 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.12 T8 ^+ `5 P3 k" I
Scan saved at 16:55:24, on 2006-5-63 O% A$ D$ F+ p( m* m' l! ?
Platform: Windows XP SP2 (WinNT 5.01.2600)+ _9 k: m e( R: s0 R- b
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)5 |6 [4 M3 A9 D N5 W* E
9 `8 P, X0 _( {- }" O1 f, F
Running processes:
- C9 ?* ?% u& ?3 Q( {( Q8 p" UC:\WINDOWS\System32\smss.exe
7 s# m7 D, @: `9 eC:\WINDOWS\system32\winlogon.exe
4 c! I2 W) T ^3 h; VC:\WINDOWS\system32\services.exe8 X9 E, o$ V: ? O
C:\WINDOWS\system32\lsass.exe
- c' M. G! M& ^8 ]; A% N5 B% zC:\Program Files\Common Files\Virtual Token\vtserver.exe
1 a. Q/ P% w1 f3 MC:\WINDOWS\system32\ibmpmsvc.exe
# b# L& U6 O# G& d8 OC:\WINDOWS\system32\svchost.exe/ ~ T4 \' k+ I6 N; P. |
C:\WINDOWS\System32\svchost.exe
# W- z3 h1 |7 FC:\Program Files\Intel\Wireless\Bin\EvtEng.exe3 `1 v- H2 @3 ~% d
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
: F1 t3 A% k5 E2 K+ DC:\WINDOWS\system32\spoolsv.exe9 i4 {7 f! O' ~. m. O# C
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE$ G5 V0 X2 t. g8 O i
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
$ C% Z- O: W6 c1 u3 eC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
; d0 }, Z1 ^) h" @8 d% q) U; WC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
x1 l& S# t, ?9 \" hC:\Program Files\F-Secure\Common\FSMA32.EXE
( T# Q0 _- H" z. {; L8 {C:\Program Files\F-Secure\Common\FSMB32.EXE
. ?2 O4 K& N9 T0 o9 oC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
4 u U. A4 L3 f: I$ e- U# z' K9 NC:\Program Files\F-Secure\Anti-Virus\fssm32.exe
" h" z3 @; v/ XC:\WINDOWS\System32\QCONSVC.EXE% v; H4 X* V9 n; L+ a8 L! i9 D& H
C:\Program Files\F-Secure\Common\FCH32.EXE. k6 R0 q( v1 n- p+ h
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe) t( t& @1 t8 L. Z2 ^1 w9 B4 ]! }
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
3 @, ~+ U! Z! E/ mC:\WINDOWS\System32\TPHDEXLG.EXE
2 [2 S6 ^7 Y$ D NC:\Program Files\F-Secure\Common\FAMEH32.EXE2 I6 I; e4 S, v. e2 ]8 \( {
C:\WINDOWS\system32\TpKmpSVC.exe: p0 |& {0 _- `/ }7 n4 {/ l4 V% c
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe1 R8 p# z X2 m" l2 M
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
4 a- F- M2 l' }0 iC:\Program Files\F-Secure\Common\FNRB32.EXE, E- t( L% A1 S5 ^/ _& q# v
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
0 S6 r' Z |, V# I gC:\Program Files\F-Secure\Common\FIH32.EXE
9 i( k# L# g9 k! G, @, ~C:\Program Files\F-Secure\Anti-Virus\fsav32.exe" C7 o, A+ r6 Y4 O$ A& s$ o$ r
C:\WINDOWS\Explorer.EXE
1 A+ ^* N; T6 I! }9 [6 oC:\Program Files\Synaptics\SynTP\SynTPLpr.exe7 i9 t# n U$ a
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
7 G2 M8 P8 [2 b& l2 N% FC:\WINDOWS\system32\hkcmd.exe. A) i2 U0 h1 [# a" ?0 o
C:\WINDOWS\system32\TpShocks.exe( g+ o0 G) }0 [. @6 x4 f, q1 c) o
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe$ l& U) q, t! U+ |( y7 N2 q2 W
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
, x( y- j7 A( T, q4 n% CC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe' |2 d8 h/ X' c( o& O0 ^
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe1 I% H! W5 |0 b! v$ N
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe+ t1 [9 |6 s" ^( {2 y# a
C:\WINDOWS\system32\dla\tfswctrl.exe" } y7 R! g$ n1 f$ }4 S; `, a
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
0 e0 F$ R* ?5 e- e0 HC:\IBMTOOLS\UTILS\ibmprc.exe c: ?3 h _; H9 i; A$ X
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE1 U- t8 y5 Z, R
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE2 Q/ |* s0 F8 G3 Y# k
C:\WINDOWS\System32\svchost.exe
# c" _6 x- ^/ F# W, p" VC:\WINDOWS\system32\rundll32.exe2 a. o% @* e! L& a+ O8 O0 V
C:\Program Files\F-Secure\Common\FSM32.EXE# g0 n) ]! p9 G0 ]% i
C:\WINDOWS\system32\CTFMON.EXE
. d3 o3 C" O* CC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe1 M( ?! b" `! d* S" Q8 N
C:\Program Files\Digital Line Detect\DLG.exe
; s3 c8 T5 g/ b% z, r& @% `C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe% \' Q. I; L: f* X3 e5 h: x
C:\Program Files\F-Secure\FSGUI\fsguidll.exe j' T6 `# O$ M+ m; X% x
C:\Program Files\Messenger\msmsgs.exe
6 y1 [; I% F y3 V& MC:\Program Files\Internet Explorer\iexplore.exe) G& \; \' D/ x; h! E
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe& _3 K6 h1 |$ A. u$ k6 X
" k5 S* j2 t! H, {O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
; [$ f% ~4 W! ?/ e$ fO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe) ^* k2 Y' T* f" j5 w8 V& b
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
8 w0 s9 T0 I# k; g4 b/ K; OO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe7 {/ K* K9 `: h3 q5 _
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
9 q& R8 u* f$ l# MO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
