Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Problems with "Skynet"


  • This topic is locked This topic is locked
12 replies to this topic

#1 Kennysside

Kennysside

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 23 July 2009 - 08:15 PM

Hi there...

So bout a month ago, I was silly enough to download some music program which resulted in Mcafee beeping and I was like "phew", just dodged a bullet there!
But no. My computer started to run slower than usual, my MSN Messenger kept logging me out instantly whenever I logged in, and it was all a mess.

Anyhows, I've tried doing regular scans with Spybot S&D, tried to scan with Mcafee (which was prevented from the skynet thingie I guess), and it did find alot of bad stuff.
The bad stuff kept coming back on every scan, so that kinda sucked!

I googled around a bit and found the thread " http://www.bleepingcomputer.com/forums/lof...hp/t236527.html ", which looked like just about the same as the problem I had!

I did what it said in the thread, but I still got the damn MSN Messenger logging out problem, so I guess it's still there...

Got a log ready from doing what the other thread said :thumbsup:

Would really appreciate some help!

Thanks!

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:11 PM

Posted 23 July 2009 - 08:23 PM

Please run RootRepeal - Rootkit Detector

Please download: RootRepeal .
Direct download link is here: RootRepeal.rar.
If you need a program to open a .RAR compressed file. Download a trial version from here: WinRAR.

Extract the program file to a new folder such as C:\RootRepeal.
Run RootRepeal.exe and go to the REPORT tab and click the Scan button.
Select ALL of the checkboxes and then click OK and the scan will start.
If you have multiple drives you only need to check the C: drive or the drive which Windows is installed to.
When done, click on Save Report.
Save it to the same location where you ran it from above, such as C:\RootRepeal
Save it as your_name_rootrepeal.txt - where your_name is your forum name
This makes it more easy to track who the log belongs to.
Now open that log and select all and copy/paste it back on your next reply please.
Quit the RootRepeal program.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Kennysside

Kennysside
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 23 July 2009 - 08:40 PM

Did what you told me to do and this is what I've got.

------------------------------------------------------------

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/07/24 03:26
Program Version: Version 1.3.2.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB69A4000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA5E6000 Size: 8192 File Visible: No Signed: -
Status: -

Name: PCI_PNP6266
Image Path: \Driver\PCI_PNP6266
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB3973000 Size: 49152 File Visible: No Signed: -
Status: -

Name: SKYNETipxexmow.sys
Image Path: C:\WINDOWS\system32\drivers\SKYNETipxexmow.sys
Address: 0xB6D55000 Size: 172032 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: spqo.sys
Image Path: spqo.sys
Address: 0xB9EA6000 Size: 1052672 File Visible: No Signed: -
Status: -

Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\WINDOWS\system32\SKYNETbigrnodk.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\SKYNETqjoenqth.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\SKYNETskltpqrt.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\SKYNETsrujovmy.dll
Status: Invisible to the Windows API!

Path: c:\windows\temp\mcafee_jkfoiiphkrmk6bs
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\windows\temp\mcmsc_kz1uo5cczo25n2s
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: C:\WINDOWS\Temp\SKYNETnxwbuwtpfp.tmp
Status: Invisible to the Windows API!

Path: c:\windows\temp\sqlite_4uiaqsmvwkaucws
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\windows\temp\sqlite_dmnadohmls8dwqu
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\windows\temp\sqlite_vnba5cvwf3mkhit
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: C:\WINDOWS\system32\drivers\SKYNETipxexmow.sys
Status: Invisible to the Windows API!

Path: c:\documents and settings\kofoed\local settings\temp\etilqs_1dx0vu8pysnaxzcgbhsn
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\kofoed\local settings\temp\etilqs_fykyheme1jb6gyfbumyz
Status: Allocation size mismatch (API: 32768, Raw: 0)

Path: C:\Documents and Settings\Kofoed\Application Data\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρϯϸϹϴϴϵϾ
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Kofoed\Application Data\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρϯϸϹϴϴϵϾϻϵЉ
Status: Locked to the Windows API!

