 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.19 C& r! K; B6 v, g9 r
Scan saved at 16:55:24, on 2006-5-6- L; c( U+ r0 Z; }# `
Platform: Windows XP SP2 (WinNT 5.01.2600)
; Y' Z0 M4 U8 X. t4 {$ ^) yMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
; {3 Y, N0 |3 O2 Z8 E, a* I; ]5 w4 b4 [( {
Running processes:
4 D( ~8 a$ o9 J1 m. ?0 Q2 eC:\WINDOWS\System32\smss.exe
% ]2 T* b4 x5 w2 o8 p+ R+ O5 h/ kC:\WINDOWS\system32\winlogon.exe1 h+ Y- {& W6 {% h x3 ~
C:\WINDOWS\system32\services.exe
3 H2 G3 A8 J! n! r) sC:\WINDOWS\system32\lsass.exe' L' i+ x. p% W) Q1 M
C:\Program Files\Common Files\Virtual Token\vtserver.exe) J. g4 z& v( b) ?* e
C:\WINDOWS\system32\ibmpmsvc.exe
3 p; \9 o% u' NC:\WINDOWS\system32\svchost.exe
& @' l* Q+ \* R9 @C:\WINDOWS\System32\svchost.exe( z6 ?# u7 Z1 Z/ X) e/ z
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
" s, y$ R! }- e5 B7 P) gC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
`# h P( y/ FC:\WINDOWS\system32\spoolsv.exe/ P/ R( V/ D6 z; t5 @8 k4 r5 l
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
& ^6 L1 P- B; F3 T* [6 r$ n$ ]* gC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
4 E& M; w. G/ N5 N' P; }C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
4 |" m. a. F$ D( S1 kC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
* o7 b5 n5 j: D* W. ]5 mC:\Program Files\F-Secure\Common\FSMA32.EXE8 d; Y5 d9 ?* R. i$ f1 T% x
C:\Program Files\F-Secure\Common\FSMB32.EXE5 c; H5 ^3 ]# b1 C) s
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
# V# s" \* `* n, f$ b. gC:\Program Files\F-Secure\Anti-Virus\fssm32.exe/ \" K/ n1 ?4 K- n! E/ Y2 N& F, R
C:\WINDOWS\System32\QCONSVC.EXE
& z: S; ?+ r( r8 bC:\Program Files\F-Secure\Common\FCH32.EXE
! V1 ~8 Y% ?; FC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe: \: l. e+ v" q5 f+ E
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
& m. o8 F8 ^9 HC:\WINDOWS\System32\TPHDEXLG.EXE
/ D( E# \& O! g$ Z6 sC:\Program Files\F-Secure\Common\FAMEH32.EXE( |( [- I9 \4 q
C:\WINDOWS\system32\TpKmpSVC.exe0 \1 H! d2 a. i2 ]5 y* u
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
+ u% N& I1 H; i# TC:\Program Files\F-Secure\Anti-Virus\fsrw.exe0 Z$ h' K N0 G! A. P: H
C:\Program Files\F-Secure\Common\FNRB32.EXE2 X$ p1 [' C. n0 |
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
" {* `& J7 }$ g0 W6 t0 ]8 P" B- P! kC:\Program Files\F-Secure\Common\FIH32.EXE6 a$ `0 ?* r0 `0 b' I1 s
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe8 w" j2 x: _7 B4 j# }
C:\WINDOWS\Explorer.EXE
4 n5 C$ v; V- O1 r4 ZC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
; T& g; D. J7 Z8 `" kC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
$ t( d3 A% }) x4 k. DC:\WINDOWS\system32\hkcmd.exe
% [) t X& b! h9 S5 I4 l: oC:\WINDOWS\system32\TpShocks.exe
. A- O" K0 z8 V, r& @- `- C' AC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe) \- v' y# d! m1 B
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
" }6 _4 ^" c0 S4 t/ mC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe' u; R+ {- M* `
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
+ l. G2 B. W( v$ {8 o5 v3 WC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe3 L5 m% O" ]; ^; i R7 V
C:\WINDOWS\system32\dla\tfswctrl.exe& D) o5 L2 l {: F9 K4 G# {
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe* w. ]) ~7 O* ^ Q/ c3 @
C:\IBMTOOLS\UTILS\ibmprc.exe) D" L ]( y" s9 r
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
6 g+ M2 b3 l1 ~# {C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
! K8 V, i T6 E( ?* xC:\WINDOWS\System32\svchost.exe) z2 o$ U* [. v; i+ `% Q
C:\WINDOWS\system32\rundll32.exe
" S' Y' U4 x( l% Y4 c- ]# t) x( ~8 k" WC:\Program Files\F-Secure\Common\FSM32.EXE& n& _ L# j7 K; s
C:\WINDOWS\system32\CTFMON.EXE
8 L. c: w% o- I" gC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
: W0 x t: j5 T- K& ^6 I! UC:\Program Files\Digital Line Detect\DLG.exe/ V, X% |" V6 i' V& k2 d
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
" m" v1 p, e2 \; KC:\Program Files\F-Secure\FSGUI\fsguidll.exe
- V3 i% {$ O5 Z+ m, m& N. `C:\Program Files\Messenger\msmsgs.exe& }4 z w4 D, l' L
C:\Program Files\Internet Explorer\iexplore.exe. P3 T9 o( D1 L, Y# R+ ~5 X
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe) o9 Y, M: B+ E/ |. a( x
8 w- u7 o$ U3 S s* B
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
* |3 z; Z1 \) S8 BO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe+ b5 q, R' ?, ?) W+ s: [- \
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe/ I ~! ^9 ]8 p/ v' t+ H
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe3 [5 _- j' L* v( O
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe$ |& A0 l4 d0 e z0 m% }$ x, ?
