 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1$ I4 K e" Z& j8 y9 T
Scan saved at 16:55:24, on 2006-5-6
9 Z* q4 i7 d& K' u5 IPlatform: Windows XP SP2 (WinNT 5.01.2600)
. W, R- C7 T" I- {; WMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
, ?# ?. \1 Z3 c- h
- R& J s( c) m0 F( J$ yRunning processes:
% |! n; G/ I8 `' G7 @) v' @4 pC:\WINDOWS\System32\smss.exe" s" j7 k4 e: g4 [) B* T% x
C:\WINDOWS\system32\winlogon.exe+ b# c* t f- L6 U# }8 s% W- i
C:\WINDOWS\system32\services.exe# l/ m" h/ e2 b o+ r
C:\WINDOWS\system32\lsass.exe* T5 @$ C( Q/ c
C:\Program Files\Common Files\Virtual Token\vtserver.exe
. `5 q, ]1 Q; y9 CC:\WINDOWS\system32\ibmpmsvc.exe
2 a' K) A7 ]) A& d$ `7 AC:\WINDOWS\system32\svchost.exe0 @/ M/ R: B% k) J, }
C:\WINDOWS\System32\svchost.exe
) y# E+ Q3 u: ?- o3 m9 @# l; _C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
% w) o4 o, ~$ KC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe G) R7 s: h3 u6 G8 [
C:\WINDOWS\system32\spoolsv.exe/ e! ^1 e% W+ K. {# a
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
. x6 q+ r# L/ _6 }; @& }. jC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
1 G2 C1 E' O% mC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe& W' B2 H% v, F& f- k
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE; m' U- }3 @; k% c1 z
C:\Program Files\F-Secure\Common\FSMA32.EXE6 ^* F/ ? ]1 [% M
C:\Program Files\F-Secure\Common\FSMB32.EXE
& Q3 d# d/ o& o1 ~& mC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
" c7 _& K" P* \) NC:\Program Files\F-Secure\Anti-Virus\fssm32.exe: }9 \: G4 o6 d- D; ^5 V
C:\WINDOWS\System32\QCONSVC.EXE
, y6 j. A G4 b0 v, ^8 q1 ^% t" QC:\Program Files\F-Secure\Common\FCH32.EXE
- i! W0 C4 f7 X ]4 rC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
`9 {' l$ m7 T6 ?C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe5 F3 h! k" { q. G, E% ?! o! a
C:\WINDOWS\System32\TPHDEXLG.EXE# x+ h8 B& P2 a# i
C:\Program Files\F-Secure\Common\FAMEH32.EXE
5 n g- e3 Y/ |% uC:\WINDOWS\system32\TpKmpSVC.exe2 F( e; a; m9 D6 N- Q. ^0 ]
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
' Y/ @9 a0 X; E0 I2 Y0 KC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
) D8 ], Q7 {# A% pC:\Program Files\F-Secure\Common\FNRB32.EXE* N: P! L6 u! E' l. m$ m' E$ m
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe# P7 y4 F5 H( @% \+ {+ m
C:\Program Files\F-Secure\Common\FIH32.EXE) y( I; e9 |/ v1 @* \
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe: ^% q. Z# W; q3 [2 l3 Q
C:\WINDOWS\Explorer.EXE4 U0 `& e9 q+ X4 m9 R" b
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe4 u: c6 d9 `8 V, S/ C! b* t
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
/ C9 K' C$ @* u% aC:\WINDOWS\system32\hkcmd.exe6 E! {- C3 A- t. K7 a( N
C:\WINDOWS\system32\TpShocks.exe
7 k5 R$ Y( v) m9 ^/ |7 B9 }C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe: b8 l7 R2 _* j5 d8 s+ o
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe' w* Q9 ]3 G4 p ^& t, w
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe; D( H/ S' w- z9 j
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe3 q. s' E# k6 D, i! X, I+ U
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
, j8 X0 l9 X V* |6 t' m8 _ hC:\WINDOWS\system32\dla\tfswctrl.exe
7 j1 m$ k- {3 iC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
9 _/ W0 k( w) s/ [' X! o7 A" pC:\IBMTOOLS\UTILS\ibmprc.exe
! c! L8 m4 [7 _3 X' YC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
8 o1 ]$ W" g# g" cC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
/ [: X+ ]4 \8 l: z7 t6 @7 GC:\WINDOWS\System32\svchost.exe
) a" q: a( ^8 l7 j1 h2 g V" cC:\WINDOWS\system32\rundll32.exe
& q7 ?* `( R0 ]7 L/ y6 H# j: VC:\Program Files\F-Secure\Common\FSM32.EXE
: }6 Q& b9 Q$ M1 W% S, f# OC:\WINDOWS\system32\CTFMON.EXE
, B. ?6 R) K3 l5 a h1 VC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe% p; r: z' N; e7 s" w
C:\Program Files\Digital Line Detect\DLG.exe: V& D2 K/ F3 S; t/ ^
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe! K" U: T6 u# ]: z, M9 ?& ]) ^) t
C:\Program Files\F-Secure\FSGUI\fsguidll.exe }. [3 |; Y( f* I# f
C:\Program Files\Messenger\msmsgs.exe
2 d( S6 Y9 q/ e; Q2 w) EC:\Program Files\Internet Explorer\iexplore.exe+ V: q, N+ S. G7 m
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe- l( R7 N4 }: I1 B2 q, N# P
! X1 c3 k1 }% l0 ?- s6 D r8 A9 tO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll8 G% b- b3 f' W" X- K
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe7 z9 T" y5 ?+ |+ Z J
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe+ ]* V* y; m: Q" W; B# O1 `
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
+ s; S& |) }$ ~" S$ E. V: m7 }O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
