A routine Spybot Scan identified Win32.PornPopUp and RightMedia Tracking Cookies as being present, but was not able to remove them.
Could you please advise how to remove these items? (needless to say, I am *not* a visitor to porn sites...!)
The scan log and DDS logs are below; the attach log is attached.
Thank you.
winsome
------------------------------------------------------------------------
SCAN LOG
31.10.2010 13:28:49 - ##### check started #####
31.10.2010 13:28:49 - ### Version: 1.6.2
31.10.2010 13:28:49 - ### Date: 31/10/2010 13:28:49
31.10.2010 13:28:52 - ##### checking bots #####
31.10.2010 13:55:55 - found: Win32.PornPopUp Tracking cookie (Internet Explorer: Paul)
31.10.2010 13:55:55 - found: Right Media Tracking cookie (Internet Explorer: Paul)
31.10.2010 13:56:02 - ##### checking usage tracking #####
31.10.2010 13:56:02 - found: Common Dialogs History 69 files
31.10.2010 13:56:02 - found: Log Activity: SchedLgU.Txt SchedLgU.Txt
31.10.2010 13:56:02 - found: Log Activity: imsins.log imsins.log
31.10.2010 13:56:02 - found: Log Activity: OEWABLog.txt OEWABLog.txt
31.10.2010 13:56:02 - found: Log Install: comsetup.log comsetup.log
31.10.2010 13:56:02 - found: Log Install: ocgen.log ocgen.log
31.10.2010 13:56:02 - found: Log Install: setupact.log setupact.log
31.10.2010 13:56:02 - found: Log Install: setupapi.log setupapi.log
31.10.2010 13:56:03 - found: Log Install: wmsetup.log wmsetup.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\mofcomp.log System32\wbem\logs\mofcomp.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wbemcore.log System32\wbem\logs\wbemcore.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wbemess.lo_ System32\wbem\logs\wbemess.lo_
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wbemess.log System32\wbem\logs\wbemess.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wbemprox.log System32\wbem\logs\wbemprox.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\winmgmt.log System32\wbem\logs\winmgmt.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wmiadap.log System32\wbem\logs\wmiadap.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wmiprov.log System32\wbem\logs\wmiprov.log
31.10.2010 13:56:04 - found: Internet Explorer Typed URL list 4 files
31.10.2010 13:56:04 - found: Internet Explorer Typed URL list 25 files
31.10.2010 13:56:04 - found: Internet Explorer Typed URL list 2 files
31.10.2010 13:56:04 - found: Internet Explorer Last used directory
31.10.2010 13:56:04 - found: Internet Explorer Download directory
31.10.2010 13:56:04 - found: Internet Explorer User agent
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: MS Management Console Recent command list 2 files
31.10.2010 13:56:07 - found: MS Management Console Recent command list 2 files
31.10.2010 13:56:07 - found: MS Direct3D Most recent application
31.10.2010 13:56:07 - found: MS Direct3D Most recent application
31.10.2010 13:56:07 - found: MS DirectDraw Most recent application
31.10.2010 13:56:08 - found: MS Office 11.0 Last opened-from-web file
31.10.2010 13:56:08 - found: MS Office 11.0 (Access) Recent database #1
31.10.2010 13:56:08 - found: MS Office 11.0 (Access) Recent database #2
31.10.2010 13:56:08 - found: MS Office 11.0 (Cliparts) Last search made 7 files
31.10.2010 13:56:08 - found: MS Office 11.0 (Excel) Recent file list 4 files
31.10.2010 13:56:08 - found: MS Office 11.0 (Excel) Recent template list 2 files
31.10.2010 13:56:08 - found: MS Office 11.0 (Outlook) Typed search term history 1 files
31.10.2010 13:56:08 - found: MS Office 11.0 (Picture Manager) Last selected folder
31.10.2010 13:56:08 - found: MS Office 11.0 (PowerPoint) Recent file list 9 files
31.10.2010 13:56:08 - found: MS Office 11.0 (Word) Recent file list
31.10.2010 13:56:08 - found: MS Office 11.0 (Word) Recent template list 8 files
31.10.2010 13:56:09 - found: MS Search Assistant Typed search terms history
31.10.2010 13:56:09 - found: Windows Drivers installation paths
31.10.2010 13:56:10 - found: Windows.OpenWith Open with list - .BMP extension 4 files
31.10.2010 13:56:10 - found: Windows.OpenWith Open with list - .CSV extension 3 files
31.10.2010 13:56:10 - found: Windows Explorer Recent wallpaper list 501 files
31.10.2010 13:56:10 - found: Windows Explorer Run history 4 files
31.10.2010 13:56:10 - found: Windows Explorer Run history 4 files
31.10.2010 13:56:10 - found: Windows Explorer Stream history 4 files
31.10.2010 13:56:10 - found: Windows Explorer Stream history 55 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history IE 6 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history IE 7 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history IE 1 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history files 211 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history files 291 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history files 7 files
31.10.2010 13:56:10 - found: Windows Explorer Last visited history 4 files
31.10.2010 13:56:11 - found: Windows Explorer Last visited history 9 files
31.10.2010 13:56:11 - found: Windows Explorer Recent file global history
31.10.2010 13:56:11 - found: Windows Media SDK Computer name
31.10.2010 13:56:11 - found: Windows Media SDK Unique ID
