wcts17skippy
New member
:sad:I have ran Spybot on my daughter's computer because she's not been able to get on. I had to run it in Safe mode, her Prevx software stopped working she said and then she started having problems. Below is the spybot log and hjt file. If someone can take a look at this for her and let us know what to do, I'm only trying to help her out. Thanks, A lot
09.09.2007 18:13:08 - ##### check started #####
09.09.2007 18:13:08 - ### Version: 1.5
09.09.2007 18:13:08 - ### Date: 9/9/2007 6:13:08 PM
09.09.2007 18:13:09 - ##### checking bots #####
09.09.2007 18:16:57 - found: SpyBlocs Settings
09.09.2007 18:16:57 - found: SpyBlocs Settings
09.09.2007 18:16:57 - found: SpyBlocs Settings
09.09.2007 18:16:58 - found: SpyDawn Program directory
09.09.2007 18:17:01 - found: SpyHeal Class ID
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Type library
09.09.2007 18:17:01 - found: SpyHeal Settings
09.09.2007 18:17:01 - found: SpyHeal Executable
09.09.2007 18:17:01 - found: SpyHeal Program directory
09.09.2007 18:17:01 - found: SpyHeal Configuration file
09.09.2007 18:17:02 - found: SpyHeal Program directory
09.09.2007 18:17:02 - found: SpyHeal Program directory
09.09.2007 18:17:02 - found: SpyHeal Link
09.09.2007 18:17:02 - found: SpyHeal Settings
09.09.2007 18:17:04 - found: SpyHeal Text file
09.09.2007 18:17:04 - found: SpyHeal Library
09.09.2007 18:17:04 - found: SpyHeal Library
09.09.2007 18:17:04 - found: SpyHeal Web page
09.09.2007 18:18:07 - found: Worldsecurityonline.FakeAlert Settings
09.09.2007 18:18:08 - found: Worldsecurityonline.FakeAlert Uninstall settings
09.09.2007 18:18:16 - found: Smitfraud-C. Settings
09.09.2007 18:19:07 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Type library
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Interface
09.09.2007 18:19:09 - found: CyberDefender Interface
09.09.2007 18:19:09 - found: CyberDefender Interface
09.09.2007 18:19:09 - found: CyberDefender Type library
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Interface
09.09.2007 18:19:10 - found: CyberDefender Type library
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Interface
09.09.2007 18:19:10 - found: CyberDefender Interface
09.09.2007 18:19:10 - found: CyberDefender Type library
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Type library
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Interface
09.09.2007 18:19:10 - found: CyberDefender Type library
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:11 - found: CyberDefender Root class
09.09.2007 18:19:11 - found: CyberDefender Class ID
09.09.2007 18:19:11 - found: CyberDefender Class ID
09.09.2007 18:19:11 - found: CyberDefender Root class
09.09.2007 18:19:11 - found: CyberDefender Root class
09.09.2007 18:19:11 - found: CyberDefender Class ID
09.09.2007 18:19:11 - found: CyberDefender Class ID
09.09.2007 18:19:11 - found: CyberDefender Class ID
09.09.2007 18:19:11 - found: CyberDefender Text file
09.09.2007 18:19:11 - found: CyberDefender Program directory
09.09.2007 18:19:19 - found: CyberDefender Configuration file
09.09.2007 18:19:19 - found: CyberDefender Library
09.09.2007 18:19:19 - found: CyberDefender File extension
09.09.2007 18:19:19 - found: CyberDefender Root class
09.09.2007 18:19:19 - found: CyberDefender User settings
09.09.2007 18:19:19 - found: CyberDefender User settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Uninstall settings
09.09.2007 18:19:19 - found: CyberDefender Uninstall settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Root class
09.09.2007 18:19:19 - found: CyberDefender Root class
09.09.2007 18:19:19 - found: CyberDefender Class ID
09.09.2007 18:19:19 - found: CyberDefender Root class
09.09.2007 18:19:19 - found: CyberDefender Root class
09.09.2007 18:19:20 - found: CyberDefender Class ID
09.09.2007 18:19:28 - found: Freeze Data
09.09.2007 18:19:28 - found: Freeze Data
09.09.2007 18:19:52 - found: WildTangent Settings
09.09.2007 18:19:52 - found: WildTangent Program directory
09.09.2007 18:19:52 - found: WildTangent Library
09.09.2007 18:19:52 - found: WildTangent Program directory
