HJT Logi Kone boottailee

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by JimiT, Jul 8, 2009.

  1. JimiT

    JimiT Member

    Joined:
    Jul 8, 2009
    Messages:
    2
    Likes Received:
    0
    Trophy Points:
    11
    Eli siis, tietokoneeni sammuilee silloin tällöin kun esim. Pelailen jotain. Epäilin itsekkin aluksi ylikuumenemista mutta, huomasin ettei lämpötila nouse paljoa pelin aikana. Tietokone tosin ei boottaa usein uusia pelejä pelailessa esim pelailen vaikkapa Counter-Strike Sourcea eikä tietokone boottaa mutta kun taas pelaan Diablo 2 jotain isompaa runia vaikkapa niin kone boottaa. Toivon että joku teistä voisi kertoa minulle että onko tässä HJT Login mukaan jotain vikaa. Kiitos.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:33:12, on 8.7.2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    F:\WINDOWS\System32\smss.exe
    F:\WINDOWS\system32\winlogon.exe
    F:\WINDOWS\system32\services.exe
    F:\WINDOWS\system32\lsass.exe
    F:\WINDOWS\system32\Ati2evxx.exe
    F:\WINDOWS\system32\svchost.exe
    F:\WINDOWS\System32\svchost.exe
    F:\WINDOWS\system32\Ati2evxx.exe
    F:\WINDOWS\system32\spoolsv.exe
    F:\WINDOWS\Explorer.EXE
    F:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE
    F:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
    F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
    F:\Program Files\Java\jre6\bin\jusched.exe
    F:\WINDOWS\system32\LVCOMSX.EXE
    F:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    F:\Program Files\Logitech\Video\LogiTray.exe
    F:\PROGRA~1\AVG\AVG8\avgtray.exe
    F:\WINDOWS\system32\ctfmon.exe
    F:\Program Files\DNA\btdna.exe
    F:\Downloads\RocketDock\RocketDock.exe
    F:\Program Files\DAEMON Tools Lite\daemon.exe
    F:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    F:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    F:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
    F:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
    F:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\FSGK32.EXE
    F:\Program Files\Java\jre6\bin\jqs.exe
    F:\Program Files\Elisa Tietoturvapalvelu\Common\FSMB32.EXE
    F:\Program Files\Logitech\Video\FxSvr2.exe
    F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    F:\Program Files\Elisa Tietoturvapalvelu\Common\FCH32.EXE
    F:\WINDOWS\system32\HPZipm12.exe
    F:\PROGRA~1\AVG\AVG8\avgrsx.exe
    F:\PROGRA~1\AVG\AVG8\avgnsx.exe
    F:\WINDOWS\system32\PnkBstrA.exe
    F:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsqh.exe
    F:\Program Files\Elisa Tietoturvapalvelu\Common\FAMEH32.EXE
    F:\WINDOWS\system32\PnkBstrB.exe
    F:\WINDOWS\system32\svchost.exe
    F:\PROGRA~1\AVG\AVG8\avgemc.exe
    F:\Program Files\Elisa Tietoturvapalvelu\FSGUI\fsguidll.exe
    F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    F:\Program Files\AVG\AVG8\avgcsrvx.exe
    F:\Program Files\Elisa Tietoturvapalvelu\FSAUA\program\fsaua.exe
    F:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fssm32.exe
    F:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
    F:\Program Files\Elisa Tietoturvapalvelu\FSAUA\program\fsus.exe
    F:\Downloads\Rainmeter\Rainmeter.exe
    F:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsav32.exe
    F:\Program Files\Mozilla Firefox\firefox.exe
    F:\Program Files\Conquer 2.0\Conquer.exe
    F:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    F:\WINDOWS\system32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1750559
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - F:\Program Files\BS_Player\tbBS_1.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - F:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - F:\Program Files\BS_Player\tbBS_1.dll
    O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - F:\Program Files\BS_Player\tbBS_1.dll
    O4 - HKLM\..\Run: [F-Secure Manager] "F:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "F:\Program Files\Elisa Tietoturvapalvelu\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [NVMixerTray] "F:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
    O4 - HKLM\..\Run: [nTrayFw] F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [LVCOMSX] F:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [ATICCC] "F:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
    O4 - HKLM\..\Run: [LogitechVideoRepair] F:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] F:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] F:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [BitTorrent DNA] "F:\Program Files\DNA\btdna.exe"
    O4 - HKCU\..\Run: [Steam] "f:\program files\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "F:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [RocketDock] "F:\Downloads\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "F:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Stardock ObjectDock.lnk = F:\Program Files\Stardock\ObjectDock\ObjectDock.exe
    O4 - Startup: WinFlip.lnk = ?
    O4 - Global Startup: Catalyst System Tray.lnk = F:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe (file missing)
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - F:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - F:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - F:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - F:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - F:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - F:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - F:\Program Files\Elisa Tietoturvapalvelu\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - F:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
    O23 - Service: FSMA - F-Secure Corporation - F:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
    O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - F:\Program Files\Elisa Tietoturvapalvelu\ORSP Client\fsorsp.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - F:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    O23 - Service: Pml Driver HPZ12 - HP - F:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: PnkBstrA - Unknown owner - F:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - F:\WINDOWS\system32\PnkBstrB.exe

    --
    End of file - 8993 bytes
     
  2. JimiT

    JimiT Member

    Joined:
    Jul 8, 2009
    Messages:
    2
    Likes Received:
    0
    Trophy Points:
    11
    bump?
     
  3. 79atanos

    79atanos Regular member

    Joined:
    May 19, 2008
    Messages:
    1,945
    Likes Received:
    15
    Trophy Points:
    48
    Jospa aloittaisit poistamalla toisen virustorjunnoista, F-Secure (Elisa Tietoturvapalvelu) tai AVG pois, sen jälkeen pitäisi koneenkin toimia ihan toisella tavalla. Haittaohjelmia ei tuossa näy.

    F-Secure tuppaa käyttämään keskusmuistia enemmän kuin AVG, mutta AVG taas on muuten melkoinen köntys eikä sisällä edes minkäänlaista suojausta rootkittejä vastaan eikä palomuuriakaan kuten F-S, joten itse suosittelisin AVG:n poistoa.
     

Share This Page