afterdawn.com  > keskustelu  > yleistä keskustelua tietokoneista  > virukset ja haittaohjelmat  > palomuurin hälytykset tiuhaan  
											 
											
												
	 
											
											
						 				 	
	
		
		
			
		
		
	 
												  
												
													
	
		
			Keskustelualueet
			Keskustelualueet
		 
		
			
				
					
						
			
			
		
					
				
			 
		
	 
														
															
															
	
			
			
				
					Palomuurin hälytykset tiuhaan
				 
				
				
					
				 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						
							
								Juffeo
							
							
								Member
								
									  2 tuotearviota 
								
							
							 
							 
						 
						19. lokakuuta 2005 @ 05:30  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Mulla on F-securen tietoturvapaketti
 Palomuuriin tulee jatkuvalla syötöllä hälytyksiä. Eli klo 9:00-9:23 on hälytyksiä tullut 1748!. Tämä kuormittaa suoritinta niin että Ctrl+Alt+Del => suorituskyky tekee teräviä nousuja 100 %:in.
 Yleensä hetkellisesti auttaa kun repäsen nettipiuhan irti ja laitan hetken päästä takaisin. Tämä sama ongelma oli mulla jokunen kk sitten ja silloin asensin vain xp uudelleen. Se auttoi mutta tulipas se nopeasti takaisin.
 Adaware + spybottia käytän säännöllisesti
 
 mikä se vika voi olla?
 eikö palomuuri suojaa ulkopuolelta tulevaa? 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								Juffeo
							
							
								Member
								
									  2 tuotearviota 
								
							
							 
							 
						 
						19. lokakuuta 2005 @ 05:33  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							ainii tossa on logi jos se auttaa
 
 Logfile of HijackThis v1.99.1
 Scan saved at 9:32:08, on 19.10.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\WELHO-~1\backweb\6629059\Program\SERVIC~1.EXE
 C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
 C:\WINDOWS\system32\CTsvcCDA.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Anti-Virus\fsgk32st.exe
 C:\Program Files\Welho-tietoturvapalvelut\backweb\6629059\program\fsbwsys.exe
 C:\Program Files\Welho-tietoturvapalvelut\Anti-Virus\FSGK32.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Anti-Virus\fssm32.exe
 C:\Program Files\Welho-tietoturvapalvelut\fswsclds.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\Program Files\Welho-tietoturvapalvelut\backweb\6629059\Program\BackWeb-6629059.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 C:\WINDOWS\System32\MsPMSPSv.exe
 C:\Program Files\Welho-tietoturvapalvelut\Common\FSMA32.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Common\FSMB32.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Common\FCH32.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Common\FAMEH32.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Anti-Virus\fsav32.exe
 C:\Program Files\Welho-tietoturvapalvelut\DFW\Program\fsdfwd.exe
 C:\Program Files\Apoint2K\Apoint.exe
 C:\WINDOWS\AGRSMMSG.exe
 C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
 C:\Program Files\Welho-tietoturvapalvelut\Common\FSM32.EXE
 C:\Program Files\Apoint2K\Apntex.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\Program Files\Microsoft IntelliType Pro\type32.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Creative\USB SBAudigy2 NX\DVDAudio\CTDVDDet.EXE
 C:\Program Files\Creative\USB SBAudigy2 NX\Surround Mixer\CTSysVol.exe
 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 C:\Program Files\D-Tools\daemon.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Messenger\MSMSGS.EXE
 C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
 C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
 C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\WINDOWS\system32\taskmgr.exe
 C:\DOCUMENTS AND SETTINGS\OMISTAJA.MAZIINA\TYÖPÖYTÄ\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O3 - Toolbar: HP-näkymä - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
 O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
 O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
 O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Welho-tietoturvapalvelut\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Welho-tietoturvapalvelut\TNB\TNBUtil.exe" /CHECKALL
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [SbUsb AudCtrl] RunDll32 sbusbdll.dll,RCMonitor
 O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
 O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\USB SBAudigy2 NX\DVDAudio\CTDVDDet.EXE
 O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\USB SBAudigy2 NX\Surround Mixer\CTSysVol.exe /r
 O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
 O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
 O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
 O4 - HKLM\..\Run: [AutoTBar] C:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
 O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
 O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
 O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
 O4 - HKCU\..\Run: [BackupNotify] C:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
 O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
 O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
 O4 - Global Startup: WinZIP  Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://creative.com/su/ocx/15015/CTSUEng.cab  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl...  O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab  O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://creative.com/su/ocx/15016/CTPID.cab  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O23 - Service: Welho-tietoturvapalvelut (BackWeb Client - 6629059) - Unknown owner - C:\PROGRA~1\WELHO-~1\backweb\6629059\Program\SERVIC~1.EXE
 O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
 O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Welho-tietoturvapalvelut\Anti-Virus\fsgk32st.exe
 O23 - Service: F-Secure Authentication Agent (FSAA) - Unknown owner - C:\Program Files\Welho-tietoturvapalvelut\Common\FSAA.EXE (file missing)
 O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Welho-tietoturvapalvelut\backweb\6629059\program\fsbwsys.exe
 O23 - Service: F-Secure Distributed Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Welho-tietoturvapalvelut\DFW\Program\fsdfwd.exe
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Welho-tietoturvapalvelut\Common\FSMA32.EXE
 O23 - Service: F-Secure Windows Security Center Legacy Detection Service (Fswsclds) - F-Secure Corporation - C:\Program Files\Welho-tietoturvapalvelut\fswsclds.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 
						19. lokakuuta 2005 @ 05:44  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Muuta ei satu silmään kuin, että sulla on kamalasti ohjelmia käynnistymässä.
 
