 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
4 ]# \4 h' Z& A8 dScan saved at 16:55:24, on 2006-5-6# u- K# [5 ?2 v. p; b3 s6 S+ S
Platform: Windows XP SP2 (WinNT 5.01.2600)
! B2 X% c4 m2 i! @1 d, fMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
1 T+ \% r; d. z
0 C/ x1 L. \0 Y, f0 c8 ?Running processes:% b2 U: Y7 n, W/ Y; o( x
C:\WINDOWS\System32\smss.exe
3 x: z3 @: v$ l3 d1 KC:\WINDOWS\system32\winlogon.exe( I4 a4 E: S. F1 ~# ?1 [. p
C:\WINDOWS\system32\services.exe
+ H' p- S' J" C3 y1 L6 GC:\WINDOWS\system32\lsass.exe1 p+ h4 }3 z+ F2 K
C:\Program Files\Common Files\Virtual Token\vtserver.exe
4 W( s& ]- z: v" S& l/ sC:\WINDOWS\system32\ibmpmsvc.exe+ X& W5 k+ _% d2 X# h1 v! z
C:\WINDOWS\system32\svchost.exe
$ M+ H5 l# G O9 lC:\WINDOWS\System32\svchost.exe
' T2 x! O; J' W- e: a3 q' k3 VC:\Program Files\Intel\Wireless\Bin\EvtEng.exe5 P! }" v4 x3 E
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe7 _; T8 W! i1 e) g2 g
C:\WINDOWS\system32\spoolsv.exe- l h1 H! z/ k0 Z
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O- K4 t$ S, z& T) V3 WC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
1 K5 I4 ~1 \5 |7 N) h. @. PC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
' d3 F4 N/ Q6 }C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE# P( b& s/ o7 V; v
C:\Program Files\F-Secure\Common\FSMA32.EXE
: o4 b: X$ O% v! w) C( UC:\Program Files\F-Secure\Common\FSMB32.EXE
]8 H Q# z+ `0 r, g b( [) i* dC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
2 K# {/ c8 O1 ?5 }3 O y$ JC:\Program Files\F-Secure\Anti-Virus\fssm32.exe; D2 i' g ]% c0 u1 H4 A2 g
C:\WINDOWS\System32\QCONSVC.EXE* t) X/ _1 S5 y- ?6 k0 K6 q
C:\Program Files\F-Secure\Common\FCH32.EXE: U8 j `8 @8 g# a4 u% N) D
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
8 l+ [0 b) |6 C2 a [C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe; _- ^8 z! s/ D4 O6 r0 ?
C:\WINDOWS\System32\TPHDEXLG.EXE
8 w/ l$ v& H0 a: t0 e: I2 p' {7 i6 nC:\Program Files\F-Secure\Common\FAMEH32.EXE
% s( W/ g7 ^0 H7 i; d. y1 gC:\WINDOWS\system32\TpKmpSVC.exe7 C3 ~" f8 ?. v# |& S; S9 w
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe2 e- ]# n+ A& ^7 F, N
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
* ^! S, k# k' r, ~/ pC:\Program Files\F-Secure\Common\FNRB32.EXE, J+ }! M3 H6 L9 X1 k/ e9 m, p, k
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
" H8 ]* ]/ c4 p2 @! F' n s1 bC:\Program Files\F-Secure\Common\FIH32.EXE
1 L0 v% @' P. ?6 E# lC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
4 E8 y; P8 C& f$ c WC:\WINDOWS\Explorer.EXE
5 l1 Q2 @, V. M4 fC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
2 y3 C* `! H5 [7 r' d+ \' rC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
) S$ C; r# y# ?5 O/ b9 E9 \C:\WINDOWS\system32\hkcmd.exe( I( N: v5 u2 v2 E4 J
C:\WINDOWS\system32\TpShocks.exe/ [0 f" q; y- ~+ ~
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe K- c/ j2 U% F/ M+ O
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe' W3 b5 u. ]' _! Q6 ?% g$ G: U
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe: k1 M! |7 ` f1 R) ]- y. E
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
3 Y5 h$ q3 |9 k0 O( h8 gC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe4 T' d7 S; [3 J0 @3 T
C:\WINDOWS\system32\dla\tfswctrl.exe
$ S# a8 Y t+ RC:\Program Files\IBM\Messages By IBM\ibmmessages.exe7 G( `( T5 q M2 X2 d
C:\IBMTOOLS\UTILS\ibmprc.exe
! D3 {3 }# ]; [6 ~% Q: QC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
) x; E2 U/ Q3 z% A+ m6 L z) lC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE7 u. u3 n' u# I; B0 s; J Z& T
C:\WINDOWS\System32\svchost.exe
- A- j' s. q+ X! |0 w2 W; A$ c T7 IC:\WINDOWS\system32\rundll32.exe
; F# p: p7 ]1 o9 eC:\Program Files\F-Secure\Common\FSM32.EXE
N6 a s: m. s# bC:\WINDOWS\system32\CTFMON.EXE
/ M9 h1 z, L d( ?" m! }8 CC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
' J' z# C- g1 ]- A/ h8 OC:\Program Files\Digital Line Detect\DLG.exe
) J0 F6 u5 a4 F, ~C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
; u1 }- o& d5 m7 Z% `( E: zC:\Program Files\F-Secure\FSGUI\fsguidll.exe
; c: a, `8 Z! f+ {6 F4 fC:\Program Files\Messenger\msmsgs.exe' u8 X& R; \. m
C:\Program Files\Internet Explorer\iexplore.exe
i7 C7 \7 M: Z1 R/ ?- g oC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe: W/ |5 Z3 ]# ?0 @1 M1 N4 {0 o, w7 r
% |5 f d. h4 t2 c2 U: F
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll( j8 L, o7 v7 _0 R, `
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe% ?6 A2 a! l1 O: B
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe0 p6 e; ]. b4 \( a5 m% W; {! f$ l
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
/ B0 `$ a- b4 _6 q' }O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
/ ~9 y; Z+ H C' _* E1 R) H* _O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
