 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1 m- B; {& Q9 ^. R
Scan saved at 16:55:24, on 2006-5-63 N& I+ z3 y: {' c5 q2 I
Platform: Windows XP SP2 (WinNT 5.01.2600)
r8 m$ J3 P4 x: d7 WMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)+ { h7 c3 g4 K( b# j
+ O( _' e/ q) [8 b+ j
Running processes:; v4 x D" g0 b$ W" ~
C:\WINDOWS\System32\smss.exe; C, B7 l# X/ P( ~/ V
C:\WINDOWS\system32\winlogon.exe. A, W: g8 y8 c3 k
C:\WINDOWS\system32\services.exe
" n U) \2 ?3 a) U" `6 S. NC:\WINDOWS\system32\lsass.exe
P' A7 r7 [1 ]1 hC:\Program Files\Common Files\Virtual Token\vtserver.exe' [5 G/ |* [$ C
C:\WINDOWS\system32\ibmpmsvc.exe7 q5 B8 v( h. _; D6 N, L
C:\WINDOWS\system32\svchost.exe3 Q9 D3 K8 I+ k4 M
C:\WINDOWS\System32\svchost.exe
9 ^$ y& q# o& S' W2 b9 uC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
( p5 S ^7 @+ j+ I, \& e" JC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
. m9 s* @: R: VC:\WINDOWS\system32\spoolsv.exe
! w) C, \- g+ L* E) x8 zC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE( e$ h0 P, Q5 a1 J% e- @* s5 @
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe/ X' R( ?( O7 J( u- ?; D
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
( {2 e; T& K. n5 S# MC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
$ n) y. K* }% [& |C:\Program Files\F-Secure\Common\FSMA32.EXE
3 }* y4 i" o6 E& pC:\Program Files\F-Secure\Common\FSMB32.EXE
# N: K- k, f8 y8 TC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
0 M" y u2 Y+ T0 V" r% \+ dC:\Program Files\F-Secure\Anti-Virus\fssm32.exe$ [7 u, ?3 k& t: L1 E( I& L5 K
C:\WINDOWS\System32\QCONSVC.EXE
) r1 [+ o1 w! I! U$ `- f* W& jC:\Program Files\F-Secure\Common\FCH32.EXE, }" r5 {6 R: }. v
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe. J4 M. i! B5 m. |
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
9 v0 T" Z% p4 c1 \C:\WINDOWS\System32\TPHDEXLG.EXE3 S0 n, D) |( P" y" z/ W7 s
C:\Program Files\F-Secure\Common\FAMEH32.EXE) Z1 J" i0 N* N
C:\WINDOWS\system32\TpKmpSVC.exe3 J/ ]6 S# I# c4 R
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe0 l# V. w$ k$ H O8 w6 D$ |! g2 X7 Y
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe- ]0 Q7 F, t9 a7 x+ O( t
C:\Program Files\F-Secure\Common\FNRB32.EXE/ y" P! O* _' f: B" v2 B
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe4 v/ {) o1 E; T. e+ A
C:\Program Files\F-Secure\Common\FIH32.EXE6 b% C" R# _) L0 W* X# M
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe/ }( Q$ `, j) u0 C
C:\WINDOWS\Explorer.EXE: W; V; S2 I1 E! k
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe5 b0 t* W( C; e4 ], r
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe( j0 \) z3 X- p, `6 n$ Y: F
C:\WINDOWS\system32\hkcmd.exe; U$ ?, P( Z0 e& x% G
C:\WINDOWS\system32\TpShocks.exe
: @- F. Z/ F4 B- ` h8 I) N. lC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
" v# G) R% j* ~/ HC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe3 r! \/ i1 o/ b2 |
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
' V, \' m6 O4 Y% d' x4 aC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
/ [6 o+ p% K" ^6 @' EC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
5 W ^2 j$ ?: K7 G0 ]! ZC:\WINDOWS\system32\dla\tfswctrl.exe4 ^0 S( e5 c$ x# [9 C* E
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe4 j- v3 E: S/ e, `' Q
C:\IBMTOOLS\UTILS\ibmprc.exe
/ ?+ r4 T; [3 d7 [( {/ LC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
' a" F+ i) d9 V0 {4 M6 m. oC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
( ] E6 f1 c5 s/ W i4 i% G- _C:\WINDOWS\System32\svchost.exe4 |( q3 z& }2 A a5 p5 H
C:\WINDOWS\system32\rundll32.exe
1 b: P( m- C8 b9 Y4 t$ RC:\Program Files\F-Secure\Common\FSM32.EXE/ y7 p* }2 Y1 u
C:\WINDOWS\system32\CTFMON.EXE% a) v, @, ? x
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe4 e* I3 \# t1 w
C:\Program Files\Digital Line Detect\DLG.exe4 l! U7 d) n1 A: ~% N6 b
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe ^1 N9 L' {& V2 }; y# m. T5 |2 t
C:\Program Files\F-Secure\FSGUI\fsguidll.exe
6 k# x* a' B! {) O' s+ v& @ aC:\Program Files\Messenger\msmsgs.exe
+ ~, \4 q2 |2 e# [8 k+ j% F2 IC:\Program Files\Internet Explorer\iexplore.exe
7 t5 Z4 Q2 a4 S, |" aC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe: {) B7 P3 |# q2 M1 j
% B X7 T1 s, R& n8 IO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
" K8 M9 H$ y6 K w$ e. rO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
' }& M7 R* U) ^0 GO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
7 L8 P9 q9 M, R8 p4 l$ B# w; EO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe) B: U# x) | w0 D
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe4 d( S, k/ i4 `: \
