hallo iedereen,
Bij het opstarten vindt norton anti-virus een trojan horse c:\start.bat.
als ik deze opzoek op de c-schijf vindt hij deze niet.
Ik heb alle manieren al geprobeerd om het te verwijderen, o.a. windows defender, adware etc. maar krijg het niet verwijderd.
Bij het opstarten wordt ook de firewall uitgeschakeld.
Zou iemand mij kunnen helpen om dit probleem op te lossen
hierbij het logje
Logfile of HijackThis v1.99.1
scan saved at 11:34:17, on 2-2-2008
platform: windows xp sp2 (winnt 5.01.2600)
msie: internet explorer v6.00 sp2 (6.00.2900.2180)
browser: Mozilla Firefox x.x
ColorCoder Build: 4136
browser: internet explorer 6.0
colorcoder build: 4136
Running Processes:
c:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\program files\windows defender\msmpeng.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe
c:\program files\home cinema\powercinema\kernel\tv\clcapsvc.exe
c:\program files\home cinema\powercinema\kernel\clml_ntservice\clmlserver.exe
c:\windows\system32\svchost.exe
c:\program files\common files\lightscribe\lssrvc.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\program files\cyberlink\shared files\richvideo.exe
c:\windows\system32\svchost.exe
c:\program files\home cinema\powercinema\kernel\tv\clsched.exe
c:\windows\explorer.exe
c:\windows\rthdcpl.exe
c:\program files\medion info display\mdionlcm.exe
c:\windows\mhotkey.exe
c:\windows\cnyhkey.exe
c:\windows\system32\cmucreye.exe
c:\program files\home cinema\powercinema\pcmservice.exe
c:\windows\vsnpstd.exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe
c:\program files\hewlett-packard\hp software update\hpwuschd2.exe
c:\program files\quicktime\qttask.exe
c:\windows\system32\rundll32.exe
c:\program files\hp\hpcoretech\hpcmpmgr.exe
c:\program files\windows defender\msascui.exe
c:\progra~1\common~1\x10\common\x10nets.exe
c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe
c:\documents and settings\sharin\mijn documenten\picasa2\picasamediadetector.exe
c:\windows\system32\ctfmon.exe
c:\program files\windows media player\wmpnscfg.exe
c:\program files\toshiba\bluetooth toshiba stack\tosbtmng.exe
c:\progra~1\incred~1\bin\imapp.exe
c:\program files\toshiba\bluetooth toshiba stack\tosa2dp.exe
c:\program files\toshiba\bluetooth toshiba stack\tosbthsp.exe
c:\progra~1\incred~1\bin\imnotfy.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\common files\microsoft shared\windows live\wlloginproxy.exe
c:\documents and settings\ton\mijn documenten\hjt\hijackthis.exe
(r0) - hkcu\software\microsoft\internet explorer\main,start page = http://www.startpagina.nl/
(r1) - hklm\software\microsoft\internet explorer\main,default_page_url = http://www.aldi.com/
(r0) - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername = koppelingen
(o2) - bho: acroiehlprobj class - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
(o2) - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
(o2) - bho: windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
(o4) - HKLM\..\Run: [nvcpldaemon] rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
(o4) - HKLM\..\Run: [nwiz] nwiz.exe /install
(o4) - HKLM\..\Run: [nvmediacenter] rundll32.exe nvmctray.dll,nvtaskbarinit
(o4) - HKLM\..\Run: [rthdcpl] rthdcpl.exe
(o4) - HKLM\..\Run: [alcmtr] alcmtr.exe
(o4) - HKLM\..\Run: [medionvfd] "c:\program files\medion info display\mdionlcm.exe"
(o4) - HKLM\..\Run: [chotkey] mhotkey.exe
(o4) - HKLM\..\Run: [ledpointer] cnyhkey.exe
(o4) - HKLM\..\Run: [cmucrrun] c:\windows\system32\cmucreye.exe
(o4) - HKLM\..\Run: [nerofiltercheck] c:\windows\system32\nerocheck.exe
(o4) - HKLM\..\Run: [imjpmig8.1] "c:\windows\ime\imjp8_1\imjpmig.exe" /spoil /remadvdef /migration32
(o4) - HKLM\..\Run: [mspy2002] c:\windows\system32\ime\pintlgnt\imscinst.exe /sync
(o4) - HKLM\..\Run: [phime2002async] c:\windows\system32\ime\tintlgnt\tintsetp.exe /sync
