Ajoin combofixin läpi ja nyt pitäisi jonkun viisaamman osata minulle kertoa,onko ok vai jotain pielessä. Koneella oli viikko sitten XP police antivirus.Enkä edes tiedä miten se tuli koneelle. Poistin sen. Käytän operaa ja niin karsittuna,kun voi olla. Myös infostealer.gampass "vieraili" myös. Jonka poistin Spyware Doctorilla,kun sivuilla sanottiin ohjelman havaitsevan ja poistavan sen. Tässä logi: ComboFix 09-02-21.01 - Zombie 2009-02-24 13:53:10.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1035.18.1534.957 [GMT 2:00] Sijainti: c:\documents and settings\Zombie\Local Settings\Application Data\Opera\Opera\profile\cache4\temporary_download\ComboFix.exe AV: Norton AntiVirus *On-access scanning disabled* (Updated) FW: Norton AntiVirus *disabled* * Uusi palautuspiste luotu . ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2009-01-24 to 2009-02-24 ))))))))))))))))) . 2009-02-19 18:14 . 2009-02-23 18:25 <KANSIO> d-------- c:\program files\Spyware Doctor 2009-02-19 18:14 . 2009-02-19 18:14 <KANSIO> d-------- c:\documents and settings\Zombie\Application Data\PC Tools 2009-02-19 18:14 . 2008-08-25 11:36 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys 2009-02-19 18:14 . 2008-08-25 11:36 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys 2009-02-19 18:14 . 2008-08-25 11:36 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys 2009-02-19 18:14 . 2008-06-02 15:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys 2009-02-19 18:13 . 2008-09-26 19:03 <KANSIO> d-------- c:\program files\Spyware Doctor v6.0.0.385(FULL) 2009-02-19 18:10 . 2008-10-23 11:55 <KANSIO> d-------- c:\program files\Spyware Doctor v6.0.0 2009-02-19 17:02 . 2009-02-24 13:09 <KANSIO> d-a------ c:\documents and settings\All Users\Application Data\TEMP 2009-02-18 23:06 . 2009-02-18 23:06 <KANSIO> d-------- c:\program files\Malwarebytes' Anti-Malware 2009-02-18 23:06 . 2009-02-18 23:06 <KANSIO> d-------- c:\documents and settings\Zombie\Application Data\Malwarebytes 2009-02-18 23:06 . 2009-02-18 23:06 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-02-18 23:06 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-18 23:06 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-02-17 15:03 . 2009-02-17 15:03 <KANSIO> d-------- c:\program files\D-Link 2009-02-15 18:33 . 2009-02-15 18:33 0 --a------ c:\windows\system32\FOXUSER.FPT 2009-02-15 18:33 . 2009-02-15 18:33 0 --a------ c:\windows\system32\FOXUSER.DBF 2009-02-15 12:54 . 2009-02-15 12:54 <KANSIO> d-------- c:\documents and settings\Zombie\.dvdcss 2009-02-12 21:29 . 2009-02-12 21:29 <KANSIO> d-------- C:\series 2009-02-10 21:23 . 2009-02-10 21:23 22,328 --a------ c:\documents and settings\Zombie\Application Data\PnkBstrK.sys 2009-02-10 21:22 . 2009-02-10 21:22 2,337,865 --a------ c:\windows\system32\pbsvc.exe 2009-02-09 00:18 . 2009-02-09 00:18 <KANSIO> d-------- c:\program files\Hamachi 2009-02-09 00:18 . 2009-02-23 14:37 <KANSIO> d-------- c:\documents and settings\Zombie\Application Data\Hamachi 2009-02-09 00:18 . 2009-02-09 00:18 25,280 --a------ c:\windows\system32\drivers\hamachi.sys 2009-01-27 20:08 . 2009-02-10 21:23 22,328 --a------ c:\windows\system32\drivers\PnkBstrK.sys 2009-01-27 20:07 . 2009-02-10 21:23 107,832 --a------ c:\windows\system32\PnkBstrB.exe 2009-01-27 20:07 . 2009-02-10 21:22 66,872 --a------ c:\windows\system32\PnkBstrA.exe . (((((((((((((((((((((((((((((((((((( Find3M-raportti )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-24 11:47 --------- d-----w c:\program files\mIRC 2009-02-24 11:47 --------- d-----w c:\documents and settings\Zombie\Application Data\uTorrent 2009-02-24 11:38 --------- d-----w c:\program files\Common Files\Symantec Shared 2009-02-24 08:57 --------- d-----w c:\documents and settings\Zombie\Application Data\OpenOffice.org2 2009-02-19 09:01 --------- d-----w c:\program files\MediaCoder 2009-02-17 16:51 --------- d-----w c:\documents and settings\Zombie\Application Data\Azureus 2009-02-10 19:09 --------- d--h--w c:\program files\InstallShield Installation Information 2009-02-03 19:37 --------- d-----w c:\program files\Azureus 2008-12-27 13:52 --------- d-----w c:\program files\Common Files\DirectX 2008-12-12 17:03 3,088,896 ------w c:\windows\system32\dllcache\mshtml.dll 2008-12-11 10:57 333,952 ----a-w c:\windows\system32\dllcache\srv.sys 2007-10-20 12:19 546 -c--a-w c:\documents and settings\Zombie\Application Data\wklnhst.dat 2007-01-15 21:50 49 -c--a-w c:\documents and settings\Zombie\Application Data\internaldb41.dat 2007-01-15 20:18 20,480 -c--a-w c:\documents and settings\Zombie\Application Data\internaldb4827.dat 2007-01-15 20:18 151 -c--a-w c:\documents and settings\Zombie\Application Data\internaldb2391.dat 2007-01-13 16:01 9,216 -c--a-w c:\documents and settings\Zombie\Application Data\internaldb8467.dat 2007-01-13 16:01 0 -c--a-w c:\documents and settings\Zombie\Application Data\internaldb6334.dat 2007-01-13 16:00 0 -c--a-w c:\documents and settings\Zombie\Application Data\internaldb5436.dat . (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet ))))))))))))))))))))))))))))))))))))))))))))) . . *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-06 68856] "PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 695808] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 84640] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-06-07 344064] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 1294336] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"="1" "UpdatesDisableNotify"="1" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\uTorrent\\utorrent.