Kone kaatuilee (apua tarvii!!!) + loki

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by AnthraXfi, Feb 26, 2007.

  1. AnthraXfi

    AnthraXfi Member

    Joined:
    Jan 15, 2005
    Messages:
    65
    Likes Received:
    0
    Trophy Points:
    16
    Eli kone kaatuilee ihan omia aikojaan etenkin peleissä.. lämmöt on ok ei viruksiakaan pitäs olla että mistä johtuu?? tässä loki

    Logfile of HijackThis v1.99.1
    Scan saved at 19:39:46, on 26.2.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\Ati2evxx.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\Ati2evxx.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\WINDOWS\Explorer.EXE
    D:\WINDOWS\RTHDCPL.EXE
    D:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    D:\Program Files\iTunes\iTunesHelper.exe
    D:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
    D:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    D:\WINDOWS\system32\ctfmon.exe
    D:\Program Files\Messenger\MSMSGS.EXE
    D:\Program Files\DAEMON Tools\daemon.exe
    D:\Program Files\MSN Messenger\MsnMsgr.Exe
    D:\Program Files\PC Protection\backweb\4384293\Program\fspex.exe
    D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    D:\PROGRA~1\PCPROT~1\backweb\4384293\Program\SERVIC~1.EXE
    D:\Program Files\PC Protection\Anti-Virus\fsgk32st.exe
    D:\Program Files\PC Protection\Anti-Virus\FSGK32.EXE
    D:\Program Files\PC Protection\backweb\4384293\program\fsbwsys.exe
    D:\Program Files\PC Protection\Anti-Virus\fssm32.exe
    D:\WINDOWS\System32\svchost.exe
    D:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    D:\Program Files\iPod\bin\iPodService.exe
    D:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
    D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    D:\Program Files\PC Protection\Common\FSMA32.EXE
    D:\Program Files\PC Protection\Common\FSMB32.EXE
    D:\Program Files\PC Protection\Common\FCH32.EXE
    D:\Program Files\PC Protection\Common\FAMEH32.EXE
    D:\Program Files\PC Protection\Anti-Virus\fsqh.exe
    D:\Program Files\PC Protection\Anti-Virus\fsrw.exe
    D:\Program Files\PC Protection\FSPC\fspc.exe
    D:\Program Files\PC Protection\FWES\Program\fsdfwd.exe
    D:\Program Files\PC Protection\Anti-Virus\fsav32.exe
    D:\Program Files\PC Protection\Common\FSM32.EXE
    D:\PROGRA~1\PCPROT~1\ANTI-S~1\fsaw.exe
    D:\Program Files\PC Protection\FSGUI\fsguidll.exe
    D:\Program Files\MSN Messenger\usnsvc.exe
    D:\PROGRA~1\Mozilla Firefox\firefox.exe
    D:\Documents and Settings\tero\Työpöytä\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [Norton GProtect] pzumwg.exe
    O4 - HKLM\..\Run: [ATICCC] "D:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [NeroCheck] D:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
    O4 - HKLM\..\Run: [F-Secure Manager] "D:\Program Files\PC Protection\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "D:\Program Files\PC Protection\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [F-Secure Startup Wizard] "D:\Program Files\PC Protection\FSGUI\FSSW.EXE" /reboot
    O4 - HKLM\..\Run: [News Service] "D:\Program Files\PC Protection\FSGUI\ispnews.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\RunServices: [Norton GProtect] pzumwg.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\MSMSGS.EXE" /background
    O4 - HKCU\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: F-Secure PC Protection Plus.lnk = D:\Program Files\PC Protection\backweb\4384293\Program\fspex.exe
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O8 - Extra context menu item: &Estä tämä kohoikkuna - D:\Program Files\PC Protection\Anti-Spyware\blockpopups.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - D:\Program Files\PC Protection\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - D:\Program Files\PC Protection\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - D:\Program Files\PC Protection\FSPC\fspcmsie.dll
    O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - D:\Program Files\PC Protection\Anti-Spyware\ieshield.dll
    O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - D:\Program Files\PC Protection\Anti-Spyware\ieshield.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: F-Secure PC Protection Plus (BackWeb Plug-in - 4384293) - BackWeb Technologies Inc. - D:\PROGRA~1\PCPROT~1\backweb\4384293\Program\SERVIC~1.EXE
    O23 - Service: COM+ Messages - Unknown owner - D:\WINDOWS\System32\svchosts.exe" -e mc-110-12-0000144 (file missing)
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - D:\Program Files\PC Protection\Anti-Virus\fsgk32st.exe
    O23 - Service: fsbwsys - F-Secure Corp. - D:\Program Files\PC Protection\backweb\4384293\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - D:\Program Files\PC Protection\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - D:\Program Files\PC Protection\FSPC\fshttps\fshttps.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - D:\Program Files\PC Protection\Common\FSMA32.EXE
    O23 - Service: iPod Service - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: ServiceLayer - Nokia. - D:\Program Files\PC Connectivity Solution\ServiceLayer.exe
     
