 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.12 p5 v( y; Y1 O# i
Scan saved at 16:55:24, on 2006-5-6
) w) `+ Z! S" Z( C5 KPlatform: Windows XP SP2 (WinNT 5.01.2600)6 ~$ N% E5 P* u" D; ]
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)* [- s: O# p0 ~/ }4 J5 c0 G4 M
W2 d6 i$ g* |5 }3 l' l+ O
Running processes:
7 D3 p5 c4 I" B/ eC:\WINDOWS\System32\smss.exe2 I! k' B) Y3 F5 e% I0 h
C:\WINDOWS\system32\winlogon.exe
% L# p; L2 @! S6 N0 ?6 ~C:\WINDOWS\system32\services.exe+ l7 Z* y( k8 a p% d
C:\WINDOWS\system32\lsass.exe
$ ~! o/ c0 B# ]! s4 ]C:\Program Files\Common Files\Virtual Token\vtserver.exe, I* x; E5 A; m6 |' Q
C:\WINDOWS\system32\ibmpmsvc.exe4 ?3 C. ^) e. V7 Z6 I
C:\WINDOWS\system32\svchost.exe
- c- U+ }. I: ]+ RC:\WINDOWS\System32\svchost.exe
, p: Y- ]$ L; P! mC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
: o }% H0 b/ ]3 NC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
# q1 Y5 @8 ]& XC:\WINDOWS\system32\spoolsv.exe+ h( {6 _: ^6 [
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
7 W; p7 p6 `) k' y, L: I+ y" _7 }C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
$ M9 d/ l# ?, G O' V7 DC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe" M# G* c3 w# L2 o M
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
( M. G$ k4 [$ H+ C7 x9 m3 g pC:\Program Files\F-Secure\Common\FSMA32.EXE# j0 p: E+ n% s# Z: \; g+ j
C:\Program Files\F-Secure\Common\FSMB32.EXE: e' y& _$ P7 Q* |' r) m
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
3 Q2 ?; n/ U. eC:\Program Files\F-Secure\Anti-Virus\fssm32.exe2 S& {' p& P }( z% @, G
C:\WINDOWS\System32\QCONSVC.EXE
, r$ C ?6 j) ]+ U9 PC:\Program Files\F-Secure\Common\FCH32.EXE6 h! Y( ]- B' i, u' }
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
1 E1 E7 t, |8 t' D' a# }C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe! q8 Q; e. A/ Y
C:\WINDOWS\System32\TPHDEXLG.EXE
2 C2 m& k, Y0 u. X F; kC:\Program Files\F-Secure\Common\FAMEH32.EXE
! h2 ?7 _ D, Q7 cC:\WINDOWS\system32\TpKmpSVC.exe
7 h9 w! P# Y/ T) {( AC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
+ A( M) Z) z$ \; q! \C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
0 u# x/ F/ U/ @0 l0 C# |5 `C:\Program Files\F-Secure\Common\FNRB32.EXE
9 i1 J, V8 R+ X0 E; a2 B5 A8 y2 _* {- HC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
" q- y8 j9 y* @: b! VC:\Program Files\F-Secure\Common\FIH32.EXE+ Y1 O3 a8 M4 b1 p2 e
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
; a) m7 x, L% X E" O+ hC:\WINDOWS\Explorer.EXE$ z) T# g5 B' |: k
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
1 g9 v' t8 ^: H1 @/ ~) c M3 f4 A1 x/ zC:\Program Files\Synaptics\SynTP\SynTPEnh.exe9 H: d: K0 Y" x+ I4 Z- c/ ^7 X
C:\WINDOWS\system32\hkcmd.exe: h& l. r' g& B& C5 [- z6 _* B% x
C:\WINDOWS\system32\TpShocks.exe& I3 z3 f1 n) M; L r
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe6 t/ V$ C$ a! u; Q2 t* f
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
9 f. H# B! a/ U0 G i& e6 i; C9 ?C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
' d) [8 h" X UC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe f9 T3 }# e H
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
. n V6 r( a# v& I& iC:\WINDOWS\system32\dla\tfswctrl.exe
9 u6 `: P6 A C8 n6 nC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
/ v, ^* [: N! V. i" r: _0 h" {4 ZC:\IBMTOOLS\UTILS\ibmprc.exe" @. P$ p( ~6 x2 t0 E1 N! H! A
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
; p) E& _0 P1 sC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
) K3 A3 X* F1 k5 @5 s" |C:\WINDOWS\System32\svchost.exe
% m; m' |/ X3 ~/ Y/ H0 R1 }7 s4 s) F0 ?C:\WINDOWS\system32\rundll32.exe
3 e* q9 }% @6 \$ a/ o+ v7 NC:\Program Files\F-Secure\Common\FSM32.EXE
2 ^5 H9 E6 F% g2 d; qC:\WINDOWS\system32\CTFMON.EXE9 @- N! S# J" u+ {3 ?# D0 q8 ?# D
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe/ Z7 [" [6 ?" s+ I
C:\Program Files\Digital Line Detect\DLG.exe, r, ]6 N5 f* y( X
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe4 U1 D3 k0 |) t
C:\Program Files\F-Secure\FSGUI\fsguidll.exe" u% ^2 B! D+ T @ V8 S$ ]
C:\Program Files\Messenger\msmsgs.exe. q0 f' t) o. T _
C:\Program Files\Internet Explorer\iexplore.exe
. ^6 @7 R! z6 P; X f+ \C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe5 N, z$ T# M" w
* {) f0 f7 a g" ] [O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
( p! w( j! C/ N/ C' T6 D. ?O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
- v; N2 j5 i. D) z: mO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" v, k, y+ H0 J" i/ l& c
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe/ H9 E; m( e4 h( A9 P
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe9 d. T' [; k. Z' G
