Browser won't go to bleepingcomputer or any other helpful site, won't update malwarebytes or adaware. Clicked McAfee Agent Updater, and halfway through it kept trying to delete "O6KO.dll" from system32 - it would try, then fail, then retry, then fail repeatedly.
I just restarted again and ran the requested files.
**Edit: Malwarebytes finally updated and ran from a flash drive, found "Koobface" and says it's deleted on restart. Added picture.
DDS.txt:
DDS (Ver_09-12-01.01) - NTFSx86
Run by cb2813 at 14:04:44.29 on Fri 03/05/2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2000.1417 [GMT -6:00]
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
FW: McAfee Host Intrusion Prevention Firewall *enabled* {2F1275E3-2F4F-43E9-944B-3F63F9BDA5F5}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
svchost.exe
C:\Program Files\Apache Group\Tomcat 4.1\bin\tomcat.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\userinit.exe
C:\Program Files\DRU\bin\DRUService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe
C:\Program Files\Java\jre1.6.0_16\bin\jqs.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
C:\WINDOWS\system32\Prot_srv.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\WINDOWS\system32\pstartSr.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe
C:\WINDOWS\system32\rcmdsvc.exe
c:\Program files\Radmin\r_server.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\CommandCenter\SmartIPMon32.exe
C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\snmpdm.exe
C:\Program Files\compapps\swstore\ssservice.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_base.exe
C:\Program Files\Gcasmon\GcasMon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\BackWeb\3836105\Program\SERVIC~1.EXE
C:\Documents and Settings\cb2813\Desktop\dds.scr
C:\WINDOWS\system32\userinit.exe
C:\Program Files\BackWeb\3836105\Program\BwGcasPortal.exe
C:\Program Files\Pointsec\Pointsec for PC\CreRec.EXE
C:\Program Files\IBM\Tivoli\Remote Control\Target\trc_gui.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://insider.web.att.com/
uSearch Bar = hxxp://search.yahoo.com
uWindow Title = Microsoft Internet Explorer provided by AT&T
mDefault_Page_URL = hxxp://myintranet.att.com
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IEEventHandler Class: {5892bfb1-4e3e-11d6-b615-0010a48fd138} - c:\program files\sbc\gcas\GCAS_I~1.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_16\bin\ssv.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre1.6.0_16\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre1.6.0_16\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfee Host Intrusion Prevention Tray] "c:\program files\mcafee\host intrusion prevention\FireTray.exe"
mRun: [WMPlayer] c:\windows\system32\wscript.exe c:\windows\Run.vbs
mRun: [SBCAssess] "c:\program files\compapps\sbcassess\SBCAssess.exe" 5
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey
mRun: [Pointsec Tray] c:\program files\pointsec\pointsec for pc\P95Tray.exe
mRun: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{14fcfe7c-ab86-428a-9d2e-bfb6f5a7aa6e}\Icon3E5562ED7.ico
uPolicies-explorer: Btn_Media = 2 (0x2)
uPolicies-explorer: SpecifyDefaultButtons = 1 (0x1)
uPolicies-explorer: NoActiveDesktop = 1 (0x1)
uPolicies-explorer: NoWindowsUpdate = 1 (0x1)
uPolicies-explorer: ForceStartMenuLogOff = 1 (0x1)
uPolicies-explorer: MemCheckBoxInRunDlg = 1 (0x1)
uPolicies-explorer: ForceRunOnStartMenu = 1 (0x1)
uPolicies-explorer: ClearRecentProgForNewUserInStartMenu = 1 (0x1)
uPolicies-explorer: NoStartMenuMyGames = 1 (0x1)
uPolicies-explorer: RestrictWelcomeCenter = 1 (0x1)
mPolicies-explorer: UseDefaultTile = 0 (0x0)
mPolicies-explorer: NoMSAppLogo5ChannelNotify = 1 (0x1)
mPolicies-system: LogonType = 0 (0x0)
mPolicies-system: consentpromptbehavioruser = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 1 (0x1)
