Hijack This Log...Please Help
-
Hijack This Log...Please Help
Hey all
This is my hijack this log, I am far from being computer saavy, so any help you could give would be greatly appreciated. I suspect the looking-for.cc virus that takes over my IE start page, causes popups, etc.
Please let me know what to do! Thanks
Logfile of HijackThis v1.97.7
Scan saved at 7:13:55 AM, on 7/30/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\Program Files\Sygate\SSA\Smc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\MWW32\MANAGER\MWMDMSVC.EXE
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
c:\WINNT\System32\dklog.exe
C:\WINNT\system32\regsvc.exe
C:\PROGRA~1\REMOTE~1\Nodesys\rwcinit.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\RemoteWare\NODESYS\RWKERNEL.EXE
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\netgy32.exe
c:\WINNT\System32\dkcktkn.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\RemoteWare\nodesys\RWCTray.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\Promon.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
C:\WINNT\system32\S3Tray2.exe
C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\WINNT\netih32.exe
C:\Program Files\Innovative Solutions\Advanced Uninstaller PRO 2004 version 6\uninstaller.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\JVolturo\LOCALS~1\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\pipfa.dll/sp.html#26512
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://pipfa.dll/index.html#26512
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://pipfa.dll/index.html#26512
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\pipfa.dll/sp.html#26512
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://pipfa.dll/index.html#26512
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\pipfa.dll/sp.html#26512
O2 - BHO: (no name) - {7DFC872A-7708-1476-67AE-570846CAEC45} - C:\WINNT\d3vz32.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SSA\Smc.exe -startgui
O4 - HKLM\..\Run: [VPN Configuration] C:\Program Files\Nortel Networks\JAN Config\JNJScript\vpncfg_usr.exe /s
O4 - HKLM\..\Run: [iPass iPassConnect c2.40.547 r1] C:\Program Files\iPass\JAN Config\JNJSCRIPT\ipasscfgu.EXE /S
O4 - HKLM\..\Run: [DkAutoReg.exe] c:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [netih32.exe] C:\WINNT\netih32.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: winlogin.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.cerebus
O15 - Trusted Zone: http://*.isb
O15 - Trusted Zone: http://*.pir
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://jjeds.jnj.com/xenroll/xenroll.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/0...ll/xscan53.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/14...3/cpbrkpie.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...866.5268287037
O16 - DPF: {A4FE4D1C-BABA-4245-9B0C-25E159E3F6AA} (LaunchIE.Browse) - https://jjeds.jnj.com/LaunchIE.ocx
O16 - DPF: {B8C23EB8-148C-479B-BC90-4BFFD0C4C7E1} (P12toToken Control) - https://jjeds.jnj.com/Encryption/P12toToken.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {D80B47AE-B5D2-4ABD-BD7F-2B27575CE36B} (P12toCAPI Control) - https://jjeds.jnj.com/Encryption/P12toCAPI.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://ecstage-gsb.webex.com/client...nt/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = na.jnj.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = na.jnj.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = na.jnj.com
O19 - User stylesheet: c:\winnt\java\my.css
-
Hello please download About:Buster Version 1.27 and unzip it to your desktop. Start it, hit Ok, Start, And Ok again to start the scan. It will generate a log. Post that log along with a new Hijack this log here.
If this doesnt work, boot into safe mode and try. How to boot into safe mode?
-
Owen,
Thanks for responding. I think I may have made some headway with this, restarted in safe mode, ran buster, ad-aware and hijack this, along with pest patrol and spy sweeper. Most scans coming up clean now, but I still can't uninstall Home Search Assistent, Shopping Wizard, and Search Extender from my computer. Here is the Buster Report and Hijack this Log...Let me know what you think. Again, Thank you, please let me know if there's something else I need to do here.
-- Scan 1 --------
About:Buster Version 2.0
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!
-- Scan 2 --------
About:Buster Version 2.0
Attempted Clean Of Temp folder.
Pages Reset... Done!