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
* {% o/ S+ O0 R" aO4 - HKLM\..\Run: [TpShocks] TpShocks.exe& R6 o; T4 Z$ b6 u
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe8 n) L6 s: M5 e9 M3 g
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup% ]3 |: A6 j5 L, X, Z+ G
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
5 {& v* S; B& j* }2 {O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe. m9 B7 ]& R/ l# T% W$ \( V
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe2 g9 K' Q! G% A$ C* d
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray* T0 t! q) h* |
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
% ^/ ?& z: G# V1 E# h5 YO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
% p7 P! W5 T+ T3 C# v Z7 A0 ^O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
5 f/ B- ]) J/ AO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe! {# `7 M$ W( p3 h
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
/ ~+ S: D( k/ GO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE& p" R% M: h% R- ]5 u3 ]* {
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor$ d B7 t7 H( A3 k
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog5 ^0 Q+ C; @$ B) u
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
' n" M1 z7 A% L: K* TO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
: E$ E% X5 a* F# W, | B( ?$ jO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
( O0 W& s; c8 D9 s5 y$ _ n5 OO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC* `% i7 L G- e4 _( ^; \7 g
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
) H: `* ], ^+ i+ pO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
Y5 k+ ~4 h4 |O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW3 s1 ]9 y7 L2 D9 W( N1 O
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
8 Z7 f9 i. z) g2 D4 H$ {- w Z1 IO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
% M5 y k- H7 Y8 |O4 - Global Startup: Digital Line Detect.lnk = ?- F; u, s& h, T9 L* l
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
/ v) v7 H, Y- x0 @' p! UO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
3 ~. |0 ~; a% |O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll8 j5 J- m* J( B \+ m# {3 E9 ]$ a
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
8 q2 E) @1 T9 fO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
: w4 s3 ?3 c/ m$ J( @6 UO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
% e1 s! Q" @$ `5 [" l' gO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
% e) N$ E7 e& r( B+ \O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
) x0 D- R( h: A% g! t' IO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
3 L( @! L2 b* R4 G: }( b$ Y; X: wO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll. A r7 w' i I' I; a0 ~
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll$ i2 z9 w: `% u, Y+ X
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll! l& o& ?! u* X5 d+ y9 s3 X
O11 - Options group: [JAVA_IBM] Java (IBM)9 k& D: e5 Q! d
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll* D' v3 [7 ?+ T: p
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
; j* A- u$ c1 U% B. A' LO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll9 h4 n L. s) m o5 {
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
, {" d1 z, z- |: nO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
" b% W, i/ c* dO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe( H+ s" H; B2 y1 h
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
* | V1 R5 Y/ j# O# vO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE- ^) y5 h( [/ P
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe6 \* v9 a9 A* N+ X% e P1 h" B
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe7 L7 |& G, C( ]+ L- R; g
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
% U/ @( v3 n" ^1 Q( mO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
w2 ]6 ~+ l% WO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
! y2 j0 C# s7 Y8 z4 B, S- {: ]$ DO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
% c0 R3 m$ Q, Y" S$ F1 e2 l5 }O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
- ?% I- Q: b$ y& O0 K3 EO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
# T1 w( D/ n2 G. q8 W* I4 iO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe+ |3 E- {' J1 c- M" g9 k& h8 F9 w
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe+ e- E+ s: f4 }' J. A% T/ Z
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
/ l" X# O0 e" r# fO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE, o4 I8 i8 _3 ]% N( l
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
- ]/ J1 Y$ ]' @* @2 V9 k+ z3 mO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|