 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.12 [% x3 \9 C" I# X" ^! R2 r P5 L
Scan saved at 16:55:24, on 2006-5-6$ c- r# T! r: k4 W6 ]
Platform: Windows XP SP2 (WinNT 5.01.2600)
" N3 j0 i: c! p, EMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)5 E9 B9 Q0 ~/ Y& ]
- n$ I# n6 v# Y* k4 T) w2 FRunning processes:
4 }$ ^( }/ C- Y3 w4 X* [; U! H2 \C:\WINDOWS\System32\smss.exe. S6 L9 t, L; \, j4 t7 R
C:\WINDOWS\system32\winlogon.exe3 u: y7 v. s) K
C:\WINDOWS\system32\services.exe" m1 K# r; a" N: _6 T6 N% ` v
C:\WINDOWS\system32\lsass.exe4 i0 S i; P* {
C:\Program Files\Common Files\Virtual Token\vtserver.exe, }. o. B. `) @2 v
C:\WINDOWS\system32\ibmpmsvc.exe$ t# s2 D$ c+ S4 Q
C:\WINDOWS\system32\svchost.exe9 Y$ L7 r K. H& b8 I
C:\WINDOWS\System32\svchost.exe0 z0 n+ W* U/ ]$ C: P
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
. _$ E+ A @6 q" t1 rC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
* c$ b) X$ a3 X5 UC:\WINDOWS\system32\spoolsv.exe( T& D6 U3 _/ m
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
- d+ ^, ^% K3 m/ LC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe; v- V" X- G: g7 q: y- b% R/ L
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
% |4 F( @8 f- c* ^; A9 c" }C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
2 l) F9 m& F5 J. kC:\Program Files\F-Secure\Common\FSMA32.EXE
5 L5 D4 M& x k6 |* h6 EC:\Program Files\F-Secure\Common\FSMB32.EXE; n& z* ]- n' M# x9 G1 k) H
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe/ o" G' }+ z: c: B) i
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe! P9 ]# v, ] m. C1 e
C:\WINDOWS\System32\QCONSVC.EXE
M+ e. U: W3 a$ H1 O% }& bC:\Program Files\F-Secure\Common\FCH32.EXE
3 X) M$ b5 K# N$ O3 EC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe, @% w; i: A/ t5 K+ I
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe9 F4 r, h: }+ I+ j, r! Z
C:\WINDOWS\System32\TPHDEXLG.EXE( _) \7 u3 R6 ^/ D6 z9 z
C:\Program Files\F-Secure\Common\FAMEH32.EXE' w4 S4 g' n' _( y/ v; P# w
C:\WINDOWS\system32\TpKmpSVC.exe" k m3 h5 @5 Z- P5 E/ S" x0 u6 g
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe1 y# R7 f1 }; O5 N+ C# z
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe3 t) F& S, U" ^. w. ]
C:\Program Files\F-Secure\Common\FNRB32.EXE \( |4 X2 X4 v2 c7 Z% L# q
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
1 S) N5 n s4 D# {3 g0 Z9 E! iC:\Program Files\F-Secure\Common\FIH32.EXE# ^( i! V" M( d' ?& |* H* ?
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
4 x, V, _! G: ?( F0 }C:\WINDOWS\Explorer.EXE& H/ }7 S* G$ z4 E
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
2 m/ p7 m# e+ [8 B8 ~ aC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1 W1 `+ B4 F$ d* kC:\WINDOWS\system32\hkcmd.exe
: D8 u( q; q$ b7 K, ^, J. p! tC:\WINDOWS\system32\TpShocks.exe
( A# ]" A/ t0 @C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
K7 } n& ~. n9 o9 R, i5 VC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe% ~, R8 D. `+ i3 N8 y( l
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe0 a! f [4 Y! E$ @# X9 _
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
7 `- E6 R- V, _2 |8 R# rC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
' Z& h* t: j9 o' K/ CC:\WINDOWS\system32\dla\tfswctrl.exe" m, z/ \3 @. N7 C; r2 k
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
9 m2 J5 E8 F" L( f, I+ h6 @C:\IBMTOOLS\UTILS\ibmprc.exe
, n* x- v: _* z1 A5 [C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE8 i/ @1 }& k" U" q
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE. C# V0 I' J3 h2 @0 g a1 g
C:\WINDOWS\System32\svchost.exe
) L2 o8 o1 A8 z* [C:\WINDOWS\system32\rundll32.exe) I- t4 M3 H ?: M& d
C:\Program Files\F-Secure\Common\FSM32.EXE
% w; Q, l8 r7 R( b: G2 [$ ^' VC:\WINDOWS\system32\CTFMON.EXE
. Z1 e w" `0 NC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
3 e2 r: d0 J8 W$ T. i# b' uC:\Program Files\Digital Line Detect\DLG.exe6 B1 h! D" r9 D
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
8 _$ }( M+ Y$ [5 z2 R: d) [! a2 nC:\Program Files\F-Secure\FSGUI\fsguidll.exe' o d1 E, q, l; m6 S Y
C:\Program Files\Messenger\msmsgs.exe/ N \+ q( ?# _6 K4 w
C:\Program Files\Internet Explorer\iexplore.exe
& G0 L _ P3 E; ~/ _C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe$ b% \5 N: |3 w7 H# o% W
y# V* `3 q3 ~' h: h
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll6 E( P' Z3 e2 G- L2 _: f
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
. _! w8 P' s) p" E1 i% W/ eO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
0 B% b4 U, ~, H; IO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe/ s7 K* U. W: C2 k0 k( b
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
