Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

SKYNET and Rootkit.Agent.ODG trojan? Removal needed


  • Please log in to reply
7 replies to this topic

#1 Limeade

Limeade

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:06:57 PM

Posted 15 August 2009 - 02:34 AM

Hello. :thumbsup: A few days ago my Firefox browser started acting up, redirecting me to webpages and not letting me download. So I switched to Google Chrome and am able to download items. I noticed, then, that every time I restarted my laptop that my NOD32 version 4.0 would pop up with a Win32/Rootkit.Agent.ODG trojan message and 'unable to clean.' So I did some investigating online and found threads about these problems and running RootRepeal. I ran it and up popped mentions of having SKYNET hidden objects.

My scans with Malwarebytes, Adaware Anniversary Edition, never turned up mentions of these, so I had no clue until I started digging around. I'm concerned, too, since I read that SKYNET sometimes is used to pick up credit card numbers/passwords. I run Vista on this laptop.

I'd appreciate any help with this. It has been hours of frustration and searches, and I'm usually so meticulous and proactive about keeping my laptop clean... I guess I'm not doing as good a job. Thank you in advance. :flowers:

Edited by Limeade, 15 August 2009 - 02:47 AM.


BC AdBot (Login to Remove)

 


#2 Blade

Blade

    Strong in the Bleepforce


  • Site Admin
  • 12,704 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:US
  • Local time:09:57 PM

Posted 15 August 2009 - 03:05 AM

Hello Limeade (I love that stuff! :trumpet: ) and :thumbsup: to BleepingComputer!

Let us see if we can kill this bugger. :flowers: Before we do that though:

I'm concerned, too, since I read that SKYNET sometimes is used to pick up credit card numbers/passwords.

This is unfortunately correct.

One or more of the identified infections has backdoor functionality.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

***************************************************

Please generate a RootRepeal log for me by following the below instructions exactly.

Note: Vista users ,, right click on desktop icon and select "Run as Administrator."

Disconnect from the Internet or physically unplug your Internet cable connection.
Close all open programs, scheduling/updating tasks and background processes that might activate during the scan including the screensaver.
Temporarily disable your anti-virus and real-time anti-spyware protection.
After starting the scan, do not use the computer until the scan has completed.
When finished, re-enable your anti-virus/anti-malware (or reboot) and then you can reconnect to the Internet.
  • Open Posted Image on your desktop.
  • At the top of the window, click Settings, then Options.
  • Click the Ssdt & Shadow Ssdt Tab.
  • Make sure the box next to "Only display hooked functions." is checked.
  • Click the "X" in the top right corner of the Settings window to close it.
  • Click the Posted Image tab.
  • Click the Posted Image button.
  • Check all seven boxes: Posted Image
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the Posted Image button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
~Blade


In your next reply, please include the following:
RootRepeal Log

Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+


#3 Limeade

Limeade
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:06:57 PM

Posted 15 August 2009 - 03:23 AM

Oh good, a limeade lover. :D Nice to meet you.

Ouch. :\ Thanks for the info link on the identity theft info. I'll be sure to get on top of that, just in case.

Here's my report.

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/14 23:48
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================

Drivers
-------------------
Name: dump_iaStor.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
Address: 0x87F0C000 Size: 753664 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9C9EA000 Size: 49152 File Visible: No Signed: -
Status: -

Name: SKYNETytxdewqn.sys
Image Path: C:\Windows\system32\drivers\SKYNETytxdewqn.sys
Address: 0x8C78B000 Size: 151552 File Visible: - Signed: -
Status: Hidden from the Windows API!

Hidden/Locked Files
-------------------
Path: C:\Documents and Settings
Status: Locked to the Windows API!

Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: C:\ProgramData\Application Data
Status: Locked to the Windows API!

Path: C:\ProgramData\Desktop
Status: Locked to the Windows API!

Path: C:\ProgramData\Documents
Status: Locked to the Windows API!

Path: C:\ProgramData\Favorites
Status: Locked to the Windows API!

Path: C:\ProgramData\Start Menu
Status: Locked to the Windows API!

Path: C:\ProgramData\Templates
Status: Locked to the Windows API!

Path: C:\Users\All Users
Status: Locked to the Windows API!

Path: C:\Users\Default User
Status: Locked to the Windows API!

Path: C:\Users\Default\Application Data
Status: Locked to the Windows API!

Path: C:\Users\Default\Cookies
Status: Locked to the Windows API!

Path: C:\Users\Default\Local Settings
Status: Locked to the Windows API!

