 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1) K" \5 h0 z# a
Scan saved at 16:55:24, on 2006-5-6' D6 ]$ G9 }7 J6 O* V) ~. k
Platform: Windows XP SP2 (WinNT 5.01.2600)
8 H0 \4 }2 \( M. a" FMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
1 a: ]$ Q+ `- U8 Y, p
; s" Q# Y+ A1 K! ^: K! V1 ^* h' _! _Running processes:
% y, [0 L: j, h- yC:\WINDOWS\System32\smss.exe
5 o/ B2 U3 f1 gC:\WINDOWS\system32\winlogon.exe
: I7 p& S& C+ G* U: IC:\WINDOWS\system32\services.exe+ @6 M( C5 i" B( X
C:\WINDOWS\system32\lsass.exe4 L2 A. t% g2 v! d4 c1 E; z
C:\Program Files\Common Files\Virtual Token\vtserver.exe& P) x) G: }" o2 l" g
C:\WINDOWS\system32\ibmpmsvc.exe/ E" A; X8 G6 ^1 b1 z
C:\WINDOWS\system32\svchost.exe
' e: X& b( R$ s: p+ }$ ?C:\WINDOWS\System32\svchost.exe8 f' `% _& Z, w4 G" x: c3 E
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe8 n. P! Q# U2 z+ R n9 ^, G7 W' x
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
! i a4 H( o4 p: A2 H* a, `7 D HC:\WINDOWS\system32\spoolsv.exe
% r0 g( a; z. A% H: y5 a5 `C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE: u0 J! t" z7 X4 h' H B1 L
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
4 b2 I6 @+ h9 w) R2 t `+ ?C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe( W6 b' }. o) s* _ u! Z
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE, T3 `# o$ H: l6 \
C:\Program Files\F-Secure\Common\FSMA32.EXE
$ e, v# K: j) n" hC:\Program Files\F-Secure\Common\FSMB32.EXE* c, d" Q' n) ^+ D
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
; t+ @5 C8 C9 l3 a& KC:\Program Files\F-Secure\Anti-Virus\fssm32.exe5 f( ]- N2 u' n( @7 L" }
C:\WINDOWS\System32\QCONSVC.EXE1 f( @1 j/ o" _) S
C:\Program Files\F-Secure\Common\FCH32.EXE4 r+ o+ S/ I) }/ W
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
8 ^5 h3 v( j+ Q. g, d9 TC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe; T* R1 P9 g. j) t6 ]2 S X
C:\WINDOWS\System32\TPHDEXLG.EXE7 C, y3 `3 E( h4 A) c: `: b
C:\Program Files\F-Secure\Common\FAMEH32.EXE, k" S& }% v9 z/ v; Q
C:\WINDOWS\system32\TpKmpSVC.exe
! K4 q0 Q& W( ~# `- A) _! RC:\Program Files\F-Secure\Anti-Virus\fsqh.exe& R3 U$ K1 k9 u, r8 w Z
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
; i$ I) L {" g! ?1 bC:\Program Files\F-Secure\Common\FNRB32.EXE' Q, C1 @5 w+ O0 d$ M6 b
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe/ a4 R, w7 l( L( J+ R6 c
C:\Program Files\F-Secure\Common\FIH32.EXE0 q ]/ w1 k' S4 t
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
& m( D: |7 w4 R. A; i; G8 X$ nC:\WINDOWS\Explorer.EXE
/ a7 ?8 @5 s6 ^. A! A9 O( |C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
$ P+ w0 H0 \. h! t, z# T' g9 YC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
. u0 _8 \3 U% l. u" b/ P& OC:\WINDOWS\system32\hkcmd.exe
# V7 ]' e0 R% {C:\WINDOWS\system32\TpShocks.exe
$ q% M( i n4 x J+ VC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe0 c& |5 c. y6 f" `! @
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe2 V* E1 M* W# u3 Z# j
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe/ ^# l6 F1 Y$ l4 w0 M
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe9 j2 [" v2 K5 l$ n4 m7 Q
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe+ p9 _: ?, |8 V7 R
C:\WINDOWS\system32\dla\tfswctrl.exe' ]5 _% j- j9 k& e, Q. w
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe9 Y0 K- J* ^3 ^2 Y3 A! p* M" s0 B% _
C:\IBMTOOLS\UTILS\ibmprc.exe
v2 t; h3 I5 TC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
" @( I5 y+ x) MC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE9 {7 }4 Z+ S9 K Q- c0 F
C:\WINDOWS\System32\svchost.exe
" m. s: W3 D# ]- f8 x' ?$ b0 |C:\WINDOWS\system32\rundll32.exe
/ O+ ]6 p. s5 [% a- R% GC:\Program Files\F-Secure\Common\FSM32.EXE
- ?; o' j+ `1 V w( L# FC:\WINDOWS\system32\CTFMON.EXE
, U0 G" v/ j1 w) DC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
" E& u! m3 k! j6 z2 l8 RC:\Program Files\Digital Line Detect\DLG.exe
* f3 [) W8 N/ }4 J. Y c* @/ RC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe+ g, x" M) e; g7 c+ G3 \- c( ^
C:\Program Files\F-Secure\FSGUI\fsguidll.exe6 i0 [6 Z5 F" g& g' B/ m
C:\Program Files\Messenger\msmsgs.exe8 L3 Q' y. j0 M
C:\Program Files\Internet Explorer\iexplore.exe8 b5 E2 F- m0 g4 a
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe- }9 ]% Y7 q1 K- \. q1 V
9 O1 D/ G! V: E4 U( I
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll I1 G9 A* A& p! R' }
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
! c4 i1 ]" K+ c6 hO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
\6 E* }; n( g/ KO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
, Y6 d% \. \. Q+ ?+ M% ?O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
, r9 y# k- I; e+ \* IO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