09.09.2007 18:19:52 - found: WildTangent Program directory
09.09.2007 18:19:52 - found: WildTangent Program directory
09.09.2007 18:19:56 - found: MalwareWipe Class ID
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:57 - found: MalwareWipe Interface
09.09.2007 18:19:57 - found: MalwareWipe Type library
09.09.2007 18:20:53 - found: Microsoft.WindowsSecurityCenter.AntiVirusOverride Settings
09.09.2007 18:23:17 - found: StarWare Settings
09.09.2007 18:23:17 - found: StarWare Settings
09.09.2007 18:23:17 - found: StarWare Settings
09.09.2007 18:24:57 - found: Fraud.ProtectionBar Settings
09.09.2007 18:24:57 - found: Fraud.ProtectionBar IE toolbar
09.09.2007 18:27:59 - found: Zlob.VideoAccessActiveXObject Settings
09.09.2007 18:30:48 - found: CoreMetrics Tracking cookie (Internet Explorer: Owner)
09.09.2007 18:30:48 - found: WebTrends live Tracking cookie (Internet Explorer: Owner)
09.09.2007 18:30:48 - found: CPXinteractive Tracking cookie (Internet Explorer: Owner)
09.09.2007 18:30:53 - ##### check finished #####
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:30:05 PM, on 9/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SpyHeals] C:\Program Files\SpyHeals\SpyHeals.exe /h
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\cdas89a.exe" /minimize
O4 - HKCU\..\Run: [Simple Star PhotoShow Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\xtras\mssysmgr.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [user32.dll] C:\Program Files\Internet Security\isamntr.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\Broderbund Party and Crafts Creator\pmremind.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - http://install.wildtangent.com/bgn/partners/bellsouth/slyder/install.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Prevx Agent (PREVXAgent) - Prevx - C:\Program Files\Prevx1\PXAgent.exe
O23 - Service: ro0 Service (ro0Srv) - Unknown owner - C:\WINDOWS\system32\ro0\ro0.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 8709 bytes
09.09.2007 18:13:08 - ##### check started #####
09.09.2007 18:13:08 - ### Version: 1.5
09.09.2007 18:13:08 - ### Date: 9/9/2007 6:13:08 PM
09.09.2007 18:13:09 - ##### checking bots #####
09.09.2007 18:16:57 - found: SpyBlocs Settings
09.09.2007 18:16:57 - found: SpyBlocs Settings
09.09.2007 18:16:57 - found: SpyBlocs Settings
09.09.2007 18:16:58 - found: SpyDawn Program directory
09.09.2007 18:17:01 - found: SpyHeal Class ID
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Interface
09.09.2007 18:17:01 - found: SpyHeal Type library
09.09.2007 18:17:01 - found: SpyHeal Settings
09.09.2007 18:17:01 - found: SpyHeal Executable
09.09.2007 18:17:01 - found: SpyHeal Program directory
09.09.2007 18:17:01 - found: SpyHeal Configuration file
09.09.2007 18:17:02 - found: SpyHeal Program directory
09.09.2007 18:17:02 - found: SpyHeal Program directory
09.09.2007 18:17:02 - found: SpyHeal Link
09.09.2007 18:17:02 - found: SpyHeal Settings
09.09.2007 18:17:04 - found: SpyHeal Text file
09.09.2007 18:17:04 - found: SpyHeal Library
09.09.2007 18:17:04 - found: SpyHeal Library
09.09.2007 18:17:04 - found: SpyHeal Web page
09.09.2007 18:18:07 - found: Worldsecurityonline.FakeAlert Settings
09.09.2007 18:18:08 - found: Worldsecurityonline.FakeAlert Uninstall settings
09.09.2007 18:18:16 - found: Smitfraud-C. Settings
09.09.2007 18:19:07 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Interface
09.09.2007 18:19:08 - found: CyberDefender Type library
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Root class
09.09.2007 18:19:08 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Interface
09.09.2007 18:19:09 - found: CyberDefender Interface
09.09.2007 18:19:09 - found: CyberDefender Interface
09.09.2007 18:19:09 - found: CyberDefender Type library
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Root class
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Application ID
09.09.2007 18:19:09 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Interface
09.09.2007 18:19:10 - found: CyberDefender Type library
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Interface