Path: c:\program files\microsoft sql server\mssql.1\mssql\log\log_97.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\program files\logitech\desktop messenger\8876480\users\kofoed\data\d0000000.fcs
Status: Allocation size mismatch (API: 512, Raw: 0)

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Messenger\kuhaim@hotmail.com\SharingMetadata\deathzyklon@hotmail.com\DFSR\Staging\CS{9C0D355C-F7B1-3AAE-B7FC-7EBD2F515AB6}\01\10-{9C0D355C-F7B1-3AAE-B7FC-7EBD2F515AB6}-v1-{CD649494-2CEE-440F-9390-E7E565D7C368}-v10-Downloaded.frx
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Messenger\kuhaim@hotmail.com\SharingMetadata\ken.nielsen77@live.dk\DFSR\Staging\CS{0AC140DF-936F-EC7D-46B5-E72FE6F0B8F7}\01\11-{0AC140DF-936F-EC7D-46B5-E72FE6F0B8F7}-v1-{CD649494-2CEE-440F-9390-E7E565D7C368}-v11-Downloaded.frx
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Messenger\kuhaim@hotmail.com\SharingMetadata\ken.nielsen77@live.dk\DFSR\Staging\CS{0AC140DF-936F-EC7D-46B5-E72FE6F0B8F7}\12\12-{CD649494-2CEE-440F-9390-E7E565D7C368}-v12-{CD649494-2CEE-440F-9390-E7E565D7C368}-v12-Downloaded.frx
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Messenger\kuhaim@hotmail.com\SharingMetadata\ken.nielsen77@live.dk\DFSR\Staging\CS{0AC140DF-936F-EC7D-46B5-E72FE6F0B8F7}\15\16-{7E56B3F4-4E0C-42FC-B263-83D809DA3961}-v15-{7E56B3F4-4E0C-42FC-B263-83D809DA3961}-v16-Downloaded.frx
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Silverlight\is\t4m1fhwk.qur\pmshauki.svi\1\s\0icir1but22nmpnsi5scfq3aem5hsyxz1410q0p4gspffyytvnaaagba\f\__LocalSettings:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Silverlight\is\t4m1fhwk.qur\pmshauki.svi\1\s\0icir1but22nmpnsi5scfq3aem5hsyxz1410q0p4gspffyytvnaaagba\f\__LocalSettings:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Silverlight\is\t4m1fhwk.qur\pmshauki.svi\1\s\0icir1but22nmpnsi5scfq3aem5hsyxz1410q0p4gspffyytvnaaagba\f\__LocalSettings:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Silverlight\is\t4m1fhwk.qur\pmshauki.svi\1\s\0icir1but22nmpnsi5scfq3aem5hsyxz1410q0p4gspffyytvnaaagba\f\__LocalSettings:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Silverlight\is\t4m1fhwk.qur\pmshauki.svi\1\s\0icir1but22nmpnsi5scfq3aem5hsyxz1410q0p4gspffyytvnaaagba\f\__LocalSettings:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!

Stealth Objects
-------------------
Object: Hidden Module [Name: SKYNETqjoenqth.dll]
Process: svchost.exe (PID: 1288) Address: 0x006e0000 Address: 57344

Object: Hidden Module [Name: SKYNETsrujovmy.dll]
Process: svchost.exe (PID: 1288) Address: 0x10000000 Address: 28672

Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_CREATE]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_CLOSE]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_POWER]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_PNP]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_CREATE]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_CLOSE]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_READ]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_CLEANUP]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_PNP]
Process: System Address: 0x8a6531f8 Address: 121

Hidden Services
-------------------
Service Name: SKYNETnkvrttop
Image PathC:\WINDOWS\system32\drivers\SKYNETipxexmow.sys

==EOF==

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:11 PM

Posted 23 July 2009 - 09:08 PM

Good, now do these and telll me how it's running.

Now the next step...