dPolicies-explorer: NoActiveDesktop = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_16\bin\jp2iexp.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFECAFE-0013-0001-0009-ABCDEFABCDEF}
DPF: {CAFECAFE-0013-0001-0018-ABCDEFABCDEF}
DPF: {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_15-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_17-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_18-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: AdobeReaderConfig - c:\program files\adobe\reader 9.0\ConfigRdr.exe
Hosts: 155.179.121.9 thtst05.dadc.sbc.com thtst05
Hosts: 155.179.121.7 thtst04.dadc.sbc.com thtst04
Hosts: 132.201.38.15 chp003b.sldc.sbc.com chp003b
Hosts: 132.201.38.7 chp002b.sldc.sbc.com chp002b
Hosts: 150.235.44.92 shp007a.sddc.sbc.com shp007a
Note: multiple HOSTS entries found. Please refer to Attach.txt
============= SERVICES / DRIVERS ===============
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2009-1-8 3840]
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-8 343760]
R0 prot_2k;prot_2k;c:\windows\system32\drivers\prot_2k.sys [2009-1-15 217024]
R0 vmscsi;vmscsi;c:\windows\system32\drivers\vmscsi.sys [2009-1-8 10880]
R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2008-7-16 31816]
R1 snmpdm_;snmpdm_;c:\windows\system32\snmpdm_.sys [2007-12-13 25472]
R2 Apache Tomcat 4.1;Apache Tomcat 4.1;c:\program files\apache group\tomcat 4.1\bin\tomcat.exe [2003-7-31 65536]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostControlService.exe [2008-11-11 808296]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostStorageService.exe [2008-11-11 20840]
R2 DRUAgent;DRUAgent;c:\program files\dru\bin\DRUService.exe [2009-1-8 139264]
R2 enterceptAgent;McAfee Host Intrusion Prevention Service;c:\program files\mcafee\host intrusion prevention\FireSvc.exe [2009-10-20 1489984]
R2 GcasMon;GCAS Control Monitor;c:\program files\gcasmon\GcasMon.exe [2006-8-21 122880]
R2 hips;McAfee HIPSCore Service;c:\program files\mcafee\host intrusion prevention\hipscore\HIPSvc.exe [2010-3-5 35696]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2009-9-25 120128]
R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\mcshield.exe [2008-7-16 144704]
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\vstskmgr.exe [2008-7-16 54608]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2010-3-5 70728]
R2 Pointsec;Pointsec;c:\windows\system32\Prot_srv.exe [2009-1-15 621120]
R2 Pointsec_start;Pointsec Service Start;c:\windows\system32\pstartSr.exe [2009-1-15 150080]
R2 r_server;Remote Administrator Service;c:\program files\radmin\r_server.exe [2010-3-5 241664]
R2 Remote Command Server;Remote Command Server;c:\windows\system32\rcmdsvc.exe [2004-9-24 41472]
R2 Smart IP Monitor;Smart IP Monitor;c:\commandcenter\SmartIPMon32.exe [2009-11-17 172032]
R2 snmpdm;snmpdm;c:\windows\system32\snmpdm.exe -l 8161 --> c:\windows\system32\snmpdm.exe -l 8161 [?]
R2 ssserviceWinService;AT&T Software Store;c:\program files\compapps\swstore\ssservice.exe [2008-7-24 81408]
R2 TRCTARGET;IBM Tivoli Remote Control - Target;c:\program files\ibm\tivoli\remote control\target\trc_base.exe [2008-4-29 356864]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2009-11-17 112128]
R3 CCIDFILTER;Broadcom Smart Card Reader Filter Driver;c:\windows\system32\drivers\ccidflt.sys [2009-11-17 12840]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [2009-11-17 32808]
R3 d553bus;Dell Wireless 5530 HSPA Mobile Broadband Minicard Device driver (WDM);c:\windows\system32\drivers\d553bus.sys [2009-11-17 300672]
R3 d553card;Dell Wireless 5530 HSPA Mobile Broadband Minicard i7;c:\windows\system32\drivers\d553card.sys [2009-11-17 378368]
R3 d553gps;Dell Wireless 5530 HSPA Mobile Broadband Minicard GPS Port;c:\windows\system32\drivers\d553gps.sys [2009-11-17 76328]
R3 d553mdfl;Dell Wireless 5530 HSPA Mobile Broadband Minicard Modem Filter;c:\windows\system32\drivers\d553mdfl.sys [2009-11-17 14976]
