Guess I'm not suprised that those P2P programs decided to stick around after being told months ago to go away. Here are the new log files:
ComboFix 09-03-31.03 - Glen 2009-04-02 7:43:17.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.3071.2668 [GMT -7:00]
Running from: c:\documents and settings\Glen\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Glen\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Glen\Application Data\Azureus
c:\documents and settings\Glen\Application Data\Azureus\.certs
c:\documents and settings\Glen\Application Data\Azureus\.keystore
c:\documents and settings\Glen\Application Data\Azureus\.lock
c:\documents and settings\Glen\Application Data\Azureus\active\6830119D4D76DE24CE568C665D818A33919975E8.dat
c:\documents and settings\Glen\Application Data\Azureus\active\6830119D4D76DE24CE568C665D818A33919975E8.dat.bak
c:\documents and settings\Glen\Application Data\Azureus\active\B1FC12ED71F95B997BE835176C6C620E4FA3A556.dat
c:\documents and settings\Glen\Application Data\Azureus\active\B1FC12ED71F95B997BE835176C6C620E4FA3A556.dat.bak
c:\documents and settings\Glen\Application Data\Azureus\active\B78E12EE65A341DAA81E050CE0186DE7BACF47CB.dat
c:\documents and settings\Glen\Application Data\Azureus\active\B78E12EE65A341DAA81E050CE0186DE7BACF47CB.dat.bak
c:\documents and settings\Glen\Application Data\Azureus\active\cache.dat
c:\documents and settings\Glen\Application Data\Azureus\active\F2B18AE7B9D81125A6B0C98AE9F104C1EDBB67E4.dat
c:\documents and settings\Glen\Application Data\Azureus\active\F2B18AE7B9D81125A6B0C98AE9F104C1EDBB67E4.dat.bak
c:\documents and settings\Glen\Application Data\Azureus\azureus.config
c:\documents and settings\Glen\Application Data\Azureus\azureus.config.bak
c:\documents and settings\Glen\Application Data\Azureus\azureus.statistics
c:\documents and settings\Glen\Application Data\Azureus\azureus.statistics.bak
c:\documents and settings\Glen\Application Data\Azureus\cnetworks.config
c:\documents and settings\Glen\Application Data\Azureus\dht\addresses.dat
c:\documents and settings\Glen\Application Data\Azureus\dht\contacts.dat
c:\documents and settings\Glen\Application Data\Azureus\dht\diverse.dat
c:\documents and settings\Glen\Application Data\Azureus\dht\general.dat
c:\documents and settings\Glen\Application Data\Azureus\dht\version.dat
c:\documents and settings\Glen\Application Data\Azureus\downloads.config
c:\documents and settings\Glen\Application Data\Azureus\downloads.config.bak
c:\documents and settings\Glen\Application Data\Azureus\friends.config
c:\documents and settings\Glen\Application Data\Azureus\friends.config.bak
c:\documents and settings\Glen\Application Data\Azureus\ipfilter.cache
c:\documents and settings\Glen\Application Data\Azureus\logs\alerts_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\clientid_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\CNetworks_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\debug_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\Friends_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\MetaSearch_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\NetStatus_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\seltrace_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\Subscriptions_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\thread_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\thread_2.log
c:\documents and settings\Glen\Application Data\Azureus\logs\v3.ads_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\v3.CMsgr_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\v3.Friends_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\v3.PMsgr_1.log
c:\documents and settings\Glen\Application Data\Azureus\logs\v3.Stream_1.log
c:\documents and settings\Glen\Application Data\Azureus\metasearch.config
