 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
) ^/ z3 |# a" [Scan saved at 16:55:24, on 2006-5-6
/ X) V9 M0 e$ T/ L8 qPlatform: Windows XP SP2 (WinNT 5.01.2600)
% j1 e% W8 A2 J2 t, i3 D; K4 D( LMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)% p8 }+ M0 N+ M& |, K& }2 L
2 K# L" |/ Q: K$ {Running processes:3 \5 T$ P7 I1 T" t" H
C:\WINDOWS\System32\smss.exe
% [2 V9 |% F5 g" G- K! m1 X) JC:\WINDOWS\system32\winlogon.exe/ l2 } U1 B2 b' ~
C:\WINDOWS\system32\services.exe
5 c" y$ D/ K8 m% Y0 z! WC:\WINDOWS\system32\lsass.exe
/ f# n& r$ F! h* IC:\Program Files\Common Files\Virtual Token\vtserver.exe1 Z4 Z2 D* ]- ^9 w: a8 p
C:\WINDOWS\system32\ibmpmsvc.exe
) T+ {3 d) }8 K3 M( c$ a7 kC:\WINDOWS\system32\svchost.exe
3 f, N' l! a& V% }% gC:\WINDOWS\System32\svchost.exe
" [- F9 Y1 H: s* f, e9 r, XC:\Program Files\Intel\Wireless\Bin\EvtEng.exe% i. ~& c8 ]8 J" Z5 \ [$ a' L
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
" j6 G, ]& x: g5 I; \" m+ I. j ~C:\WINDOWS\system32\spoolsv.exe
# c' n+ c; V6 r5 n5 t4 `& _& N fC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
# b2 W" E, m* T. DC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
3 C. a. v; w: z3 w* P1 JC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
5 _* e+ [% |6 BC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
9 }; H2 |( x$ ^9 h6 |+ o; ]7 B5 M# l2 dC:\Program Files\F-Secure\Common\FSMA32.EXE
: g+ l3 Y8 l1 cC:\Program Files\F-Secure\Common\FSMB32.EXE6 M! q. a8 V, U9 `
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
2 B4 I0 w' x6 V% C; W6 kC:\Program Files\F-Secure\Anti-Virus\fssm32.exe; i0 K6 u( f9 l6 J ]2 l8 A; c
C:\WINDOWS\System32\QCONSVC.EXE l; i' {. U- @% G3 V3 A
C:\Program Files\F-Secure\Common\FCH32.EXE2 h/ B( o) P4 b% ^% G* v) g5 t
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe3 T) }2 h( c. j6 H" L+ Y
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
/ i T5 K% k" m$ MC:\WINDOWS\System32\TPHDEXLG.EXE
% I) a% l! T2 wC:\Program Files\F-Secure\Common\FAMEH32.EXE8 j0 u" z2 f0 \9 z2 e1 n* i( O
C:\WINDOWS\system32\TpKmpSVC.exe
* t+ P! _$ w7 d% U: H" Z# ~C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
% ?( s& C; W9 B9 ]' l8 p( MC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
9 a/ E) K" C5 k5 OC:\Program Files\F-Secure\Common\FNRB32.EXE e7 |0 ]0 ^4 {/ k2 @" |5 {
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe9 f; b/ E# g H. y$ N# n
C:\Program Files\F-Secure\Common\FIH32.EXE
' m, a# ?9 D5 PC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
9 @$ L% N$ G! Y, H$ gC:\WINDOWS\Explorer.EXE
+ D, { H _& [) n* RC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
8 s. D4 w/ E jC:\Program Files\Synaptics\SynTP\SynTPEnh.exe- \/ G& ]6 ?% T- Q+ a/ z+ v4 M
C:\WINDOWS\system32\hkcmd.exe
/ w" L7 k( G" |: x1 U. V% |2 S4 OC:\WINDOWS\system32\TpShocks.exe, M& P2 S& g7 U
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe( W: S6 k# T& R" E8 {+ l
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe. W7 ]9 q1 A( ~( Q; z
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe l7 v* E. Y0 |, n" Z
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe4 r1 c) }! B3 k6 d5 C: e
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" t1 O$ p: S: p5 ^% f) [/ k# T
C:\WINDOWS\system32\dla\tfswctrl.exe! r5 o: y% W, M6 a' U( e
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
& \2 h+ d( v! E9 F1 Y' rC:\IBMTOOLS\UTILS\ibmprc.exe- H; x4 o) A7 c
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE( j$ Z7 m* W% |4 {( L
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE. Y9 n e, ?( X' S2 S5 w! I
C:\WINDOWS\System32\svchost.exe
E* w7 H' W1 f' ]6 mC:\WINDOWS\system32\rundll32.exe/ f0 Z7 t& e: Q- n$ u7 H
C:\Program Files\F-Secure\Common\FSM32.EXE
4 d3 ~9 S1 @7 A: Q6 _3 V( I( Y \0 ]: @C:\WINDOWS\system32\CTFMON.EXE1 v3 n- n) ^6 T$ `, {( Y6 O
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
: y4 D, ?7 o2 C" K: I5 UC:\Program Files\Digital Line Detect\DLG.exe/ g/ P0 O2 K8 L2 _ }) P7 g
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
* T$ l7 T9 c: Y8 \C:\Program Files\F-Secure\FSGUI\fsguidll.exe3 h% R6 ~, S! n4 Q/ w
C:\Program Files\Messenger\msmsgs.exe& h% s$ R# O6 [+ y9 c& ^
C:\Program Files\Internet Explorer\iexplore.exe; i/ K, W" f- h) W( A
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
* E% X7 D, G0 }3 S/ _1 U
; x# o o6 h" D) bO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
. @9 m! R- c1 X* a, J QO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
- r3 w0 I/ |$ L9 lO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe* @9 e! o0 R i! q
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe; U$ P- h- L" B% [& [0 O$ `8 ]( Q
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe5 r5 \; F5 A v