+ B' D( o1 m$ M' bO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
. h5 H2 Z# y( G0 |" TO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
0 m V. v6 {# g1 e6 J4 g& q8 U0 PO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe: A9 _3 T$ ^! L L6 F8 t
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
/ b- V( ^5 u! D, aO4 - HKLM\..\Run: [TP4EX] tp4ex.exe x9 [6 I: Q* W
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe- @0 _+ c. u) Y4 @
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
, v* `+ |4 k1 o0 y& RO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray8 k" z5 Q3 f2 Y
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
7 |2 h% X2 p' W* F/ _9 S( iO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
* i/ }! X; p( q9 F* Y" Y7 BO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe& |) X+ f4 l. S6 S. F7 i
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe, F( A% ]1 k( u3 _
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE% ]; [& R1 E' ]+ `' I
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
$ R- p: O" J5 `2 oO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
- z- ^6 K5 c% \$ S/ mO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
1 [( v( L9 b) [6 XO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32. Z; ]3 @: W; L- k2 \0 [ \
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE$ h% W1 }1 H5 o3 \8 G w
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
: Y6 q# I* }$ w5 n$ ~O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
( p) h# A' D. oO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
( G, o* u0 X A) C. ~# l" ]& h$ ^: a* {O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
* a: G# z& O, u2 G, j: m9 UO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW# H4 ^( z% \7 o( d& c
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
+ ^9 E% R* ^5 r; z' {+ A% ^O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe, {4 |% h/ }5 n
O4 - Global Startup: Digital Line Detect.lnk = ?
7 R3 Q2 J+ B8 j2 |7 nO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe+ w+ N9 ~2 J- K
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm( X$ g6 P9 J" c- M( y7 j
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
" F w3 J! a' g k9 H QO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll0 O" h" B% ?& k% R3 i5 H+ C
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
. _- A5 H# {7 ~: TO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
: P* W4 x/ X" s1 Y6 T4 [( CO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe) Y3 E7 w- k( u, V
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe2 ~( S4 u q% C6 a
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe5 n5 |7 w0 D# s; C! M
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
- k3 j$ @# h! ]9 s) h# E7 m" r- Z9 xO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
/ }6 K& }! n7 v" WO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll4 K& \9 A0 C% a7 k) v
O11 - Options group: [JAVA_IBM] Java (IBM)" r9 I7 M* B6 _) K( Q
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll2 D9 o4 z5 x# q1 `
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
( Y$ J0 ]# y ^9 V9 F" A$ TO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll$ ]2 ?, ^( T2 F
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll! S# h l' @/ T, l
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE+ \% U$ y9 ]! |2 F' }
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe2 `+ k# D$ s) N& }' i" J5 C
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe- N& a9 }" M1 {5 T7 c
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE- c2 p# t* ?3 p7 [
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe! L+ N* Z6 a+ Y' z/ W" @* j
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
: }/ ~, b; E* z6 q) ^' eO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE2 P' {5 b+ K) L! c( [" ~
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe* n( X& c2 M0 |# T( f4 u+ O, V
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe* U9 A, O6 X. ]3 a0 _) l
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
" }" W' P, A0 H/ s' V1 bO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)3 u, {8 j3 ]7 ^2 G
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
4 V; h, N" Y* qO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe* z- F5 }- |$ D2 n n
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe7 n; P# g6 J1 _5 K! K2 o
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe. F# z) g2 A0 Z' u$ o
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
8 ^# o. |0 n, E* f/ |O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe( O3 k+ J0 W7 F3 I
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|