ComboFix 08-05-15.3 - Basile 2008-05-19 23:14:26.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1437 [GMT 2:00]
Endroit: C:\Documents and Settings\Basile\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Basile\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
* Resident AV is active
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE ::
C:\WINDOWS\BM1342f95b.xml
C:\WINDOWS\system32\bjhiiquw.dll
C:\WINDOWS\system32\bysqdyam.dll
C:\WINDOWS\system32\gogufmyb.dll
C:\WINDOWS\system32\ieabuurm.dll
C:\WINDOWS\system32\ktisrxkf.dll
C:\WINDOWS\system32\lccirfnl.dll
C:\WINDOWS\system32\ljJYoLCu.dll
C:\WINDOWS\system32\maydqsyb.ini
C:\WINDOWS\system32\orgckbvv.dll
C:\WINDOWS\system32\tbwcqvkg.ini
C:\WINDOWS\system32\urqoNhGw.dll
C:\WINDOWS\system32\wfnkfgdi.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM1342f95b.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bjhiiquw.dll
C:\WINDOWS\system32\bysqdyam.dll
C:\WINDOWS\system32\gogufmyb.dll
C:\WINDOWS\system32\ieabuurm.dll
C:\WINDOWS\system32\ktisrxkf.dll
C:\WINDOWS\system32\lccirfnl.dll
C:\WINDOWS\system32\ljJYoLCu.dll
C:\WINDOWS\system32\ltclsegj.ini
C:\WINDOWS\system32\maydqsyb.ini
C:\WINDOWS\system32\orgckbvv.dll
C:\WINDOWS\system32\tbwcqvkg.ini
C:\WINDOWS\system32\urqoNhGw.dll
C:\WINDOWS\system32\wfnkfgdi.dll
C:\WINDOWS\system32\wGhNoqru.ini
C:\WINDOWS\system32\wGhNoqru.ini2
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-19 to 2008-05-19 ))))))))))))))))))))))))))))))))))))
.
2008-05-19 23:17 . 2008-05-19 23:17 294 ---hs---- C:\WINDOWS\system32\ltclsegj.ini
2008-05-19 23:16 . 2008-05-19 23:16 22 --a------ C:\WINDOWS\pskt.ini
2008-05-19 23:16 . 2008-05-19 23:17 0 --a------ C:\WINDOWS\BM1342f95b.xml
2008-05-19 20:45 . 2008-05-19 20:45 114,688 --a------ C:\WINDOWS\system32\jgeslctl.dll
2008-05-19 20:42 . 2008-05-19 20:42 134,656 --a------ C:\WINDOWS\system32\ajfqmaat.dll
2008-05-19 20:42 . 2008-05-19 20:42 2,560 --a------ C:\WINDOWS\system32\axokkylk.exe
2008-05-19 20:40 . 2008-05-19 20:40 124,928 --a------ C:\WINDOWS\system32\rdsynmng.dll
2008-05-19 17:00 . 2008-05-19 20:36 <REP> d-------- C:\WINDOWS\system32\CatRoot2
2008-05-18 18:47 . 2008-05-18 18:47 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-18 18:47 . 2008-05-18 18:47 <REP> d-------- C:\Documents and Settings\Basile\Application Data\Malwarebytes
2008-05-18 18:47 . 2008-05-18 18:47 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-18 18:47 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-18 18:47 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-17 20:00 . 2008-05-17 20:00 55,591 --a------ C:\Program Files\update.zip
2008-05-17 16:17 . 2008-05-19 23:14 <REP> d-------- C:\QUARANTINE
2008-05-17 16:17 . 2008-03-15 17:57 199,445 --a------ C:\Documents and Settings\Basile\Application Data\toolbar.dll
2008-05-17 16:17 . 2008-03-15 15:24 82,937 --a------ C:\Documents and Settings\Basile\Application Data\space1.exe
2008-04-27 17:00 . 2008-05-05 20:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TrackMania
2008-04-25 11:26 . 2008-04-25 11:26 <REP> d-------- C:\Program Files\Ventrilo
2008-04-25 11:26 . 2008-04-25 11:27 <REP> d-------- C:\Documents and Settings\Basile\Application Data\Ventrilo
2008-04-22 00:32 . 2008-04-22 00:32 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-22 00:32 . 2008-04-22 00:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-20 22:54 . 2008-04-20 23:10 <REP> d-------- C:\Program Files\DVDFab Express
2008-04-20 22:54 . 2008-04-29 14:25 <REP> d-------- C:\Documents and Settings\Basile\Application Data\Vso
2008-04-20 22:54 . 2008-04-20 22:54 81,920 --a------ C:\Documents and Settings\Basile\Application Data\ezpinst.exe
2008-04-20 22:54 . 2008-04-20 22:54 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-04-20 22:54 . 2008-04-20 22:54 47,360 --a------ C:\Documents and Settings\Basile\Application Data\pcouffin.sys
2008-04-20 14:55 . 2008-04-20 23:12 <REP> d-------- C:\Documents and Settings\Basile\Application Data\dvdcss
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-18 19:55 --------- d-----w C:\Program Files\eMule
2008-05-18 14:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-12 21:08 --------- d-----w C:\Program Files\mIRC
2008-05-12 11:07 --------- d-----w C:\Documents and Settings\Basile\Application Data\teamspeak2
2008-05-04 11:13 --------- d-----w C:\Program Files\Mumble
2008-04-25 09:26 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-04-06 12:29 --------- d-----w C:\Program Files\HLSW
2008-04-03 07:00 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-02 16:25 --------- d-----w C:\Program Files\Java
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-23 09:37 --------- d-----w C:\Program Files\Octoshape Streaming Services
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 12:58 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:35 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
.
