 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1$ @. F2 t0 E; e- ^4 G4 D+ \
Scan saved at 16:55:24, on 2006-5-6
5 c0 O4 \) }" ]$ ^0 v6 m2 e) t5 @$ GPlatform: Windows XP SP2 (WinNT 5.01.2600): J7 t* l# o6 [$ u0 Z6 I
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
& m5 s% z$ t/ a( c/ L* g5 n" R
6 s* I3 s6 L+ I# f* ]) n; aRunning processes:, e1 ^& E% S3 y
C:\WINDOWS\System32\smss.exe7 B$ s l6 P+ ?! ~) Y4 y
C:\WINDOWS\system32\winlogon.exe
4 }% C) @8 N6 M5 p# X0 P0 E! pC:\WINDOWS\system32\services.exe
/ `6 ^ f/ X3 Y3 B* L, z1 YC:\WINDOWS\system32\lsass.exe
8 ?6 G! U" K {* J" mC:\Program Files\Common Files\Virtual Token\vtserver.exe
" A8 t( U5 |5 t% LC:\WINDOWS\system32\ibmpmsvc.exe
8 F9 ?( V- |, c8 U$ m+ kC:\WINDOWS\system32\svchost.exe3 ^5 }# v& L8 J
C:\WINDOWS\System32\svchost.exe
$ _4 [' u; O) F( S3 Q) zC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
4 j: M6 e2 r% J3 d( ?C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
9 k0 P/ m6 `6 p. F- Q0 qC:\WINDOWS\system32\spoolsv.exe* j( P, ` M" g& C5 M
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
- M0 I8 _1 B9 M( u5 u c" W# m- oC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
& g" c% V/ S% h U4 {5 jC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
/ V9 ]0 P5 j# I$ Y4 |* j9 VC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
2 ?1 o4 V! ?7 I+ H+ U( [; s& CC:\Program Files\F-Secure\Common\FSMA32.EXE# H! L4 u4 S! A! ~$ }+ W% y
C:\Program Files\F-Secure\Common\FSMB32.EXE
. y% L' i) o& qC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe9 @4 `8 P; J( X" s; U6 v8 h% O( F8 G
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
" ?6 d. s$ l2 Q2 B2 ]2 c" jC:\WINDOWS\System32\QCONSVC.EXE# n# v% ~( J* X% k1 g2 `
C:\Program Files\F-Secure\Common\FCH32.EXE7 @ R% M% K- ?8 Q
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe: ~% {5 e- _" n' f2 v
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
9 V0 d f/ x1 A) P6 jC:\WINDOWS\System32\TPHDEXLG.EXE
2 R8 M1 ~- L) k( sC:\Program Files\F-Secure\Common\FAMEH32.EXE
$ J+ o% B; W; yC:\WINDOWS\system32\TpKmpSVC.exe
4 Z- a. j) P+ x5 YC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
# [, a' @4 b/ k3 b, Q0 D wC:\Program Files\F-Secure\Anti-Virus\fsrw.exe w3 z& ]" J/ w5 N# G
C:\Program Files\F-Secure\Common\FNRB32.EXE
" x4 T8 t5 ]5 g* c. Y( ?C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe: U+ H. B$ J& P: Z# {/ F8 l
C:\Program Files\F-Secure\Common\FIH32.EXE8 i, R/ V' u1 K3 P( J) H) g8 G
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
* g( W( m8 X6 A; I) ^C:\WINDOWS\Explorer.EXE6 i f3 }2 w1 g. o0 N. A
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe( o2 i" E* q5 \" v8 {/ z
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
0 `- w9 e' d0 [+ yC:\WINDOWS\system32\hkcmd.exe' f4 T5 s' u7 |7 U3 P
C:\WINDOWS\system32\TpShocks.exe/ S! T R4 v+ h2 n1 I* t. X
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe! u. [' @ }, T. i! t* f
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
1 V1 n8 x0 c lC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
6 C5 ^3 E. z! w# w) U6 l7 S# Z( JC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe# ~: w$ Y* r8 k4 A0 \
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
" M9 Q8 W# p: m& M2 ?C:\WINDOWS\system32\dla\tfswctrl.exe
- {+ a2 F, J! a6 H$ b7 t. iC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
9 Q2 q% b7 n* X2 ?C:\IBMTOOLS\UTILS\ibmprc.exe) E G4 o4 s4 }6 P: q
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
* Y2 U" \) q) h3 K+ ~C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
# i6 O* d% x; `4 V$ |- \! gC:\WINDOWS\System32\svchost.exe
5 ?( l- C3 v& W/ }- ZC:\WINDOWS\system32\rundll32.exe) G0 k" p/ M* x8 M+ s4 m
C:\Program Files\F-Secure\Common\FSM32.EXE7 c8 y4 L2 {; R% T8 U
C:\WINDOWS\system32\CTFMON.EXE
7 R1 r$ @ M+ g8 t4 yC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
" L- q0 ^- ]# a. gC:\Program Files\Digital Line Detect\DLG.exe
- s: @* h2 A& ?1 {! S& F- M8 s: MC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe/ P! H5 H' i3 P1 E# f
C:\Program Files\F-Secure\FSGUI\fsguidll.exe
# d$ S/ q3 |& L/ O- s! ~' K# G3 n! oC:\Program Files\Messenger\msmsgs.exe- @9 C' H" j0 `- b! R* m
C:\Program Files\Internet Explorer\iexplore.exe
6 w9 g3 z3 [" ?/ X8 h j1 qC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
% J1 K, p7 }% A0 _& E H1 M9 G) S+ k2 X1 d" Z6 V
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll9 X5 Z2 Q# T( X- n' w# m
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
6 s- r" {) o& z+ [' D& S' qO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe1 e/ L: |5 p1 h3 U: w
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
6 W2 Y$ x# c. A: I) N" LO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
