 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
0 r3 @; C9 N- {, t [/ @Scan saved at 16:55:24, on 2006-5-6/ ^/ ~$ [% _# ^; D6 X) R
Platform: Windows XP SP2 (WinNT 5.01.2600)
- R% F- N4 b% K/ {9 v# ?/ BMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
3 H- h# u0 B- @9 m7 P7 r" ^) r" T8 {/ ]8 C0 ~+ m8 K1 I4 w
Running processes:: H# B$ m% T( T z k& x: F
C:\WINDOWS\System32\smss.exe; R9 ~# G0 M; S" n/ y0 @; E1 q
C:\WINDOWS\system32\winlogon.exe
9 I- U: D6 q! J; b1 ^% U0 j4 lC:\WINDOWS\system32\services.exe1 G. ?3 j5 |) ^& d
C:\WINDOWS\system32\lsass.exe
$ t+ I$ ?' I- N6 Z, H4 R3 rC:\Program Files\Common Files\Virtual Token\vtserver.exe
' K* W3 A0 R6 |3 s( q9 M9 J, sC:\WINDOWS\system32\ibmpmsvc.exe
* z: q& C! d/ v) n0 G% A; tC:\WINDOWS\system32\svchost.exe r8 G# b) U/ |: ~: ]
C:\WINDOWS\System32\svchost.exe
8 D1 g; U$ }# I: [+ ~C:\Program Files\Intel\Wireless\Bin\EvtEng.exe; F9 e j3 _2 G& U' ^
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe6 A4 R; s, O* u/ g! a9 d$ t
C:\WINDOWS\system32\spoolsv.exe" C4 c6 U& M" }! l7 I3 S# t
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE$ |1 T: \! J$ d' X3 ^+ f8 Z3 t
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
5 }9 l% j. F2 v+ [- ~+ i& MC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
& \& Z/ x' f6 C' O: c+ {, VC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE, s( `' v% @% }0 k
C:\Program Files\F-Secure\Common\FSMA32.EXE
5 W5 ^+ z# ~# F! F! c; \0 }$ sC:\Program Files\F-Secure\Common\FSMB32.EXE
0 N I( k5 A' ?( m5 {$ yC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe; W" w; s" r. z" ]2 @ ]1 i4 q' b
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
6 M, b: S" p) gC:\WINDOWS\System32\QCONSVC.EXE; U) O% r, |; a0 n/ B% `0 r
C:\Program Files\F-Secure\Common\FCH32.EXE
- a8 f8 G, B# j( B& [. P# R8 wC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe1 i! Y! j$ v& ?' }. t2 }& g9 C
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe0 j* [/ W/ _ @% |5 j' a5 m7 e
C:\WINDOWS\System32\TPHDEXLG.EXE
$ m; [: g9 K' O- R/ O+ kC:\Program Files\F-Secure\Common\FAMEH32.EXE
: U$ Q- O7 e f$ k" yC:\WINDOWS\system32\TpKmpSVC.exe+ N9 D8 F' q9 y$ w3 Q! X& y8 c
C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
; j5 e% @+ f# vC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
% c! ~: {4 \4 G' E3 n0 sC:\Program Files\F-Secure\Common\FNRB32.EXE
* Y! Y9 n, E5 n2 d* y) G% yC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe. Z* m0 E) X0 `& o
C:\Program Files\F-Secure\Common\FIH32.EXE
; l, t. u" k: H9 @: r. TC:\Program Files\F-Secure\Anti-Virus\fsav32.exe, E W: k" M" I+ E2 C1 n) c
C:\WINDOWS\Explorer.EXE
# h! j. _+ S, F7 F% }8 v3 ^3 E' p9 U7 jC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
1 d) q, ^8 B j1 E& I. \6 Y3 XC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
+ ?4 t( X' I8 p5 h! R2 YC:\WINDOWS\system32\hkcmd.exe& K# u% r/ O: e
C:\WINDOWS\system32\TpShocks.exe
+ ^1 n- [+ Q5 @ a0 O8 k O! Z7 VC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe4 q- t; v! j* w! H) u% X
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
- U3 ~0 q$ t& q7 V5 z% C( zC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
. _6 c# M R* G/ X, C( ?! z/ @C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
" Q3 ]. c- k0 uC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
9 U2 R' d) P% A8 r( vC:\WINDOWS\system32\dla\tfswctrl.exe
" A) R: V% L/ p5 _C:\Program Files\IBM\Messages By IBM\ibmmessages.exe- r# R7 k, h) m) ], z. D/ R; d
C:\IBMTOOLS\UTILS\ibmprc.exe" z; d6 h; P) M" Z X o9 \
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE8 ~, v7 {9 ?/ H! O
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE. u; }7 T) v4 \2 L. }% y
C:\WINDOWS\System32\svchost.exe
& n2 O0 u* y3 Y$ VC:\WINDOWS\system32\rundll32.exe0 x$ a* J! j$ r
C:\Program Files\F-Secure\Common\FSM32.EXE
2 r+ I, I$ m: |" C7 cC:\WINDOWS\system32\CTFMON.EXE
, Q8 ] o, Z( IC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe) Y) M8 h, ?# F" q4 v
C:\Program Files\Digital Line Detect\DLG.exe
2 S/ l9 q" _" P7 h1 u" D' NC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
+ F6 u; ]1 U: K7 `7 m9 aC:\Program Files\F-Secure\FSGUI\fsguidll.exe
! R/ v# C* ^+ I; z2 `1 ?; j; ]C:\Program Files\Messenger\msmsgs.exe9 Q0 c& k! Z. P$ G% D8 m2 {" {
C:\Program Files\Internet Explorer\iexplore.exe) J" [/ @/ v0 R6 f4 O" Y% e- d ~5 T
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
O6 I( t* D9 ^$ ]5 p. ~1 M [9 S0 d3 L- R, x) O' Z
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll+ ^/ y" P. Y% `1 C' O
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe, w3 s1 w4 ~/ f7 M6 e- y+ r
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe( Q- q8 W y" T4 A: V) H
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe7 Z2 M$ U! S- t, G
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe6 |; v; |* {% u; i/ z6 _! U( t6 C