c:\documents and settings\Glen\Application Data\Azureus\metasearch.config.bak
c:\documents and settings\Glen\Application Data\Azureus\net\pm_33490.dat
c:\documents and settings\Glen\Application Data\Azureus\net\pm_default.dat
c:\documents and settings\Glen\Application Data\Azureus\sidebarauto.config
c:\documents and settings\Glen\Application Data\Azureus\sidebarauto.config.bak
c:\documents and settings\Glen\Application Data\Azureus\tables.config
c:\documents and settings\Glen\Application Data\Azureus\tables.config.bak
c:\documents and settings\Glen\Application Data\Azureus\timingstats.dat
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37593.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37594.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37595.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37596.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37597.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37598.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37599.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37600.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37601.tmp\patch.jar
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37603.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37604.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37606.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37607.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37608.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37609.tmp
c:\documents and settings\Glen\Application Data\Azureus\tmp\AZU37610.tmp
c:\documents and settings\Glen\Application Data\Azureus\torrents\(PSX-NTSC)Final_Fantasy_VIII.ISO_xExUxBxExRx_.4020406.TPB.torrent
c:\documents and settings\Glen\Application Data\Azureus\torrents\AZU37602.tmp
c:\documents and settings\Glen\Application Data\Azureus\torrents\AZU37605.tmp
c:\documents and settings\Glen\Application Data\Azureus\torrents\AZU53229.tmp
c:\documents and settings\Glen\Application Data\Azureus\torrents\AZU8788.tmp
c:\documents and settings\Glen\Application Data\Azureus\torrents\Final_Fantasy_7__8___9_[PSX]_with_ePSXe_1.70.4283045.TPB.torrent
c:\documents and settings\Glen\Application Data\Azureus\tracker.config
c:\documents and settings\Glen\Application Data\Azureus\tracker.config.bak
c:\documents and settings\Glen\Application Data\Azureus\unsentdata.config
c:\documents and settings\Glen\Application Data\Azureus\unsentdata.config.bak
c:\documents and settings\Glen\Application Data\Azureus\update.log
c:\documents and settings\Glen\Application Data\Azureus\update.properties
c:\documents and settings\Glen\Application Data\Azureus\v3.Friends.dat
c:\documents and settings\Glen\Application Data\Azureus\v3.Friends.dat.bak
c:\documents and settings\Glen\Application Data\Azureus\VuzeActivities.config
c:\program files\Vuze
c:\program files\Vuze\plugins\azemp\azemp_2.0.32.jar
c:\program files\Vuze\plugins\azemp\azemp_2.0.32.zip
c:\program files\Vuze\plugins\azemp\azemp_2.0.34.jar
c:\program files\Vuze\plugins\azemp\azemp_2.0.34.zip
c:\program files\Vuze\plugins\azemp\azmplay.exe.bak
c:\program files\Vuze\plugins\azemp\cp1250-a.raw.bak
c:\program files\Vuze\plugins\azemp\cp1250-b.raw.bak
c:\program files\Vuze\plugins\azemp\font.desc.bak
c:\program files\Vuze\plugins\azemp\osd-mplayer-a.raw.bak
c:\program files\Vuze\plugins\azemp\osd-mplayer-b.raw.bak
c:\program files\Vuze\plugins\azemp\plugin.properties_2.0.32
c:\program files\Vuze\plugins\azemp\plugin.properties_2.0.34
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.5.jar
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.5.zip
c:\program files\Vuze\plugins\azupnpav\plugin.properties_0.2.5
.
((((((((((((((((((((((((( Files Created from 2009-03-02 to 2009-04-02 )))))))))))))))))))))))))))))))
.