Logfile of HijackThis v1.97.7
Scan saved at 8:42:55 AM, on 7/31/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\Program Files\Sygate\SSA\Smc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\MWW32\MANAGER\MWMDMSVC.EXE
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
c:\WINNT\System32\dklog.exe
C:\WINNT\system32\regsvc.exe
C:\PROGRA~1\REMOTE~1\Nodesys\rwcinit.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\RemoteWare\NODESYS\RWKERNEL.EXE
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
c:\WINNT\System32\dkcktkn.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\RemoteWare\nodesys\RWCTray.exe
C:\WINNT\system32\Promon.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
C:\WINNT\system32\S3Tray2.exe
C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\JVolturo\Desktop\HijackThis.exe
C:\DOCUME~1\JVolturo\LOCALS~1\Temp\AboutBuster.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SSA\Smc.exe -startgui
O4 - HKLM\..\Run: [DkAutoReg.exe] c:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: winlogin.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://jjeds.jnj.com/xenroll/xenroll.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...866.5268287037
O16 - DPF: {A4FE4D1C-BABA-4245-9B0C-25E159E3F6AA} (LaunchIE.Browse) - https://jjeds.jnj.com/LaunchIE.ocx
O16 - DPF: {B8C23EB8-148C-479B-BC90-4BFFD0C4C7E1} (P12toToken Control) - https://jjeds.jnj.com/Encryption/P12toToken.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {D80B47AE-B5D2-4ABD-BD7F-2B27575CE36B} (P12toCAPI Control) - https://jjeds.jnj.com/Encryption/P12toCAPI.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://ecstage-gsb.webex.com/client...nt/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = na.jnj.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = na.jnj.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = na.jnj.com
O19 - User stylesheet: c:\winnt\java\my.css
-
Looking better,
Close all browser windows, restart Hijack This and put a checkmark next to the following entries:
O19 - User stylesheet: c:\winnt\java\my.css
Click Fix Checked
Then you seriously need to pay a visit to Windows Update and download ALL Critical Updates and Service Packs.
You are on Windows 200 SP2, the current version is SP4, youare also using IE5.5 and the current most secure version is IE6. Visit Windows Update to correct this. That might have also been the cause of this hijacking.
Post a fresh log after you have done all that
-
Owen
Used windows update as suggested, installed all possible updates. Should be more current now. Fixed aforementioned file on Hijack This...here is the Buster Log and Hijack This log...let me know what you think... Thanks again!
-- Scan 1 --------
About:Buster Version 2.0
Attempted Clean Of Temp folder.
Pages Reset... Done!
-- Scan 2 --------
About:Buster Version 2.0
Attempted Clean Of Temp folder.
Pages Reset... Done!
Logfile of HijackThis v1.97.7
Scan saved at 6:43:02 PM, on 8/1/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\ibmpmsvc.exe
C:\Program Files\Sygate\SSA\Smc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\MWW32\MANAGER\MWMDMSVC.EXE
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
c:\WINNT\System32\dklog.exe
C:\WINNT\system32\regsvc.exe
C:\PROGRA~1\REMOTE~1\Nodesys\rwcinit.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\RemoteWare\NODESYS\RWKERNEL.EXE
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
c:\WINNT\System32\dkcktkn.exe
C:\Program Files\RemoteWare\nodesys\RWCTray.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\Promon.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
C:\WINNT\system32\S3Tray2.exe
C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Innovative Solutions\Advanced Uninstaller PRO 2004 version 6\uninstaller.exe
C:\Program Files\ThinkPad\Utilities\tponscr.exe
C:\Documents and Settings\JVolturo\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://oncall.ncsus.jnj.com/ompfsi/homepage.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://oncall.ncsus.jnj.com/ompfsi/homepage.asp
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SSA\Smc.exe -startgui
O4 - HKLM\..\Run: [DkAutoReg.exe] c:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: winlogin.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://jjeds.jnj.com/xenroll/xenroll.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...866.5268287037
O16 - DPF: {A4FE4D1C-BABA-4245-9B0C-25E159E3F6AA} (LaunchIE.Browse) - https://jjeds.jnj.com/LaunchIE.ocx
O16 - DPF: {B8C23EB8-148C-479B-BC90-4BFFD0C4C7E1} (P12toToken Control) - https://jjeds.jnj.com/Encryption/P12toToken.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {D80B47AE-B5D2-4ABD-BD7F-2B27575CE36B} (P12toCAPI Control) - https://jjeds.jnj.com/Encryption/P12toCAPI.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://ecstage-gsb.webex.com/client...nt/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = na.jnj.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = na.jnj.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = na.jnj.com
-
Thats looking much better, I'd give you the clean bill of health. You already have Antivirus and Firewall, but have a read of the information below for better spyware protection.