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XI.SP1\\RpcSandraSrv.exe"= "c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XI.SP1\\Win32\\RpcDataSrv.exe"= "c:\\Program Files\\eMule\\eMule.exe"= "c:\\Program Files\\mIRC\\mirc.exe"= "c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"= "c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\WINDOWS\\system32\\dpnsvr.exe"= "c:\\Program Files\\Hamachi\\hamachi.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\games\\Tom.Clancys.Rainbow.Six.Vegas.2-RELOADED\\Binaries\\R6Vegas2_Game.exe"= "c:\\games\\Tom.Clancys.Rainbow.Six.Vegas.2-RELOADED\\Binaries\\R6Vegas2_Launcher.exe"= "c:\\Program Files\\Opera\\Opera.exe"= R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-17 99376] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-02-19 356920] --- Muut muistissa olevat ajurit/palvelut --- *Deregistered* - mchInjDrv [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{56aa5373-b0a0-11dc-bf32-001a923e7218}] \shell\open\command - %SystemRoot%\Explorer.exe /idlist,%I,%L [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6bc1e3e4-a5d5-11dd-bfbc-00134698eb50}] \Shell\AutoRun\command - L:\setupSNK.exe . 'Ajoitetut tehtävät'-kansion sisältö 2009-02-20 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Zombie.job - c:\progra~1\NORTON~3\Navw32.exe [2006-09-07 03:38] 2009-02-24 c:\windows\Tasks\Tarkistetaan Windows Live -työkalurivin päivitykset.job - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20] . . ------- Täydentävä tarkistus ------- . uStart Page = hxxp://laser.narr.as/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = <local> uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &Search IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm IE: Avaa uuteen etuvälilehteen - c:\program files\Windows Live Toolbar\Components\fi-fi\msntabres.dll.mui/230?4ec538eddede40558abb43686ad0ece5 IE: Avaa uuteen taustavälilehteen - c:\program files\Windows Live Toolbar\Components\fi-fi\msntabres.dll.mui/229?4ec538eddede40558abb43686ad0ece5 . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-24 13:54:09 Windows 5.1.2600 Service Pack 3 NTFS tarkistaa piilotettuja prosesseja ... tarkistaa piilotettuja käynnistysarvoja ... tarkistaa piilotettuja tiedostoja ... tarkistus on valmis piilotetut tiedostot: 0 ************************************************************************** . --------------------- LUKITUT REKISTERIAVAIMET --------------------- [HKEY_USERS\S-1-5-21-367143751-31405543-1353113861-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1DE218EC-2736-1FB1-4F21-576E03EEDD6F}*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\�•€|ÿÿÿÿ"•€|þ»Ów*] "b049C053C7D38EE4AB9A00CB3B5D2472"="C?\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\PUBPLACE.HTT" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•Ów*] "b049C053C7D38EE4AB9A00CB3B5D2472"="C?\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\PUBPLACE.HTT" . --------------------- Prosesseihin ladatut DLLt --------------------- - - - - - - - > 'winlogon.exe'(652) c:\windows\system32\Ati2evxx.dll . Valmistumisajankohta: 2009-02-24 13:55:46 ComboFix-quarantined-files.txt 2009-02-24 11:55:25 Ennen ajoa: 24 917 315 584 tavua vapaana Ajon jälkeen: 24,987,774,976 tavua vapaana WindowsXP-KB310994-SP2-Home-BootDisk-FIN.EXE [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect 181 --- E O F --- 2009-02-12 01:05:38 Kiitoksia.
Lataa TÄSTÄ HJTInstall.exe * Tallenna HJTInstall.exe työpöydällesi. * Tuplaklikkaa HJTInstall.exe-kuvaketta työpöydälläsi. * Oletuksena se asentaa itsensä hakemistoon C:\Program Files\Trend Micro\HijackThis. * Klikkaa Install. * Asennusohjelma luo HijackThis-kuvakkeen työpöydälle. * Kun asennus on valmis, se käynnistää HijackThisin. * Klikkaa Do a system scan and save a logfile-painiketta. Ohjelma aloittaa skannauksen ja lokin pitäisi avautua Muistioon. * Klikkaa ensin "Muokkaa > Valitse kaikki" sitten "Muokkaa > Kopioi" kopioidaksesi koko lokin sisällön. * Liitä lokin sisältö seuraavaan vastaukseesi. * ÄLÄ käytä Analyse This-nappulaa, sen löydöt ovat vaarallisia väärinymmärrettyinä. * ÄLÄ fixaa HijackThis-ohjelmalla vielä mitään. Suurin osa sen löydöistä ovat joko harmittomia tai jopa tarpeellisia.
Tässä HJT-logi Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:25:54, on 25.2.2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\WINDOWS\explorer.exe C:\Program Files\mIRC\mirc.exe C:\Program Files\Winamp\winamp.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Opera\opera.exe C:\Documents and Settings\Zombie\Työpöytä\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://laser.narr.as/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user') O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://plaza.fi/ O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP1\Win32\RpcDataSrv.exe O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP1\RpcSandraSrv.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe -- End of file - 6082 bytes Kiitoksia. Testasin netin HJT-log analyzeriä,mutta ei vissin ole 100%?? Onkohan mitään ongelmaa vai pelkkää?