9 @% I1 F5 U; [* o1 B! F5 a( z9 AO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
. O& }. p2 H5 J, AO4 - HKLM\..\Run: [TpShocks] TpShocks.exe: r- @* w' X) s8 P
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
% `: |/ E0 K+ l2 i& \O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup4 @ {% g/ d: H
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
, P# G$ M& ?. VO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe) }" G+ k# y9 e) A# y# A
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe. Z0 i2 T7 E1 `5 G
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray0 j8 n0 h2 O- \# Y1 {
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r: d% N% S' k- z+ s3 w
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe, Q2 E# K" U/ @( n! f! b
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
- l7 o) C- v, ^1 @& W# O0 jO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe& f& s) Z& Y+ N3 e
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
8 C$ B9 x; }: y: s, S3 i. aO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
: U& h% W* e/ l/ e dO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
- i& X7 [0 h0 \( U; sO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
$ W: Z" { z. I5 w- ^O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
' B: X' @% u, b& LO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
$ `2 {7 H1 o- Q2 y: c8 s* D& z( R& OO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
* h( q6 [: J1 T2 N/ S# N. h" tO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC/ K$ y$ r/ Q) M! F; l" U
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName$ ?/ c+ f# k& z# T( x" a* X" ^
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash& q$ ?0 G" @8 @( z* D" D! A
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW; _4 W t" W9 H Q: a
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe) a6 G: l5 `7 f) h ]
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe$ ?+ T/ _9 h" H: j9 [3 K
O4 - Global Startup: Digital Line Detect.lnk = ?
! C1 y6 G* t; `& n: C8 }O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
2 o2 O: v& a7 s2 QO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
% r: t; R; M d9 M, `O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll& T& Y6 v- ^8 r+ g9 k# e! X% \
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
( I" `* J7 C* p' @' j% @5 R- P2 uO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
: ~, Z7 w" B O3 l" P. g7 YO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
' O6 ]8 A: N; f+ k; g% i6 NO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe+ u4 g; ?- J/ E1 J8 h
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
2 ~8 R& B7 M, k, y f( e' OO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
/ D9 b% g5 L! F, \, {O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
. V0 r; g0 N8 u3 T6 c- W! H3 [O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll5 N- g2 O) z8 e) x
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll) Q" O1 p$ D3 I) v/ `
O11 - Options group: [JAVA_IBM] Java (IBM)- o) E" {/ f0 ^( b. [0 A" H/ U
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll/ b4 M6 ~- [, |
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
7 H Y# ]2 D& c$ oO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
3 g: V# Q0 j8 Z* o8 @+ |" FO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll5 j( |% O5 _- v/ u c
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
3 ]: h9 k% y1 }1 i3 e" p1 w+ rO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe/ t1 j4 W3 T. E1 e
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe7 F' O% N# O) r" X; u7 L! v1 V
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
& U$ L, y. d/ Y3 m( lO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
; d6 k ]+ r HO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe/ E& @- m, m5 }
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE( |8 B8 k& p) I& L& y N4 Q- W# J; v
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
1 e4 U5 v" P, q; B/ C0 c& L* Y% vO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe! V) c& X0 ]2 `+ k: J. N
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe9 n/ B* L1 c! D
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
' ]3 K$ K% z9 Y/ B4 ]. GO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE+ D* Q( H0 q/ Y+ [% y4 |
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe a. m0 c9 b0 i+ n1 H: r8 t
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
0 W0 J- t; s) e" e/ gO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
0 X% O! f y/ s$ ^; `+ FO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
; e+ @0 e. c3 w& eO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe& [5 z+ G" o' h6 g+ Z
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|