Announcement

Collapse
No announcement yet.

ติดโทรจันboot.exe ลบยังไงก็ไม่ออก ช่วยผมด้วยคับ

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • ติดโทรจันboot.exe ลบยังไงก็ไม่ออก ช่วยผมด้วยคับ

    ติดมาจาจากthumbที่เอาไปเสียบในทรูช๊อปมาครับ
    ตอนนี้พอเข้าวินโด้ปุ๊บ nodจะเตือนว่ามีboot.exe แล้วมันก็ลบไป
    ซักไม่ถึง5วินาที มันก็เตือนอีก เป็นแบบนี้ไปเรื่อยๆครับ
    อันนี้ logfile ของ hijackthisนะครับ ช่วยดูให้ทีว่าต้องลบตัวไหน
    หรือถ้ามีวิธีอื่นที่จะแก้ ช่วยบอกด้วยนะคับ ขอบคุนครัล

    Logfile of HijackThis v1.97.7
    Scan saved at 1025, on 31/1/2551
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\boot.exe
    C:\windows\system32\boot.exe
    C:\windows\inf\boot.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\BenQ\BenQ Surround\BenQSurround.exe
    C:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Eset\nod32kui.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    D:\ETC\Program\autorunkiller.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    D:\Kay\Program\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    F0 - system.ini: Shell=explorer.exe boot.exe
    F1 - win.ini: load=c:\windows\system32\boot.exe
    F1 - win.ini: run=c:\windows\inf\boot.exe
    F2 - REG:system.ini: Shell=explorer.exe boot.exe
    O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
    O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe -H
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [BenQSurround] C:\Program Files\BenQ\BenQ Surround\BenQSurround.exe
    O4 - HKLM\..\Run: [Q-HotkeyMgr] "C:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe"
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [protect_autorun] D:\ETC\Program\autorunkiller.exe /start
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - Startup: Winamp Agent.lnk = C:\Program Files\Winamp\winampa.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: ดาวน์โหลดทั้งหมดโดยใช้ FlashGet - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: ดาวน์โหลดโดยใช้ FlashGet - C:\Program Files\FlashGet\jc_link.htm
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: FlashGet (HKLM)
    O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab


    ปล. S-41 เข้า safe modeยังไงเหรอครับ

  • #2
    notebook ส่วนใหญ่จะเข้า safe mode กด f12 หรือไม่ก็ f8 ครับ

    Comment


    • #3
      ลองเข้าไปลบ reg. ใน HKEY_CURRENT_USER - software - microsoft - window NT - currentversion - แล้วลองดูใน window หรือ winlogon นี่แหละ ผมไม่แน่ใจ มันจะมีตัวที่เกี่ยวกับ boot.exe อยู่ ถ้าเจอแล้วลบเลยครับ
      เพิ่งโดนไปเหมือนกัน

      Comment


      • #4
        ไม่รู้ว่าลบได้ยังครับ แต่ตอนนี้ปัญหาใหม่เกิดขึ้นแทน กลายเป็นว่าบู๊ทวินโด้ทุกครั้ง เครื่องจะฟ้องว่า วินโด้หา boot.exeไม่เจอ
        แล้วปัญหาที่ตามมาคือดับเบิ้ลคลิกเพื่อเปิดdriveต่างๆไม่ได้เลยครับ

        Comment


        • #5
          โหลดตัวนี้ไปใช้เน้อ http://www.nod32th.com/component/opt...d,290/lang,en/
          เพื่อคืนค่า registry ให้กลับมาเป็นเหมือนเดิมก่อน แล้วเข้า run ใน start menu พิมพ์ regedit แล้วไปที่ HKEY_CURRENT_USER - software - microsoft - window NT - currentversion - window
          หาตัวที่ดูแล้วมันน่าจะเกี่ยวกับไอ้ boot.exe อ่ะนะ มันมีอยู่ตัวเดียว (โทดทีคับจำไม่ได้จิงๆ) แล้วลบออกเลยครับ พอรีสตาร์ทใหม่ก็หายเป็นปกติ
          เครื่องที่ทำงานเพิ่งโดนเมื่อวันจันทร์นี้เอง search ไม่ได้ เข้า run งงไปพักนึงเลย
          ลองดูนะครับ ผมทำแบบนี้แล้วหายนะ

          Comment


          • #6
            ถ้าลบไม่ออก ลองเข้า safe mode ดูก่อน แล้วสแกนแล้วก็ลบครับ

            Comment


            • #7
              แงๆช่วยที

              Running processes:

              C:\windows\System32\smss.exe
              C:\windows\system32\csrss.exe
              C:\windows\system32\winlogon.exe
              C:\windows\system32\services.exe
              C:\windows\system32\lsass.exe
              C:\windows\system32\svchost.exe
              C:\windows\system32\svchost.exe
              C:\windows\System32\svchost.exe
              C:\windows\system32\svchost.exe
              C:\windows\system32\svchost.exe
              C:\windows\system32\spoolsv.exe
              C:\windows\Explorer.EXE
              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\windows\system32\RUNDLL32.EXE
              C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\Program Files\Eset\nod32krn.exe
              C:\windows\system32\nvsvc32.exe
              C:\windows\system32\svchost.exe
              C:\WINDOWS\system32\wdfmgr.exe
              C:\windows\System32\alg.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\windows\system32\NOTEPAD.EXE
              C:\DOCUME~1\Smart\LOCALS~1\Temp\Rar$EX00.265\HijackThis v1.99.0.1.exe

              --------------------------------------------------

              Checking Windows NT UserInit:

