 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1( N- J$ p4 c0 H5 X$ I
Scan saved at 16:55:24, on 2006-5-6 j8 O S8 L6 r4 [$ j& J+ H
Platform: Windows XP SP2 (WinNT 5.01.2600)" I" o. d' Y. P: c0 x( w4 l! O
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
3 {, O8 J" a8 K* _& i! i4 b1 H, u+ M( E0 C. g
Running processes:7 b2 x4 F: g3 V5 }
C:\WINDOWS\System32\smss.exe
* A; i$ F: y$ r' {% l+ Z! jC:\WINDOWS\system32\winlogon.exe0 x# O/ H: z& `$ P
C:\WINDOWS\system32\services.exe" A$ v( i1 G- b
C:\WINDOWS\system32\lsass.exe- n8 p& z8 d( w; e
C:\Program Files\Common Files\Virtual Token\vtserver.exe+ ]0 h# U( h5 A4 \) J/ x/ k
C:\WINDOWS\system32\ibmpmsvc.exe% d9 Z+ \3 G. t& e4 J, H- @& ~7 S
C:\WINDOWS\system32\svchost.exe
! F8 p- o6 C' W8 m* bC:\WINDOWS\System32\svchost.exe4 u7 f7 i: g. C# T
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe8 X2 Y% s1 {5 G; w7 A+ j6 j9 p
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe5 K$ J7 k; c, z" N
C:\WINDOWS\system32\spoolsv.exe6 g4 Y& k- z7 i9 X5 D0 X
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE7 C% W7 v2 ]" W
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
" O* {/ y' ~5 j hC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
( _2 o3 y* ~4 c8 g9 h+ aC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
/ ]8 c0 t" w& G- RC:\Program Files\F-Secure\Common\FSMA32.EXE; o; A) x* h, N, Y& K
C:\Program Files\F-Secure\Common\FSMB32.EXE9 S( Y& k( e/ u& u8 U
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
. N/ C, Y$ _5 \) IC:\Program Files\F-Secure\Anti-Virus\fssm32.exe @. {! I3 [; M3 I; S& J' H
C:\WINDOWS\System32\QCONSVC.EXE, ^, B4 c" J7 c
C:\Program Files\F-Secure\Common\FCH32.EXE F% E$ y% U8 o7 \+ M0 W- O
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe2 W( s: `1 f2 p4 ]" d9 E4 _- m7 o
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe* @1 ^! N3 z' {/ R& }
C:\WINDOWS\System32\TPHDEXLG.EXE6 l2 \, z# o' U8 u) T' H
C:\Program Files\F-Secure\Common\FAMEH32.EXE2 t0 K# M* I! \- o, N3 _0 }
C:\WINDOWS\system32\TpKmpSVC.exe0 s! H7 T1 t0 O; `; ~& I& ?) J
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe S( Q% N, {& Z
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe) h) v0 }' o# _0 H; [2 h+ D! x
C:\Program Files\F-Secure\Common\FNRB32.EXE- h# l8 w* F+ W* P3 K3 G: m0 v
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe; L: Q2 a8 S8 C
C:\Program Files\F-Secure\Common\FIH32.EXE2 _% }. l L+ `" R3 Q$ \) H+ Z: C
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
; \/ [8 z# t1 S9 m! WC:\WINDOWS\Explorer.EXE, b1 X2 c, X) t. @, R: K
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
! M9 l% z! G; P! H! ^C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" z. v. M/ a) I M; Z
C:\WINDOWS\system32\hkcmd.exe% A( M/ e" W: H0 b6 [5 V5 m \
C:\WINDOWS\system32\TpShocks.exe
1 b' e; t: j/ n% {. ?C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
# g4 u% c: ~7 f. \0 U/ b0 O! J5 d# EC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
) A9 T6 X. \0 K; K3 s9 JC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
$ j, W9 }* v7 W$ }! [C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
/ q- @) U% J4 _; h- A6 V) SC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
2 n; W6 N9 E' Q YC:\WINDOWS\system32\dla\tfswctrl.exe
8 v5 ]2 z* T$ R& ?# \* mC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
) a" w" F- a8 \7 |C:\IBMTOOLS\UTILS\ibmprc.exe
1 J% t( d6 b. w" I0 ]9 P( A- R- l5 qC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE; @! f$ `8 |, t/ K0 T( j
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
/ A( o1 e) l) E% OC:\WINDOWS\System32\svchost.exe D7 E7 w) B( Y: k, ^
C:\WINDOWS\system32\rundll32.exe
0 ^- V$ S6 E$ W/ z+ b# \C:\Program Files\F-Secure\Common\FSM32.EXE' v1 ?# E! m4 p k7 Q
C:\WINDOWS\system32\CTFMON.EXE
2 L. V+ P5 s: ?C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
0 p( q+ c, o- a2 K0 F) aC:\Program Files\Digital Line Detect\DLG.exe
( y/ I' Z! l6 DC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
/ z& z. C# O! D' g2 [+ R6 PC:\Program Files\F-Secure\FSGUI\fsguidll.exe
& P' H6 H& r6 m' e, ^6 HC:\Program Files\Messenger\msmsgs.exe
# ]* r2 G7 A1 h7 o2 b' oC:\Program Files\Internet Explorer\iexplore.exe5 U! H, {( H. H* T e I
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
- ^% v8 B9 J/ \- P7 E Q) V* z: c; l3 q" \
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll3 x0 R& Z& w H: a$ o
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
/ N6 c8 b% J6 M, y7 @O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe, @0 @3 Q1 R/ A8 e" m
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe+ K! c+ ^- z" q& _
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe9 N0 N; v* H2 \