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
4 F3 O9 V) S8 m9 J$ V4 _/ V$ K# [O4 - HKLM\..\Run: [TpShocks] TpShocks.exe. O4 V( W5 \7 n# P1 V: s
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe# g8 E( ~7 [2 P1 j- Q0 B
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup% @; |0 b- n; L( g, s
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe% j s. Z8 R- l( W
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe0 l" [( w/ }' f+ q! U
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe( Q" F& i6 u! D4 W3 R( B
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
# s4 }: _: Y+ s6 BO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
# Q: J) ?! I. i T/ ?. d, @. kO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe2 S; q! |3 r( B/ d7 k
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe1 I& U$ z* U# t+ Q3 M
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
* K/ ?9 X$ v* K. x( `6 l! o; ^5 EO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE: @0 C- F! X6 N0 p* q
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
" r: H5 N; ]! m- Z9 lO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
8 T) o3 Y( j+ N" h/ |4 IO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog7 L$ n, g( B; Y$ J7 k; X, i4 e
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration320 g6 e2 Y, r3 T- Z% J8 _
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE' Q2 D, O: P: s3 ?, W* I
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
! _1 b% l- M% Z7 i" A4 R" \0 aO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
: @! i5 D! O- m6 iO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName$ J+ B/ p7 c; f. k
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
8 p1 ?1 ~* t3 o& R% ?O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
2 u' R' i, A/ V1 {# yO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
5 T" |: A9 F4 X- P- D r" g+ r! @; E7 TO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
4 _7 z% \) j! KO4 - Global Startup: Digital Line Detect.lnk = ?
1 n8 I5 F& T% F! v) L6 |7 d3 vO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
" N) ?: W1 y1 yO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm7 p! X7 m; E( n* G# r
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll& n Z1 ?; `9 F
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
) z/ V- c( `% ~" ]- |0 O: m% `O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll" b1 X W$ ^0 v7 n. d
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
; g1 H5 `) a4 o) ]O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe5 g, W; h% ]( I; `: J" G$ K
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe/ V& T/ \$ d. e2 ^
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe8 H* F. k- a p- A l( i
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll7 P/ i i1 [4 k
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
0 X1 e8 r0 f9 X$ T* A5 L$ \O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll& S7 A# c k! m) l0 v: V
O11 - Options group: [JAVA_IBM] Java (IBM)# L# F3 z1 r9 F
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll$ A' q6 r& b3 t& M4 o1 v+ _
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
! h5 q$ o3 W U/ wO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
8 g: `# o T; b4 A3 cO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll* a. R9 D: K( a; }1 o! v% X d( L
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
% k1 s. R$ a- N$ U+ I! c$ vO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
5 y! X Y# {6 K7 N" ZO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
2 K! f- y$ L: Q8 g; sO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
! m& @' {2 C( X% l) ?4 EO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe6 ]( @9 _9 P$ E+ m5 L
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe. d% _% Z) u' t) ^$ e# l& V
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
; B; o3 F4 F/ QO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
+ R. N; v1 R0 m; XO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
' f( P8 H. Q$ d% a. DO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe- g4 K# y+ N2 G+ p5 J& y
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
# X0 H* q3 [& s& u' M) \# TO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE- g6 m6 c& Q. h$ u% \
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe' F4 C0 l; b8 L+ S9 h; Q
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
( J* P0 V0 E+ ?( T2 bO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe& p% `4 s& \: `1 W$ A, V
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
3 `* {' r8 o( @; g5 IO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
+ }* s1 P |% {4 z) S; t& sO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|