  2. Jurppis

    Jurppis Regular member

    Joined:
    Feb 22, 2006
    Messages:
    659
    Likes Received:
    0
    Trophy Points:
    26
    Mene http://www.virustotal.com/en/indexf.html

    Paina valitse ja navigoi system32 kansioon
    Etsi sieltä tiedosto pzumwg.exe (jos ei löydy, laita piilotiedostot näkyviin)
    Kun olet löytänyt tiedoston, tuplaklikkaa sitä ja paina send
    Skannauksessa kestää vähän, odota kärsivällisesti.
    Lähetä skannaustulokset viestiketjuusi
     
    Last edited: Feb 27, 2007
  3. AnthraXfi

    AnthraXfi Member

    Joined:
    Jan 15, 2005
    Messages:
    65
    Likes Received:
    0
    Trophy Points:
    16
    En löytänyt tommosta tiedostoa koneesta ja sen jälkeen koko kone sekosi ja jouduin laittaan windowsin uudestaan... mutta silti kaatuilee... tässä uus loki

    Logfile of HijackThis v1.99.1
    Scan saved at 18:15:01, on 3.3.2007
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\savedump.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\WINDOWS\Explorer.EXE
    D:\Program Files\PC Protection\Common\FSM32.EXE
    D:\WINDOWS\RTHDCPL.EXE
    D:\WINDOWS\System32\ctfmon.exe
    D:\Program Files\MSN Messenger\MsnMsgr.Exe
    D:\Program Files\Messenger\msmsgs.exe
    D:\Program Files\PC Protection\backweb\4384293\Program\fspex.exe
    D:\PROGRA~1\PCPROT~1\backweb\4384293\Program\SERVIC~1.EXE
    D:\Program Files\PC Protection\Anti-Virus\fsgk32st.exe
    D:\Program Files\PC Protection\Anti-Virus\FSGK32.EXE
    D:\Program Files\PC Protection\backweb\4384293\program\fsbwsys.exe
    D:\Program Files\PC Protection\Anti-Virus\fssm32.exe
    D:\Program Files\PC Protection\Common\FSMA32.EXE
    D:\Program Files\PC Protection\Common\FSMB32.EXE
    D:\Program Files\PC Protection\Common\FCH32.EXE
    D:\Program Files\PC Protection\Common\FAMEH32.EXE
    D:\Program Files\PC Protection\Anti-Virus\fsqh.exe
    D:\Program Files\PC Protection\Anti-Virus\fsrw.exe
    D:\Program Files\PC Protection\FSPC\fspc.exe
    D:\Program Files\PC Protection\Anti-Virus\fsav32.exe
    D:\Program Files\PC Protection\FWES\Program\fsdfwd.exe
    D:\PROGRA~1\PCPROT~1\ANTI-S~1\fsaw.exe
    D:\Program Files\PC Protection\FSGUI\fsguidll.exe
    D:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    D:\WINDOWS\System32\wuauclt.exe
    D:\WINDOWS\System32\wuauclt.exe
    D:\Documents and Settings\tero\Työpöytä\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [F-Secure Manager] "D:\Program Files\PC Protection\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "D:\Program Files\PC Protection\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [F-Secure Startup Wizard] "D:\Program Files\PC Protection\FSGUI\FSSW.EXE" /reboot
    O4 - HKLM\..\Run: [News Service] "D:\Program Files\PC Protection\FSGUI\ispnews.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [zzzHPSETUP] E:\Setup.exe \RESET
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: F-Secure PC Protection Plus.lnk = D:\Program Files\PC Protection\backweb\4384293\Program\fspex.exe
    O8 - Extra context menu item: &Estä tämä kohoikkuna - D:\Program Files\PC Protection\Anti-Spyware\blockpopups.htm
