 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
* w7 x. [) W% h. sScan saved at 16:55:24, on 2006-5-63 O) M1 v, N. R
Platform: Windows XP SP2 (WinNT 5.01.2600)
5 ^. q: Q9 T) |- ^+ F/ WMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
( \& P& w* Y, C' }/ k- I K" J6 B; D7 q8 A# N# m9 f) g9 v9 M' ]) Q% h
Running processes:0 L2 y n% Z: f& K
C:\WINDOWS\System32\smss.exe% t4 A3 F7 N3 H, |( k
C:\WINDOWS\system32\winlogon.exe2 d4 S0 k R2 e1 n& I# {' M( |
C:\WINDOWS\system32\services.exe
2 \6 ~+ w1 {0 |! a' B1 FC:\WINDOWS\system32\lsass.exe$ {# m5 u: _, m5 V1 k4 C% J; ]/ K1 m) u
C:\Program Files\Common Files\Virtual Token\vtserver.exe
% t) l- B% T6 f, W( K( GC:\WINDOWS\system32\ibmpmsvc.exe
8 `1 z3 `9 [$ q: _C:\WINDOWS\system32\svchost.exe( t5 p4 b( V5 Z
C:\WINDOWS\System32\svchost.exe. ]9 S; J5 i2 R0 t! h! k' V2 _
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
6 | t% R7 s, [: H' @C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
1 ~$ z0 g& X+ _ GC:\WINDOWS\system32\spoolsv.exe$ ? U6 h$ {" \+ y, U
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE) A2 Y* m# [& G
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe# L( v# P' o# W* s' J' n
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe! W. u( Q. s4 [$ l
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
$ C$ c, W9 E* PC:\Program Files\F-Secure\Common\FSMA32.EXE9 D* c8 _% J& |- Y# G
C:\Program Files\F-Secure\Common\FSMB32.EXE0 |6 U: o N) d, \1 k
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe1 z9 z9 ]1 i$ Y# o
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
3 ]9 y0 S0 Q9 k8 S0 A4 a6 b% @5 cC:\WINDOWS\System32\QCONSVC.EXE
4 [, Q: l9 P5 ?, aC:\Program Files\F-Secure\Common\FCH32.EXE0 G6 ~5 o3 j3 `. f# |' z
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
" [! j0 V# N* k7 O! BC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe7 j$ P H' h8 \% L" i0 _# X1 k
C:\WINDOWS\System32\TPHDEXLG.EXE# y4 V$ ^# `9 T
C:\Program Files\F-Secure\Common\FAMEH32.EXE% p2 ], E2 g+ ]
C:\WINDOWS\system32\TpKmpSVC.exe( \' F6 \- Y. Z9 X
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe0 {* Y0 i; O( O+ s5 s! d3 y) m4 O8 F
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe7 U9 @& O6 O F+ Y4 a: c
C:\Program Files\F-Secure\Common\FNRB32.EXE
: z6 v- K# g& X& j E1 vC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe5 Z# p- K3 e% { w
C:\Program Files\F-Secure\Common\FIH32.EXE
+ v; g" P0 w/ X/ w6 L1 V8 }C:\Program Files\F-Secure\Anti-Virus\fsav32.exe: J9 b* B' p5 f0 s4 b. J/ p
C:\WINDOWS\Explorer.EXE+ q# A# F0 z3 A' i# n9 [
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe/ g6 x7 _) H+ U
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe8 w6 T7 Z' L; b# o8 P4 H# w3 X
C:\WINDOWS\system32\hkcmd.exe( A. P Q6 G% }1 Z! x5 I
C:\WINDOWS\system32\TpShocks.exe
$ Z. o9 H$ G/ y7 {3 v- PC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe* O1 R8 v9 I' q! r4 H3 \1 W
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe! w9 f$ u9 J' M8 l2 M
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
$ P6 F7 s" j& F3 V9 O6 R& t5 iC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
