 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
7 p4 G8 Y8 K* ?Scan saved at 16:55:24, on 2006-5-63 z4 T; d) |4 e& ^' T
Platform: Windows XP SP2 (WinNT 5.01.2600)
I- B) B& s+ M4 j5 N; UMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
3 x8 E9 ]; ~ Q+ I4 n' C: ]4 f
, M0 X0 J4 _- }* j* B* L$ DRunning processes:1 p9 b+ ]7 L G! u
C:\WINDOWS\System32\smss.exe# B( a9 m- ]& e" I4 }% C+ {8 i5 w
C:\WINDOWS\system32\winlogon.exe
0 `) @3 T1 ?- P. g& v. R/ [+ mC:\WINDOWS\system32\services.exe5 N" P" @% J6 J
C:\WINDOWS\system32\lsass.exe) ]% ~/ L. R5 [, m
C:\Program Files\Common Files\Virtual Token\vtserver.exe5 k3 W2 M7 K% @
C:\WINDOWS\system32\ibmpmsvc.exe
( t0 I$ v9 k7 C) x, Y, bC:\WINDOWS\system32\svchost.exe0 n( J# E2 z( Z+ n# r y
C:\WINDOWS\System32\svchost.exe
# L% Y1 E& r2 \- CC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
5 i% m" ^5 L6 O0 z' CC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe4 i; z: \" T3 ^0 _9 ^; r1 b- L
C:\WINDOWS\system32\spoolsv.exe) j5 S) g8 |% w0 ~- p2 g
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE' V2 j0 K9 q, \) A6 w( c
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
7 I9 F! {2 a* y( J6 @$ SC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
& i- h9 A+ ?$ u: K# h& FC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
0 @ M$ u1 _" \, g) p3 \- k! r% w; }C:\Program Files\F-Secure\Common\FSMA32.EXE- H/ S- \( y& C; U( j
C:\Program Files\F-Secure\Common\FSMB32.EXE% }. }1 |0 s0 v: t N5 f% ~$ {
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe: N* D8 b: g" _( x& G3 W
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
- K' J/ c2 ^, _: j6 ZC:\WINDOWS\System32\QCONSVC.EXE. @8 Y1 t7 `0 o4 X
C:\Program Files\F-Secure\Common\FCH32.EXE1 K* b( T, k6 D* P3 D+ N" k
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe) r0 C+ T, d0 E9 e! a2 D. k
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe" B0 v! _) N$ l! a9 d. H) G
C:\WINDOWS\System32\TPHDEXLG.EXE7 E0 ^* x, k' _* R8 R5 U- Y7 @
C:\Program Files\F-Secure\Common\FAMEH32.EXE" o O) ^( \. S$ m% _. q
C:\WINDOWS\system32\TpKmpSVC.exe
% S% F6 n# \! x/ Y+ o7 [C:\Program Files\F-Secure\Anti-Virus\fsqh.exe% i7 W, N) m \" {9 ~
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe+ x' e7 y& j) E
C:\Program Files\F-Secure\Common\FNRB32.EXE
6 `9 N: t. c3 e1 \3 r, qC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe, f# f# T1 o. C. d8 K2 U3 W
C:\Program Files\F-Secure\Common\FIH32.EXE
+ H) q, Y0 K1 F# F7 q8 EC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
; `% A7 W: ]- T, Y; z% hC:\WINDOWS\Explorer.EXE- o3 ?# b' l, O. ^
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
* R$ _6 y4 \& I! b5 cC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
. \8 V% _) Q! G. r" CC:\WINDOWS\system32\hkcmd.exe
* e1 W3 {! F; A2 c, q- o0 x* H$ RC:\WINDOWS\system32\TpShocks.exe
! k" M8 j8 b; H" i8 NC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
9 f2 z$ ]: P. u7 gC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe5 C. E5 `' x; G
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
' ?9 ^7 |7 k: n% ?8 M( U3 fC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
6 b( w! T4 A' A4 {& ~C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe3 h3 \2 c# g* d# |+ D+ r3 D/ i
C:\WINDOWS\system32\dla\tfswctrl.exe
: q2 ?0 j1 N, J2 xC:\Program Files\IBM\Messages By IBM\ibmmessages.exe
! y( c/ ~' C' iC:\IBMTOOLS\UTILS\ibmprc.exe
1 S# P ~- o% i' V- R$ ]C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE* P) B/ `8 Z- i; l/ r1 X- U
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
' r5 {9 t( P2 \- K2 TC:\WINDOWS\System32\svchost.exe6 f+ T3 t( g/ B; E7 M# A ]
C:\WINDOWS\system32\rundll32.exe+ I' y( x/ [' [# k2 i/ _. \3 U: u
C:\Program Files\F-Secure\Common\FSM32.EXE
. [0 L( L! [" s- L- I# J- rC:\WINDOWS\system32\CTFMON.EXE
- _, e, e7 \/ `9 G# C. X9 EC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
0 }! V: W/ s. f$ R; MC:\Program Files\Digital Line Detect\DLG.exe# y" H/ C6 k1 s5 S6 M m& b+ P; r
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
0 r3 d( t* K( D# g& `# s* c% Y1 XC:\Program Files\F-Secure\FSGUI\fsguidll.exe
6 ?+ ]/ ?6 o5 f: D/ e8 h zC:\Program Files\Messenger\msmsgs.exe
1 T- z' [$ T5 [9 \& \! r6 ~+ Z, E# P7 zC:\Program Files\Internet Explorer\iexplore.exe
- K3 w) {# }$ xC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
# X* v/ @/ R/ s8 b3 g" H$ H; t; c2 q1 r6 y
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll2 s! U( V% \% \/ p1 ?5 z8 Z
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe) @& P- U& C: L2 |; V$ X
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe/ `/ c( C1 n! F8 M% K9 ]
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe C U6 c8 R7 e
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe$ x* i; u+ w5 A- e! F% g
