 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
$ G0 K" F2 [- c; i p7 eScan saved at 16:55:24, on 2006-5-6
7 T9 m" X# G- T* M, SPlatform: Windows XP SP2 (WinNT 5.01.2600)' z8 [1 m3 g9 `0 z3 N6 `3 H
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
! ^, L- M; [$ h6 l3 t/ q+ I8 a/ Y
& W6 M1 e) x7 n7 y6 H+ L! QRunning processes:, `4 e+ D( y$ m _- V; W
C:\WINDOWS\System32\smss.exe
, J4 [3 }% a. k& TC:\WINDOWS\system32\winlogon.exe
# G4 r; {) F, l3 D6 _7 A4 `C:\WINDOWS\system32\services.exe+ W7 ~/ F: v0 V, s; z% X
C:\WINDOWS\system32\lsass.exe# G; u# E- g7 ^7 W$ P
C:\Program Files\Common Files\Virtual Token\vtserver.exe1 L1 @% m: c* g' F3 F
C:\WINDOWS\system32\ibmpmsvc.exe; P3 U. P A4 x8 ~1 f+ h5 y, ?8 M
C:\WINDOWS\system32\svchost.exe
$ v& y- a/ {7 P5 FC:\WINDOWS\System32\svchost.exe
9 w: u+ j! g4 e% [+ dC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
" r( B+ X0 z. n. }! c' eC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe8 |( z0 i! y5 v- R3 l7 z# Q
C:\WINDOWS\system32\spoolsv.exe9 k) L+ o- x) u. _( s
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE F% W' [. |0 i& B
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
7 X M& x# |1 Y0 jC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe1 }% ^- u/ Z$ A
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
' O; Y" x0 k' _( y) IC:\Program Files\F-Secure\Common\FSMA32.EXE
) L) N6 @4 } ]' a1 r8 pC:\Program Files\F-Secure\Common\FSMB32.EXE
0 {7 s" w' h) z7 N% YC:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
9 E' C- U% A& A, u* e1 G PC:\Program Files\F-Secure\Anti-Virus\fssm32.exe+ K& y# @" M$ S( U- X1 o
C:\WINDOWS\System32\QCONSVC.EXE
" @9 @, e' v& O! CC:\Program Files\F-Secure\Common\FCH32.EXE
; f7 l: P* @; j) i/ fC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
, Y' f3 P( V+ ~# z7 E* z; mC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
$ {) N* F) ^* K( z6 C# pC:\WINDOWS\System32\TPHDEXLG.EXE, G1 X* T/ z7 Y+ v
C:\Program Files\F-Secure\Common\FAMEH32.EXE
) x! D' x8 ]( x: S2 P" uC:\WINDOWS\system32\TpKmpSVC.exe
2 r( F+ k3 H' \! ~$ }% Y; m3 x" IC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
+ x. k7 S5 G) o8 R. G7 m& p' kC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
& _+ e, d+ Z, N y3 v: sC:\Program Files\F-Secure\Common\FNRB32.EXE
7 \; f }' V! |C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
4 V, ~5 m7 g/ }, zC:\Program Files\F-Secure\Common\FIH32.EXE4 P1 x% _0 A: P# J5 i, r$ k
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe e6 s8 L( J6 Q* R& o i `: r7 t
C:\WINDOWS\Explorer.EXE
+ F/ D8 j3 w; _C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
9 }* d( Y; j5 ^C:\Program Files\Synaptics\SynTP\SynTPEnh.exe- i; e9 k& g7 H, `2 u0 g D
C:\WINDOWS\system32\hkcmd.exe5 q7 Q( {: K- Y) y; y6 l
C:\WINDOWS\system32\TpShocks.exe
1 J3 ]7 k, `: @C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe4 z$ e8 M \: T; N( }
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
@ T% ^1 K2 YC:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe: [3 @3 Q* A/ T1 W+ J
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe$ r# P% W$ G" S) i' P
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
5 q, f: v% `8 j" l: H/ ZC:\WINDOWS\system32\dla\tfswctrl.exe0 T) K( N5 A9 s5 g/ N: T
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe+ I6 N4 m$ V/ k+ ?. v& I
C:\IBMTOOLS\UTILS\ibmprc.exe
3 g9 d) ~$ I) U IC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE3 z# F" A' G1 _' U
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
, B* a5 ?# E6 N% r7 iC:\WINDOWS\System32\svchost.exe
) \, P/ K0 }/ jC:\WINDOWS\system32\rundll32.exe) z8 W8 L! E) ]9 t
C:\Program Files\F-Secure\Common\FSM32.EXE+ d/ R- ~- U) L Z
C:\WINDOWS\system32\CTFMON.EXE& Y+ f1 i1 E8 f* |1 \# ]& d! U. [% o
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
5 Y3 J# |: J' y& Y4 OC:\Program Files\Digital Line Detect\DLG.exe
5 A2 W/ v+ O6 {# d7 d9 vC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe! b) S4 X3 k" ~% D% \" _" z! \
C:\Program Files\F-Secure\FSGUI\fsguidll.exe
' R9 K, Q" h& }+ P) P7 c& a) G5 T' x) ]C:\Program Files\Messenger\msmsgs.exe
5 m7 E( m3 z! x- z5 U hC:\Program Files\Internet Explorer\iexplore.exe
; `3 P0 i% _- M2 NC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe$ C, c9 g1 r+ ~4 f' ?9 ?
