 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1. u4 l, v2 n6 [: ~
Scan saved at 16:55:24, on 2006-5-6
8 u- o) q7 b! U- l, f. d2 zPlatform: Windows XP SP2 (WinNT 5.01.2600)
: F- E' K t+ q) ~1 O2 f0 {MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)6 X: U6 ?, R' ]% h" \, W8 G3 L& v
* J+ G; i5 Y5 t& bRunning processes:
4 [1 n. e! l4 D4 p: X) `C:\WINDOWS\System32\smss.exe
7 a4 `$ m+ E& Q5 h% q# f0 R: IC:\WINDOWS\system32\winlogon.exe
( R# o/ O9 |% e- l+ ?C:\WINDOWS\system32\services.exe
- {% V/ J' }4 ^2 a- XC:\WINDOWS\system32\lsass.exe
* M3 |2 p1 g5 g T9 a& ~C:\Program Files\Common Files\Virtual Token\vtserver.exe
% x3 z6 ?3 v8 T& lC:\WINDOWS\system32\ibmpmsvc.exe
- M. \ Z( B) j1 ^, K) M# kC:\WINDOWS\system32\svchost.exe$ B! n/ m" P5 [3 D1 u/ [; Y0 i) V
C:\WINDOWS\System32\svchost.exe
; c' J/ s, y$ o- g. w2 i2 \8 tC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
6 F% G4 H$ i5 o+ l; X' B( ^C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe& G4 E6 g/ y {; I+ [( F
C:\WINDOWS\system32\spoolsv.exe! C6 n7 c$ D* S
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE2 }" ~( I: j2 z( ^; F1 l! U' H6 L) }0 F
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe! N6 d5 t$ C- a2 J8 t
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
7 h2 C" f& v; M9 g2 m# J) O" JC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
! M# n% Z: ?( y7 \( Y/ GC:\Program Files\F-Secure\Common\FSMA32.EXE/ r" L1 p, f5 M9 B
C:\Program Files\F-Secure\Common\FSMB32.EXE2 k* p# T3 Q ]" P
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
$ n7 Z$ h1 \/ B6 F' CC:\Program Files\F-Secure\Anti-Virus\fssm32.exe
, j5 s q" v8 rC:\WINDOWS\System32\QCONSVC.EXE
6 @( s: [1 x; ] tC:\Program Files\F-Secure\Common\FCH32.EXE( @& i* j- u' d9 R" ~* q
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe! j! `5 i1 X# ~& e5 W" N
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
" @% E1 n" }: e ^8 z0 F1 j& s+ e6 WC:\WINDOWS\System32\TPHDEXLG.EXE- B5 T* G1 m6 q9 A8 W: ^7 l+ I* x
C:\Program Files\F-Secure\Common\FAMEH32.EXE' r( L! Q& o! I5 O5 y
C:\WINDOWS\system32\TpKmpSVC.exe( s9 s. r1 A% A) G' f0 H/ Y- B
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe6 X! U6 C* u! r2 K) T
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
% R7 e& c0 b' m" ^C:\Program Files\F-Secure\Common\FNRB32.EXE
" W4 `9 ]5 v, {, b% iC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe) M- f: Z6 q2 q+ h2 C
C:\Program Files\F-Secure\Common\FIH32.EXE
( t2 k, c ?" g( KC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
! Q( n( R! L n `, v4 v. lC:\WINDOWS\Explorer.EXE
/ d' y( h0 q$ u* ]: D: G/ BC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
2 Q! V8 i1 T7 e; U3 _C:\Program Files\Synaptics\SynTP\SynTPEnh.exe+ u0 d& n% ~0 }: }; W+ j
C:\WINDOWS\system32\hkcmd.exe
: y1 t' t; ~& M9 q2 G) @C:\WINDOWS\system32\TpShocks.exe0 I# a& f- m$ J f; i' C
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe1 b2 s; p% R4 l6 I, t+ I
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
2 J- d D7 b T% ` gC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
% z' }* L ?( Q; N2 B$ d# hC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe/ J2 i& F/ D; G9 ? N6 t4 N2 h/ A5 g
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
/ b4 W& ~, b( QC:\WINDOWS\system32\dla\tfswctrl.exe
2 N- l) t2 j! q6 ]. Y8 K' nC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
& j: C, C3 e0 z% `C:\IBMTOOLS\UTILS\ibmprc.exe; R$ ~6 Q. k' x
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
+ ^/ J" z# x- l- [! w# yC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
5 Y" N1 U' k7 H5 u4 k! CC:\WINDOWS\System32\svchost.exe
+ A, C% Q8 d0 E$ a1 Q6 yC:\WINDOWS\system32\rundll32.exe: ~7 L$ b! g) T% Q, z
C:\Program Files\F-Secure\Common\FSM32.EXE* H+ c) ~1 d/ y/ g" C, M
C:\WINDOWS\system32\CTFMON.EXE* Y! M4 m* @9 M
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
6 h' t0 O9 G1 U- |6 Q3 M1 vC:\Program Files\Digital Line Detect\DLG.exe
3 K! d4 M% U# J, P. L. ]. vC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
4 d v) N/ x8 ^( TC:\Program Files\F-Secure\FSGUI\fsguidll.exe0 D4 T5 p0 ?' r' S$ M- t
C:\Program Files\Messenger\msmsgs.exe
5 p& _3 G. I. p, a5 U# V5 RC:\Program Files\Internet Explorer\iexplore.exe! c) a, }9 |* o9 A
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
6 ?4 U# c G. J' V1 q* v, H: l4 `- [5 r X4 a
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
+ x8 N- m+ h! B* S5 p+ j0 O& s8 |" ?O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe7 j( P' y; j' a. @3 }$ d
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe2 Y7 x, l0 p h) o
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