Path: C:\Users\Default\My Documents
Status: Locked to the Windows API!

Path: C:\Users\Default\NetHood
Status: Locked to the Windows API!

Path: C:\Users\Default\PrintHood
Status: Locked to the Windows API!

Path: C:\Users\Default\Recent
Status: Locked to the Windows API!

Path: C:\Users\Default\SendTo
Status: Locked to the Windows API!

Path: C:\Users\Default\Start Menu
Status: Locked to the Windows API!

Path: C:\Users\Default\Templates
Status: Locked to the Windows API!

Path: C:\Windows\System32\SKYNETerrvifxp.dll
Status: Invisible to the Windows API!

Path: C:\Windows\System32\SKYNETeuncysmq.dll
Status: Invisible to the Windows API!

Path: C:\Windows\System32\SKYNETkdpbeoni.dat
Status: Invisible to the Windows API!

Path: C:\Windows\System32\SKYNETkxfmipig.dll
Status: Invisible to the Windows API!

Path: C:\Windows\System32\SKYNETmbnkvpdb.dat
Status: Invisible to the Windows API!

Path: C:\Windows\System32\SKYNETvotchpru.dll
Status: Invisible to the Windows API!

Path: C:\Windows\System32\SKYNETwktsvlbp.dat
Status: Invisible to the Windows API!

Path: C:\Windows\System32\SKYNETxsvqqtbk.dat
Status: Invisible to the Windows API!

Path: C:\Windows\Temp\SKYNETegfpssoswc.tmp
Status: Invisible to the Windows API!

Path: C:\Users\Default\Documents\My Music
Status: Locked to the Windows API!

Path: C:\Users\Default\Documents\My Pictures
Status: Locked to the Windows API!

Path: C:\Users\Default\Documents\My Videos
Status: Locked to the Windows API!

Path: C:\Users\Public\Documents\My Music
Status: Locked to the Windows API!

Path: C:\Users\Public\Documents\My Pictures
Status: Locked to the Windows API!

Path: C:\Users\Public\Documents\My Videos
Status: Locked to the Windows API!

Path: c:\windows\microsoft.net\framework\netfxsbs12.hkf
Status: Allocation size mismatch (API: 36864, Raw: 45056)

Path: C:\Windows\System32\drivers\SKYNETytxdewqn.sys
Status: Invisible to the Windows API!