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper* e' s0 X. I$ ^9 L; {/ D
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe- m, a0 K, A$ ]
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe. _' g( T1 q( C
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup& ]; c. |% d" x4 P8 ~# I5 D ~
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe) T) m ~* B7 D( `7 T" B
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
/ A4 Q3 T" `) G0 p$ x+ C, iO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
4 s& F" ?, I* {9 ?O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
' o( X. A) K- m1 c0 f: q6 hO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
4 X* S) v& K: J( S+ jO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
. d8 g/ M) G% yO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
1 c8 X z: P, j$ }. `5 d SO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
3 o- c8 ?8 P7 O) n& JO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE* _8 H H0 t( ]. I
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
, M( I( i/ y: I8 u( K% N: nO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor. c; Y& F$ p- E/ w E
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
1 j- q* S/ J7 z# P4 r0 m9 oO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
: F0 b/ ~2 k7 v/ M2 q& E* O6 ?( w7 hO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
2 o9 s0 ]; q @2 Z: xO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
( N6 w1 E5 p* {: c% ]O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC5 J/ h& ^$ g% V, K/ E. d3 Z I0 |
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName# x! S$ o4 P* w3 S# q
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
" o, r( P: K, @4 w8 b3 i' [/ uO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
9 ~5 P% l. Y: jO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe, B1 z! z+ J$ `, k5 q. Z
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
# u t- p/ Q: n5 uO4 - Global Startup: Digital Line Detect.lnk = ?
: g* `- C8 T. I8 u9 |% UO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe/ p" V) f1 r' P9 j
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
* P! {$ p+ J) D3 CO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
1 Z j6 W) ^/ BO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll0 T" X! {* F0 J/ s# V
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
4 Z8 \1 ]& `: l* \0 ?# EO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
2 i! _" c* l; p1 u$ L2 m0 CO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
# ?( J- U& v1 s" j0 ?O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe l. |8 t% d) X4 S5 j0 `) X
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
+ G8 x2 I0 B: T- o- ~; lO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
. O, h& v P6 P7 j/ {* dO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
/ o9 I; e% \* Q8 Q) p: O8 XO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
# \0 i9 R+ ~/ _" w% z/ QO11 - Options group: [JAVA_IBM] Java (IBM)2 t4 @1 ^ m1 I
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll7 `) `: T( ~' Y% ]) ?- f
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll0 }) w- {0 x, Z. d$ I' r5 q8 C
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll9 p$ n/ x8 _% }' q
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll, b4 ]. r( p' ~/ G
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
" |4 J' o4 K1 F2 H- zO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe, d# w5 k2 V. Q9 J+ z
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe! C# ?! f1 i4 K" z0 L: _# j- I
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE' X4 E9 y8 X- c# D; J
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
0 W+ N6 V; D8 }; }8 WO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe' c* N' L. J& V" I; V" s, D8 ^
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE3 R+ X5 x; {: f& J% @1 K
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
$ I+ X, @8 |; K% ^O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe4 Z2 y1 g( y6 H6 J+ x3 j0 j+ \
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe. n7 z: x1 u& y/ w
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)+ O- O+ s5 }* a
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE2 Z4 u9 w2 Y, p
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
8 S4 N7 U+ ^0 p8 r+ t$ M( yO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
' X# Z9 W r4 {+ G, zO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
; q0 Q* ~, ^) f3 ?3 AO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE) j. z% Y5 i( C+ `# e4 d- D" V8 w8 ~
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
* E# @& o5 g) y+ f& kO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|