Hi Dan
Here is the
ComboFix Report
ComboFix 08-03-29.1 - Owner 2008-03-29 16:38:30.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.76 [GMT -5:00]Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
-- Script messages for sUBs --
VFind -tf -d+2007 -s282624 "C:\Program Files\????????*[0-9].dll"
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Owner\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Owner\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Owner\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\seekmo
C:\Program Files\seekmo\seekmohook.dll
C:\WINDOWS\180ax.exe
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\default.htm
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\stcloader.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\tmp12.tmp
C:\WINDOWS\system32\tmp13.tmp
C:\WINDOWS\system32\tmp16.tmp
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll
----- BITS: Possible infected sites -----
hxxp://80.93.48.74.
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-29 )))))))))))))))))))))))))))))))
.
2008-03-28 19:12 . 2008-03-28 19:42 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-03-28 18:55 . 2008-03-28 18:55 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-03-28 18:55 . 2008-03-28 18:55 <DIR> d-------- C:\WINDOWS\ehome
2008-03-28 18:37 . 2002-08-29 05:39 1,998,848 --a------ C:\WINDOWS\SYSTEM32\wmploc.dll
2008-03-28 18:36 . 2002-08-29 05:41 674,816 --a------ C:\WINDOWS\SYSTEM32\sxs.dll
2008-03-28 18:34 . 2002-08-29 05:41 3,494,303 --------- C:\WINDOWS\SYSTEM32\nv4_disp.dll
2008-03-28 18:33 . 2002-08-29 05:41 1,622,528 --a------ C:\WINDOWS\SYSTEM32\netshell.dll
2008-03-28 18:31 . 2002-04-22 20:18 766,934 --a------ C:\WINDOWS\SYSTEM32\instcat.sql
2008-03-28 18:30 . 2002-08-29 05:41 1,004,032 --a------ C:\WINDOWS\explorer.exe
2008-03-28 18:28 . 2002-08-29 05:41 578,560 --a------ C:\WINDOWS\SYSTEM32\appwiz.cpl
2008-03-28 18:19 . 2004-08-04 00:31 169,984 --a------ C:\WINDOWS\SYSTEM32\sccbase.dll
2008-03-28 18:19 . 2004-07-17 13:34 67,866 --------- C:\WINDOWS\SYSTEM32\drivers\netwlan5.img
2008-03-28 18:19 . 2004-07-17 13:48 66,082 --------- C:\WINDOWS\SYSTEM32\c_28603.nls
2008-03-28 18:19 . 2004-08-04 00:46 42,537 --a------ C:\WINDOWS\SYSTEM32\keyboard.sys
2008-03-28 18:19 . 2004-08-04 00:22 929 --a------ C:\WINDOWS\SYSTEM32\homepage.inf
2008-03-26 20:53 . 2008-03-26 20:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-03-26 20:32 . 2008-03-26 20:32 <DIR> d-------- C:\Program Files\CCleaner
2008-03-24 21:04 . 2008-03-24 21:04 <DIR> d-------- C:\_OTMoveIt
2008-03-24 19:00 . 2008-03-24 19:08 212 --a------ C:\delete.bat
2008-03-23 20:18 . 2008-03-23 20:18 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-23 20:03 . 2008-03-23 20:55 <DIR> d-------- C:\SDFix
2008-03-23 09:05 . 2008-03-23 09:05 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-23 08:22 . 2008-03-23 08:22 <DIR> d-------- C:\Program Files\stc
2008-03-23 08:21 . 2008-03-23 08:21 <DIR> d-------- C:\WINDOWS\FLEOK
2008-03-23 08:21 . 2008-03-23 08:21 <DIR> d-------- C:\Program Files\zango
2008-03-23 08:21 . 2008-03-23 08:21 <DIR> d-------- C:\Program Files\180solutions
2008-03-23 08:21 . 2008-03-23 08:21 <DIR> d-------- C:\Program Files\180searchassistant
2008-03-23 08:21 . 2008-03-23 08:22 <DIR> d-------- C:\Program Files\180search assistant
2008-03-23 08:21 . 2008-03-23 08:21 19,712 --a------ C:\WINDOWS\SYSTEM32\SIPSPI32.dll
2008-03-23 08:21 . 2008-03-23 08:21 19,712 --a------ C:\WINDOWS\didduid.ini
2008-03-23 07:41 . 2006-12-20 12:40 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-03-23 07:41 . 2006-12-20 12:40 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-03-23 07:23 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
