 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.18 R$ I' a5 n2 s8 X+ C
Scan saved at 16:55:24, on 2006-5-68 W3 J9 A+ G, x2 B; I* F0 { t
Platform: Windows XP SP2 (WinNT 5.01.2600). b5 D0 F* {7 I& G) W
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
, l' x1 L% P( P' ~; a* I
$ m. z$ d2 G- w6 ~3 RRunning processes:2 {- S$ ~+ v+ |5 c9 W
C:\WINDOWS\System32\smss.exe
& V% W0 O$ x L& d. e% _" r. |( nC:\WINDOWS\system32\winlogon.exe
5 j' g! Y: c" s; H, ]4 L, G; F3 uC:\WINDOWS\system32\services.exe
$ W; j' d9 d4 K8 s4 L( kC:\WINDOWS\system32\lsass.exe7 N0 W6 Y( z; x7 G( Y/ @8 z
C:\Program Files\Common Files\Virtual Token\vtserver.exe; [0 p" D* t+ I
C:\WINDOWS\system32\ibmpmsvc.exe& e2 v- {- b! D( D
C:\WINDOWS\system32\svchost.exe
9 N/ z' ~8 d6 a$ x" TC:\WINDOWS\System32\svchost.exe4 i- V1 P! k' N" h: z" S
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
- v8 j, e$ W) ]% vC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe | q( n0 F* g/ `8 t
C:\WINDOWS\system32\spoolsv.exe$ x# A! |. k c* W
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
5 I L& [. u. s* h1 n% H; BC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe1 J! \! j% z! \$ g
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe& ~2 m. ~( u' B; C# Y2 g9 E7 o9 W
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE" }& r) w" x, D2 V" Y. ~* R
C:\Program Files\F-Secure\Common\FSMA32.EXE
( b, M/ a2 b& P: T! k" i1 a7 }C:\Program Files\F-Secure\Common\FSMB32.EXE4 [; h' b' w+ q; D5 V+ P5 |
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe) @: T& M0 z5 F# ^
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
. i# r. U- m0 N9 a. O; ~C:\WINDOWS\System32\QCONSVC.EXE9 o( n! L h* ]
C:\Program Files\F-Secure\Common\FCH32.EXE4 q1 C7 g* R6 o' ?
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe) b3 s( _ U$ q* M( G
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe, Q; S% [' ^+ f0 z
C:\WINDOWS\System32\TPHDEXLG.EXE( D( y9 H& q$ S `. P4 Y, E: `
C:\Program Files\F-Secure\Common\FAMEH32.EXE6 q; d# @! w/ O7 ~
C:\WINDOWS\system32\TpKmpSVC.exe
# F" p/ ~# b& m, \0 G) bC:\Program Files\F-Secure\Anti-Virus\fsqh.exe" ~2 K! d. C* n; p; X ^% L
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
" f( z1 Z" l( }2 _7 F7 o& t6 bC:\Program Files\F-Secure\Common\FNRB32.EXE
4 G: | O, n# Z/ o. G& k" u' Z. r- |C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe. ?+ F+ @- j( U; q. p& }% R `
C:\Program Files\F-Secure\Common\FIH32.EXE
- K5 r9 B( W$ J# CC:\Program Files\F-Secure\Anti-Virus\fsav32.exe
/ X1 a( n' l& c! |- q% ?1 FC:\WINDOWS\Explorer.EXE
5 K3 s! s/ ^; m# y8 DC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
, \4 O, X( S1 V# U, h# N( NC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
/ c/ }) R: a$ X x+ e2 V$ @2 v6 `) eC:\WINDOWS\system32\hkcmd.exe
& _. x$ k; Q+ c1 yC:\WINDOWS\system32\TpShocks.exe
0 M! c+ [. E$ Y* M6 ~C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
. ~" z) x. u& o% r9 d" W0 cC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe/ n$ h; K& y% J
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe- A0 p+ i$ j- u1 I
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe3 b, p/ P) J, v3 v+ q, u
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe+ i% l8 Z+ u) i
C:\WINDOWS\system32\dla\tfswctrl.exe) Y( _5 @0 G& z) v
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
. K7 g$ y# ?# F7 {* QC:\IBMTOOLS\UTILS\ibmprc.exe! {. w) r( s* X1 L2 H2 }8 y* K ^
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
3 q2 _, N" d' _& |' q) vC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
2 W, n. W* w, a) w: r7 b8 ^ x7 BC:\WINDOWS\System32\svchost.exe4 U- v$ @% Z8 O! i. `
C:\WINDOWS\system32\rundll32.exe! H$ k) i! r* w. s3 {- e2 }6 \
C:\Program Files\F-Secure\Common\FSM32.EXE+ e0 C& z: v. y' G! ~
C:\WINDOWS\system32\CTFMON.EXE; T- C5 J: ^8 f ?$ R( w% D
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe( x2 @1 Y9 I1 l+ X
C:\Program Files\Digital Line Detect\DLG.exe* O& ~% r8 g! @2 S4 c3 O
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe m' q' d% S! M% B; p' Y0 z4 ^, E
C:\Program Files\F-Secure\FSGUI\fsguidll.exe4 ~. o- E3 { [. {3 r! x
C:\Program Files\Messenger\msmsgs.exe
: e Y5 z q4 I1 hC:\Program Files\Internet Explorer\iexplore.exe' \) T; Z/ d7 y( s5 G; q
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
2 \6 `: b3 b% X, j1 a9 W. T2 P! d
) X8 _! ?$ m8 K5 u& @$ _$ N0 uO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
0 v8 n6 i6 W. uO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe% q8 R1 i# O5 P0 ]( s* F0 P7 }. _
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe: f0 F& T6 G6 h6 m* p9 V
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe5 U! m7 U1 U" u0 B5 K2 D