6 b4 I( K2 N$ PO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll: t/ v. {& q/ J! [( m
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
$ G+ r! Q" j- y! xO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe6 W# p% N5 `. i+ k
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
6 V+ {8 C$ b. Z5 Q- }- \* ]1 cO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
+ C9 T" g9 U/ v4 rO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
1 N- a# c! q0 l8 QO4 - HKLM\..\Run: [TpShocks] TpShocks.exe: n2 ]6 j# U6 x5 l
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe& a$ p9 R9 ^; C( u7 b( [" R
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
# K' w) q% c: b% ^2 rO4 - HKLM\..\Run: [TP4EX] tp4ex.exe
7 r/ h7 ~2 D$ j8 W8 zO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
5 Q% v9 O' y6 |+ l: e6 o( [O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe, j# g+ f1 {4 m9 q& g
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
0 I3 [5 ~6 I) I3 OO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
& s& @3 O8 l: P3 N2 M7 c! XO4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe& Z2 M" {: S x a
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
) r# j! w$ h& l: b( t6 `O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe, T; R! ]1 c, _6 I1 R
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE( n- `3 L1 b: I4 f9 L" T+ p5 B
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
( ?& x$ S7 q' U [" H- jO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
4 f3 Z. [" P5 C( fO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
8 E5 M/ X) F+ yO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32) ?' O3 a, b$ ~( a6 M N2 _& l
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
7 X" K( z5 I2 ^ E5 T5 U0 QO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC/ z" Y* P3 O9 |* [ W( y
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
9 {1 t5 R [/ b5 [2 sO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
; u* y' m" _! U- h8 zO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
1 Q* S; f8 A- P, d+ [$ IO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
- C* A/ f6 Q* z4 c! D. y1 Z. P0 LO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe# B' a% S* R7 T6 Y
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
! ~6 t1 [& j5 P# ]6 [+ N: d& cO4 - Global Startup: Digital Line Detect.lnk = ?
+ I5 R. S; U8 c: I0 W; S: ]O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
7 s! f n( z. P0 GO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm) r) q4 B X2 J3 b
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll0 N" `) k% }& x1 A
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll1 v' |8 x. Y! S% O4 {
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll$ w0 x. O N# |
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
! s7 _+ @+ u& u7 ^) u2 i" ]2 r t, ZO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe2 l/ J! h' K o+ @$ }& j
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
, R" u1 @9 c4 f; ], T* }6 |O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe9 b. \( |) ^+ _( s
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
8 X, w/ x+ m( W" v" R. q6 j. zO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll* V% D8 l b( U/ C' |; [! N6 F
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
% A7 Z8 L7 [& C( T, o {O11 - Options group: [JAVA_IBM] Java (IBM)( y( B# G, O ~8 e& j8 Q# C& l$ N
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
' Z' H- F8 K) p ]! DO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll9 j2 u+ Z+ @) V# ^9 Z
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
9 o: v) {, u* F: d( f4 yO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
( S1 f6 @8 z1 m) NO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE1 ^, Y% |6 {, r
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe4 A2 z m- C# D) y" E) {
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe6 n6 C* O& W* a# Y
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE% C O4 D4 d9 [. X% H0 }
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
$ M6 A( G8 {$ c$ l+ YO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
& l1 g! [9 t- u( C7 r9 O( nO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE) x; V$ u4 ~! W2 x. F7 q
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe2 j8 ]2 g7 p% [% m# f
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
6 W2 Z$ Z) J9 J! U0 S) K/ a xO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe' r! g) ~7 r% g
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing) }- |- X- ?; ^9 R. I5 c
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
& ?1 W- V: C- O7 S- p: m, o" x8 QO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe1 ~8 a, z& V8 b% |9 V
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe" ] O1 Y1 Z4 r g
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe) n3 X; Z2 X. l3 n0 Y; I
O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
( B; k: l" h9 {9 H! E" bO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe4 }/ X# d9 B; _& Y6 |# J# C
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|