Path: C:\Windows\System32\wbem\PRINTF~1.MOF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_b7e00e6c7b30b69b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_8550c6b5d18a9128.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df56e60dc5df.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_7b33aa7d218504d2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_365945b9da656e4d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a620671dde41.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_5c94f2bbe7d4aaf6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_b7e10f227b2fceff.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9818.0_none_b7e811947b297f6d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_abac38a907ee8801.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9848.0_none_a6e6a8980e994a5d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c0566bec5b24.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.1.microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_8b7b15c031cda6db.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9848.0_none_b7e811287b298060.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c35eb.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_818f59bf601aa775.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8dd7dea5d5a7a18a.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053e8c6967ba9d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9849.0_none_b7e911727b2899b7.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_4ddfc6cd11929a02.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_7dd1e0ebd6590e0b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_81c25f21d3d46d84.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_a6dea5dc0ea08098.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9841.0_none_a6dfa6920e9f98fc.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.1.0.0_none_6c030d6fdc86522c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_61305e07e4f1bc01.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d60651e.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9849.0_none_a6e7a8e20e9863b4.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\935df4549e21123a2efb986a707f54475380a037519679510e4b4dfc4bdb5767.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\b080e112e69d2e9c8e71acd39a81f0d469d837625ceb8ed73b5b87da1fd1424c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\70f19edeeb8e3329aad18f744094ea0319d2ecc78dd6a12559a1e765c42418f7.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\bd83dce340498e7c363093c2fc74dfb58e1ec17770453905172c7471fadd9333.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\71503c1b988fb27a41668f3ba35468d268daf07e8e79cf7b82a1ef64a8d213a1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\989e628160e12c984a435d2bb2a335ad043e006646150c7b1f3bb52dccd842cc.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\d5ecf2ab9387e082648bbcccd6eceb9d67b096939150833d0ae3066b3a1a676e.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\ef483ae0673e2975dd4224fe26749623c1c702b8b3fded10161417459e1771a7.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\8b414e757cb8b153bff77dd00a36556aea3adab25ce15f3e8b184ffbf41ba7a2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\3582cf91bea0e0e7b5f4b8a168a2e4bf248a01f764aa3c5d7c4f352ebc681e9d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\msil_jsc_b03f5f7f11d50a3a_6.0.6000.16720_none_a7f9fcdcd724c803\JSCEXE~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\msil_jsc_b03f5f7f11d50a3a_6.0.6000.20883_none_91321380f0c70cf6\JSCEXE~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\msil_jsc_b03f5f7f11d50a3a_6.0.6001.18000_none_a7d3f834d777a15b\JSCEXE~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\msil_jsc_b03f5f7f11d50a3a_6.0.6001.18111_none_a7d4e192d776d4a4\JSCEXE~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\msil_jsc_b03f5f7f11d50a3a_6.0.6001.22230_none_9109522ef11c4db7\JSCEXE~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_cs-cz_d9f4bc64420b8d63\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_da-dk_772e9c8b38518962\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_de-de_745a31c73a27ddfc\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_cs-cz_7388dcab642949ec\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_da-dk_10c2bcd25a6f45eb\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_de-de_0dee520e5c459a85\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_cs-cz_598a353c315310f3\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_da-dk_f6c4156327990cf2\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_de-de_f3efaa9f296f618c\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-machine_config_ocm_b03f5f7f11d50a3a_6.0.6000.16720_none_f570e12815568682\MACHIN~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-machine_config_ocm_b03f5f7f11d50a3a_6.0.6000.20883_none_dea8f7cc2ef8cb75\MACHIN~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-machine_config_ocm_b03f5f7f11d50a3a_6.0.6001.18111_none_f54bc5de15a89323\MACHIN~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-machine_config_ocm_b03f5f7f11d50a3a_6.0.6001.22230_none_de80367a2f4e0c36\MACHIN~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6000.16720_none_7b4eba45cecd6936\IEEXEC~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6000.20883_none_6486d0e9e86fae29\IEEXEC~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6001.18111_none_7b299efbcf1f75d7\IEEXEC~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6001.22230_none_645e0f97e8c4eeea\IEEXEC~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-sys_data_oraclient_perfcoun_b03f5f7f11d50a3a_6.0.6000.16720_none_85fe1e046d872951\_DATAO~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-sys_data_oraclient_perfcoun_b03f5f7f11d50a3a_6.0.6000.16720_none_85fe1e046d872951\_DATAO~2.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-sys_data_oraclient_perfcoun_b03f5f7f11d50a3a_6.0.6000.20883_none_6f3634a887296e44\_DATAO~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-sys_data_oraclient_perfcoun_b03f5f7f11d50a3a_6.0.6000.20883_none_6f3634a887296e44\_DATAO~2.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-sys_data_oraclient_perfcoun_b03f5f7f11d50a3a_6.0.6001.18000_none_85d8195c6dda02a9\_DATAO~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-sys_data_oraclient_perfcoun_b03f5f7f11d50a3a_6.0.6001.18000_none_85d8195c6dda02a9\_DATAO~2.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-sys_data_oraclient_perfcoun_b03f5f7f11d50a3a_6.0.6001.18111_none_85d902ba6dd935f2\_DATAO~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-sys_data_oraclient_perfcoun_b03f5f7f11d50a3a_6.0.6001.18111_none_85d902ba6dd935f2\_DATAO~2.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_policy.1.2.microsof..op.security.azroles_31bf3856ad364e35_6.0.6000.16386_none_ea83414c2e75b887\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_ini_31bf3856ad364e35_6.0.6000.16708_none_c8df4fb390304286\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_ini_31bf3856ad364e35_6.0.6000.20864_none_c9240bcea982249a\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6000.16708_none_78c5c5708f85fc49\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6000.20864_none_790a818ba8d7de5d\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6000.16708_none_7ab8208b3397ed7d\_TRANS~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6000.20864_none_7afcdca64ce9cf91\_TRANS~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6001.18096_none_7c3b0d6b31094a12\_TRANS~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6001.22208_none_7d27fbfc49dc1e38\_TRANS~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6000.16708_none_807ba2c12fe38edc\_TRANS~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6000.20864_none_80c05edc493570f0\_TRANS~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_ini_31bf3856ad364e35_6.0.6000.20864_none_329d12c028538d21\_SMSVC~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6001.22208_none_30df444827c761d0\_SMSVC~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_ini_31bf3856ad364e35_6.0.6001.18096_none_ca623c938da19f1b\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6001.18096_none_7a48b2508cf758de\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globaluserinterfacecf_31bf3856ad364e35_6.0.6000.16708_none_ac1fffb2b6ba9be9\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globaluserinterfacecf_31bf3856ad364e35_6.0.6000.20864_none_ac64bbcdd00c7dfd\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globaluserinterfacecf_31bf3856ad364e35_6.0.6001.18096_none_ada2ec92b42bf87e\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globaluserinterfacecf_31bf3856ad364e35_6.0.6001.22208_none_ae8fdb23ccfecca4\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_caspol_b03f5f7f11d50a3a_6.0.6000.16720_none_6bfcb0a8ef8c6f2e\CASPOL~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_caspol_b03f5f7f11d50a3a_6.0.6000.20883_none_5534c74d092eb421\CASPOL~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_caspol_b03f5f7f11d50a3a_6.0.6001.18000_none_6bd6ac00efdf4886\CASPOL~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_caspol_b03f5f7f11d50a3a_6.0.6001.18111_none_6bd7955eefde7bcf\CASPOL~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_caspol_b03f5f7f11d50a3a_6.0.6001.22230_none_550c05fb0983f4e2\CASPOL~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6001.22208_none_7d103549a497546b\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6000.16830_none_29a6eeebde589a97\PRINTF~1.MOF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6000.21023_none_2a3e34a2f76b9db7\PRINTF~1.MOF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6001.18000_none_2bad9989db66dd67\PRINTF~1.MOF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6001.18226_none_2b9dff39db71a7a1\PRINTF~1.MOF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-p..oler-filterpipeline_31bf3856ad364e35_6.0.6001.22389_none_2be9bd5af4bd3b16\PRINTF~1.MOF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6000.16720_none_0bca521ee450d037\NETFXS~1.HKF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6000.20883_none_0c16103ffd9c63ac\NETFXS~1.HKF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6001.18111_none_0dbc60fae16e5e8e\NETFXS~1.HKF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6001.22230_none_0e2f5da3fa9d1ce3\NETFXS~1.HKF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_en-us_0186d9b7953a1394\_DATAO~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_en-us_0186d9b7953a1394\_DATAP~2.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_en-us_01d297d8ae85a709\_DATAO~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_en-us_01d297d8ae85a709\_DATAP~2.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18000_en-us_0382b64f92506f7c\_DATAO~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18000_en-us_0382b64f92506f7c\_DATAP~2.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_en-us_0378e8939257a1eb\_DATAO~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_en-us_0378e8939257a1eb\_DATAP~2.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_en-us_03ebe53cab866040\_DATAO~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_en-us_03ebe53cab866040\_DATAP~2.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-sys_data_oraclient_perfcoun_b03f5f7f11d50a3a_6.0.6001.22230_none_6f0d7356877eaf05\_DATAO~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-sys_data_oraclient_perfcoun_b03f5f7f11d50a3a_6.0.6001.22230_none_6f0d7356877eaf05\_DATAO~2.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalmonospacecf_31bf3856ad364e35_6.0.6000.16708_none_820ff368b2f34b62\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalmonospacecf_31bf3856ad364e35_6.0.6000.20864_none_8254af83cc452d76\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalmonospacecf_31bf3856ad364e35_6.0.6001.18096_none_8392e048b064a7f7\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalmonospacecf_31bf3856ad364e35_6.0.6001.22208_none_847fced9c9377c1d\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalsansserifcf_31bf3856ad364e35_6.0.6000.16708_none_4c6d3f4bfe5170cb\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.6000.16708_none_b25b01638e2dbfa3\_TRANS~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.6000.20864_none_b29fbd7ea77fa1b7\_TRANS~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_ini_31bf3856ad364e35_6.0.6000.16708_none_c1843fad322b4004\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_ini_31bf3856ad364e35_6.0.6000.20864_none_c1c8fbc84b7d2218\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_ini_31bf3856ad364e35_6.0.6001.18096_none_c3072c8d2f9c9c99\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_ini_31bf3856ad364e35_6.0.6001.22208_none_c3f41b1e486f70bf\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_vrg_31bf3856ad364e35_6.0.6000.16708_none_3432eb0d0dced274\_SMSVC~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_vrg_31bf3856ad364e35_6.0.6000.20864_none_3477a7282720b488\_SMSVC~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_vrg_31bf3856ad364e35_6.0.6001.18096_none_35b5d7ed0b402f09\_SMSVC~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_vrg_31bf3856ad364e35_6.0.6001.22208_none_36a2c67e2413032f\_SMSVC~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalsansserifcf_31bf3856ad364e35_6.0.6001.18096_none_4df02c2bfbc2cd60\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalsansserifcf_31bf3856ad364e35_6.0.6001.22208_none_4edd1abd1495a186\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalserifcf_31bf3856ad364e35_6.0.6000.16708_none_319b7f14a2b4f78c\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalserifcf_31bf3856ad364e35_6.0.6000.20864_none_31e03b2fbc06d9a0\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalserifcf_31bf3856ad364e35_6.0.6001.18096_none_331e6bf4a0265421\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalserifcf_31bf3856ad364e35_6.0.6001.22208_none_340b5a85b8f92847\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6001.22208_none_7b35a0e1a5ca2d04\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6000.16708_none_74dcd7a292078251\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6000.20864_none_752193bdab596465\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6001.18096_none_765fc4828f78dee6\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6001.22208_none_774cb313a84bb30c\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6000.16708_none_7aa059d88e5323b0\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6000.20864_none_7ae515f3a7a505c4\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6001.18096_none_7c2346b88bc48045\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_ini_31bf3856ad364e35_6.0.6001.22208_none_cb4f2b24a6747341\_SERVI~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_ini_31bf3856ad364e35_6.0.6001.18096_none_33db43850c7307a2\_SMSVC~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_ini_31bf3856ad364e35_6.0.6001.22208_none_34c832162545dbc8\_SMSVC~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6000.16708_none_2e6f68d711833115\_SMSVC~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6000.20864_none_2eb424f22ad51329\_SMSVC~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6001.18096_none_2ff255b70ef48daa\_SMSVC~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.6001.18096_none_b3ddee438b9f1c38\_TRANS~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6001.18096_none_81fe8fa12d54eb71\_TRANS~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globalsansserifcf_31bf3856ad364e35_6.0.6000.20864_none_4cb1fb6717a352df\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6001.22208_none_82eb7e324627bf97\_TRANS~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.Processes
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1360 Status: Locked to the Windows API!

