 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
9 p0 \) E q* I8 f! e1 m* u" `Scan saved at 16:55:24, on 2006-5-6# P- i. `- k/ W
Platform: Windows XP SP2 (WinNT 5.01.2600)# U, U) I/ {4 {' B- u
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* G7 t) h' h; j9 K
5 q& {- T4 d) T8 n$ A- QRunning processes:
& P* v) V/ j4 N, p! Q/ l! r" A. W- QC:\WINDOWS\System32\smss.exe s/ s$ r6 l k) h' D# Z1 w* d6 U
C:\WINDOWS\system32\winlogon.exe
! {! ^5 h7 @% r5 k# _% |* W* RC:\WINDOWS\system32\services.exe
3 q# m4 C' w& C, @( N+ c0 ^+ IC:\WINDOWS\system32\lsass.exe
& l# d9 \$ e Y( A/ E }C:\Program Files\Common Files\Virtual Token\vtserver.exe- A: R2 L4 m% c6 C$ x9 L
C:\WINDOWS\system32\ibmpmsvc.exe
, p* D7 v0 F1 T$ F1 j3 J7 O. OC:\WINDOWS\system32\svchost.exe
; N) H# G1 o6 |: ]C:\WINDOWS\System32\svchost.exe3 U4 g, h | x# O) I
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
% `, a, \& f4 e, l. SC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe; C- S" e8 d5 K# i0 Q( b
C:\WINDOWS\system32\spoolsv.exe
1 P4 h8 L. G3 b0 |, q: l1 \4 LC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE, W+ o% X8 T# _: r
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
! p2 g' p! Z/ i0 v# Y5 @7 E) TC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe5 y: B% c% V9 m; I& Z) h
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE9 y7 i% s/ f+ L' O" W( j* e$ h# ^! p
C:\Program Files\F-Secure\Common\FSMA32.EXE
* _. Q# s( X( @4 E7 SC:\Program Files\F-Secure\Common\FSMB32.EXE
6 g4 D: N' k3 v" S& [: U" J7 NC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
* ]+ y8 y1 m0 I- _5 x& [C:\Program Files\F-Secure\Anti-Virus\fssm32.exe9 ~: b! O. ^1 G: Q' n
C:\WINDOWS\System32\QCONSVC.EXE2 j" C. ^- r/ _# z
C:\Program Files\F-Secure\Common\FCH32.EXE3 L! K; V; f2 ]# u! G
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
" w% n+ ? ?3 K; Y& j% e$ [C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
/ @" ], v/ t; d& z$ P( @5 t2 ^' ?! vC:\WINDOWS\System32\TPHDEXLG.EXE' J( Q" \4 V* p2 r3 b$ `
C:\Program Files\F-Secure\Common\FAMEH32.EXE7 _2 |4 [& r8 P9 D& Y4 t: k- E$ A+ A
C:\WINDOWS\system32\TpKmpSVC.exe9 c/ d3 P2 I0 u2 K
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe4 ]0 y$ B; F/ K6 z
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe+ H4 _( A: F0 K( u
C:\Program Files\F-Secure\Common\FNRB32.EXE
9 G& V, a- \% w# T1 Q- {C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
; ]* e' j i' {5 X8 X. k6 U: ]C:\Program Files\F-Secure\Common\FIH32.EXE
) q! ?0 o% Q8 \. z. }( ]C:\Program Files\F-Secure\Anti-Virus\fsav32.exe+ z, ]% J0 _' `
C:\WINDOWS\Explorer.EXE
% D: y' ]& Z9 e; O, cC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
! V, D1 W$ ]- a4 cC:\Program Files\Synaptics\SynTP\SynTPEnh.exe2 C, m$ N, r7 B$ p
C:\WINDOWS\system32\hkcmd.exe
8 `/ S# R, e7 @& l) ~' }0 u2 ]C:\WINDOWS\system32\TpShocks.exe
5 b" r" T q1 [% W5 G( L8 |3 ~C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe1 f- @) s) g: i* p- }
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" S8 P f' J5 K3 R9 H# ?