31.10.2010 13:56:11 - found: Windows Media SDK Volume serial number
31.10.2010 13:56:11 - found: Cookie Cookie (977)
31.10.2010 13:56:11 - found: Cache Cache (2287)
31.10.2010 13:56:11 - found: History History (2531)
31.10.2010 13:56:11 - found: Cookie Cookie (201)
31.10.2010 13:56:11 - ##### check finished #####
--------------------------------------------------------------------------
DDS log
DDS (Ver_10-10-31.01) - NTFSx86
Run by Paul at 9:26:06.28 on 01/11/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.210 [GMT 0:00]
AV: Sophos Anti-Virus *On-access scanning enabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Mindjet\MindManager 7\MMReminderService.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Mindjet\MindManager 7\PDF-XChange\pdfSaver\pdfSaver3.exe
C:\Program Files\Messenger\msmsgs.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\CICJ5BZV\dds[1].scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
BHO: CmjBrowserHelperObject Object: {07a11d74-9d25-4fea-a833-8b0d76a5577a} - c:\program files\mindjet\mindmanager 7\Mm7InternetExplorer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - c:\program files\sophos\sophos anti-virus\SophosBHO.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: Foxit Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus DX4000 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatibee.exe /fu "c:\windows\temp\E_S8D.tmp" /EF "HKCU"
uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe"
uRun: [pdfSaver3] "c:\program files\mindjet\mindmanager 7\pdf-xchange\pdfsaver\pdfSaver3.exe"
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [RegistryBooster] "c:\program files\uniblue\registrybooster\launcher.exe" delay 20000
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [MMReminderService] c:\program files\mindjet\mindmanager 7\MMReminderService.exe
mRun: [pdfSaver3]
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\paul\startm~1\programs\startup\micros~1.lnk - c:\windows\installer\{90110409-6000-11d3-8cfe-0150048383c9}\outicon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoup~1.lnk - c:\program files\sophos\autoupdate\ALMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{a7091e1d-36a4-47f1-a739-173cc341414f}\Icon3E5562ED7.ico
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {941E1A34-C6AF-4baa-A973-224F9C3E04BF} - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - c:\program files\mindjet\mindmanager 7\Mm7InternetExplorer.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: refworks.com
Trusted Zone: refworks.com\www
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1251192861784
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1251452557796
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://bridgecam6.halton.gov.uk/activex/AMC.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://refworks.webex.com/client/T27LB/webex/ieatgpc.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\coreftp\pftpns.dll
AppInit_DLLs: c:\progra~1\sophos\sophos~1\SOPHOS~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\paul\applic~1\mozilla\firefox\profiles\p83u9gxg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-9-25 64288]
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\drivers\tdrpm258.sys [2010-7-23 911680]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [2010-3-27 111232]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [2010-3-27 38912]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\common files\acronis\cdp\afcdpsrv.exe [2010-7-23 2480048]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-8-12 1357464]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2010-3-27 80936]
R2 SAVService;Sophos Anti-Virus;c:\program files\sophos\sophos anti-virus\SavService.exe [2010-3-27 98304]
R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;c:\program files\sophos\autoupdate\ALsvc.exe [2010-6-2 172032]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2010-8-24 92008]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [2010-7-23 160704]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15008]
S2 gupdate1ca2bcbd9513014;Google Update Service (gupdate1ca2bcbd9513014);c:\program files\google\update\GoogleUpdate.exe [2009-9-2 133104]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [2010-3-27 14976]
=============== Created Last 30 ================
2010-10-21 13:00:40 -------- d-----w- c:\program files\Trusteer Rapport
2010-10-18 15:28:30 -------- d-----w- c:\docume~1\paul\applic~1\webex
==================== Find3M ====================
2010-09-18 11:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-07 20:42:42 1826096 ----a-w- c:\windows\system32\auto_reactivate.exe
2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-21 17:45:02 130088 ----a-w- c:\windows\system32\sdccoinstaller.dll
2010-08-21 17:39:53 23552 ----a-w- c:\windows\system32\sophosboottasks.exe
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-08-12 12:15:20 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-08-12 09:01:40 100 ----a-w- c:\windows\system32\prsgrc.dll
============= FINISH: 9:28:07.65 ===============
Could you please advise how to remove these items? (needless to say, I am *not* a visitor to porn sites...!)