R3 d553mdfl2;Dell Wireless 5530 HSPA Mobile Broadband Minicard Modem 2 Filter;c:\windows\system32\drivers\d553mdfl2.sys [2009-11-17 14976]
R3 d553mdm;Dell Wireless 5530 HSPA Mobile Broadband Minicard Modem Driver;c:\windows\system32\drivers\d553mdm.sys [2009-11-17 387200]
R3 d553mdm2;Dell Wireless 5530 HSPA Mobile Broadband Minicard Modem 2 Driver;c:\windows\system32\drivers\d553mdm2.sys [2009-11-17 431616]
R3 d553nd5;Dell Wireless 5530 HSPA Mobile Broadband Minicard NetworkAdapter (NDIS);c:\windows\system32\drivers\d553nd5.sys [2009-11-17 25984]
R3 d553unic;Dell Wireless 5530 HSPA Mobile Broadband Minicard NetworkAdapter (WDM);c:\windows\system32\drivers\d553unic.sys [2009-11-17 402944]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [2009-11-17 244368]
R3 FirehkMP;FirehkMP;c:\windows\system32\drivers\firehk.sys [2007-9-20 44680]
R3 HIPK;McAfee Inc. HIPK;c:\windows\system32\drivers\HIPK.sys [2009-1-8 107960]
R3 HIPPSK;McAfee Inc. HIPPSK;c:\windows\system32\drivers\HIPPSK.sys [2009-1-8 38680]
R3 HIPQK;McAfee Inc. HIPQK;c:\windows\system32\drivers\HIPQK.sys [2009-1-8 35584]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2009-11-17 110080]
R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2009-1-8 72936]
R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2009-1-8 33960]
R3 Sony_EricssonWWSC;Dell Wireless 5530 HSPA Mobile Broadband Minicard PC SC Port;c:\windows\system32\drivers\d553scard.sys [2009-11-17 25640]
S?3 BackWeb Plug-in - 3836105;GCAS-SWBT BackWeb Portal;c:\progra~1\backweb\3836105\program\SERVIC~1.EXE [2009-11-17 32807]
S1 o6ko;Cache Helper Protocol Client Driver;\??\c:\windows\system32\drivers\o6ko.sys --> c:\windows\system32\drivers\o6ko.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-5 135664]
S2 srvoko6;Midi System Error Driver IPv6 Internet Provider Image;c:\windows\system32\svchost.exe -k netsvc6 [2009-1-8 14336]
S3 Firehk;McAfee NDIS Intermediate Filter;c:\windows\system32\drivers\firehk.sys [2007-9-20 44680]
S3 NvtSp50;NvtSp50 NDIS Protocol Driver;c:\windows\system32\drivers\nvtsp50.sys --> c:\windows\system32\drivers\NvtSp50.sys [?]
S3 USBSER34;USBSER34;c:\windows\system32\drivers\USBSER34.SYS [2009-12-7 37456]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
=============== Created Last 30 ================
2010-03-05 20:01:42 40777 ----a-w- c:\windows\system32\api_hook_list.dat
2010-03-05 20:01:32 39816 ----a-w- c:\windows\system32\HIPIS0e011af.dll
2010-03-05 19:10:26 70728 ----a-w- c:\windows\system32\mfevtps.exe
2010-03-05 16:03:44 90112 ----a-w- c:\windows\system32\admdll.dll
2010-03-05 16:03:40 0 d-----w- c:\program files\Radmin
2010-03-05 14:09:02 0 d-----w- c:\program files\AntiRemover13
2010-03-03 13:44:25 0 d-----w- c:\docume~1\cb2813\applic~1\Malwarebytes
2010-03-03 13:44:18 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-03 13:44:17 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-03 13:23:17 1 ----a-w- c:\windows\ligh
2010-03-01 14:25:36 0 d-----w- c:\docume~1\cb2813\applic~1\att connect
2010-02-23 17:34:02 0 d-----w- C:\Bluebook
2010-02-23 17:07:09 0 d-----w- c:\documents and settings\cb2813\.NETSMART_500
2010-02-18 16:58:31 0 d-----w- c:\documents and settings\cb2813\InterWise
2010-02-18 15:27:10 0 d-----w- c:\docume~1\cb2813\applic~1\McAfee
2010-02-12 18:37:30 0 d-----w- c:\program files\DivX
2010-02-12 18:37:30 0 d-----w- c:\program files\common files\DivX Shared
2010-02-04 20:20:52 0 d-----w- C:\QUARANTINE
==================== Find3M ====================
2010-02-05 05:49:30 136512 ----a-w- c:\windows\system32\KevlarSigs.dll
2010-01-08 18:25:04 29092413 ----a-w- C:\SCCM_INSTALL_cS_v4R1b.EXE
============= FINISH: 14:05:14.04 ===============
Attached File(s)
-
kf13.jpg (277.24K)
Number of downloads: 6
This post has been edited by seedlings: 05 March 2010 - 04:17 PM

Help
This topic is locked

Back to top