Rerun Rootrepeal. After the scan completes, go to the files tab and find these files:

C:\WINDOWS\system32\SKYNETqjoenqth.dll
C:\WINDOWS\system32\SKYNETsrujovmy.dll
C:\WINDOWS\system32\drivers\SKYNETipxexmow.sys


Then use your mouse to highlight it in the Rootrepeal window.
Next right mouse click on it and select *wipe file* option only.
Then immediately reboot the computer.


Next run MBAM (MalwareBytes):

NOTE: Before saving MBAM please rename it to zztoy.exe....now save it to your desktop.

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer),
they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your
    operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed
with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing
all the malware.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 Kennysside

Kennysside
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 23 July 2009 - 09:12 PM

Aight, I'll do that first thing tomorrow! :thumbsup:

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:11 PM

Posted 23 July 2009 - 09:32 PM

Ok, I look back then :thumbsup:
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 Kennysside

Kennysside
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 24 July 2009 - 04:36 AM

Now that's weird!
I did the scan again, just as I did the first time, but now only half of the files shows!
The SKYNET ones most certainly aren't there.

Here's the second report if it can help in any way.

---------------------------------------------------------

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/07/24 04:16
Program Version: Version 1.3.2.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB69A4000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA5E6000 Size: 8192 File Visible: No Signed: -
Status: -

Name: PCI_PNP6266
Image Path: \Driver\PCI_PNP6266
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB3BF6000 Size: 49152 File Visible: No Signed: -
Status: -

Name: SKYNETipxexmow.sys
Image Path: C:\WINDOWS\system32\drivers\SKYNETipxexmow.sys
Address: 0xB6D55000 Size: 172032 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: spqo.sys
Image Path: spqo.sys
Address: 0xB9EA6000 Size: 1052672 File Visible: No Signed: -
Status: -

Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\Documents and Settings\Kofoed\Application Data\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρϯϸϹϴϴϵϾ
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Kofoed\Application Data\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρϯϸϹϴϴϵϾϻϵЉ
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Messenger\kuhaim@hotmail.com\SharingMetadata\deathzyklon@hotmail.com\DFSR\Staging\CS{9C0D355C-F7B1-3AAE-B7FC-7EBD2F515AB6}\01\10-{9C0D355C-F7B1-3AAE-B7FC-7EBD2F515AB6}-v1-{CD649494-2CEE-440F-9390-E7E565D7C368}-v10-Downloaded.frx
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Messenger\kuhaim@hotmail.com\SharingMetadata\ken.nielsen77@live.dk\DFSR\Staging\CS{0AC140DF-936F-EC7D-46B5-E72FE6F0B8F7}\01\11-{0AC140DF-936F-EC7D-46B5-E72FE6F0B8F7}-v1-{CD649494-2CEE-440F-9390-E7E565D7C368}-v11-Downloaded.frx
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Messenger\kuhaim@hotmail.com\SharingMetadata\ken.nielsen77@live.dk\DFSR\Staging\CS{0AC140DF-936F-EC7D-46B5-E72FE6F0B8F7}\12\12-{CD649494-2CEE-440F-9390-E7E565D7C368}-v12-{CD649494-2CEE-440F-9390-E7E565D7C368}-v12-Downloaded.frx
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Messenger\kuhaim@hotmail.com\SharingMetadata\ken.nielsen77@live.dk\DFSR\Staging\CS{0AC140DF-936F-EC7D-46B5-E72FE6F0B8F7}\15\16-{7E56B3F4-4E0C-42FC-B263-83D809DA3961}-v15-{7E56B3F4-4E0C-42FC-B263-83D809DA3961}-v16-Downloaded.frx
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Silverlight\is\t4m1fhwk.qur\pmshauki.svi\1\s\0icir1but22nmpnsi5scfq3aem5hsyxz1410q0p4gspffyytvnaaagba\f\__LocalSettings:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Silverlight\is\t4m1fhwk.qur\pmshauki.svi\1\s\0icir1but22nmpnsi5scfq3aem5hsyxz1410q0p4gspffyytvnaaagba\f\__LocalSettings:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Silverlight\is\t4m1fhwk.qur\pmshauki.svi\1\s\0icir1but22nmpnsi5scfq3aem5hsyxz1410q0p4gspffyytvnaaagba\f\__LocalSettings:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Silverlight\is\t4m1fhwk.qur\pmshauki.svi\1\s\0icir1but22nmpnsi5scfq3aem5hsyxz1410q0p4gspffyytvnaaagba\f\__LocalSettings:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Kofoed\Local Settings\Application Data\Microsoft\Silverlight\is\t4m1fhwk.qur\pmshauki.svi\1\s\0icir1but22nmpnsi5scfq3aem5hsyxz1410q0p4gspffyytvnaaagba\f\__LocalSettings:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!

