Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

PLEASED HELP! SKYNET Rootkit Infection!


  • This topic is locked This topic is locked
4 replies to this topic

#1 niteprlr

niteprlr

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Location:Tampa, Fl
  • Local time:08:47 PM

Posted 02 July 2009 - 05:37 PM

I believe that I picked up the SKYNET rootkit somehow.
I have tried to remove it with MBAM, SAS and HJT to no avail.
Please help me, as formatting and re-installing is not a viable option.

I am running XP Pro SP3 and use Firefox 3.5
Bitdefender is my AV and I use a NAT router, and have an anti-malware HOSTS file in use.
Let me know what other pertinent info that you may need.


When in Firefox, all of my search results are hijacked, AND after a while, my desktop wallpaper will change to a blue background with red lettering stating that my system is infected and then a security scanner opens and starts to scan my system (which I didn't install of course).
When in safe mode I do not have any of those symptoms.
MBAM does pick up the infection, but it re-spawns after reboot.
SAS doesn't even see it.
I even tried SMITFRAUDFIX which did not work.
The attached files were created while in safe mode, because my system just hangs forever in normal mode. I am actually able to boot into windows, but cpu usage stays at 100% and I cannot seem to get any programs opened.

GMER found the following files:

\windows\system32\drivers\SKYNETlclqmuuj.sys
\windows\system32\SKYNETwbdmeixe.dll
\windows\system32\SKYNETpyyusirt.dat
\windows\system32\SKYNETnadvdnow.dat

Thanks in advance!

Attached Files



BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:07:47 PM

Posted 03 July 2009 - 03:13 AM

Hello niteprlr,

Posted Image

No need to reformat with this rootkit. :thumbup2: Please do delete SmitfraudFix, as it isn't relevant here.

I need for you to go offline completely and disable ALL your protective programs after you download ComboFix, but before you run it. Sometimes those programs interfere with it, and we don't want that! :)

This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please, along with a new HijackThis log.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

If ComboFix will not run the first time, then rename ComboFix.exe to nite.exe and try it again. :)

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 niteprlr

niteprlr
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Location:Tampa, Fl
  • Local time:08:47 PM

Posted 03 July 2009 - 09:52 PM

Thank you for the quick reply.
Here is the combofix log.
I anxiously wait for your next reply!
TIA

Attached Files



#4 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:07:47 PM

Posted 04 July 2009 - 01:58 AM

Hello,

I see you ran ComboFix more than once. :thumbup2: If SKYNET was there before, it isn't now. Are you still being redirected?

tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#5 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:07:47 PM

Posted 09 July 2009 - 07:13 AM

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users