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe& d$ s' g- R5 o$ A( T
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
. i' v) ?6 r+ X3 ~C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
, J/ m7 a0 ?' w% Y( x5 k4 p0 dC:\WINDOWS\system32\dla\tfswctrl.exe
% l: A" |! [# y1 _- jC:\Program Files\IBM\Messages By IBM\ibmmessages.exe6 @6 u( j# ?' O6 R% e. t- W
C:\IBMTOOLS\UTILS\ibmprc.exe
+ m& J" Y9 w) Z6 R5 lC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE, f0 W( h+ i% u) G7 z- r( E. K
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE# Y# d0 Q. c5 I, A
C:\WINDOWS\System32\svchost.exe. d T: M* ~7 o+ r2 b- e$ ~0 }
C:\WINDOWS\system32\rundll32.exe4 ]8 U* j% [) K! u
C:\Program Files\F-Secure\Common\FSM32.EXE4 U$ F$ E% }2 V* V2 \
C:\WINDOWS\system32\CTFMON.EXE
7 L! k/ l% j7 }# o7 T, T) G5 kC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
( h) `. U+ C! M/ L: ^$ Z5 w7 _C:\Program Files\Digital Line Detect\DLG.exe
4 f S) Y8 r) T+ P7 {' J* Q) t8 |C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
4 p5 S2 l. o! a$ C6 l/ a% @C:\Program Files\F-Secure\FSGUI\fsguidll.exe
- R: P7 Y1 T$ {+ h2 aC:\Program Files\Messenger\msmsgs.exe
- t, G0 `/ \) g$ XC:\Program Files\Internet Explorer\iexplore.exe9 \! t* X6 {9 O
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
; O! J$ [5 D- Z$ v4 |) J* c. j( x1 D' I! V. H
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
+ h" ?, C+ y* r( ]# d* wO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe4 s4 o, a' O. D _
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe% [4 m9 A$ M7 r4 [- y1 ?& C% f
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
7 K" n" x( Y& r" L- @& q3 UO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
3 b; p4 G3 y/ ?+ K- t9 wO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
$ {/ ^- L* Q$ u5 `% dO4 - HKLM\..\Run: [TpShocks] TpShocks.exe3 b2 D! T/ R% x5 \" N' ~2 }
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe; N% e9 u0 `! U8 n
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
8 |5 v8 Z' r1 |: C9 ?4 oO4 - HKLM\..\Run: [TP4EX] tp4ex.exe7 _" p* A% P* _, }; o
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
( ^0 B8 v" C4 ~' e$ q) pO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe7 r9 Y- D1 s" g' K2 x1 A
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray* @& p( d: o7 c$ P
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r. a0 @/ _# }" B
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe6 d2 q6 K# K3 \
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
3 a4 Z4 s+ S4 \5 `7 L! cO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe3 v1 X* E2 e9 `& M* [3 D
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE/ C6 |) v; _+ M0 t1 O
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE) w- C0 Z! x# R7 W4 n$ a
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
0 p- h; m( P! F9 C# }O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog/ O& h( I* ]" V$ C0 p5 d! @6 L
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration321 p! W2 x1 m L9 c1 O' Q3 M( b
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE. M& d, H3 m3 C% `2 [3 G. s
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC# X* p& |, c0 K" f K; ]
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC$ W+ U/ [# m' E! S: @- y7 S
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
; v( U7 w& W3 {' QO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash6 C1 h6 B/ ^; F* ^
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW/ A, ?+ ?$ X. h5 d
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe( o9 h- R7 `$ \5 o, T9 Y, z
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe& X& H2 f. e# F* H
O4 - Global Startup: Digital Line Detect.lnk = ?
9 y# N# V0 M! t, ^0 k8 h2 hO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
5 k u& i0 |9 i7 c4 ^O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
& {# ?1 {# V! F# K8 e$ O1 TO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
! n7 I7 o7 o) J: \O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll; \, K! g& C" Z: E$ o. |
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll& l4 d/ Q! b' v0 q6 H$ b o. f9 A
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
; Z3 Z s' O: ~O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
! K s- \( V' N0 |# cO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
( X- y9 `$ [- P. r% W0 ~- R/ \- IO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe4 y, a7 H. _/ p9 U4 _1 N2 @
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
/ ^/ ]: A1 M6 W) M1 @O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll( {8 _" k9 ~) u2 X
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
3 U5 V$ _8 p1 ]' s0 b2 w9 YO11 - Options group: [JAVA_IBM] Java (IBM)
; D0 H/ }8 n; o- W' K ^O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
0 W* E1 c) r7 \O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
' T; G9 E3 t9 H* X# gO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll" {7 j+ n2 N0 u% J
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
, q3 k" U3 ]1 NO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
- P3 h+ @1 Q$ @% rO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
$ j% k1 ?5 Q0 E6 MO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
6 z, m7 C3 W; S% i: U. OO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE* m5 \* t- l- e1 @5 ^3 P
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe# d. v0 [, t0 @' g ?" x1 I, m; c1 C
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe$ N% m/ T( ?$ O D- f
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE! ?+ m- S: d: r9 a1 f
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
% d, \! l4 ?, ?: k& tO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
2 v5 ~ ?" x9 P" `: RO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe' l' T# w2 Z$ p+ t7 b. z
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
/ _9 n0 J+ _+ j( Y. EO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
2 q8 ^7 P% G: }" W1 o; YO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe) u" t E. c* [* x5 N8 Z* N
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe& x7 w9 I/ q1 ?, h4 d
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe' P' V2 y6 A5 P' k \5 h
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
; M8 Q# e |* p" }% j- b) KO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe# q, _7 s3 \7 a% }5 M
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|