    O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - D:\Program Files\PC Protection\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - D:\Program Files\PC Protection\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - D:\Program Files\PC Protection\FSPC\fspcmsie.dll
    O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - D:\Program Files\PC Protection\Anti-Spyware\ieshield.dll
    O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - D:\Program Files\PC Protection\Anti-Spyware\ieshield.dll
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
    O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1172935956468
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O23 - Service: F-Secure PC Protection Plus (BackWeb Plug-in - 4384293) - BackWeb Technologies Inc. - D:\PROGRA~1\PCPROT~1\backweb\4384293\Program\SERVIC~1.EXE
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - D:\Program Files\PC Protection\Anti-Virus\fsgk32st.exe
    O23 - Service: fsbwsys - F-Secure Corp. - D:\Program Files\PC Protection\backweb\4384293\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - D:\Program Files\PC Protection\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - D:\Program Files\PC Protection\FSPC\fshttps\fshttps.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - D:\Program Files\PC Protection\Common\FSMA32.EXE

     
  4. Jurppis

    Jurppis Regular member

    Joined:
    Feb 22, 2006
    Messages:
    659
    Likes Received:
    0
    Trophy Points:
    26
    Logi näyttää kyllä puhtaalta. Olisiko kyseessä mahdollisesti rautavikaa, esimerkiksi muisti(t) rikki?

    Yks juttu voidaan silti fiksata. Avaa HijackThis, paina do a system scan only ja merkkaa tämä:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    Sulje kaikki muut avoimet ikkunat ja paina fix cheked


    Windows kannattaa päivittää SP2:seen
    http://windowsupdate.microsoft.com/
     
  5. AnthraXfi

    AnthraXfi Member

    Joined:
    Jan 15, 2005
    Messages:
    65
    Likes Received:
    0
    Trophy Points:
    16
    kone on 3 kuukautta vanha ja muistit on uudet... nooh täytyy koittaa selvitellä mistä johtuu... paskamaista vaan kun ei kerkee ees peliä alottaan nii kone buuttaa ittensä
     
  6. AnthraXfi

    AnthraXfi Member

    Joined:
    Jan 15, 2005
    Messages:
    65
    Likes Received:
    0
    Trophy Points:
    16
    Nyt kone kaatu ja sen jälkeen tuli viesti et "järjestelmä on palautunut vakavasta virheestä" katsoin tiedot niin löyty tämmöset

    D:\windows\minidump\mini030307-01.dmp ja
    D:\docume~1\tero\locals~1\temp\wer15.tmp.dir00\sysdata.xml

    ei voi muuta sanoa kun apua
     
  7. Jurppis

    Jurppis Regular member

    Joined:
    Feb 22, 2006
    Messages:
    659
    Likes Received:
    0
    Trophy Points:
    26
  8. AnthraXfi

    AnthraXfi Member

    Joined:
    Jan 15, 2005
    Messages:
    65
    Likes Received:
    0
    Trophy Points:
    16
    Kiitti tästä... hyökkäänkin ton kotelon kimppuun samantien :)
     

Share This Page