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe' d. z# V) Q* i3 ]: M2 Z" ]
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
! Q7 `- J( _0 L- A. q/ kO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
% ]5 L' p+ Z# g0 eO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe1 ]# H" ?# ?1 A1 N' \9 @1 O1 `' a
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
5 b$ w+ J# E7 r$ g- LO4 - HKLM\..\Run: [TP4EX] tp4ex.exe
+ f, b0 ^1 U. v( |2 gO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe, W6 n' j4 v/ J) @
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
6 @* T( A' L/ n( ZO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray0 |& s# \# k0 e
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r1 }: m+ _( @5 H* }$ x: ` E, R
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe. a/ Z7 s% \5 e& r- a- H5 J
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
( Q% P4 j. |4 UO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
2 f# C* m( g; u; S" EO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
. K6 a% l' R/ C5 e- jO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
# j6 Y+ \6 U) g( @+ w/ JO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor m7 \+ P- I' c b1 a# R
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
1 x; p0 o) @; ^5 x/ ~O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
( F; G8 j9 u. g% RO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
6 K, N. S7 H4 CO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC3 a p* o+ [/ B, A( j3 @
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC* o( k; h4 L6 j6 I% r0 N# Y
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
. \1 v( M& ~& D" {: L% Z: zO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
2 {6 S3 v; A! y% g& X+ L4 SO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
. D/ J' @1 h8 m" R$ @ qO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe% ~; {) f9 }# F6 n. G' M
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe7 A1 F2 J# R+ I, A* S% s
O4 - Global Startup: Digital Line Detect.lnk = ?
- |. v% n( D& {& D$ WO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe0 c( F& |& \. f9 r
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm5 x! k! T0 `- ]( L, P6 |
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll' L8 C' J3 f+ N7 Y4 J& |$ k
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
+ g1 R8 u% t0 d* b# ^" M$ YO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll! r6 c5 I' v- `6 Y. Q3 x
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
1 P1 }& Z: D& W8 m% m- IO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe! h+ {/ W. R" B5 Y
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
: R+ t2 J- N n: @ |5 SO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
# w$ C5 H/ Z7 h1 g: p: F( CO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
: T/ h3 s/ ~/ H* s3 U; \. Q5 tO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll- N$ _. x* B+ U3 @0 p' w6 N1 D$ Z
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll& E, o! I2 c! j4 B6 f
O11 - Options group: [JAVA_IBM] Java (IBM)
" u+ u. H( B0 m ?4 S4 pO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll& |1 a' a" R/ z4 V; s% V
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll* J0 Y' q. c( s
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll& Y' b- o2 C, R6 y# _
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
5 x& x9 D. G B$ t; [$ qO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
6 M& l& {$ L+ {9 a9 O4 t+ fO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
8 C* O! C" z6 j* {- FO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe' G! Z, x1 _) ]: f
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
: o7 t; T% H' E, fO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe0 n8 }0 a# A3 ?2 }
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
2 k5 I/ J1 U8 @! _O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE" n @" C$ n$ h$ |1 T5 h
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe7 d& M3 y& K& T
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe; R6 F0 z; q# ^* q& }* d
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe/ H- _3 B3 Y5 k2 r
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
5 c- Q# P6 r2 S# u, i: GO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE( r) P0 r& |; \& J3 q7 D, |9 ]
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe7 |4 U: A1 |7 ?, _9 _
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe& |' w$ G$ |/ N# P
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe7 q! o2 p+ m) T/ w V
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
! a% x9 p. {: x2 qO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
& ^, T4 E4 D9 T+ f- X6 gO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|