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
% K1 k# ~$ a9 |: Z) J( t. GO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
. k' e; v _* q6 `O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
/ r" E9 O9 L0 k+ T/ h2 z. b9 uO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup5 q# y& a0 W `# `8 S
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe8 E( z; W4 _9 Z6 A o6 x z
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe1 Q0 C& b; e5 X
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
r# E/ I& q1 ^3 L& @O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
5 X+ ~- R# M; {" U$ O! gO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r, ?/ ?2 p5 G2 d* u7 @9 g; E
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe _2 ~7 n) A. Z( x. d8 D
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe/ G, n1 _# x2 K, r
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe* Q$ q, \9 ~" t% I7 d$ I
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE9 M0 w0 l3 q' o; v% }0 d
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
0 l9 v! b" i, @( D6 _4 EO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor6 x$ Y8 i8 E M/ q9 B4 }$ V" O& Q
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
% P* x) V9 p& u: r/ l7 PO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration323 S6 e: t8 V# {
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
% N' m+ k& ~! m5 YO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
8 I. {+ Z+ s( q# dO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
2 i7 U2 S6 B1 G8 SO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
! P" ^2 A) [ }1 P1 ZO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
3 x9 |2 ~! k! r8 y$ }6 VO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW; O1 D& b8 ^) L- F
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe5 c* U: v1 h' [' [) @7 x+ i3 \ z
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe4 B6 j8 ~9 b" m: J' v
O4 - Global Startup: Digital Line Detect.lnk = ?
2 n! W+ G; \; g0 t5 Z: lO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
' x; h9 Y/ J. i( t. L) k! \O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm! b, e! A$ X4 ?/ y! \9 Z
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
# k& @5 h$ m& {$ jO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
: Q. u7 _( T8 `# F! }$ \O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll7 r/ b' i8 g% Y6 o7 `8 D
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
9 f) a5 d" X8 c! OO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe5 m M9 M& J- ^! {
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe0 A: t" H& `" w6 t. I
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe8 B/ n2 ]& y/ K5 G. A/ N: \
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll, H; H3 r/ C+ o8 V
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
6 ]1 Z6 |8 _% [4 |& j8 z1 W2 JO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
` t# e" a& E/ g- b+ J CO11 - Options group: [JAVA_IBM] Java (IBM)
: J5 m$ w, J. n6 x% _* Z$ B: `! rO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
! |" m( ]' r+ r, uO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll; r- _ L0 y* E$ j) k. {/ h
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
) A2 e( V: `! k# VO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll! ?" [/ Y1 x" g1 j+ G
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
9 a* @# z2 |3 ?: U- oO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe7 W% ^0 ` H/ F, l" L% a
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
/ h: P9 `5 L' C' V! r. y7 X# yO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
4 @, P, ]2 l1 m* M- {4 @O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe5 Z5 {- G g$ B5 U. A) t6 k
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
: ^; {8 A6 d6 }' X: C2 K5 a& tO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE a; k4 ^* G3 h
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
) h- l0 O! S) `O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
6 W0 |5 g) ~- KO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe4 O' O! L4 A# Q; w7 \* c$ @; o* a
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
6 v7 y. b+ C) k* X1 uO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE; H0 R4 Z* m! ]1 b* I
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe# [' R- W7 c- X# H) _/ N
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe. B! z, s& h4 i2 E" u
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
. x* I+ A/ U3 `7 T6 q' q' Z, zO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
5 z+ V i! Z6 H; h3 \O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe0 j; ?: y$ J; }" h7 G
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|