Preventing it returning
After your problem has been resolved on the forum, it is an absoulute MUST to do the following steps to prevent the problem returning. Click on the link to get access to the software or webpage that I'm referring to.
1. Visit Windows Update
Pay a visit to Windows Update and scan for and download ALL Critical Updates and Service Packs. New updates are usually released monthly so check back to Windows Update every month.
2. Download Antivirus Software-
If you haven't already got Antivirus software, you should download and install AVG Antivirus. It is freeware and is updated nearly every 2 days (sometimes more frequently if there are a lot of new viruses) and in my opinion, is better than some Antivirus software such as Norton. Antivirus software will prevent viruses infecting your system and it is important that you update it every two days or every week at the most.
3. Download a Firewall-
If you haven't already got a firewall, it is Very important that you download one. Firewalls will prevent unauthorised access to your computer and stop data leaking out of your computer. You may think that it won't happen to you, but Hackers don't care who you are, what you do, where you live or what you had for tea last Sunday on your holiday in the Lake District, they want your data. Firewalls will keep these sneaks out and one of the best is Sygate Personal Firewall, which happens to be freeware.
4. Spyware Scanners-
It is important that as well as having real time spyware protection, you have a spyware scanning application. If you have not already been told to download one earlier in this thread, it is a good idea to download Spybot Search And Destroy and Ad-aware. They are both spyware scanners and will search for a remove spyware. It is recommended that you have both, because one will pick up entries that the other misses. It is even a good idea to download these if you have other programs such as ASE, Spysweeper, Pest Patrol, etc, because one spyware scanner will not pick up everything. Please remember to update your spyware scanners weekly/fortnightly.
5. Prevent Spyware slipping through Internet Explorer-
Quite a lot of spyware slips through Internet Explorer if your settings are not tight enough. Spyware Blaster will help you prevent spyware slipping through and installing tracking cookies. Simply run it via Start> Programs> Spyware Blaster and click Enable All Protection and it will protect you. It doesn't even have to be open! Remember to update weekly/fortnightly.
6. Constant Spyware Protection-
It is important to have constant spyware protection. Spyware Guard works like an antivirus program but detects Spyware instead. It will constantly protect your system. Check for updates monthly.
All Of these steps are very important and it is HIGHLY recommended that you download all of the programs mentioned for your own safety. Remember to Update everything (including Windows using Windows Update)! It is also a good idea to perform weekly/fortnightly scans with Spybot S&D, Ad-aware and your antivirus software.
And last of all, please remember, that common sense is your greatest tool. Without it, spyware and other related Malware would rule!
-
I also forgot to ask, hows it running?
-
Download, update and run
CWShredder
Click Fix, don't just scan. Let it fix everything it asks about.
Restart HijackThis and put checks next to the following, close all browser windows (including this one) then click on 'Fix Checked':
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://oncall.ncsus.jnj.com/ompfsi/homepage.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://oncall.ncsus.jnj.com/ompfsi/homepage.asp
O4 - Global Startup: winlogin.exe
If you didn't set these restrictions fix these two as well:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
Then run a search for and delete winlogin.exe
Download the latest version (1.98.1) of HijackThis then post another log.
Owen, your link for HJT is a few days behind, maybe you could link directly to SWI which changes automatically when Merijn updates it.
-
Messed up a bit there. Missed the winlogin and Restrictions present. Don't know what I was doing. My apologies.
In regards to Hijack This, I'll update my site. Its easier for me so I can remember the URL and SpywareInfo is always very busy so it gives the site a bit of a break.