, R+ |5 t9 [3 \; W' s; _7 tO4 - HKLM\..\Run: [TpShocks] TpShocks.exe! V* h5 V3 X% Z- r% U& a- _5 R! ]; @
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe# [ W/ V7 I2 d( b$ `9 M$ @5 a# r
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup6 W' D6 ?3 q- p6 x" {/ I
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
+ n% F/ k' o1 T. M: ~: B" Q! \O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe3 j7 F! C0 A" }2 T* S" @% [
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe) I$ t3 x8 a# U ~4 s* H; Z
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray/ i3 t% @& E( g6 g* Q; j
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
) x# W( s2 E6 ?. Y6 L7 B5 ^5 q) V1 ?O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe. F; p6 m" w% e5 P9 B- ]) m6 i
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe/ M9 {7 v& @9 J! D" d% n
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe7 w9 U2 s j2 |" e
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE _9 E3 w% z l( A& ?2 u
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE n* B2 w2 {3 {/ r/ O4 A; G
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor6 |+ c7 m" X, G, D% A# ?. _& G- [# D$ y
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog0 ~- b# h# O/ i7 K+ q
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32$ a% I; T6 p/ Y, h
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE+ Y/ d( f( V; C* T
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
5 ]$ e5 }& [& JO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
. e# K% e! U2 x. s" [& ~O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName ^3 Y3 Q+ }& j) y3 M
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
. Q: V5 G9 K+ J1 n, l0 zO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
9 L& l+ _5 n2 [; X! l. V" DO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe: G2 S7 E8 d7 V4 E% n; Z$ u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
+ ?/ p: n* Q1 t8 e) WO4 - Global Startup: Digital Line Detect.lnk = ?+ o# j. ]. _4 L$ t% f9 w; d
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
4 u. ~, t, q' }$ W" wO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
( K, j3 s2 X9 ]6 ^( D# W5 M$ WO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
% g) S/ K. t. X4 g) y, kO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll& v# o+ R! _% S
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
8 \- C& U8 Y9 o) EO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
/ o! u$ y e; s* I/ \# qO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe( e, n3 q2 k0 i; K1 Q
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe4 l3 y! V9 G) b( ^% d; m
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
. q2 S; H' ]/ t9 U1 b! Z/ bO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll* K! h9 v5 @9 l4 Y
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
& t7 a; ]6 {0 i: K5 cO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll! l3 N8 U% v( u% ~$ d/ O
O11 - Options group: [JAVA_IBM] Java (IBM): A- @1 P# o# J: ]: e) l
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll# a: i2 q/ L h" p M1 p
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll' x. n; ?" K m( s+ q' w* X
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
) t; q, L2 ~+ x" S- c! s, qO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
9 g$ c0 x8 f A( ?$ t( _/ u2 D7 _: JO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE0 I. L+ C" N8 f# i* m1 I* n7 n
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
( ]+ h* ~; N6 ~* U: nO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe6 W4 X$ J! T7 p4 N: l0 o
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE. z2 c0 ~* x% r% B4 b- n' n6 H
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe/ P/ m- n, x+ E. X/ e/ V+ C
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe* \; ]5 W. W! M6 `5 F5 O
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE- X3 Q/ j- b1 `" r
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe* o3 m# B! {/ U. ^4 k
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
9 \* b& }; F" M2 S0 c; ?, qO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
: D" }6 O( W* B: J! f- tO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
' ], i0 t5 q# H, Y0 KO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
, I. M: ?# F9 G* f0 lO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe6 \/ G& l& C+ Z! z1 n& e) ~# r8 A
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe3 V J+ ?9 o' h+ O: r" f
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe) H0 q* Z) e+ t
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE0 Y+ i' h+ R. ~! C% ~' k3 J
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe2 ~) B( v8 D# L+ ?- ^+ P+ t8 }: ^
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|