(((((((((((((((((((((((((((((
snapshot@2008-05-18_15.18.22.92 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-18 13:16:05 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-19 21:16:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-18 13:20:01 245,760 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
+ 2008-05-19 21:17:24 16,384 --sha-w C:\WINDOWS\TEMP\Cookies\index.dat
+ 2008-05-19 21:17:24 32,768 --sha-w C:\WINDOWS\TEMP\Fichiers Internet temporaires\Content.IE5\index.dat
+ 2008-05-19 21:17:24 16,384 --sha-w C:\WINDOWS\TEMP\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{209e872d-11ab-4414-b915-26376a9a72dd}]
2008-05-19 20:42 134656 --a------ C:\WINDOWS\system32\ajfqmaat.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"Steam"="c:\program files\valve\steam\steam.exe" [2008-04-07 19:01 1271032]
"Octoshape Streaming Services"="C:\Program Files\Octoshape Streaming Services\Basile\OctoshapeClient.exe" [2006-02-13 18:33 214648]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 14:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 17:28 16126464 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-04-04 19:22 1822720 C:\WINDOWS\SkyTel.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 18:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 18:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 18:43 81920]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2006-11-30 09:50 112216]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 14:39 136768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"1071cac7"="C:\WINDOWS\system32\jgeslctl.dll" [2008-05-19 20:45 114688]
"BM1342f95b"="C:\WINDOWS\system32\rdsynmng.dll" [2008-05-19 20:40 124928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\basilebanane\\counter-strike\\hl.exe"=
"C:\\Program Files\\Valve\\Steam\\Steam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"D:\\Basile\\World of Warcraft\\BackgroundDownloader.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l151x86.sys [2007-07-03 13:06]
S3 SetupNTGLM7X;SetupNTGLM7X;D:\NTGLM7X.sys []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-19 23:16:58
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
C:\WINDOWS\system32\ltclsegj.ini 294 bytes
Scan termin‚ avec succŠs
Les fichiers cach‚s: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\Mctray.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-19 23:18:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-19 21:18:16
ComboFix2.txt 2008-05-19 18:36:49
ComboFix3.txt 2008-05-18 13:18:48
Pre-Run: 24,724,316,160 octets libres
Post-Run: 24,725,184,512 octets libres
182 --- E O F --- 2008-05-16 07:19:40
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:20, on 19/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\program files\valve\steam\steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Basile\Bureau\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: {dd27a9a6-7362-519b-4144-ba11d278e902} - {209e872d-11ab-4414-b915-26376a9a72dd} - C:\WINDOWS\system32\ajfqmaat.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [1071cac7] rundll32.exe "C:\WINDOWS\system32\jgeslctl.dll",b
O4 - HKLM\..\Run: [BM1342f95b] Rundll32.exe "C:\WINDOWS\system32\rdsynmng.dll",s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Program Files\Octoshape Streaming Services\Basile\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuw(...)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{05BA8D1F-4F6D-4B37-BF2F-9EA6642F92EA}: NameServer = 212.27.54.252,212.27.53.252
O17 - HKLM\System\CS1\Services\Tcpip\..\{05BA8D1F-4F6D-4B37-BF2F-9EA6642F92EA}: NameServer = 212.27.54.252,212.27.53.252
O17 - HKLM\System\CS2\Services\Tcpip\..\{05BA8D1F-4F6D-4B37-BF2F-9EA6642F92EA}: NameServer = 212.27.54.252,212.27.53.252
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 6613 bytes