The scan log and DDS logs are below; the attach log is attached.
Thank you.
winsome
------------------------------------------------------------------------
SCAN LOG
31.10.2010 13:28:49 - ##### check started #####
31.10.2010 13:28:49 - ### Version: 1.6.2
31.10.2010 13:28:49 - ### Date: 31/10/2010 13:28:49
31.10.2010 13:28:52 - ##### checking bots #####
31.10.2010 13:55:55 - found: Win32.PornPopUp Tracking cookie (Internet Explorer: Paul)
31.10.2010 13:55:55 - found: Right Media Tracking cookie (Internet Explorer: Paul)
31.10.2010 13:56:02 - ##### checking usage tracking #####
31.10.2010 13:56:02 - found: Common Dialogs History 69 files
31.10.2010 13:56:02 - found: Log Activity: SchedLgU.Txt SchedLgU.Txt
31.10.2010 13:56:02 - found: Log Activity: imsins.log imsins.log
31.10.2010 13:56:02 - found: Log Activity: OEWABLog.txt OEWABLog.txt
31.10.2010 13:56:02 - found: Log Install: comsetup.log comsetup.log
31.10.2010 13:56:02 - found: Log Install: ocgen.log ocgen.log
31.10.2010 13:56:02 - found: Log Install: setupact.log setupact.log
31.10.2010 13:56:02 - found: Log Install: setupapi.log setupapi.log
31.10.2010 13:56:03 - found: Log Install: wmsetup.log wmsetup.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\mofcomp.log System32\wbem\logs\mofcomp.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wbemcore.log System32\wbem\logs\wbemcore.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wbemess.lo_ System32\wbem\logs\wbemess.lo_
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wbemess.log System32\wbem\logs\wbemess.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wbemprox.log System32\wbem\logs\wbemprox.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\winmgmt.log System32\wbem\logs\winmgmt.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wmiadap.log System32\wbem\logs\wmiadap.log
31.10.2010 13:56:03 - found: Log Shutdown: System32\wbem\logs\wmiprov.log System32\wbem\logs\wmiprov.log
31.10.2010 13:56:04 - found: Internet Explorer Typed URL list 4 files
31.10.2010 13:56:04 - found: Internet Explorer Typed URL list 25 files
31.10.2010 13:56:04 - found: Internet Explorer Typed URL list 2 files
31.10.2010 13:56:04 - found: Internet Explorer Last used directory
31.10.2010 13:56:04 - found: Internet Explorer Download directory
31.10.2010 13:56:04 - found: Internet Explorer User agent
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:05 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:06 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: Adobe FlashPlayer Cookies Text file
31.10.2010 13:56:07 - found: MS Management Console Recent command list 2 files
31.10.2010 13:56:07 - found: MS Management Console Recent command list 2 files
31.10.2010 13:56:07 - found: MS Direct3D Most recent application
31.10.2010 13:56:07 - found: MS Direct3D Most recent application
31.10.2010 13:56:07 - found: MS DirectDraw Most recent application
31.10.2010 13:56:08 - found: MS Office 11.0 Last opened-from-web file
31.10.2010 13:56:08 - found: MS Office 11.0 (Access) Recent database #1
31.10.2010 13:56:08 - found: MS Office 11.0 (Access) Recent database #2
31.10.2010 13:56:08 - found: MS Office 11.0 (Cliparts) Last search made 7 files
31.10.2010 13:56:08 - found: MS Office 11.0 (Excel) Recent file list 4 files
31.10.2010 13:56:08 - found: MS Office 11.0 (Excel) Recent template list 2 files
31.10.2010 13:56:08 - found: MS Office 11.0 (Outlook) Typed search term history 1 files
31.10.2010 13:56:08 - found: MS Office 11.0 (Picture Manager) Last selected folder
31.10.2010 13:56:08 - found: MS Office 11.0 (PowerPoint) Recent file list 9 files
31.10.2010 13:56:08 - found: MS Office 11.0 (Word) Recent file list
31.10.2010 13:56:08 - found: MS Office 11.0 (Word) Recent template list 8 files
31.10.2010 13:56:09 - found: MS Search Assistant Typed search terms history
31.10.2010 13:56:09 - found: Windows Drivers installation paths
31.10.2010 13:56:10 - found: Windows.OpenWith Open with list - .BMP extension 4 files
31.10.2010 13:56:10 - found: Windows.OpenWith Open with list - .CSV extension 3 files
31.10.2010 13:56:10 - found: Windows Explorer Recent wallpaper list 501 files
31.10.2010 13:56:10 - found: Windows Explorer Run history 4 files
31.10.2010 13:56:10 - found: Windows Explorer Run history 4 files
31.10.2010 13:56:10 - found: Windows Explorer Stream history 4 files
31.10.2010 13:56:10 - found: Windows Explorer Stream history 55 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history IE 6 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history IE 7 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history IE 1 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history files 211 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history files 291 files
31.10.2010 13:56:10 - found: Windows Explorer User Assistant history files 7 files
31.10.2010 13:56:10 - found: Windows Explorer Last visited history 4 files
31.10.2010 13:56:11 - found: Windows Explorer Last visited history 9 files
31.10.2010 13:56:11 - found: Windows Explorer Recent file global history
31.10.2010 13:56:11 - found: Windows Media SDK Computer name
