \; j( HC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
& g8 W5 [. \, @: P. ~+ fC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe A% x1 |0 d, Y/ z. F
C:\WINDOWS\System32\TPHDEXLG.EXE& z# c& J8 n4 b! X
C:\Program Files\F-Secure\Common\FAMEH32.EXE
* ^$ R- f* l3 h" G# d# uC:\WINDOWS\system32\TpKmpSVC.exe
. M+ t5 E' A* |4 D, s7 w% fC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
' {# Q' Q8 n8 E. p3 Q2 P* H& TC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
9 ]4 r. F/ B2 |" j3 j# a; J% MC:\Program Files\F-Secure\Common\FNRB32.EXE( G# F) J1 B* E3 q3 [% y
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
1 L3 N4 }# \7 G6 O5 i' M) SC:\Program Files\F-Secure\Common\FIH32.EXE
' u% J9 U) ^1 N7 [C:\Program Files\F-Secure\Anti-Virus\fsav32.exe7 T+ M, b) _4 B3 |" k
C:\WINDOWS\Explorer.EXE
0 d$ V; z7 G o2 x' EC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
5 r- o0 I [1 a: w7 v& x4 bC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
$ R" u T2 M* {1 JC:\WINDOWS\system32\hkcmd.exe4 w! s6 {; t" M. `$ F4 U$ P
C:\WINDOWS\system32\TpShocks.exe1 a7 K" z- c" @) m7 i3 e1 F
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe0 S& ~! E8 q) ~4 ]( |) [ b- ^
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe- V/ y0 y% A9 V/ C8 X
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
5 \6 l2 Q( @6 fC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe& K) c4 b- N2 u8 p% c. ^( n4 A+ {
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe D( f! U* E2 M' d: ]- R
C:\WINDOWS\system32\dla\tfswctrl.exe
4 @/ d9 T& d$ X& A4 X& J! ZC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
( |% W. x0 h( H) q& AC:\IBMTOOLS\UTILS\ibmprc.exe
% e9 v5 V0 S* G) R+ b+ JC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE1 [" L! W& x$ k
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
1 G$ Z) V8 _3 k3 y W( i! L6 vC:\WINDOWS\System32\svchost.exe( ~0 |% E# D. i/ l! _
C:\WINDOWS\system32\rundll32.exe# r' _1 |& R6 [' y& O
C:\Program Files\F-Secure\Common\FSM32.EXE
0 F y5 Q& @& jC:\WINDOWS\system32\CTFMON.EXE6 O; P0 A& m q% o G) ~& \4 v
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe: I$ O( e$ ^! U8 ^1 a/ d
C:\Program Files\Digital Line Detect\DLG.exe
6 M$ a- ]4 |0 ~: d' K* l* GC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
: {5 z: b, o( KC:\Program Files\F-Secure\FSGUI\fsguidll.exe/ C# k2 F" V3 i. {/ g. E
C:\Program Files\Messenger\msmsgs.exe/ `0 n& X( E" H t9 M* k
C:\Program Files\Internet Explorer\iexplore.exe' W" z2 ?! c0 {# k' i ^
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe3 I* i: i1 _1 h5 Y5 y1 X
+ ~6 z; x) _1 J* {. I! z4 b R1 q0 J. T
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll# L5 ~2 [4 r& t2 R% W5 B3 Q* u
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
$ D8 p5 S% u. I9 GO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
, h8 ?6 ?% l$ D' l& |; ?1 OO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
4 U' j. ]' Q9 X) u+ p# |O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
: m) `0 f0 ~) |9 Q; gO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
" r6 F# B: m" v% PO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
! J. t. C# r1 m" QO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe6 q: H2 G' Q8 B: @' f( O- c
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup8 Q2 h" ?1 A7 S; v
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
q( p; C9 `+ Y2 h9 q" M. x8 [O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
7 S% n" P; S* H8 ?& ~O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
, x0 i0 q& {3 T4 {# lO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray; z/ _* t1 M, [& }$ i
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
* d) w0 B6 L) k) jO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
" m1 \) g) U% v% l4 m. UO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe- d5 J* M% B% g; K' c! j( U
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe; P/ s$ P3 I0 T4 l! m
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
1 |; S- H# g8 c' ZO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
9 U' }! k1 Z( |5 oO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor) m) ]6 ~/ n1 d
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog( K/ ], x2 S+ F M
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
; M& t. U" D& `/ O. ?2 @O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE5 W) @* D4 _! z( V. F' l" G3 Y
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
0 @+ Q. H" S9 b9 i* B. eO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC. A/ V1 J+ P' I7 D/ ^1 W6 n
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName3 \. V7 X8 m: q
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash8 V* K( F. M# i" C$ k8 e9 T
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
8 I4 C) H- a C9 I) T6 S! }" {O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe% |! F/ N/ O, t/ m
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe5 U1 E Z5 V- R) K# H8 }" P
O4 - Global Startup: Digital Line Detect.lnk = ?
9 ~( _; O% L" O" ~, } T& _O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe; ] f+ U% i4 x8 N1 d
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm& {# R( L# q+ w6 {7 v
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
G& c' X) a' h5 z$ OO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll, O4 y+ k/ t4 V4 ?$ S
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll6 n7 [ \% Y! C0 l, L
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll2 H* y# B" w9 y( p1 i; A2 I
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
# B+ O& M4 ~. KO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe" q! R8 k- e; B* y9 d* I
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe! J( A' Q! q- D5 p3 X7 M; T
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
, g5 C! E9 o* B: tO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll8 V7 w) m9 f L4 { l0 t4 q9 \
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll* k7 r0 |# @- Q; d& h, |0 v! m. ^1 V
O11 - Options group: [JAVA_IBM] Java (IBM)) B0 V7 i; \( U( u' P/ d
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll3 P4 u- r/ j0 Z- c3 H' x# ^
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll% ^, D% M9 h) V/ {$ S/ ]
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll# u# b% _- u3 C% s
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
/ k, G" a$ b# C* z' CO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE* ]3 E" v, Q' c% h- o) [
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe, ^5 R1 Y- w+ m/ H
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe) l- L" `1 x( ?+ [ _
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE' B, `& U; E! L1 A! z F
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
4 S- m# M( ^# R# CO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
% |; v0 e4 N5 o2 rO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE! s: [; H- c* s) Y/ U5 \" P; I3 d; E
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe l! o8 w O! N
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
" E4 d7 V% B; hO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe" K$ D) Q& S5 o
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
' w+ I$ U4 ?1 m) t: ? _O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
- M' m* B6 F3 PO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe+ L- |3 e: V& I9 u7 L
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe8 u2 s! \. {( V( u K
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
1 d5 t3 `* Q& j3 FO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE; y* A( p) H: ~' f- ]# e
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe& G* Y( f4 u+ y" _: j
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|