 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1. A; u P; ]9 ` O" Q
Scan saved at 16:55:24, on 2006-5-6# o3 o8 G( Z/ m E' c
Platform: Windows XP SP2 (WinNT 5.01.2600)
% f8 |) y9 f4 P0 I8 V$ y4 OMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)- X$ X* r! H" b
5 [1 X0 \8 i% a1 ?% sRunning processes:
1 C9 ]. ]1 E1 bC:\WINDOWS\System32\smss.exe Y3 {; u+ U2 }1 }
C:\WINDOWS\system32\winlogon.exe
. T4 A) y2 q! {& w/ ~C:\WINDOWS\system32\services.exe9 v- z! {5 m* Z
C:\WINDOWS\system32\lsass.exe
; _: X) P4 k& d# H5 zC:\Program Files\Common Files\Virtual Token\vtserver.exe- F- z& j% O5 X8 X, u
C:\WINDOWS\system32\ibmpmsvc.exe: l; [0 v& }7 U7 @! f0 l2 g- l0 z4 G
C:\WINDOWS\system32\svchost.exe0 Z/ X7 x; F# G- e5 R( h' M
C:\WINDOWS\System32\svchost.exe2 W5 C; a4 U" f/ h& M7 d2 W
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe' G1 _" s4 w) O; _. p3 i0 u
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
; W9 K; T; z" l: K; [ t% U8 Z. T6 }C:\WINDOWS\system32\spoolsv.exe
: s; c- Q6 @& E. ^; l: m/ jC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
# Y* @- J! ]0 I3 aC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
- B2 e1 x+ m; @# I3 |; S6 `C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
/ Y/ ?0 x+ }/ BC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE# x* @- H% {6 [0 Q
C:\Program Files\F-Secure\Common\FSMA32.EXE! m, F' y% Y# O7 Z h
C:\Program Files\F-Secure\Common\FSMB32.EXE
1 G' R2 Y8 F4 ~4 vC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
% I# o- u' N7 @3 ?7 k6 X" J6 e3 rC:\Program Files\F-Secure\Anti-Virus\fssm32.exe
; X+ `0 ^0 T- k% b VC:\WINDOWS\System32\QCONSVC.EXE, ]% P" x: B) n4 h |& r) T& M( G
C:\Program Files\F-Secure\Common\FCH32.EXE
, @* G0 q+ I2 ?! q- @C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
/ A* G3 T) E7 h/ ]* W. K5 HC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe9 S. @$ q1 t% _. ^
C:\WINDOWS\System32\TPHDEXLG.EXE
0 O* z% \1 M& j- v+ n# {+ n' _ zC:\Program Files\F-Secure\Common\FAMEH32.EXE4 E: b! l& u( \6 p6 @0 C! ^
C:\WINDOWS\system32\TpKmpSVC.exe: t) a! g! _2 ^( O
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe" O) E( s9 x: o: V9 t3 x
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
* O: F' w" _1 ^) M: H0 B1 @C:\Program Files\F-Secure\Common\FNRB32.EXE
& S1 j( G. V" E; g0 VC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe# r6 `4 n$ X1 F+ s
C:\Program Files\F-Secure\Common\FIH32.EXE0 K3 j4 R0 f$ d5 p5 H, r
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe s$ [( h A7 h4 s) p- l
C:\WINDOWS\Explorer.EXE
% g7 f6 a: g7 T( T, H4 AC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
9 N1 D" K. Q5 M5 R* FC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1 {) N Y4 I9 L* m9 OC:\WINDOWS\system32\hkcmd.exe4 T% F# v4 Z U& f# Y$ W+ s
C:\WINDOWS\system32\TpShocks.exe
1 p! w- U! @5 D5 y% IC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe' E5 Y5 W4 Q' z: l
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
* u* u* S/ l6 ]: m. y1 o) NC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe3 r/ c3 b4 U" H8 h' S( V$ X$ u
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe8 {! M( {0 ^8 [
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe& E& Y8 M. _2 t8 u4 _: @* p
C:\WINDOWS\system32\dla\tfswctrl.exe
3 K( D% s z7 Y( QC:\Program Files\IBM\Messages By IBM\ibmmessages.exe: A8 d: t! ^8 g/ X+ f+ Y
C:\IBMTOOLS\UTILS\ibmprc.exe. t5 `9 D/ M2 d- W5 J/ s8 S
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
# s% \! E, V3 [C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE/ \5 m Y3 V$ _8 p. Q: J7 k
C:\WINDOWS\System32\svchost.exe
: I' x( F# x* F0 \( Y7 xC:\WINDOWS\system32\rundll32.exe" Z! e. G( l/ G" ?3 ^( X# ^
C:\Program Files\F-Secure\Common\FSM32.EXE2 Z; H: @8 ~' B% N2 ]3 |
C:\WINDOWS\system32\CTFMON.EXE P2 S8 S3 ~( v5 @; V0 z
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
3 z/ Q i+ ]# ?. r5 JC:\Program Files\Digital Line Detect\DLG.exe7 a$ N5 N7 c, l; Z7 I
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
! O( a) I `! f0 H* V& JC:\Program Files\F-Secure\FSGUI\fsguidll.exe( G* B2 p8 b; q( y" S
C:\Program Files\Messenger\msmsgs.exe
2 h" ?; W" v4 P ?/ y: MC:\Program Files\Internet Explorer\iexplore.exe
4 k: G$ l- }% |, X- ~/ s* XC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe9 C. g/ F9 ?7 J$ A0 G5 w& S6 @
* m% F; ~& |0 l( H$ @5 A
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll2 H4 O1 t! K7 @3 K9 e* U
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe9 E* C6 D0 x0 k, V( F0 r
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
9 x: n9 v; `1 N' \ e: eO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
% R! o! G7 _1 J3 VO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe2 s* b# d3 S0 f; }6 ~$ V