(o4) - HKLM\..\Run: [phime2002a] c:\windows\system32\ime\tintlgnt\tintsetp.exe /imename
(o4) - HKLM\..\Run: [antivirusregistration] c:\program files\ca\etrust antivirus\register.exe
(o4) - HKLM\..\Run: [pcmservice] "c:\program files\home cinema\powercinema\pcmservice.exe"
(o4) - HKLM\..\Run: [instanton] "c:\program files\cyberlink\powercinema linux\ion_install.exe /c "
(o4) - HKLM\..\Run: [snpstd] c:\windows\vsnpstd.exe
(o4) - HKLM\..\Run: [hpdj taskbar utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe
(o4) - HKLM\..\Run: [hp software update] "c:\program files\hewlett-packard\hp software update\hpwuschd2.exe"
(o4) - HKLM\..\Run: [quicktime task] "c:\program files\quicktime\qttask.exe" -atboottime
(o4) - HKLM\..\Run: [bluetoothauthenticationagent] rundll32.exe bthprops.cpl,,bluetoothauthenticationagent
(o4) - HKLM\..\Run: [hp component manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
(o4) - HKLM\..\Run: [windows defender] "c:\program files\windows defender\msascui.exe" -hide
(o4) - HKLM\..\Run: [support audio cool poll] c:\documents and settings\all users\application data\internet spam support audio\soft logo.exe
(o4) - HKLM\..\Run: [avp] "c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe"
(o4) - HKLM\..\Run: [picasa media detector] c:\documents and settings\sharin\mijn documenten\picasa2\picasamediadetector.exe
(o4) - HKCU\..\Run: [incredimail] c:\program files\incredimail\bin\incmail.exe /c
(o4) - HKCU\..\Run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
(o4) - HKCU\..\Run: [updatemgr] c:\program files\adobe\acrobat 7.0\reader\adobeupdatemanager.exe acrdb7_0_9
(o4) - HKCU\..\Run: [wmpnscfg] c:\program files\windows media player\wmpnscfg.exe
(o4) - HKCU\..\Run: [proc spam] c:\docume~1\ton\applic~1\onesty~1\dart bias surf.exe
(o4) - Global Startup: bluetooth manager.lnk = ?
(o8) - extra context menu item: e&xporteren naar microsoft excel - res://c:\progra~1\micros~4\office11\excel.exe/3000
(o9) - extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.5.0_04\bin\npjpi150_04.dll
(o9) - extra 'tools' menuitem: sun java console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.5.0_04\bin\npjpi150_04.dll
(o9) - extra button: anti-virus voor internet statistieken - {1f460357-8a94-4d71-9ca3-aa4acf32ed8e} - c:\program files\kaspersky lab\kaspersky anti-virus 7.0\scieplgn.dll
(o9) - extra button: onderzoek - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~4\office11\refiebar.dll
(o9) - extra button: (no name) - {b205a35e-1fc4-4ce3-818b-899dbbb3388c} - c:\program files\common files\microsoft shared\encarta search bar\encsbar.dll
(o9) - extra button: messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
(o9) - extra 'tools' menuitem: windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
(o14) - iereset.inf: start_page_url=http://www.aldi.com/
(o16) - dpf: {17492023-c23a-453e-a040-c7c580bbf700} (windows genuine advantage validation tool) - http://go.microsoft.com/fwlink/?linkid=39204
(o16) - dpf: {4f1e5b1a-2a80-42ca-8532-2d05cb959537} (msn photo upload tool) - http://gfx2.hotmail.com/mail/w2/resources/msnpupld.cab
(o16) - dpf: {6414512b-b978-451d-a0d8-fcfdf33e833c} (wuwebcontrol class) - http://update.microsoft.com/windowsupdate/v6/v5controls/en/x86/client/wuweb_site.cab?1130364442791
(o16) - dpf: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (muwebcontrol class) - http://update.microsoft.com/microsoftupdate/v6/v5controls/en/x86/client/muweb_site.cab?1131365030359
(o16) - dpf: {6e5e167b-1566-4316-b27f-0ddab3484cf7} (image uploader control) - http://www.mijnalbum.nl/skin/v2/system/upload/imageuploader4.cab
(o16) - dpf: {b38870e4-7ecb-40da-8c6a-595f0a5519ff} (msnmessengersetupdownloadcontrol class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
