Hi, I had to scan in safe mode.. i originally saw 4 skynet stealth programs running before the rootrepeal program crashed. here are the contents .. let me know how we can remove these bastards!
THanks again, DAVID
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Time: 2009/07/01 10:00
Program Version: Version 1.3.0.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: aj7imbih.SYS
Image Path: C:\WINDOWS\System32\Drivers\aj7imbih.SYS
Address: 0xB84A6000 Size: 421888 File Visible: No Signed: -
Status: -
Name: dump_nvata.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_nvata.sys
Address: 0xB82BB000 Size: 102400 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79BB000 Size: 8192 File Visible: No Signed: -
Status: -
Name: giveio.sys
Image Path: giveio.sys
Address: 0xF7A50000 Size: 1664 File Visible: No Signed: -
Status: -
Name: PCI_NTPNP6990
Image Path: \Driver\PCI_NTPNP6990
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB78F1000 Size: 49152 File Visible: No Signed: -
Status: -
Name: SKYNETuugwyllo.sys
Image Path: C:\WINDOWS\system32\drivers\SKYNETuugwyllo.sys
Address: 0xB82FC000 Size: 163840 File Visible: - Signed: -
Status: Hidden from Windows API!
Name: speedfan.sys
Image Path: speedfan.sys
Address: 0xF798B000 Size: 5248 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\WINDOWS\system32\SKYNETdoclkdjl.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\SKYNEThmtpiyoj.dat
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\SKYNETlmcmqcnd.dat
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\SKYNETnipptaod.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\drivers\SKYNETuugwyllo.sys
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\David\Application Data\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρϴϱЄϱЃϵϳЅ
Status: Locked to the Windows API!
Path: C:\Documents and Settings\David\Application Data\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρЂϻϵЉЃϵϳЅ
Status: Locked to the Windows API!
Path: C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BTRLYO3N\Skynet-monder-gen-google-redirect-t243203[1].htm
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BTRLYO3N\Skynet-monder-gen-google-redirect-t243203[1].html&pid=1566945&st=15
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\VKBMN6ZY\Skynet-monder-gen-google-redirect-t243203[1].htm
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\VKBMN6ZY\Skynet-monder-gen-google-redirect-t243203[1].html&pid=1566945&st=15
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\David\Favorites\Links\Lexus es300\Links\Links\NotronAntiVirus\Links\Banking and Financing\Banking and Financing\Briana Banks, Briana Banks Pics, Briana Banks Images, Briana Banks Pictures, Briana Banks Movies, Briana Banks Videos.url:favicon
Status: Locked to the Windows API!
Path: C:\Documents and Settings\David\Favorites\Links\Lexus es300\Links\Links\NotronAntiVirus\Links\Banking and Financing\Banking and Financing\77735BerryBabes @ All Internet Hot Sexy Babes Raven Riley, Jordan Capri, Brandi Belle, Kate's Playground and other..url:favicon
Status: Locked to the Windows API!
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8b80a1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_CREATE]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_CLOSE]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_READ]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_WRITE]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_QUERY_EA]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_SET_EA]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_CLEANUP]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_POWER]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: nvata, IRP_MJ_PNP]
Process: System Address: 0x8b80b1e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x8b7441e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x8b7441e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x8b7441e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x8b7441e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8b7441e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b7441e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b7441e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8b7441e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x8b7441e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b7441e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x8b7441e8 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CREATE]
Process: System Address: 0x8b5c0680 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CLOSE]
Process: System Address: 0x8b5c0680 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_READ]
Process: System Address: 0x8b5c0680 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_WRITE]
Process: System Address: 0x8b5c0680 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b5c0680 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b5c0680 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_POWER]
Process: System Address: 0x8b5c0680 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b5c0680 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_PNP]
Process: System Address: 0x8b5c0680 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_CREATE]
Process: System Address: 0x8b78f790 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_CLOSE]
Process: System Address: 0x8b78f790 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b78f790 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b78f790 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_POWER]
Process: System Address: 0x8b78f790 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b78f790 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_PNP]
Process: System Address: 0x8b78f790 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8b80c1e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8b80c1e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8b80c1e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8b80c1e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b80c1e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b80c1e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8b80c1e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8b80c1e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8b80c1e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b80c1e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8b80c1e8 Size: 121
Object: Hidden Code [Driver: aj7imbihЅ剒敬Ёఅ䵃䥖橘-쫁蘙憙, IRP_MJ_CREATE]
Process: System Address: 0x8b68a1e8 Size: 121
Object: Hidden Code [Driver: aj7imbihЅ剒敬Ёఅ䵃䥖橘-쫁蘙憙, IRP_MJ_CLOSE]
Process: System Address: 0x8b68a1e8 Size: 121
Object: Hidden Code [Driver: aj7imbihЅ剒敬Ёఅ䵃䥖橘-쫁蘙憙, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b68a1e8 Size: 121
Object: Hidden Code [Driver: aj7imbihЅ剒敬Ёఅ䵃䥖橘-쫁蘙憙, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b68a1e8 Size: 121
Object: Hidden Code [Driver: aj7imbihЅ剒敬Ёఅ䵃䥖橘-쫁蘙憙, IRP_MJ_POWER]
Process: System Address: 0x8b68a1e8 Size: 121
Object: Hidden Code [Driver: aj7imbihЅ剒敬Ёఅ䵃䥖橘-쫁蘙憙, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b68a1e8 Size: 121
Object: Hidden Code [Driver: aj7imbihЅ剒敬Ёఅ䵃䥖橘-쫁蘙憙, IRP_MJ_PNP]
Process: System Address: 0x8b68a1e8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x8b745790 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x8b745790 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b745790 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b745790 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x8b745790 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b745790 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x8b745790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_CREATE]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_CLOSE]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_READ]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_CLEANUP]
Process: System Address: 0x8b58b790 Size: 121
Object: Hidden Code [Driver: CdfsЅఉ敓, IRP_MJ_PNP]
Process: System Address: 0x8b58b790 Size: 121
==EOF==