Stealth Objects
-------------------
Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: wininit.exe (PID: 696) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: services.exe (PID: 740) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: lsass.exe (PID: 756) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: lsm.exe (PID: 764) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETerrvifxp.dll]
Process: svchost.exe (PID: 916) Address: 0x00940000 Size: 53248

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 916) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: winlogon.exe (PID: 940) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 1028) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 1072) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 1212) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 1252) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 1296) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 1420) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: SLsvc.exe (PID: 1476) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 1528) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 1632) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: spoolsv.exe (PID: 1872) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 1976) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: Dwm.exe (PID: 648) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: taskeng.exe (PID: 908) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: ekrn.exe (PID: 852) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: Explorer.EXE (PID: 1192) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: Iaantmon.exe (PID: 1600) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: sqlservr.exe (PID: 1648) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 2160) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: PSIService.exe (PID: 2204) Address: 0x003c0000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: Switcher.exe (PID: 2268) Address: 0x00900000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: sqlbrowser.exe (PID: 2336) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: sqlwriter.exe (PID: 2436) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: STacSV.exe (PID: 2600) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: MSASCui.exe (PID: 2660) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: Apoint.exe (PID: 2668) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: jusched.exe (PID: 2676) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: AppMonUtility.exe (PID: 2688) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: ISBMgr.exe (PID: 2696) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: IAAnotif.exe (PID: 2708) Address: 0x00390000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: VCDDaemon.exe (PID: 2724) Address: 0x00180000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: rundll32.exe (PID: 2784) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: egui.exe (PID: 2844) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: ehtray.exe (PID: 2876) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: wmpnscfg.exe (PID: 2884) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 3096) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: VESMgr.exe (PID: 3120) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: rundll32.exe (PID: 3152) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: VCSW.exe (PID: 3184) Address: 0x00340000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: svchost.exe (PID: 3224) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: VESMgrSub.exe (PID: 3268) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: SearchIndexer.exe (PID: 3300) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: xaudio.exe (PID: 3320) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: VzCdbSvc.exe (PID: 3424) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: VzFw.exe (PID: 3616) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: WUDFHost.exe (PID: 3796) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: ehmsas.exe (PID: 3988) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: wmpnetwk.exe (PID: 1220) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: SPMgr.exe (PID: 4712) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: ApMsgFwd.exe (PID: 4884) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: Apntex.exe (PID: 4944) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 5224) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: default.dll]
Process: chrome.exe (PID: 5224) Address: 0x6c7a0000 Size: 352256

