 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1* `% |( _7 f$ Q4 h, r9 Y% L
Scan saved at 16:55:24, on 2006-5-6; A. r. m; j. y6 S' o
Platform: Windows XP SP2 (WinNT 5.01.2600)
3 d$ E: W1 D0 RMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
9 F" C, Q8 ]+ ?1 e, d
# e9 d9 W9 U9 o2 [" ?# fRunning processes:6 g- p8 R5 c# Y. g6 ]3 Y* W
C:\WINDOWS\System32\smss.exe: d7 H# I! y) h* W" X
C:\WINDOWS\system32\winlogon.exe
$ M# x; G3 J7 h/ a% O: yC:\WINDOWS\system32\services.exe0 r- @/ K: F, \
C:\WINDOWS\system32\lsass.exe
: x6 t( b1 o, Y4 j1 NC:\Program Files\Common Files\Virtual Token\vtserver.exe! v) q' q6 y" L) j+ b: P
C:\WINDOWS\system32\ibmpmsvc.exe
1 t; n5 q+ L" j4 QC:\WINDOWS\system32\svchost.exe
$ {& g* Z5 A5 l6 ~' ZC:\WINDOWS\System32\svchost.exe. _4 C0 Y9 w6 t% g
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe# H* T8 B$ p/ j/ s
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe4 J) v/ K7 \" I9 o, l
C:\WINDOWS\system32\spoolsv.exe
& X9 c& |3 `! J: d( P" ~C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
1 v b; o: b1 x% zC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe `7 Z+ c9 T: A1 N- H8 |
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe# @# d. A# \" f# L0 y
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
/ H, b& x7 z+ |6 kC:\Program Files\F-Secure\Common\FSMA32.EXE" ~& @" t/ d& {. [/ {, y( n; s8 u* Z# i
C:\Program Files\F-Secure\Common\FSMB32.EXE% \8 S! s% P3 o* W
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
% ^" W: y4 R2 B4 B& B9 u8 WC:\Program Files\F-Secure\Anti-Virus\fssm32.exe
3 R" T& Q( @# A( V1 L0 J7 a( ^C:\WINDOWS\System32\QCONSVC.EXE) [1 }, U- r) n8 ~, I B
C:\Program Files\F-Secure\Common\FCH32.EXE% ~5 z0 W( N& W$ w
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
# n- Z; [7 t; ^C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe8 j0 V7 K, R- ~) q7 G
C:\WINDOWS\System32\TPHDEXLG.EXE
! A! s+ P/ A4 W0 WC:\Program Files\F-Secure\Common\FAMEH32.EXE
* Y+ Z& r6 B2 E9 hC:\WINDOWS\system32\TpKmpSVC.exe- c) M% h2 }3 M/ T0 } e1 C, x4 |
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
" V: v) V4 d6 t; Q4 g) |! |; @C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
4 O5 o( K9 k: h. ~0 x& k, i4 sC:\Program Files\F-Secure\Common\FNRB32.EXE6 ~* d3 R* G- y5 B5 `
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe6 G% {: f. l1 d* a% h2 t4 U
C:\Program Files\F-Secure\Common\FIH32.EXE
5 n: f" D5 Y1 G' ~1 CC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
: O) a- t# r7 H. }C:\WINDOWS\Explorer.EXE
0 [$ F" S. H: v7 EC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
+ }# H/ b' m) ? |0 GC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2 ?/ b g+ h6 s# a' @: [C:\WINDOWS\system32\hkcmd.exe3 D7 j5 y4 C) F# ]- }- J9 `: T. A' P
C:\WINDOWS\system32\TpShocks.exe% l- a4 s0 f( @# I( \9 Q
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
( ]6 r' w& D' B# g1 E1 t( X0 yC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe7 q$ p i9 O0 q) k
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
; x0 r% k5 e0 ` ~. q P3 LC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
# u8 N( {) x" c6 B7 d% GC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
4 @" a- a: w' C3 K& p# ZC:\WINDOWS\system32\dla\tfswctrl.exe
# e& n1 Y; N O* ^C:\Program Files\IBM\Messages By IBM\ibmmessages.exe. y* |8 F9 T! _3 `
C:\IBMTOOLS\UTILS\ibmprc.exe7 i/ ?& m7 V5 _0 j: a5 ?( a
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE8 G+ k( B; h: D* M$ Q- e# `
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE+ p6 e7 n8 T2 g; r
C:\WINDOWS\System32\svchost.exe
/ ^& d$ P; S" fC:\WINDOWS\system32\rundll32.exe
: s2 N1 \0 }4 h$ x6 h# M9 }; DC:\Program Files\F-Secure\Common\FSM32.EXE! U* u: c3 j, W8 f4 \! O @( M
C:\WINDOWS\system32\CTFMON.EXE. ^* z) b R' a. X5 [; f
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
: `$ q1 @! O6 T1 ^' F# Q: @C:\Program Files\Digital Line Detect\DLG.exe: [1 @ t& Y; ]! `" B ~1 G
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe/ p! j6 s; n# i" C0 t- T
C:\Program Files\F-Secure\FSGUI\fsguidll.exe; K2 H# c% b# w$ B8 z
C:\Program Files\Messenger\msmsgs.exe
. ]% B% }& I0 p6 v& O, l" a- jC:\Program Files\Internet Explorer\iexplore.exe1 ~8 O0 s) _: y
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe7 f5 w5 Z1 q$ |5 ?/ }, u& Q
, t; J& I- k! J7 Y- {+ |. CO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll- H- v4 h: Y, a8 D
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
: P+ O& c ~- E. R% `' `( nO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe$ x0 I) y/ G# {
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
; S: S/ y$ M3 v5 vO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe4 ?/ x0 b6 |5 B+ M4 k