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
. K- ~* Q9 W) ~1 iO4 - HKLM\..\Run: [TpShocks] TpShocks.exe' x" O' ]' _" a8 c- x7 H
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe# N( [, T* a+ A5 F0 V7 |# J
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
. B' {3 ?$ D9 |3 |5 a# [ N5 IO4 - HKLM\..\Run: [TP4EX] tp4ex.exe- b7 a& W( J/ s5 V% L+ I$ G+ J' w
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe8 J/ @% |) W7 i. Q, ?
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
* T- g3 U; U9 m5 g# e' j) z- NO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
* \' R o; B9 v. i, ^6 |O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
# F; w1 m, b; g& s& {6 \' D: C i zO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
% G) I! M9 l6 G- U4 a- d& o5 wO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe H: a" w6 g( G' Y' A U
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
& J. _& J; g( r( _4 {+ Q' Q7 GO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
( |5 s: G, G7 p I5 z; K4 zO4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE: s# h- H; A! f( n# `* M. N
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor9 Y( G" e7 ^6 {, t/ a; ?3 G
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog) Q/ [" X1 ~- q/ A7 `) ~
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
/ L$ j+ H3 m l4 }5 e. hO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
! Y- a1 ?; \9 i5 o& x7 C& E0 MO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
! D7 T$ }- v; KO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
$ h! M- p. k8 v( AO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName, X' {" |* r1 p: }+ v; S9 @
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
) M- D5 P2 U: k+ E! d, tO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
6 S Q' E, ]2 `) jO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe8 A, q" S) e. ?' R6 W5 F7 @
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe- a' ~' M+ W4 i9 \8 X/ Z" r# |1 O3 ]
O4 - Global Startup: Digital Line Detect.lnk = ?! \" f$ }! I* ?! K& w
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
1 x1 P7 x' v8 UO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
! N+ Y1 J; i! R* v' J& RO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
7 r# j$ t3 J3 f5 m KO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
( R, W6 j: g+ [O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
7 u: k0 t9 G, ^4 H3 U7 l: s8 vO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll. z( h0 @6 [! P. p
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
1 X7 f0 d; n- ~! X) j2 pO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe- t0 }3 O2 z( c
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe; T6 Q+ P! v7 j: I" I- z) `: L! a
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll/ Y/ s& ]3 k( ?2 d! W
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
8 m9 x* b! o, e9 @$ w$ W4 S0 zO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll+ O" A) B/ } z+ I8 s5 k
O11 - Options group: [JAVA_IBM] Java (IBM)5 K6 z4 C3 k8 l4 c7 R5 I
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
5 ]7 W8 Y$ H8 G" Y/ M# K+ gO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll" E( q* P! o: v* l, v2 Y* M" _
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll4 X' T& m9 P( R$ X0 K$ B
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll$ n4 m7 d+ J+ F2 A" G/ m
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE* U' d e" b% u0 M3 Q
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
3 k9 g; T" C- N/ M( g+ e" GO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe" y v }) d) ~5 ]9 S* z) [* |1 _
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
1 F+ F ?- \4 |; [7 @O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
~- y' X e& o1 S9 Q' h) Z' rO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
( r7 F3 [3 y. Q2 W/ NO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
2 Z, \; b& }" m/ d' |2 lO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe! o2 i% H" `- ^. h! k5 s
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
( X( N, Y' W: _, o, C$ FO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe3 g9 a# r3 ]3 u- T/ m5 @1 d
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)( Y/ J7 u& F- x `
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
j2 `7 t+ g6 FO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
) ]+ H6 @5 n! b! @9 E/ \O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
0 G# n6 X. T) n) q8 j9 _ XO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe; [" K# X* e7 h' @
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE3 [% j" a, G8 Z) ?
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
+ @6 c/ M, S2 J( p$ l6 G8 Z, sO23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|