              [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
              UserInit = C:\WINDOWS\system32\userinit.exe,

              --------------------------------------------------

              Autorun entries from Registry:
              HKLM\Software\Microsoft\Windows\CurrentVersion\Run

              IMJPMIG8.1 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
              NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

              --------------------------------------------------

              File association entry for .SCR:
              HKEY_CLASSES_ROOT\scrfile\shell\open\command

              (Default) = "%1" %*

              --------------------------------------------------

              Shell & screensaver key from C:\windows\SYSTEM.INI:

              Shell=*INI section not found*
              SCRNSAVE.EXE=*INI section not found*
              drivers=*INI section not found*

              Shell & screensaver key from Registry:

              Shell=Explorer.exe
              SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
              drivers=*Registry value not found*

              Policies Shell key:

              HKCU\..\Policies: Shell=*Registry value not found*
              HKLM\..\Policies: Shell=*Registry value not found*

              --------------------------------------------------


              Enumerating Browser Helper Objects:

              (no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing) - {02478D38-C3F9-4efb-9B51-7695ECA05670}
              (no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
              ShoppingReport - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing) - {100EB1FD-D03E-47FD-81F3-EE91287F9465}
              flashget urlcatch - C:\Program Files\FlashGet\jccatch.dll - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7}
              (no name) - (no file) - {7E853D72-626A-48EC-A868-BA8D5E23E045}
              (no name) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
              (no name) - C:\Program Files\FlashGet\getflash.dll - {F156768E-81EF-470C-9057-481BA8380DBA}

              --------------------------------------------------

              Enumerating Download Program Files:

              [{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}]
              CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

              [{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}]
              CODEBASE = http://ak.exe.imgfarm.com/images/noc...1.0.0.15-3.cab

              [BDSCANONLINE Control]
              InProcServer32 = C:\WINDOWS\BDOSCAN8\oscan82.ocx
              CODEBASE = http://download.bitdefender.com/reso...an8/oscan8.cab

              [NanoInstaller Class]
              InProcServer32 = C:\WINDOWS\Downloaded Program Files\NanoInst.dll
              CODEBASE = http://www.nanoscan.com/cabs/nanoinst.cab

              [SFLauncherTDE Class]
              InProcServer32 = C:\WINDOWS\system32\STARTE~1.DLL
              CODEBASE = http://www.sf.in.th/activex/StarterSFTDE.cab

              [Shockwave Flash Object]
              InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
              CODEBASE = http://download.macromedia.com/pub/s...sh/swflash.cab

              [Driver Agent ActiveX Control]
              InProcServer32 = C:\WINDOWS\Downloaded Program Files\driveragent.ocx
              CODEBASE = http://driveragent.com/files/driveragent.cab

              --------------------------------------------------

              Enumerating ShellServiceObjectDelayLoad items:

              PostBootReminder: C:\windows\system32\SHELL32.dll
              CDBurn: C:\windows\system32\SHELL32.dll
              WebCheck: C:\windows\system32\webcheck.dll
              SysTray: C:\WINDOWS\system32\stobject.dll

              --------------------------------------------------
              End of report, 5,466 bytes
              Report generated in 0.047 seconds

              Command line options:
              /verbose - to add additional info on each section
              /complete - to include empty sections and unsuspicious data
              /full - to include several rarely-important sections
              /force9x - to include Win9x-only startups even if running on WinNT
              /forcent - to include WinNT-only startups even if running on Win9x
              /forceall - to include all Win9x and WinNT startups, regardless of platform
              /history - to list version history only

              Comment


              • #8
                แงๆช่วยที

                Logfile of HijackThis v1.99.1
                Scan saved at 852, on 13/3/2551
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                Running processes:
                C:\windows\System32\smss.exe
                C:\windows\system32\csrss.exe
                C:\windows\system32\winlogon.exe
                C:\windows\system32\services.exe
                C:\windows\system32\lsass.exe
                C:\windows\system32\svchost.exe
                C:\windows\system32\svchost.exe
                C:\windows\System32\svchost.exe
                C:\windows\system32\svchost.exe
                C:\windows\system32\svchost.exe
                C:\windows\system32\spoolsv.exe
                C:\windows\Explorer.EXE
                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                C:\windows\system32\RUNDLL32.EXE
                C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                C:\Program Files\Eset\nod32krn.exe
                C:\windows\system32\nvsvc32.exe
                C:\windows\system32\svchost.exe
                C:\WINDOWS\system32\wdfmgr.exe
                C:\windows\System32\alg.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\DOCUME~1\Smart\LOCALS~1\Temp\Rar$EX02.141\HijackThis v1.99.0.1.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                R3 - URLSearchHook: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll (file missing)
                O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                O3 - Toolbar: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll (file missing)
                O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O8 - Extra context menu item: &ดาวน์โหลดทั้งหมดโดยใช้ FlashGet - C:\Program Files\FlashGet\jc_all.htm
                O8 - Extra context menu item: &ดาวน์โหลดโดยใช้ FlashGet - C:\Program Files\FlashGet\jc_link.htm
                O8 - Extra context menu item: ส่&งออกไปยัง Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                O9 - Extra button: การวิจัย - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/noc...1.0.0.15-3.cab
                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
                O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
                O16 - DPF: {8E82893F-7ED1-4811-A247-580DCC0E2629} (SFLauncherTDE Class) - http://www.sf.in.th/activex/StarterSFTDE.cab
                O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: MsInfo Service (MsInfo) - Unknown owner - C:\RECYCLER\MsInfo\MsInfo.exe (file missing)
                O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
                O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

                Comment

                Working...
                X