2008-03-23 07:11 . 2008-03-23 07:46 3,216 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2008-03-23 07:09 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\SYSTEM32\VCCLSID.exe
2008-03-23 07:09 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
2008-03-23 07:09 . 2008-03-22 15:49 86,528 --a------ C:\WINDOWS\SYSTEM32\VACFix.exe
2008-03-23 07:09 . 2008-03-15 17:16 82,432 --a------ C:\WINDOWS\SYSTEM32\IEDFix.exe
2008-03-23 07:09 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
2008-03-23 07:09 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\SYSTEM32\WS2Fix.exe
2008-03-22 20:05 . 2008-03-22 20:05 <DIR> d-------- C:\WINDOWS\McAfee.com
2008-03-22 17:20 . 2008-03-22 17:20 64,512 --a------ C:\Documents and Settings\All Users\Application Data\jmjczmzg.dll
2008-03-22 17:20 . 2008-03-22 17:20 21,248 --a------ C:\WINDOWS\shdocpl.dll
2008-03-22 17:20 . 2008-03-22 17:20 19,200 --a------ C:\WINDOWS\SYSTEM32\shdocpe.dll
2008-03-22 17:20 . 2008-03-22 17:20 18,944 --a------ C:\WINDOWS\msa64chk.dll
2008-03-22 17:20 . 2008-03-22 17:20 18,944 --a------ C:\WINDOWS\123messenger.per
2008-03-22 17:20 . 2008-03-22 17:20 18,432 --a------ C:\WINDOWS\SYSTEM32\ntnut32.exe
2008-03-22 17:20 . 2008-03-22 17:20 15,872 --a------ C:\WINDOWS\ntnut.exe
2008-03-22 17:20 . 2008-03-22 17:20 13,824 --a------ C:\WINDOWS\shdocpe.dll
2008-03-22 17:20 . 2008-03-22 17:20 9,216 --a------ C:\WINDOWS\SYSTEM32\MSNSA32.dll
2008-03-22 17:20 . 2008-03-22 17:20 8,704 --a------ C:\WINDOWS\msapasrc.dll
2008-03-22 17:19 . 2008-03-22 17:19 <DIR> d-------- C:\Program Files\Sysmnt
2008-03-22 17:19 . 2008-03-22 17:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-22 17:16 . 2008-03-22 17:16 <DIR> d-------- C:\Program Files\Common Files\Oberon Media
2008-03-22 17:16 . 2008-03-22 18:07 <DIR> d-------- C:\Program Files\Chill
2008-03-22 17:15 . 2008-03-23 09:41 <DIR> d-------- C:\Program Files\Bat
2008-03-05 13:43 . 2008-03-05 13:43 229,532 --ah----- C:\WINDOWS\SYSTEM32\BIT71.tmp
2008-03-02 16:42 . 2008-03-24 07:42 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-02 16:42 . 2008-03-02 16:42 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-29 13:25 --------- d-----w C:\Program Files\Lx_cats
2008-03-25 01:42 --------- d-----w C:\Program Files\GamesBar
2008-03-25 01:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\GamesBar
2008-03-23 00:53 61,224 ----a-w C:\WINDOWS\JAVA\GoToAssistDownloadHelper.exe
2008-03-22 23:06 --------- d-----w C:\Program Files\Comcast Play Games
2008-03-22 22:45 --------- d-----w C:\Program Files\Common Files\Scanner
2008-03-22 22:14 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-28 01:04 --------- d-----w C:\Program Files\McAfee
2008-02-06 14:51 171,400 ----a-w C:\WINDOWS\system32\drivers\mfehidk.sys
2008-01-28 23:33 --------- d-----w C:\Program Files\View22
2008-01-28 02:25 --------- d-----w C:\Program Files\Lexmark 5400 Series
2008-01-28 02:25 --------- d-----w C:\Documents and Settings\Vinnie\Application Data\5400 Series
2001-07-22 02:45 94,784 --sh--w C:\WINDOWS\twain.dll
2001-08-18 05:36 46,592 --sh--w C:\WINDOWS\twain_32.dll
2001-08-18 05:36 995,383 --sh--w C:\WINDOWS\SYSTEM32\mfc42.dll
2001-08-18 05:36 50,688 --sh--w C:\WINDOWS\SYSTEM32\msvcirt.dll
2002-08-29 10:41 401,462 --sha-w C:\WINDOWS\SYSTEM32\msvcp60.dll
2002-08-29 10:41 323,072 --sha-w C:\WINDOWS\SYSTEM32\msvcrt.dll
2001-08-18 05:36 9,728 --sh--w C:\WINDOWS\SYSTEM32\regsvr32.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-15 19:25 28739]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 11:04 52736]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-06 16:56 61440]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2001-06-15 17:34 212992]