2009-04-01 07:50 . 2006-03-03 08:07 143,360 --a------ c:\windows\system32\dunzip32.dll
2009-04-01 07:50 . 2009-04-01 22:59 6,819 --a------ c:\windows\system32\Config.MPF
2009-04-01 07:48 . 2009-04-01 07:48 <DIR> d-------- c:\program files\McAfee.com
2009-04-01 07:48 . 2009-04-01 07:50 <DIR> d-------- c:\program files\McAfee
2009-04-01 07:48 . 2009-04-01 07:48 <DIR> d-------- c:\program files\Common Files\McAfee
2009-04-01 07:48 . 2007-11-22 06:44 201,320 --a------ c:\windows\system32\drivers\mfehidk.sys
2009-04-01 07:48 . 2007-07-13 06:20 113,952 --a------ c:\windows\system32\drivers\Mpfp.sys
2009-04-01 07:48 . 2007-11-22 06:44 79,304 --a------ c:\windows\system32\drivers\mfeavfk.sys
2009-04-01 07:48 . 2007-12-02 12:51 40,488 --a------ c:\windows\system32\drivers\mfesmfk.sys
2009-04-01 07:48 . 2007-11-22 06:44 35,240 --a------ c:\windows\system32\drivers\mfebopk.sys
2009-04-01 07:48 . 2007-11-22 06:44 33,832 --a------ c:\windows\system32\drivers\mferkdk.sys
2009-03-30 19:54 . 2009-03-30 19:55 <DIR> d-------- c:\program files\ERUNT
2009-03-28 01:53 . 2009-03-30 16:15 442 --a------ c:\windows\wininit.ini
2009-03-16 20:00 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-03-16 20:00 . 2004-08-03 22:58 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2009-03-07 22:54 . 2005-05-26 16:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-01 14:50 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2009-03-31 02:41 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-31 02:41 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-30 22:59 61,440 --sha-w c:\windows\system32\bakefuni.exe
2009-03-29 23:13 61,440 --sha-w c:\windows\system32\defisebe.exe
2009-03-29 09:26 61,440 --sha-w c:\windows\system32\suhokamo.exe
2009-03-28 21:26 61,440 --sha-w c:\windows\system32\wumoyuvo.exe
2009-03-28 11:45 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-28 09:02 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-28 08:32 61,440 --sha-w c:\windows\system32\nipavuyo.exe
2009-02-18 04:52 --------- d-----w c:\documents and settings\Glen\Application Data\Move Networks
2009-02-08 21:14 --------- d-----w c:\documents and settings\Glen\Application Data\CyberLink
2009-02-08 21:14 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2009-02-08 21:10 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-08 21:10 --------- d-----w c:\program files\CyberLink
2009-02-02 15:53 --------- d-----w c:\documents and settings\Glen\Application Data\InterVideo
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-12-05 1237042]
"EPSON Stylus CX5400"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE" [2003-05-26 99840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-11 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-11 81920]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-13 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"nwiz"="nwiz.exe" [2007-05-11 c:\windows\system32\nwiz.exe]
c:\documents and settings\Glen\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Loadout Manager.lnk - c:\program files\Belkin\Nostromo\nost_LM.exe [2003-06-23 442368]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\McAfee\\MSC\\mcmscsvc.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R0 ABIT-IO;ABIT-IO;c:\windows\system32\drivers\ABIT-IO.sys [2008-12-29 4608]
R3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [2003-07-23 22821]
S2 0195581238597297mcinstcleanup;McAfee Application Installer Cleanup (0195581238597297);c:\docume~1\Glen\LOCALS~1\Temp\
019558~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\Glen\LOCALS~1\Temp\
019558~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S3 s3legacy;s3legacy;c:\windows\system32\drivers\s3legacy.sys [2009-01-04 65664]
.
Contents of the 'Scheduled Tasks' folder
2009-04-01 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2009-04-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/a/
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-02 07:44:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-04-02 7:45:05
ComboFix-quarantined-files.txt 2009-04-02 14:45:03
ComboFix2.txt 2009-04-01 16:02:13
Pre-Run: 31,105,257,472 bytes free
Post-Run: 31,102,918,656 bytes free
221
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:46:44 AM, on 4/2/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\Nostromo\nost_LM.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/a/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1230654169656
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: McAfee Application Installer Cleanup (0195581238597297) (0195581238597297mcinstcleanup) - Unknown owner - C:\DOCUME~1\Glen\LOCALS~1\Temp\019558~1.EXE (file missing)
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 5010 bytes