 Esim. nämä vois ottaa pois (eli fixata):
 
 O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe 
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 
 O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE 
 O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" 
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot 
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE 
 
 On siellä varmaan muitakin.
 
 Ja lisäks aja varoiks eScanni:
 
 Hae täältä -> http://koti.mbnet.fi/pattaya1/escanmwav.htm  eScan, asenna, päivitä ja skannaa sivulle olevien ohjeiden mukaan. Lähetä sitten ne "örkkitulokset" (ohje tuolla sivulla, alin kuva ja sen yläpuolella oleva teksti). 
 
 Laita uus HjT-loki ja ne eScanin tulokset. 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								Juffeo
							
							
								Member
								
									  2 tuotearviota 
								
							
							 
							 
						 
						19. lokakuuta 2005 @ 08:58  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							ajoin myös eScanin mutta tuloksena ei ollut mitään muuta kuin kaksi erroria.
 
 Mikä aiheuttaa ton suman palomuurissa?
 onko se normaalia vain?
 esim nyt kun vedin piuhan irti ja laitoin takaisin. On ollut paljon rauhallisempaa noin 30 hälytystä 3h.
 
 Logfile of HijackThis v1.99.1
 Scan saved at 12:53:39, on 19.10.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\WELHO-~1\backweb\6629059\Program\SERVIC~1.EXE
 C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
 C:\WINDOWS\system32\CTsvcCDA.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Anti-Virus\fsgk32st.exe
 C:\Program Files\Welho-tietoturvapalvelut\backweb\6629059\program\fsbwsys.exe
 C:\Program Files\Welho-tietoturvapalvelut\Anti-Virus\FSGK32.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Anti-Virus\fssm32.exe
 C:\Program Files\Welho-tietoturvapalvelut\fswsclds.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\Program Files\Welho-tietoturvapalvelut\backweb\6629059\Program\BackWeb-6629059.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 C:\WINDOWS\System32\MsPMSPSv.exe
 C:\Program Files\Welho-tietoturvapalvelut\Common\FSMA32.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Common\FSMB32.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Common\FCH32.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Common\FAMEH32.EXE
 C:\Program Files\Welho-tietoturvapalvelut\Anti-Virus\fsav32.exe
 C:\Program Files\Welho-tietoturvapalvelut\DFW\Program\fsdfwd.exe
 C:\Program Files\Apoint2K\Apoint.exe
 C:\WINDOWS\AGRSMMSG.exe
 C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
 C:\Program Files\Welho-tietoturvapalvelut\Common\FSM32.EXE
 C:\Program Files\Apoint2K\Apntex.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\Program Files\Microsoft IntelliType Pro\type32.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Creative\USB SBAudigy2 NX\DVDAudio\CTDVDDet.EXE
 C:\Program Files\Creative\USB SBAudigy2 NX\Surround Mixer\CTSysVol.exe
 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
 C:\Program Files\D-Tools\daemon.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Messenger\MSMSGS.EXE
 C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
 C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
 C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\Outlook Express\msimn.exe
 C:\Program Files\Microsoft Office\Office\WINWORD.EXE
 C:\WINDOWS\msagent\AgentSvr.exe
 C:\Documents and Settings\Omistaja.MAZIINA\Työpöytä\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O3 - Toolbar: HP-näkymä - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
 O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
 O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Welho-tietoturvapalvelut\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Welho-tietoturvapalvelut\TNB\TNBUtil.exe" /CHECKALL
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [SbUsb AudCtrl] RunDll32 sbusbdll.dll,RCMonitor
 O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
 O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\USB SBAudigy2 NX\DVDAudio\CTDVDDet.EXE
 O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\USB SBAudigy2 NX\Surround Mixer\CTSysVol.exe /r
 O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
 O4 - HKLM\..\Run: [AutoTBar] C:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
 O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
 O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
 O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
 O4 - HKCU\..\Run: [BackupNotify] C:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
 O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
 O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 O4 - Global Startup: WinZIP  Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://creative.com/su/ocx/15015/CTSUEng.cab  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl...  O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab  O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://creative.com/su/ocx/15016/CTPID.cab  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O23 - Service: Welho-tietoturvapalvelut (BackWeb Client - 6629059) - Unknown owner - C:\PROGRA~1\WELHO-~1\backweb\6629059\Program\SERVIC~1.EXE
 O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
 O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Welho-tietoturvapalvelut\Anti-Virus\fsgk32st.exe
 O23 - Service: F-Secure Authentication Agent (FSAA) - Unknown owner - C:\Program Files\Welho-tietoturvapalvelut\Common\FSAA.EXE (file missing)
 O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Welho-tietoturvapalvelut\backweb\6629059\program\fsbwsys.exe
 O23 - Service: F-Secure Distributed Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Welho-tietoturvapalvelut\DFW\Program\fsdfwd.exe
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Welho-tietoturvapalvelut\Common\FSMA32.EXE
 O23 - Service: F-Secure Windows Security Center Legacy Detection Service (Fswsclds) - F-Secure Corporation - C:\Program Files\Welho-tietoturvapalvelut\fswsclds.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Mainos
							 
						 
						 
					 
					
						
							
							  
								
							
						 
					 
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 
						19. lokakuuta 2005 @ 09:26  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Se voi johtua siitä, että jos et ole NATin takana. Tosin toi 1700 ja rapiat kuulostaa aika paljolta. Jälkimmäinen kuulostaa jo paremmalta :) 
							
						
						
						
						
						 
					 
				
				
			
			
			
			
			
		
		
	
			
			
		
	 
 
					
						
							afterdawn.com  > keskustelu  > yleistä keskustelua tietokoneista  > virukset ja haittaohjelmat  > palomuurin hälytykset tiuhaan