* v# M9 `) u$ h9 oO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
0 q7 V! q$ P( y! T# R3 K) _O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
3 ?& L P& B9 [" i: |O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
8 @9 @; q: ^0 J% `O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
, n+ \0 w# y1 aO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe8 s7 G6 Q4 V8 p3 ?! u
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
' ^$ S4 o; W% s m Q4 b2 h) }- v; \O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
! L' W5 V3 @( |2 a& t, Q& aO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r& Z5 m0 O3 }* ?( K# g
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
, b; [: K6 B& M/ C) p6 l! XO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
1 o. P3 r% L& L' jO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
( \( L5 i3 ]5 n% Y& N8 n7 iO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE7 \% L8 Z, ]) |. z, i
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
/ m* \# A3 v7 r$ `O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
$ F+ M" M- t" L3 ]O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog4 w- k n4 u0 {. U' w0 V/ s
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32. O) _7 _- O5 O/ O3 S; N; G, ^9 m
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
! J1 g7 M- U) I' r F- C7 H+ W0 y! SO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC, J3 e7 p) h3 v2 T3 h1 M; |: y7 e
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC9 A3 Q. u; _# c% S H
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName2 e2 K, h3 q& S4 [* {/ |! F E' C
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash4 n7 q+ L/ M4 @8 d5 S: X
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW3 l4 K* J! o: m+ w2 E
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe# V" e: Q; p$ y0 B j/ `
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
. ?) W( L+ u H7 UO4 - Global Startup: Digital Line Detect.lnk = ?* L5 L; T# g, {) H
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe' i& A* o" q: P4 l. ]
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm6 Z, N0 b2 X* M) q
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
* L" P- |& a1 LO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll u! T3 o* a: M( e1 U
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll* P" s" t+ z0 [" [5 J
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll3 i/ w4 U/ S, G1 i+ T
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
7 K* T( R8 J$ [: h' U! yO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
5 O0 V) `3 r& e2 P# c' JO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe1 c5 P# G0 u8 n3 Q6 l
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
% X# [( ] N2 g& R. T) o% }O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll. v h# r$ c1 X$ Y y
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll% V2 I. d. X3 j/ m i) v% |
O11 - Options group: [JAVA_IBM] Java (IBM)
! x* D# l, N7 U8 W( ?8 P$ d7 ~O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll* V' M0 w1 x& B: U; n' f
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
2 h4 p+ v0 i4 X9 s9 _" v' y, k/ dO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll+ {- k* l: e/ ~ I5 ^+ v( Z
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
8 _0 ~" r" h, ]$ U: z& \# yO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE2 L; ]& T2 }% t2 i* k" r3 M
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
! r7 |8 }" h6 ?( {- Z1 YO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
^/ K" W9 l; ?8 yO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
! o% H, c8 U0 ~! [7 r1 kO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe& X! {5 x; V0 ?) u0 r4 N
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
! J6 u) {( A0 f/ `0 N* }. f2 W+ ^O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE1 N& U, t+ q5 i4 h9 o- T
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
, k D& j; I. C/ D& [# V; J2 OO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe+ X( n5 `# ~! f
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe, r7 |4 ^5 {4 W4 i2 G+ t) u$ W
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)/ `2 D8 ^3 M; H8 U* O8 }1 |- j
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
2 I+ ~& q0 N, [" ?7 |' y" @O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
( {& S: x+ L+ h, c! CO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
/ h8 @" S* I9 p4 \" g6 k4 i) L3 \O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe* l" v: X" O4 w/ @+ R; d) e G
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE6 w, ]2 F, V# P
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
6 y+ N* z4 [4 P0 g, R$ a! ^3 tO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|