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
3 Y2 t8 l2 ]9 H! ~ B yO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
! M) F% `; S1 d" P4 MO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe' i/ ~7 g5 m- ]
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup$ [$ R1 L- [9 V3 }/ ^
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
6 u0 Q" E2 E- C% ~O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe6 J# y! K9 \% S+ b( t0 _, f! T
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe$ t4 g0 R* E! ^+ b* e- L, S
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray4 D; f& n* u# A: J+ |
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
0 q7 v" A- n5 n+ D% y% }- Z; VO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
' I4 m/ x- O: i. g+ x5 P& N6 AO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
- R- S2 ~% }8 a* m" DO4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe7 E2 w3 i/ L) J2 H3 t
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
% \3 E2 O( y& r7 ` ZO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
( U& f% X4 V" \7 GO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
5 k9 \6 @2 g. q7 p/ u! n; bO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog" o4 \ i0 _5 R* g
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
9 e8 I, x Y9 o( e( t0 P0 s' s1 K" AO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE0 ]1 {. T7 S5 R. G- V% W4 y* N
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
$ o( N- \6 p3 r( wO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC8 K! E3 r% _( G& r* B p' s( k
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
9 }5 P4 l. ^5 l5 xO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
( p: Y! t$ V) `- j% W. b* cO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
( O$ Y) p' i; eO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe P7 X% [1 i: C; e
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe, }) O5 Q) ` k e
O4 - Global Startup: Digital Line Detect.lnk = ?, n5 H% [# [4 g( d
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
3 e+ L Q1 z: r& _. q- MO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm2 i/ G8 _5 [" @3 W1 w. G+ o8 J
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll# f6 k& }( D1 |/ o$ t9 V& m: n
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
. U" V" ^2 |( \) Q* `- gO9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll) |* F8 V5 {7 Y' x$ r
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll1 t: |5 ^- K N- I. {! ~- D8 Y
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe) s8 ~( \7 g" E8 y6 x+ l
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe2 n Y1 C# `1 S
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe/ A) Q/ _( W, |$ d X
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll) z- G/ _7 p9 [3 D" L
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll- H8 O1 E& q2 ~
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll' T a2 P% b4 T# j
O11 - Options group: [JAVA_IBM] Java (IBM)) D) w0 n( b0 f. k7 O- w
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll# S- z% a" u( r0 I4 Y( V5 b
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll
0 d6 A$ b* j) X6 kO20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
3 b( q$ S5 ?( A( R( OO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
7 ?, n& P7 ~- IO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE0 s& G& o' n/ `& i l! q
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
% p. G5 t( x/ ~, n8 V; d4 n& }, IO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
- G+ d/ Y6 k3 h' S- r% l: N% lO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
; F; \3 x* C: }8 QO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
5 t1 c% O$ w% i+ T8 K5 F2 qO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
* d4 i0 i: t) ~* Q4 w2 UO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
8 y4 \) | w i" |% U! P6 O9 }O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
' N9 D! t+ ]6 \5 H$ r: DO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
; }! ], s t7 z" Y ?# c1 X+ J+ wO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe4 _2 y9 H; @- f, w5 k/ V+ y
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)( c& J2 {. N: i9 V, x
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE" r% j( |6 q5 i! B
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
2 B& M6 J( Y3 [! a7 u& T+ v3 ?/ @O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
- Y) N; J; z. H8 aO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe8 I* N8 P/ r! o
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE* a" v: \0 _; ]% S
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe8 r5 G, w$ C2 r/ o# c: F& p3 ?1 O
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|