(o16) - dpf: {daf94f73-2aa6-44d8-a562-a28831820d34} (pixum easyuploadx control) - http://www.pixum.de/int/easyupload/imguploader.cab
(o18) - protocol: livecall - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\msnmes~1\msgrap~1.dll
(o18) - protocol: msnim - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\msnmes~1\msgrap~1.dll
(o20) - winlogon notify: klogon - c:\windows\system32\klogon.dll
(o20) - winlogon notify: wgalogon - c:\windows\system32\wgalogon.dll
(o21) - ssodl: wpdshserviceobj - {aaa288ba-9a4c-45b0-95d7-94d524869db5} - c:\windows\system32\wpdshserviceobj.dll
(o23) - Service: kaspersky anti virus 7.0 (avp) - unknown owner - c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe" -r (file missing)
(o23) - Service: cyberlink background capture service (cbcs) (clcapsvc) - unknown owner - c:\program files\home cinema\powercinema\kernel\tv\clcapsvc.exe
(o23) - Service: cyberlink task scheduler (cts) (clsched) - unknown owner - c:\program files\home cinema\powercinema\kernel\tv\clsched.exe
(o23) - Service: cyberlink media library service - cyberlink - c:\program files\home cinema\powercinema\kernel\clml_ntservice\clmlserver.exe
(o23) - Service: google updater service (gusvc) - google - c:\program files\google\common\google updater\googleupdaterservice.exe
(o23) - Service: installdriver table manager (idrivert) - macrovision corporation - c:\program files\common files\installshield\driver\11\intel 32\idrivert.exe
(o23) - Service: lightscribeservice direct disc labeling service (lightscribeservice) - hewlett-packard company - c:\program files\common files\lightscribe\lssrvc.exe
(o23) - Service: nvidia display driver service (nvsvc) - nvidia corporation - c:\windows\system32\nvsvc32.exe
(o23) - Service: cyberlink richvideo service(crvs) (richvideo) - unknown owner - c:\program files\cyberlink\shared files\richvideo.exe
(o23) - Service: x10 device network service (x10nets) - x10 - c:\progra~1\common~1\x10\common\x10nets.exe
copyright nano, created for nationaal computer forum www.nationaalcomputerforum.nl[/hijack]
Bij het opstarten vindt norton anti-virus een trojan horse c:\start.bat.
als ik deze opzoek op de c-schijf vindt hij deze niet.
Ik heb alle manieren al geprobeerd om het te verwijderen, o.a. windows defender, adware etc. maar krijg het niet verwijderd.
Bij het opstarten wordt ook de firewall uitgeschakeld.
Zou iemand mij kunnen helpen om dit probleem op te lossen
hierbij het logje
Logfile of HijackThis v1.99.1
scan saved at 11:34:17, on 2-2-2008
platform: windows xp sp2 (winnt 5.01.2600)
msie: internet explorer v6.00 sp2 (6.00.2900.2180)
browser: Mozilla Firefox x.x
ColorCoder Build: 4136
browser: internet explorer 6.0
colorcoder build: 4136
Running Processes:
c:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\program files\windows defender\msmpeng.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe
c:\program files\home cinema\powercinema\kernel\tv\clcapsvc.exe
c:\program files\home cinema\powercinema\kernel\clml_ntservice\clmlserver.exe
c:\windows\system32\svchost.exe
c:\program files\common files\lightscribe\lssrvc.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\program files\cyberlink\shared files\richvideo.exe
c:\windows\system32\svchost.exe
c:\program files\home cinema\powercinema\kernel\tv\clsched.exe
c:\windows\explorer.exe
c:\windows\rthdcpl.exe
c:\program files\medion info display\mdionlcm.exe
c:\windows\mhotkey.exe
c:\windows\cnyhkey.exe
c:\windows\system32\cmucreye.exe
c:\program files\home cinema\powercinema\pcmservice.exe
c:\windows\vsnpstd.exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe
c:\program files\hewlett-packard\hp software update\hpwuschd2.exe
c:\program files\quicktime\qttask.exe
c:\windows\system32\rundll32.exe
c:\program files\hp\hpcoretech\hpcmpmgr.exe
c:\program files\windows defender\msascui.exe
c:\progra~1\common~1\x10\common\x10nets.exe
