Options

Please help? Had to go home to be able to access you!

I think my network has been hijacked or something! Between the server and client computers at work, I can't access anything and both computers are running insanely slow. I tried for three hours this morning to get to you guys here and neither would load the forums page, let alone let me search to see if there was a reply to my post from Friday.

I copied my HJT log onto a disk and brought it home. Please please please take a look and let me know if there is something nasty in there!!! I can't tell you how much I would appreciate it! Also, if I didn't follow proper etiquette or protocol in my message on Friday, please forgive me - I was a total stress case!

Logfile of HijackThis v1.99.1
Scan saved at 10:32:17 AM, on 7/24/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\BackUp Solutions\CBSysTray.exe
C:\PROGRA~1\Webshots\webshots.scr
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://watson.microsoft.com/dw/dcp.asp?CLCID=1033&EXENAME=generic&BRAND=WINDOWS
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: BackUp Solutions TaskBar Icon.LNK = C:\Program Files\BackUp Solutions\CBSysTray.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: BackUp Solutions TaskBar Icon.LNK = C:\Program Files\BackUp Solutions\CBSysTray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152564738828
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/chuzzle/popcaploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = InnovativeAdvisoryServices.local
O17 - HKLM\Software\..\Telephony: DomainName = InnovativeAdvisoryServices.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A50BF66-1250-499E-BDF2-5F69C36C212C}: Domain = innovativeadvisoryservices.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A50BF66-1250-499E-BDF2-5F69C36C212C}: NameServer = 192.168.0.10
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = InnovativeAdvisoryServices.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = innovativeadvisoryservices.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = InnovativeAdvisoryServices.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = innovativeadvisoryservices.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = innovativeadvisoryservices.local
O23 - Service: Connected Agent Service (AgentSrv) - Connected Corporation - C:\Program Files\BackUp Solutions\AgentSrv.EXE
O23 - Service: PTI Common Server (CommonServer) - Unknown owner - C:\Centerpiece5\commonserver.exe
O23 - Service: PTI Centerpiece Server (CpServer) - Performance Technologies Inc., - C:\Centerpiece5\CpServer.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DCS Loader (DCSLoader) - Oki Data Corporation - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PTI Pricing Server (PricingServer) - Unknown owner - C:\Centerpiece5\pricingserver.exe
O23 - Service: PTI DataEngine (svcDataEngine) - Performance Technologies, Inc. - C:\Centerpiece5\ptiDataEngine.exe

I don't have the ability to download anything right now. I tried to download and install the updates for Sypbot and AdAware and the computer wouldn't let me.

Thanks so much!

Shari

Comments

  • edited July 2006
    See me here, down on my knees. I'm beggin now!!!! I'm not that good at this computer stuff and I really need help!!? I don't know what to do here. I will be bypassing the server and keeping everything on my computer once I get this all worked out, but I can't function right now without the network/decent internet access.

    :respect: Please would somebody help?????

    Shari
  • edited July 2006
    Maybe I'm in the wrong forum? I just know that I didn't make the changes to the network to create such a mess so I figured it must be some sort of malware. I went through my log myself and the only things I could come up with is some O17s that weren't there the last time you guys helped me out and I ran a clean log.

    O17 - HKLM\System\CCS\Services\Tcpip\..\{5A50BF66-1250-499E-BDF2-5F69C36C212C}: Domain = innovativeadvisoryservices.local
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5A50BF66-1250-499E-BDF2-5F69C36C212C}: NameServer = 192.168.0.10
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = innovativeadvisoryservices.local
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = innovativeadvisoryservices.local
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = innovativeadvisoryservices.local

    Not sure what all these are about - what do you guys think?

    Oh - I tried once again to update AdAware and Spybot and my network internet connection is totally unusable. I can't connect to anywhere now - even if I wait the 10 minutes it took Friday and Monday! Even-so, ran them and they came up clean.

    Thanks.
  • edited July 2006
    Is the reason for no reply because it's my work computer? I'm the only person in the office! It's just little ole me all by myself. Although, now that I think of it, when McAfee wanted to charge me $150 for help even though I had their virus protection you guys helped me fix my computer there too. My boss swears by the stinkin firewall in the router, but I keep telling him that's not enough. Once I'm able to access the internet again I will be installing one you guys recommend.

    Can you tell me what I am doing wrong here?
  • edited July 2006
    Thanks anyway.
  • TroganTrogan London, UK
    edited July 2006
    meljoemom, I'm sorry you havn't had a reply. :(

    I've reopened your thread, becuase I'd like to try and help. If you would like help, please post a new HijackThis log.

    Again, I do apologise!
  • edited July 2006
    I may take you up on that as soon as I get a router that works. I finally figured out that my router has gone bad (how lame am I that I didn't check the connections in the first place????)

    No worries on the reply. You guys are great to even man this forum in the first place. I just figured my problem belonged elsewhere.

    I'll have to get back to you in a day or two.

    Thanks so much!

    Shari
  • TroganTrogan London, UK
    edited July 2006
    I may take you up on that as soon as I get a router that works. I finally figured out that my router has gone bad (how lame am I that I didn't check the connections in the first place????)
    It happens to us all. :) Your problem was probably best asked in the Networking forum as this seemed to be a networking issue.

    Let me know if how things go. :)
  • edited July 2006
    Thanks so much! I am at work and on line with access to the network again! 3 hours on the phone was worth it.:clap:

    All fixed up with noplace to go!

    Have a great day/night
  • TroganTrogan London, UK
    edited July 2006
    I'm glad you got it sorted. Its not always malware thats the problem. ;)

    Regarding the HijackThis log: Its clean but Java needs updating, and since older versions have vulnerabilities that malware can use to infect your system, it would be a good idea to update it.

    Follow these steps to remove older version Java components.
    • Close any programmes you may have running, ESPECIALLY your web browser
    • Click Start > Control Panel.
    • Click Add/Remove Programs.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove all versions of Java.
    • Reboot your computer once all Java components are removed.
    Then download the latest version of Java Runtime Environment, and install it to your computer.

    Let me know how things go, and if I can help with anything else or if we can mark this resolved. :)
Sign In or Register to comment.