Stealth Objects
-------------------
Object: Hidden Module [Name: SKYNETqjoenqth.dll]
Process: svchost.exe (PID: 1288) Address: 0x006e0000 Address: 57344

Object: Hidden Module [Name: SKYNETsrujovmy.dll]
Process: svchost.exe (PID: 1288) Address: 0x10000000 Address: 28672

Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8afde1f8 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x8aee0500 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_CREATE]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_CLOSE]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_POWER]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: agse8xz3ࠅఊ祓ᜀ恸, IRP_MJ_PNP]
Process: System Address: 0x8ae2c1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x8b03d1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x8af7a1f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8afe01f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x8a6cf1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x8ae6e1f8 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x8a7214c0 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_CREATE]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_CLOSE]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_READ]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_CLEANUP]
Process: System Address: 0x8a6531f8 Address: 121

Object: Hidden Code [Driver: WINDOWS, IRP_MJ_PNP]
Process: System Address: 0x8a6531f8 Address: 121

Hidden Services
-------------------
Service Name: SKYNETnkvrttop
Image PathC:\WINDOWS\system32\drivers\SKYNETipxexmow.sys

==EOF==

#8 Kennysside

Kennysside
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 24 July 2009 - 11:50 AM

Update -

Scanned 4 more times JUST to make sure, and the SKYNET ones are still not showing :thumbsup:

#9 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:11 PM

Posted 24 July 2009 - 02:08 PM

Good, let's do an Online scan to double check.
Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#10 Kennysside

Kennysside
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 24 July 2009 - 10:06 PM

Alright...

I did what you told me to and this is what it shows.

Scan statistics
Files scanned 204141
Threat names 3
Infected objects 74
Suspicious objects 0
Duration of the scan 04:03:51

I tried to click the " Scan Report " button, but the "inner screen" freezes, it's just blank and I can't click "save report as..." :s
At first I could click the button, but after the first click it turned grey and unclickable...

Any suggestions?
Leaving the window open in case there's some trick to it

#11 Kennysside

Kennysside
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:04:11 AM

Posted 25 July 2009 - 09:23 AM

Alright...

I ran the Kaspersky Online Scan one more time, just to make sure.
Same thing came up. :l

#12 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,421 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:11 PM

Posted 25 July 2009 - 09:41 AM

Looks like you will need to run HJT/DDS.
Please follow this guide. go and do steps 6 and 7 ,, Preparation Guide For Use Before Using Hijackthis. Then go here HijackThis Logs and Virus/Trojan/Spyware/Malware Removal ,click New Topic,give it a relevant Title and post that complete log.

Let me know if it went OK.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#13 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,993 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:10:11 PM

Posted 26 July 2009 - 11:08 PM

Hello,

Now that you have posted a log here: http://www.bleepingcomputer.com/forums/t/244333/problems-with-skynet/ you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a HJT Team member, nor should you ask for help elsewhere. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the HJT Team should be the only members that you take advice from, until they have verified your log as clean.

To avoid confusion, I am closing this topic. Good luck with your log.

Orange Blossom :thumbsup:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users