c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe
c:\documents and settings\sharin\mijn documenten\picasa2\picasamediadetector.exe
c:\windows\system32\ctfmon.exe
c:\program files\windows media player\wmpnscfg.exe
c:\program files\toshiba\bluetooth toshiba stack\tosbtmng.exe
c:\progra~1\incred~1\bin\imapp.exe
c:\program files\toshiba\bluetooth toshiba stack\tosa2dp.exe
c:\program files\toshiba\bluetooth toshiba stack\tosbthsp.exe
c:\progra~1\incred~1\bin\imnotfy.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\common files\microsoft shared\windows live\wlloginproxy.exe
c:\documents and settings\ton\mijn documenten\hjt\hijackthis.exe
(r0) - hkcu\software\microsoft\internet explorer\main,start page = http://www.startpagina.nl/
(r1) - hklm\software\microsoft\internet explorer\main,default_page_url = http://www.aldi.com/
(r0) - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername = koppelingen
(o2) - bho: acroiehlprobj class - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
(o2) - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
(o2) - bho: windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
(o4) - HKLM\..\Run: [nvcpldaemon] rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
(o4) - HKLM\..\Run: [nwiz] nwiz.exe /install
(o4) - HKLM\..\Run: [nvmediacenter] rundll32.exe nvmctray.dll,nvtaskbarinit
(o4) - HKLM\..\Run: [rthdcpl] rthdcpl.exe
(o4) - HKLM\..\Run: [alcmtr] alcmtr.exe
(o4) - HKLM\..\Run: [medionvfd] "c:\program files\medion info display\mdionlcm.exe"
(o4) - HKLM\..\Run: [chotkey] mhotkey.exe
(o4) - HKLM\..\Run: [ledpointer] cnyhkey.exe
(o4) - HKLM\..\Run: [cmucrrun] c:\windows\system32\cmucreye.exe
(o4) - HKLM\..\Run: [nerofiltercheck] c:\windows\system32\nerocheck.exe
(o4) - HKLM\..\Run: [imjpmig8.1] "c:\windows\ime\imjp8_1\imjpmig.exe" /spoil /remadvdef /migration32
(o4) - HKLM\..\Run: [mspy2002] c:\windows\system32\ime\pintlgnt\imscinst.exe /sync
(o4) - HKLM\..\Run: [phime2002async] c:\windows\system32\ime\tintlgnt\tintsetp.exe /sync
(o4) - HKLM\..\Run: [phime2002a] c:\windows\system32\ime\tintlgnt\tintsetp.exe /imename
(o4) - HKLM\..\Run: [antivirusregistration] c:\program files\ca\etrust antivirus\register.exe
(o4) - HKLM\..\Run: [pcmservice] "c:\program files\home cinema\powercinema\pcmservice.exe"
(o4) - HKLM\..\Run: [instanton] "c:\program files\cyberlink\powercinema linux\ion_install.exe /c "
(o4) - HKLM\..\Run: [snpstd] c:\windows\vsnpstd.exe
(o4) - HKLM\..\Run: [hpdj taskbar utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe
(o4) - HKLM\..\Run: [hp software update] "c:\program files\hewlett-packard\hp software update\hpwuschd2.exe"
(o4) - HKLM\..\Run: [quicktime task] "c:\program files\quicktime\qttask.exe" -atboottime
(o4) - HKLM\..\Run: [bluetoothauthenticationagent] rundll32.exe bthprops.cpl,,bluetoothauthenticationagent
(o4) - HKLM\..\Run: [hp component manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
(o4) - HKLM\..\Run: [windows defender] "c:\program files\windows defender\msascui.exe" -hide
(o4) - HKLM\..\Run: [support audio cool poll] c:\documents and settings\all users\application data\internet spam support audio\soft logo.exe
(o4) - HKLM\..\Run: [avp] "c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe"
(o4) - HKLM\..\Run: [picasa media detector] c:\documents and settings\sharin\mijn documenten\picasa2\picasamediadetector.exe
(o4) - HKCU\..\Run: [incredimail] c:\program files\incredimail\bin\incmail.exe /c
(o4) - HKCU\..\Run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
(o4) - HKCU\..\Run: [updatemgr] c:\program files\adobe\acrobat 7.0\reader\adobeupdatemanager.exe acrdb7_0_9
(o4) - HKCU\..\Run: [wmpnscfg] c:\program files\windows media player\wmpnscfg.exe
(o4) - HKCU\..\Run: [proc spam] c:\docume~1\ton\applic~1\onesty~1\dart bias surf.exe
(o4) - Global Startup: bluetooth manager.lnk = ?