: u, h& [ M ?& C- [) z4 oO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper& k/ C ~" c; T" X) M
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe A! G; N& ^! J# J( G& N: w
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
$ y% ?$ \) f$ t& e9 N& I1 bO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup2 i4 \ N5 r/ D; b! p$ ~5 i, u# }
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
3 ]1 {2 x/ E0 t( B( gO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe9 Q# c! p3 g0 K7 K
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
0 y8 G: x# E: C7 H* y1 |O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray' ^9 G/ X0 L: o' _! \; Y/ S
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
0 h; S, }+ U2 O# FO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
& _: `4 I" W& v. aO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe5 ^. P+ o8 r3 f1 f
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
* \+ k6 z2 B A" N: V3 y, Q, vO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
3 }, K+ w1 D! G9 s' EO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
3 Z, B0 O' C7 t) p% |1 U+ WO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
. q8 k0 K/ y4 b4 Q% ]3 ]; N1 J. I$ zO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog0 H. j; |. k6 ? F2 C
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32+ E* R$ r' R9 C0 W4 ?
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE* M e0 L! c2 S1 C& Z% K3 i9 S0 _9 B
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC2 n) ^& |. A7 b6 ~7 [; F
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC! m) b. ]( S$ {0 D* I8 Z3 B
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
- A9 b! _0 Z; W5 \1 a5 v n& W4 rO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
8 k- @& ^8 i: [9 o" K! B4 ~O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW6 C" h# |0 B* u, \
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
1 L8 c% ^" q+ r" O4 BO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 Z$ S5 z9 V) L, I" aO4 - Global Startup: Digital Line Detect.lnk = ?
% j! v0 u* z, ?8 }O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe( P+ B: k3 \6 i) f* @
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
+ F2 p$ ^& J8 E, `0 Y) r' H" xO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll4 B+ v4 i5 y3 b& q# ^" \3 i& C" i
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
- y& J( f& z. j5 x0 SO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll2 S/ t' P6 \, L' h
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll2 _$ M s7 ^6 Q; E; G9 w
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe2 I2 s7 y; v" U( f( y
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe- L9 j, V. e. m
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
1 H% s2 y5 t1 @; x) t" jO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll! k2 ^0 Q3 N8 S7 O2 S8 S: E3 \
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll1 n( E- B0 {4 E, T( A
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll+ K3 O# {% W. u
O11 - Options group: [JAVA_IBM] Java (IBM)3 p' D7 _$ [# X4 F
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll% I1 y2 d8 N0 A
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
4 M- j/ C/ H) C2 g" z ?O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
/ s" y3 @2 ?+ J" s. C: lO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll. u+ ?" X& u, p* _" d
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE' F& k& _8 G2 V# F# ~8 e! U1 t
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe1 _9 S0 j# ^) U& t0 q, u: \
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
! A" V! h6 G% XO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
h: `: ^" C' M* s* G4 I1 r1 [) R1 |O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe# z( |+ N6 t3 Z- T
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe6 k# ]9 P) ~1 m% Z
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE+ x6 y) u! C. t# y
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe- l" Y" F) S$ B# y
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
( m( c% r: p5 l- EO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
X7 u6 G6 f0 C/ `( m; |) IO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
z3 [3 Y- R5 {! HO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE" h. G4 Z) W2 W/ V
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
7 r1 b+ j$ Q4 u' NO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe0 S8 F' r2 T) a t8 ]: R
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe0 L5 W9 g2 i' T+ F% o
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE+ |% {5 n, T% L6 c% W( E
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe, N) v' y' c7 z/ e+ S
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|