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper5 y! X6 X4 ?1 W# J6 l2 n7 _
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
_9 ~ c/ m$ L# R4 d* N, NO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
1 e$ j$ N5 I5 x4 _0 IO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
4 q* O8 [* y& `6 pO4 - HKLM\..\Run: [TP4EX] tp4ex.exe$ E+ e" a: ~2 H' o7 @8 w" ^* {1 S+ R
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe: z8 m/ S# }5 {9 \2 S- J6 w/ j# E3 o
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe, M* E8 z- M* A+ P
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray' c( v* j9 \* n. y
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r! J( g- C6 o9 z7 V* q6 d: d
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe" B) V& \, ^3 t1 o2 @, r# s$ p1 }
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe. C+ f/ x4 r3 Y* k2 ~/ T0 p; S
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
6 r% F3 E1 J7 g) ]* xO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
0 N( M% N7 }% r! p- n1 }2 rO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
& l6 K$ f R3 O, z. D. ]; _O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
& ^4 g& g+ `5 ]0 F. ~) DO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog# b8 j+ j1 M. B+ H& T2 Z" l
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
3 H1 z1 [, c* C7 I0 G: o/ ~% CO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
) O, Z$ }( A4 X8 fO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
1 J7 h" f/ t" t; d) ~O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
7 ^. B# H: L5 p F3 ~O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName4 o/ R3 z- b% U; o/ J6 P
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash" r+ A7 r8 B0 E; M" ~
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW2 p% ~# a5 s$ {1 ?' M3 e
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
8 f1 i, W0 T; w1 s5 E/ jO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
- B& H; E% W7 ^& }; ?' H8 A. d: @O4 - Global Startup: Digital Line Detect.lnk = ?
( d5 u$ |* o0 q( b9 h, M/ I# `O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe/ N( X" C) v- O6 b$ B% U( ~
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm0 u2 Z: g4 U) M3 }# G$ ?5 b2 g9 [4 D
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
* V/ i+ M7 D6 C5 S3 r* MO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll9 _) W" Z" U. \. f, @1 L
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
7 l0 q) `0 A J4 ^* nO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
/ |& l) H1 p! c. I N/ Y4 W3 AO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
+ t9 J" D0 r& e% gO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
: L" F& N) V* S) Y; wO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe& A& k8 R8 v, e* M7 I6 [
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll X6 w) j# G9 Z5 Y3 u2 `
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll9 F; o) T8 ~; `! [& \
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
2 d/ L# \* N" n; v) M( V; d5 aO11 - Options group: [JAVA_IBM] Java (IBM)
5 Z+ [! e1 c3 X- C5 V( gO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
9 T; w& D( s& c% S( [) `O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll1 ^% s8 J, j" x
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll) C! r( @' N4 c6 O7 I6 K+ b3 s, j
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll2 O9 w9 H6 w9 v- D+ L' {
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE, b) l) f$ ^4 Y& M5 V6 Y
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
i8 j8 x+ _2 }; d5 `O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe$ c% p) O4 s2 t. B& W
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
& _& r$ G( y+ `( c5 P/ G* ]O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
, ^9 S; C% A8 c8 I3 l8 ~- E( a7 V1 SO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe s7 u, H! |4 H( }4 j* h. i X
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE9 ~5 ]1 ?3 C7 I9 p! d
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
( t2 p8 p0 J- y+ I/ UO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
7 o( j" G! |$ a% h3 f( m: T* sO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe- M6 [. k! P: i v! {" z
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)$ S7 u2 k2 Y5 h k d# v# T
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
' _. L* z- @5 P4 B0 f8 ZO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
; d2 d" E% d/ QO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
6 C, T/ |) H G. x* mO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe6 l% k4 A$ Q& a) v, n
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE5 e. K; t- _; H2 }
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe; b/ g3 q5 G& x" J
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|