(o8) - extra context menu item: e&xporteren naar microsoft excel - res://c:\progra~1\micros~4\office11\excel.exe/3000
(o9) - extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.5.0_04\bin\npjpi150_04.dll
(o9) - extra 'tools' menuitem: sun java console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.5.0_04\bin\npjpi150_04.dll
(o9) - extra button: anti-virus voor internet statistieken - {1f460357-8a94-4d71-9ca3-aa4acf32ed8e} - c:\program files\kaspersky lab\kaspersky anti-virus 7.0\scieplgn.dll
(o9) - extra button: onderzoek - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~4\office11\refiebar.dll
(o9) - extra button: (no name) - {b205a35e-1fc4-4ce3-818b-899dbbb3388c} - c:\program files\common files\microsoft shared\encarta search bar\encsbar.dll
(o9) - extra button: messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
(o9) - extra 'tools' menuitem: windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
(o14) - iereset.inf: start_page_url=http://www.aldi.com/
(o16) - dpf: {17492023-c23a-453e-a040-c7c580bbf700} (windows genuine advantage validation tool) - http://go.microsoft.com/fwlink/?linkid=39204
(o16) - dpf: {4f1e5b1a-2a80-42ca-8532-2d05cb959537} (msn photo upload tool) - http://gfx2.hotmail.com/mail/w2/resources/msnpupld.cab
(o16) - dpf: {6414512b-b978-451d-a0d8-fcfdf33e833c} (wuwebcontrol class) - http://update.microsoft.com/windowsupdate/v6/v5controls/en/x86/client/wuweb_site.cab?1130364442791
(o16) - dpf: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (muwebcontrol class) - http://update.microsoft.com/microsoftupdate/v6/v5controls/en/x86/client/muweb_site.cab?1131365030359
(o16) - dpf: {6e5e167b-1566-4316-b27f-0ddab3484cf7} (image uploader control) - http://www.mijnalbum.nl/skin/v2/system/upload/imageuploader4.cab
(o16) - dpf: {b38870e4-7ecb-40da-8c6a-595f0a5519ff} (msnmessengersetupdownloadcontrol class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
(o16) - dpf: {daf94f73-2aa6-44d8-a562-a28831820d34} (pixum easyuploadx control) - http://www.pixum.de/int/easyupload/imguploader.cab
(o18) - protocol: livecall - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\msnmes~1\msgrap~1.dll
(o18) - protocol: msnim - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\msnmes~1\msgrap~1.dll
(o20) - winlogon notify: klogon - c:\windows\system32\klogon.dll
(o20) - winlogon notify: wgalogon - c:\windows\system32\wgalogon.dll
(o21) - ssodl: wpdshserviceobj - {aaa288ba-9a4c-45b0-95d7-94d524869db5} - c:\windows\system32\wpdshserviceobj.dll
(o23) - Service: kaspersky anti virus 7.0 (avp) - unknown owner - c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe" -r (file missing)
(o23) - Service: cyberlink background capture service (cbcs) (clcapsvc) - unknown owner - c:\program files\home cinema\powercinema\kernel\tv\clcapsvc.exe
(o23) - Service: cyberlink task scheduler (cts) (clsched) - unknown owner - c:\program files\home cinema\powercinema\kernel\tv\clsched.exe
(o23) - Service: cyberlink media library service - cyberlink - c:\program files\home cinema\powercinema\kernel\clml_ntservice\clmlserver.exe
(o23) - Service: google updater service (gusvc) - google - c:\program files\google\common\google updater\googleupdaterservice.exe
(o23) - Service: installdriver table manager (idrivert) - macrovision corporation - c:\program files\common files\installshield\driver\11\intel 32\idrivert.exe
(o23) - Service: lightscribeservice direct disc labeling service (lightscribeservice) - hewlett-packard company - c:\program files\common files\lightscribe\lssrvc.exe
(o23) - Service: nvidia display driver service (nvsvc) - nvidia corporation - c:\windows\system32\nvsvc32.exe
(o23) - Service: cyberlink richvideo service(crvs) (richvideo) - unknown owner - c:\program files\cyberlink\shared files\richvideo.exe
(o23) - Service: x10 device network service (x10nets) - x10 - c:\progra~1\common~1\x10\common\x10nets.exe
copyright nano, created for nationaal computer forum www.nationaalcomputerforum.nl[/hijack]
Comment