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper! F; N/ A% R6 z! \' l
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe- |* T- j& m* Q! m5 Y3 |" a- I9 P
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
4 m( u' @3 j$ R% s' E1 C. gO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
/ [- l# [1 l: dO4 - HKLM\..\Run: [TP4EX] tp4ex.exe9 L+ Q( X/ Z. j; J3 u6 _
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
$ O, F4 d- M1 E7 o7 DO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
9 f" O6 X# W1 q U/ k4 X. i8 yO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray% H) S! X, a" i5 F0 j0 K
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
J9 `7 y( `& C) b* F7 BO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe& l1 W; C* ^& ?; c* V
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
3 z' _# T9 H' X0 E! u6 \- K; }' i% pO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
( ~' M1 E) U D! q/ l1 X0 dO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
' u1 T6 h; e0 c: @- ]O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE/ C: K R6 D. C& |$ J
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor: L+ ]9 c& w$ O! g* a6 P8 }
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
w y! ]- N$ W0 {" b4 g$ V. AO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration324 k9 {! s X2 _8 d
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE8 V. h" G: C8 V" v1 n3 [
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
) N& C9 [) n' F; FO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
4 Q7 V) _" B+ o5 o2 N, zO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName( K3 k6 Z9 a$ g2 v: v5 [% i/ x' S
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
) z4 M$ w. v) k" g% l' \O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
+ a6 m2 M7 f0 K6 n. @) sO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
( B5 }! c; @# a/ D C' v3 U( mO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
5 A9 T6 R/ C2 |/ `# m# PO4 - Global Startup: Digital Line Detect.lnk = ?
, A+ r2 m* N2 r9 S) LO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe; L. g. u$ _2 `! k9 ~
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm1 F; o: o8 J0 j+ @5 ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
" j; q0 T% O/ E& {* c! {O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
# _$ a* p7 A5 U0 XO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll* f% a$ p* Z/ F) Q: R
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
0 w1 s! i! c# `! {, xO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe. n3 t) p) u* R" J
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe3 k8 z5 n9 o* |! p9 p
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
6 o4 u& }, [) |+ W3 H. r" _O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll& l- Z2 O+ ?' z' O
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll9 |1 w, Q/ @, c6 T' C
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll/ t+ Y m3 F5 A6 v5 _! p; {
O11 - Options group: [JAVA_IBM] Java (IBM)
: {, f) X. A% [+ ?) x9 W9 Q$ KO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll& H u5 |: \* D- H! O
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
8 i; m: u1 n8 o" G" m9 F" ]O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll# e. U# h% ], B9 ?' a
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll+ l% f& W9 R+ \. y
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE6 ~2 ]1 J5 i+ m0 Q4 H: M( w
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
; ]( F- {5 m% B; n! O& eO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe P: E- t% _1 ^
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE) T6 Y$ C/ h3 G) V7 H: x7 M2 D
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
& L2 h* v, [% F. X1 M+ N$ { _( BO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
! v* x6 w: j0 k" A% yO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
8 G; l9 |" q9 i' V/ ZO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
3 `* p6 A# |! |* [1 u1 @/ yO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
8 U: F; Y7 Q7 l+ bO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe' w. |# m' @6 v+ T/ E2 L$ `
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
) L5 }# u2 ^' ?0 U, rO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
, @) I0 d5 f0 ~, W+ r7 _) K+ oO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
5 \- _) b5 K9 K( y, L9 H1 wO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
% U) O( w9 C0 j( m: W# S2 s5 n6 rO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
$ ?/ v& o2 H7 LO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE& I* A1 p/ x0 e8 B3 h* @
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe7 [7 n* T, `4 G
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|