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 5224) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 5320) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 5320) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 5556) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 5556) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: taskeng.exe (PID: 4260) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 3996) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 3996) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 4412) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 4412) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 5000) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 5000) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 5076) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 5076) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 5688) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 5688) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 5060) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 5060) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 4596) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 4596) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 2580) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 2580) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 5932) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 5932) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 3472) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 3472) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 5152) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 5152) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 2372) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 2372) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: chrome.exe (PID: 5440) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: en-US.dll]
Process: chrome.exe (PID: 5440) Address: 0x6cad0000 Size: 106496

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: conime.exe (PID: 2216) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETvotchpru.dll]
Process: RootRepeal.exe (PID: 3956) Address: 0x10000000 Size: 32768

Object: Hidden Code [ETHREAD: 0x870efd78]
Process: System Address: 0x871a8790 Size: 1000

Hidden Services
-------------------
Service Name: SKYNETpvoxihpi
Image Path: C:\Windows\system32\drivers\SKYNETytxdewqn.sys

==EOF==


I hope that came out alright.

#4 Blade

Blade

    Strong in the Bleepforce


  • Site Admin
  • 12,704 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:US
  • Local time:09:57 PM

Posted 15 August 2009 - 03:27 AM

Good, I can see the rootkit. :thumbsup:

Now the next step...

Rerun Rootrepeal. After the scan completes, go to the files tab and find these files:

C:\Windows\System32\drivers\SKYNETytxdewqn.sys

Then use your mouse to highlight it in the Rootrepeal window.
Next right mouse click on it and select *wipe file* option only.
Then immediately reboot the computer.



Rerun Malwarebytes like this:

Open MBAM in normal mode and click Update tab, select Check for Updates,when done
click Scanner tab,select Quick scan and scan.
After scan click Remove Selected, post the new scan log here, and Reboot

~Blade


In your next reply, please include the following:
Malwarebytes log

Edited by Blade Zephon, 15 August 2009 - 03:28 AM.

Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+


#5 Limeade

Limeade
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:06:57 PM

Posted 15 August 2009 - 04:21 AM

Thanks for the help so far. :thumbsup:


Malwarebytes' Anti-Malware 1.40
Database version: 2628
Windows 6.0.6001 Service Pack 1

8/15/2009 2:20:37 AM
mbam-log-2009-08-15 (02-20-37).txt

Scan type: Quick Scan
Objects scanned: 89266
Time elapsed: 7 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 9

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\SKYNETkdpbeoni.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\SKYNETmbnkvpdb.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\SKYNETwktsvlbp.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\SKYNETxsvqqtbk.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\SKYNETerrvifxp.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\SKYNETeuncysmq.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\SKYNETkxfmipig.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\SKYNETvotchpru.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\drivers\SKYNETytxdewqn.sys (Trojan.Agent) -> Quarantined and deleted successfully.

#6 Blade

Blade

    Strong in the Bleepforce


  • Site Admin
  • 12,704 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:US
  • Local time:09:57 PM

Posted 15 August 2009 - 10:39 PM

Great. . . you're almost good to go! :thumbsup:

Let's run the following just to be sure there aren't any stragglers.

Please download ATF Cleaner by Atribune & save it to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main "Select Files to Delete" choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.
  • Click Exit on the Main menu to close the program.
Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".

***************************************************

Please download and scan with SUPERAntiSpyware Free
  • Double-click SUPERAntiSypware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If it will not start, go to Start > All Prgrams > SUPERAntiSpyware and click on Alternate Start.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
  • Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (uncheck all others):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen and exit the program.
  • Do not run a scan just yet.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". When logging in, do NOT log in under the account titled "Admin" or "Administrator"

Scan with SUPERAntiSpyware as follows:
  • Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes" and reboot normally.
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
~Blade


In your next reply, please include the following:
SUPERAntiSpyware Log

Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+


#7 Limeade

Limeade
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:06:57 PM

Posted 16 August 2009 - 01:21 PM

It took quite a while last night to run, or I would have posted sooner. :thumbsup:


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/16/2009 at 01:47 AM

Application Version : 4.27.1002

Core Rules Database Version : 4058
Trace Rules Database Version: 1998

Scan type : Complete Scan
Total Scan Time : 03:08:15

Memory items scanned : 280
Memory threats detected : 0
Registry items scanned : 8687
Registry threats detected : 0
File items scanned : 260663
File threats detected : 0

#8 Blade

Blade

    Strong in the Bleepforce


  • Site Admin
  • 12,704 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:US
  • Local time:09:57 PM

Posted 16 August 2009 - 04:37 PM

Looks good :thumbsup:

How's everything running?

Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users