09.09.2007 18:19:10 - found: CyberDefender Interface
09.09.2007 18:19:10 - found: CyberDefender Type library
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Type library
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Class ID
09.09.2007 18:19:10 - found: CyberDefender Interface
09.09.2007 18:19:10 - found: CyberDefender Type library
09.09.2007 18:19:10 - found: CyberDefender Root class
09.09.2007 18:19:11 - found: CyberDefender Root class
09.09.2007 18:19:11 - found: CyberDefender Class ID
09.09.2007 18:19:11 - found: CyberDefender Class ID
09.09.2007 18:19:11 - found: CyberDefender Root class
09.09.2007 18:19:11 - found: CyberDefender Root class
09.09.2007 18:19:11 - found: CyberDefender Class ID
09.09.2007 18:19:11 - found: CyberDefender Class ID
09.09.2007 18:19:11 - found: CyberDefender Class ID
09.09.2007 18:19:11 - found: CyberDefender Text file
09.09.2007 18:19:11 - found: CyberDefender Program directory
09.09.2007 18:19:19 - found: CyberDefender Configuration file
09.09.2007 18:19:19 - found: CyberDefender Library
09.09.2007 18:19:19 - found: CyberDefender File extension
09.09.2007 18:19:19 - found: CyberDefender Root class
09.09.2007 18:19:19 - found: CyberDefender User settings
09.09.2007 18:19:19 - found: CyberDefender User settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Uninstall settings
09.09.2007 18:19:19 - found: CyberDefender Uninstall settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Settings
09.09.2007 18:19:19 - found: CyberDefender Root class
09.09.2007 18:19:19 - found: CyberDefender Root class
09.09.2007 18:19:19 - found: CyberDefender Class ID
09.09.2007 18:19:19 - found: CyberDefender Root class
09.09.2007 18:19:19 - found: CyberDefender Root class
09.09.2007 18:19:20 - found: CyberDefender Class ID
09.09.2007 18:19:28 - found: Freeze Data
09.09.2007 18:19:28 - found: Freeze Data
09.09.2007 18:19:52 - found: WildTangent Settings
09.09.2007 18:19:52 - found: WildTangent Program directory
09.09.2007 18:19:52 - found: WildTangent Library
09.09.2007 18:19:52 - found: WildTangent Program directory
09.09.2007 18:19:52 - found: WildTangent Program directory
09.09.2007 18:19:52 - found: WildTangent Program directory
09.09.2007 18:19:56 - found: MalwareWipe Class ID
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:56 - found: MalwareWipe Interface
09.09.2007 18:19:57 - found: MalwareWipe Interface
09.09.2007 18:19:57 - found: MalwareWipe Type library
09.09.2007 18:20:53 - found: Microsoft.WindowsSecurityCenter.AntiVirusOverride Settings
09.09.2007 18:23:17 - found: StarWare Settings
09.09.2007 18:23:17 - found: StarWare Settings
09.09.2007 18:23:17 - found: StarWare Settings
09.09.2007 18:24:57 - found: Fraud.ProtectionBar Settings
09.09.2007 18:24:57 - found: Fraud.ProtectionBar IE toolbar
09.09.2007 18:27:59 - found: Zlob.VideoAccessActiveXObject Settings
09.09.2007 18:30:48 - found: CoreMetrics Tracking cookie (Internet Explorer: Owner)
09.09.2007 18:30:48 - found: WebTrends live Tracking cookie (Internet Explorer: Owner)
09.09.2007 18:30:48 - found: CPXinteractive Tracking cookie (Internet Explorer: Owner)
09.09.2007 18:30:53 - ##### check finished #####
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:30:05 PM, on 9/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SpyHeals] C:\Program Files\SpyHeals\SpyHeals.exe /h
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\cdas89a.exe" /minimize
O4 - HKCU\..\Run: [Simple Star PhotoShow Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\xtras\mssysmgr.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [user32.dll] C:\Program Files\Internet Security\isamntr.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\Broderbund Party and Crafts Creator\pmremind.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - http://install.wildtangent.com/bgn/partners/bellsouth/slyder/install.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Prevx Agent (PREVXAgent) - Prevx - C:\Program Files\Prevx1\PXAgent.exe
O23 - Service: ro0 Service (ro0Srv) - Unknown owner - C:\WINDOWS\system32\ro0\ro0.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 8709 bytes