0 D8 g: n! N0 c: @/ Q( ~" @C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe3 A' V2 X# W- q( Q1 ?
C:\WINDOWS\system32\dla\tfswctrl.exe2 k4 o' B n( Q% ~
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
& T2 H0 v! P- m: y8 _$ S# |% JC:\IBMTOOLS\UTILS\ibmprc.exe. D& Z: N. q; `: c3 @7 c$ S
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE9 e2 w6 b# m& K
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
3 r) v) S n5 sC:\WINDOWS\System32\svchost.exe
4 H/ z( ^6 z2 z& h! rC:\WINDOWS\system32\rundll32.exe0 F! I6 `& u$ y$ J, T
C:\Program Files\F-Secure\Common\FSM32.EXE
7 J. D( m! N" T, ] N, ]C:\WINDOWS\system32\CTFMON.EXE
, }+ \$ v Z, \- E8 ]& M% nC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe+ `$ B; g& N' U+ N: w3 Z3 l
C:\Program Files\Digital Line Detect\DLG.exe2 \9 _3 |5 R. s- q/ b) _/ s8 U
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe4 ]9 Y9 ?! ~, ^8 a
C:\Program Files\F-Secure\FSGUI\fsguidll.exe1 g. R1 R2 `7 v" ?6 ^5 g0 a8 W, A
C:\Program Files\Messenger\msmsgs.exe5 x! Y+ }9 G/ O
C:\Program Files\Internet Explorer\iexplore.exe
" M7 S# C7 Y- j' M/ k/ Y- x/ FC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe4 a7 L, d* @/ w6 V4 `" B2 C
$ i4 b4 V) e2 T
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
) }$ d* G, @0 w" _' _ F: j4 t7 pO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
( a; I7 f( n4 Z. V, v A+ OO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe) F3 V9 s* j: L( |0 I+ j, u
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
. m3 \$ Y* z/ U. F5 B+ `O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
( q+ A9 F' l/ K3 yO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper* f O% |; Z: X4 Y
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
! j- G! ]4 _: m, LO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe9 v/ o1 b% Y6 l# @* p# H
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
: h, b/ v9 d- R6 UO4 - HKLM\..\Run: [TP4EX] tp4ex.exe2 u' e7 s! k9 e9 G# @3 L5 ^+ N
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
9 g( l9 L6 y2 N9 W5 f( s/ y4 uO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe5 ?% j; r9 \4 t% h9 @3 a
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
+ c" ] o4 [% }, A# m- J; C# x3 C: CO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
! O& l6 ]$ [# t2 R% X6 N" zO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
+ D3 H K8 u, G4 j/ \O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
* N8 p3 ?$ I" a/ IO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
5 R- H( m# g3 A8 BO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
' S/ Y% i7 D1 p% QO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE' f' f5 G! Q/ ~
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
) l" R+ E3 |4 G+ u1 y- k4 ~1 sO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
% f; j- H- S# B1 Q5 RO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
( O, z1 v J% G$ R( o( k% ZO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE* f- \% d' Z. d) I- {
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC& g8 A: c% i' l
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
( l( K) ]) g7 o7 Z9 ^3 xO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName8 s' r0 P+ f- ^2 b' G
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash7 j/ r) R2 ]+ b. S8 }' u4 D
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW6 ?' [5 j t( p$ m! j4 n
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe$ L1 v* O3 v* e7 z1 {, }( {9 [
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
7 [; i( M# I: c0 FO4 - Global Startup: Digital Line Detect.lnk = ?
. Y5 g% l3 ~( U; t3 b7 XO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
7 ]% G/ K$ u9 S* c, {* S) w: g) ]O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
9 t' E, |" j4 c9 R. @O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
4 ~. o/ k/ I0 L% n6 dO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll4 d O% f0 H, A+ e# h5 h* c
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll2 D* L& }# M/ i
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll' t3 s0 C$ P' y- {5 [# l
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe- U$ {# X3 e4 a) ]1 t' O* D2 ]
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
2 _7 M' h L& f" ?) ZO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe5 ?! @. K- ~/ W H0 x
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll G( t* B+ f/ V
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
# X( G3 M; H. A5 C# f' GO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
; e. F6 p' J5 l- D3 KO11 - Options group: [JAVA_IBM] Java (IBM)
% ]* J2 h# `. h/ KO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll0 }# B% F8 h: I1 [% c
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
- t# V8 H+ a2 f2 t% M6 ?/ SO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
2 s+ m0 v+ w" c: B! gO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
. n) C- i! ]0 L( i7 rO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
0 q7 A1 K! I BO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
& J7 M. W1 ~6 k0 J zO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe2 F% c7 E& R, n I: l
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE6 j3 A& ?4 l+ n
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe+ e. P6 \* d3 T5 F) p4 o
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
0 N3 b6 \$ }' X7 {! I+ G o1 a! ~# kO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE! O( K6 I! v( u- b& ~
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe) v J8 e9 O# }
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe n1 D9 L1 {, ~- a, R# N+ N8 t' m
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
$ {& q- j; U0 }: A; yO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)( W3 t- J; g% R) D
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
$ M a* D8 J3 p- @3 ^8 `3 yO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe+ J0 \: m0 t; Y+ B( m5 v
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
4 v5 |. U3 I/ H2 l& w5 [9 u) u5 iO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe& ~- s7 ~5 Y, _* P% X; O/ @4 Q
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
0 f' h5 O; A) |8 t( e5 d9 mO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe9 N W0 Y4 @: K( c8 w. L# d. r1 V0 r9 ~
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|