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper8 B# v" G. `; Y6 p/ |; K& Q
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
% ]% H2 M g5 H' E3 p8 M' ZO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
1 g. D' x( ~: D9 _" _9 |: L- JO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
8 f6 q, E8 K8 y) ~" A# PO4 - HKLM\..\Run: [TP4EX] tp4ex.exe3 {% @% K1 j; i0 V: A/ ?
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
& a% K; ^! O& L1 C7 s7 {. ^4 PO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe0 j& K# _6 c2 n! {$ [/ w
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
( D+ I4 V* t: | _% MO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
% Q. L) G4 q2 @0 L8 LO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
6 y# O- g0 w) E$ }O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe3 E1 T& m C$ P" |
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
$ K! m6 A$ G. A- ?& X' h6 L. IO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE! e; R) q7 F% t% j4 x
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE9 N5 N# f. ?. j, W1 r: A
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
+ d' t: |% K6 q8 }' s. l7 xO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog. ?& [( I) g* _& c
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
) T9 Y2 e! E: P7 Q/ YO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
; V. X; X9 @5 G& |# _/ lO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
) ^) n- J+ n5 V& C4 _: F3 W" H: xO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
6 f8 i" G+ g, h( e: Y: f; xO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName j% e7 Z4 [& O/ _- C. }
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash) j% K4 i: U% O) ?
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW) b0 }+ ?$ J7 G" j9 @
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe! P9 [9 ^; v" t/ h* ]
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
9 ^7 H& U2 t" G; m$ t' GO4 - Global Startup: Digital Line Detect.lnk = ?8 d& g# t* ~" S- I2 b2 L; Y
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe8 x h5 u6 a8 _3 D7 X5 p
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm I1 W. w/ I% I) g" Q6 [
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
- j' P# q. n- I9 kO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
# a5 z; f5 k* bO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll/ C3 E2 J0 O9 q! k6 v8 S
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
! D+ C, p8 ~8 M$ u9 F* d3 d, KO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe+ M! h1 Y) L) q
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
7 j+ E" z5 g9 J9 l8 g6 i" r1 z. @' vO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe8 C p* @* U J# e7 {! V- B
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
" X, w& N; u! W3 `# y; @$ D$ AO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
, `9 P& y4 Y, r4 j9 s2 M- ^O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll% n) `& u |- B6 e+ |
O11 - Options group: [JAVA_IBM] Java (IBM): U% m J7 l- \. N
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
J- V% a5 W/ E7 L4 w: W5 U( sO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll. g* z; |# p: D( p4 c0 p
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
4 @' |( |. F+ x+ C" T% zO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
. Z( N; @; r" v P# d) CO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
8 X! q2 s& a' }O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe& ~- {0 R5 U# Z% F
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
9 K( M: L# d }; PO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE: A3 u! `/ r! @0 Z* L* }8 S
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
3 B$ ^* D+ n7 | k1 d1 \! KO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe9 ?3 W+ v$ ~& P2 o4 p' y
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
3 b/ ?/ d7 m$ _ ~O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
) _& P6 A; h3 }2 a! Y: JO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
, p: a- C W' G" D2 }5 K1 aO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe9 a, m4 E- K8 K8 i' W; L2 A
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)4 D2 p$ H4 f$ W1 ~* _4 ~% u
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
2 X0 B* N/ R$ U2 @* u& V M# @: UO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
+ q% u* c: y- A# {. N# O4 zO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
$ w U# ?1 ]) u7 l5 X1 `O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
; J6 `& r6 U- X& r5 }' [8 jO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE6 g5 d' M+ W- u/ [2 \
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe: q! j9 p' I2 f& `- }9 [
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|