"NvCplDaemon"="NvQTwk" []
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2001-08-07 19:25 143360]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2001-08-07 18:36 90112]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2001-07-03 16:13 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-03 19:35 98304]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 08:36 299008]
"WheelMouse"="Amoumain.exe" []
"lxctmon.exe"="C:\Program Files\Lexmark 5400 Series\lxctmon.exe" [2007-01-11 12:57 291760]
"Lexmark 5400 Series Fax Server"="C:\Program Files\Lexmark 5400 Series\fm3032.exe" [2006-07-10 21:30 294912]
"EzPrint"="C:\Program Files\Lexmark 5400 Series\ezprint.exe" [2006-06-07 01:05 98304]
"LXCTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll" [2006-06-07 10:09 106496]
.
Contents of the 'Scheduled Tasks' folder
"2006-12-20 18:16:06 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2006-12-20 18:16:06 C:\WINDOWS\Tasks\ISP signup reminder 3.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2007-11-15 07:08:46 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-01-01 06:00:22 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2006-12-20 18:16:04 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2006-12-20 18:16:04 C:\WINDOWS\Tasks\Registration reminder 2.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2006-12-20 18:16:05 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-29 16:44:44
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCTCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-29 16:53:04
ComboFix-quarantined-files.txt 2008-03-29 21:52:54
Pre-Run: 25,793,454,080 bytes free
Post-Run: 25,779,306,496 bytes free
And here is the new hijackthis log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:28:06 PM, on 3/29/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\lxctcoms.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\System32\wuauclt.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\GE\97769 Dual Scroll Optical Mouse\Amoumain.exe
C:\Program Files\Lexmark 5400 Series\lxctmon.exe
C:\Program Files\Lexmark 5400 Series\ezprint.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.comcast.net/toolbar2.0/search/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://comcast.net/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.comcast.net/toolbar2.0/search/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [WheelMouse] Amoumain.exe
O4 - HKLM\..\Run: [lxctmon.exe] "C:\Program Files\Lexmark 5400 Series\lxctmon.exe"
O4 - HKLM\..\Run: [Lexmark 5400 Series Fax Server] "C:\Program Files\Lexmark 5400 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 5400 Series\ezprint.exe"
O4 - HKLM\..\Run: [LXCTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) -
http://www.comcastsupport.com/oneclickfix/tgctlsr.cabO16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) -
http://playgames.comcast.net/online2/pi ... 0.0.32.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v ... b56649.cabO16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) -
http://onlinedesigner.hgtv.com/images/app/view22rte.cabO16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) -
http://playgames.comcast.net/online2/go ... dfever.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-l ... cfscan.cabO23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: lxct_device - - C:\WINDOWS\System32\lxctcoms.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
--
End of file - 7123 bytes
Thanks
Anna