31.10.2010 13:56:11 - found: Windows Media SDK Unique ID
31.10.2010 13:56:11 - found: Windows Media SDK Volume serial number
31.10.2010 13:56:11 - found: Cookie Cookie (977)
31.10.2010 13:56:11 - found: Cache Cache (2287)
31.10.2010 13:56:11 - found: History History (2531)
31.10.2010 13:56:11 - found: Cookie Cookie (201)
31.10.2010 13:56:11 - ##### check finished #####
--------------------------------------------------------------------------
DDS log
DDS (Ver_10-10-31.01) - NTFSx86
Run by Paul at 9:26:06.28 on 01/11/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.210 [GMT 0:00]
AV: Sophos Anti-Virus *On-access scanning enabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Mindjet\MindManager 7\MMReminderService.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Mindjet\MindManager 7\PDF-XChange\pdfSaver\pdfSaver3.exe
C:\Program Files\Messenger\msmsgs.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\CICJ5BZV\dds[1].scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
BHO: CmjBrowserHelperObject Object: {07a11d74-9d25-4fea-a833-8b0d76a5577a} - c:\program files\mindjet\mindmanager 7\Mm7InternetExplorer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - c:\program files\sophos\sophos anti-virus\SophosBHO.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: Foxit Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus DX4000 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatibee.exe /fu "c:\windows\temp\E_S8D.tmp" /EF "HKCU"
uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe"
uRun: [pdfSaver3] "c:\program files\mindjet\mindmanager 7\pdf-xchange\pdfsaver\pdfSaver3.exe"
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [RegistryBooster] "c:\program files\uniblue\registrybooster\launcher.exe" delay 20000
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [MMReminderService] c:\program files\mindjet\mindmanager 7\MMReminderService.exe
mRun: [pdfSaver3]
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\paul\startm~1\programs\startup\micros~1.lnk - c:\windows\installer\{90110409-6000-11d3-8cfe-0150048383c9}\outicon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoup~1.lnk - c:\program files\sophos\autoupdate\ALMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{a7091e1d-36a4-47f1-a739-173cc341414f}\Icon3E5562ED7.ico
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {941E1A34-C6AF-4baa-A973-224F9C3E04BF} - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - c:\program files\mindjet\mindmanager 7\Mm7InternetExplorer.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: refworks.com
Trusted Zone: refworks.com\www
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1251192861784
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1251452557796
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://bridgecam6.halton.gov.uk/activex/AMC.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://refworks.webex.com/client/T27LB/webex/ieatgpc.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\coreftp\pftpns.dll
AppInit_DLLs: c:\progra~1\sophos\sophos~1\SOPHOS~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\paul\applic~1\mozilla\firefox\profiles\p83u9gxg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-9-25 64288]
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\drivers\tdrpm258.sys [2010-7-23 911680]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [2010-3-27 111232]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [2010-3-27 38912]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\common files\acronis\cdp\afcdpsrv.exe [2010-7-23 2480048]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-8-12 1357464]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2010-3-27 80936]
R2 SAVService;Sophos Anti-Virus;c:\program files\sophos\sophos anti-virus\SavService.exe [2010-3-27 98304]
R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;c:\program files\sophos\autoupdate\ALsvc.exe [2010-6-2 172032]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2010-8-24 92008]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [2010-7-23 160704]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15008]
S2 gupdate1ca2bcbd9513014;Google Update Service (gupdate1ca2bcbd9513014);c:\program files\google\update\GoogleUpdate.exe [2009-9-2 133104]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [2010-3-27 14976]
=============== Created Last 30 ================
2010-10-21 13:00:40 -------- d-----w- c:\program files\Trusteer Rapport
2010-10-18 15:28:30 -------- d-----w- c:\docume~1\paul\applic~1\webex
==================== Find3M ====================
2010-09-18 11:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-07 20:42:42 1826096 ----a-w- c:\windows\system32\auto_reactivate.exe
2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-21 17:45:02 130088 ----a-w- c:\windows\system32\sdccoinstaller.dll
2010-08-21 17:39:53 23552 ----a-w- c:\windows\system32\sophosboottasks.exe
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-08-12 12:15:20 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-08-12 09:01:40 100 ----a-w- c:\windows\system32\prsgrc.dll
============= FINISH: 9:28:07.65 ===============