# }6 e, S# N N( x( Z3 @O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe5 ~ D3 F7 \7 \1 `4 S; y) R
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper: z: o# A% h+ f7 f. s; K4 r" u
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe, H/ I0 ?* m/ A3 J5 g2 j( \) ^
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
3 n! b9 p" f7 b3 A/ cO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
- D- ` B- O5 ]9 X3 g) WO4 - HKLM\..\Run: [TP4EX] tp4ex.exe- [3 y# R* h9 q6 ?
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe+ k; y$ e0 g- H) B, q, m
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
B$ `2 ~6 ?6 w6 c o8 pO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray2 \ N- ^; v+ e$ ], c/ G& @4 B
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
5 P) m2 o5 ] @( s& g- _O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
1 }/ i" @7 D: l# C1 eO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe) e5 p) J- ~+ `0 W: e
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe) C r' y3 J9 G. e. R }
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE- K8 U/ a l: m5 Q7 }& {' w
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE+ }. N. l# e& {& r% E5 Q
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
9 U3 u/ m8 n5 w" \, S% U" zO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
+ g- t, g2 G- f/ n1 @4 YO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
* Q0 [/ d5 ^ |O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE+ A: D4 h/ w5 A0 o' x3 w$ v
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
, w) n* Q; L' z- W* @2 NO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
C$ d" v: P* p; V' LO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
+ }2 X4 B, m9 a5 kO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
" s' @ H8 H1 B0 ^+ U# }) CO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
/ v; q F; J& I& |/ F9 c. {O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
$ z. ^8 B3 _, J$ k- C" tO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe% v3 c4 M+ Q! e" L& M4 Z0 @4 ]
O4 - Global Startup: Digital Line Detect.lnk = ?
! S0 R) S+ W5 D' D" d5 N( D! X- _O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
|5 j/ ~5 e+ B: {O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm3 x% T( s: b' c1 N6 [
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll; q0 [+ h( D: |# @/ ~: H
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
' F2 w6 @9 J& l* x" A) UO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
1 I6 \1 Y% E8 v* g* y* pO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll6 g/ P. I9 R$ p8 F& g
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
9 t$ R7 ~6 j4 a& TO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe6 B( {, H- P3 ~& ~' r! x
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe( u2 f1 a: ]# u! X
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
* s% {- y5 n9 K2 fO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll; N' i M+ ~4 ~0 f4 ^
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
- t5 C p! _0 r- qO11 - Options group: [JAVA_IBM] Java (IBM)0 R/ o3 D( y; {: |! }& }+ G+ i
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
+ p( O6 r& i, x, VO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll1 E# \0 P3 Y+ R5 L3 Z. X6 P
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll7 T, m$ l$ q# H8 {6 z
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
4 s* w- \& Y% ?: K0 c" pO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE$ ~( u* D* l% Q
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe6 _* I/ ^! `: H! x( }
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
, Y9 B& T, c& e4 S9 ?. q0 H+ MO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE. V4 D) ^0 _/ Q0 W
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
6 i7 i! T, R' d, RO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe5 K! w7 F. L" _0 A! j
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
% T4 Y& Z; H7 _5 r/ _$ N' F) UO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe' {2 P2 L, O9 u; t- N
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe, _2 c. ^: f/ \' X$ X( s6 D) m
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
$ a# W; ?2 N& M2 U. L: A5 EO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)8 ~* M4 z/ H, P/ j
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
- g3 L3 M( C" ~: V8 E0 Q/ ZO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
& R2 k: @. n/ Y6 {O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
, N3 R9 h b% E4 wO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe) i. v* T* t, o! T, M
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE2 |/ v* m8 i: z# s7 J# J) a
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
% j4 T+ b$ _/ Y3 [8 ]5 iO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|