( A. b! E& _+ \& ~; kO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
% u6 y' R* ?9 t8 ]2 F4 V: vO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe' j: G% Z/ X" s3 r" [# s7 G
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
1 K' g& h' S, L7 E6 [' j h8 hO4 - HKLM\..\Run: [TP4EX] tp4ex.exe( ]; o3 ]) @5 Y( U: [ L
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
: `! I: q( x, r! U8 ?& yO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe' l" v3 K2 U8 u, D0 y0 @, l
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
* S+ Y, j: T4 R. [O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r+ |9 j: \' x5 j% A! b" |* W- C. r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
. R- n" o$ T4 a8 m. B; G+ }$ tO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe. ~5 o7 Z' L* y3 ?% z v
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe0 L3 x& B5 U( Q9 _& N3 r/ ?
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
+ ^7 G( p, T' kO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE: f+ V/ L1 O' j) k; W
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor8 E' j0 J& F* K O# w8 \# c; T: L
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog- _4 z8 C0 K* s" M
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
" [1 T: a6 k/ r/ h/ E/ ZO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE, N( y4 F% I, _1 z" k
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC& P& G+ ?( ?. K2 E n- b$ ~
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC8 z2 M( g) J+ c: W6 p, c
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName% j$ _& b: j* O. ^7 b4 Y
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
z- D6 H; A- u& h. w$ @: KO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW. N$ W$ T2 x' Z. R
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe& u' g9 ]; Y X
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe7 `* @6 W$ t7 {* F6 s& S
O4 - Global Startup: Digital Line Detect.lnk = ?8 V' W& M+ ?7 Q. s m
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
; p/ n( r# v0 {O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
5 {5 [) \, ^9 ?8 Y9 IO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
$ A8 v' d- j5 J' ZO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
7 F: Y: C M( a( d. Y& jO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
! Y. t, \( G4 B9 R: ]O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll& J6 ?$ o- J" l+ \0 n! e
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
" r% ~% |7 X2 A9 S, \0 b1 K6 wO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe \. \8 U6 W: n' s! j0 g
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe' _/ f4 R: o+ I' M# w9 ?6 I6 T6 S
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
3 A, N& f0 O( _0 [' N: J1 T! DO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
. ^# w$ M/ c: Z' @7 o% cO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll# T# j0 U9 V* `6 E( Q
O11 - Options group: [JAVA_IBM] Java (IBM)
" X: A9 \* @+ W6 @0 P0 ?2 R) fO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll& y4 ]8 t5 ~! q5 B; w' W
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
+ n5 p& b/ a# X$ d& k, _O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll* f* d* o+ `3 b& J! ^6 O
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
6 ]- Z) K" |/ ]O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
; @: o; \4 o1 u/ U, U4 ZO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
1 x! P. g' ?0 m: C$ k3 jO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe- u. W% C& V8 _: s+ W, B
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE, r5 h- z+ J8 U, t j+ a
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
" x0 |2 s) N: A8 b" JO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
7 {" f: f( s' `4 i9 m: @2 bO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE4 Y. T" O# m1 f
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe+ j Y ^2 L: P" v/ m
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe0 Q1 B' W( U* J( h x* ^; L8 t. `
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
, P, |( p& E7 _O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
6 b: `' w6 ~2 V) PO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE. m$ R, e7 g0 q* @
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe5 h( M! O! z8 ?% W0 e, {
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe) v& v0 H- o* S, o: q- m0 P
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
$ B8 W) f# N" ]* ^3 p! LO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
1 G( k. ~* a* `' K# E+ `( j* O' lO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe4 G, ^1 p" j. A; z0 W
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|