Posted 19 August 2009 - 01:47 PM
Hello all. This is a great site and knowing that I can post stuff here and get some advice and some help makes these malware/spyware flareups less aggravating by half. So thank you.
Here's my situation: I'm using a friend's Lenovo R61i laptop, and I need to give it back to her in a few days. I'd like to give it back clean! I had used MBAM, SpybotS&D, and RootRepeal to eradicate a host of problems shortly after borrowing the computer-- or so I thought.
At the time, MBAM found a variety of malware and quarantined or successfully deleted all of it. RootRepeal found several elements of SKYNET, which I had thought I'd succeeded in wiping. Today, however, a routine MBAM scan took almost twice as long as a typical full scan had been taking last week, yet found nothing. This made me suspicious, so I ran RRepeal again, and it found a buncha stuff. When I attempted to wipe the hidden service "SKYNETksrtlwos" (path: C:\WINDOWS\system32\drivers\SKYNETsrssnkap.sys) the wiper could not find the file on the system. Huh?
Sneaky malware. I was already getting out of my depth, so I know I need help from you-all with this one.
Here is the log from this morning's RRepeal scan. I also have logs saved from the previous wipe, both before and after. Help?
ROOTREPEAL © AD, 2007-2009
Scan Start Time: 2009/08/19 13:56
Program Version: Version 184.108.40.206
Windows Version: Windows XP SP3
Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys
Address: 0x9C57E000 Size: 819200 File Visible: No Signed: -
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0x9AAA6000 Size: 49152 File Visible: No Signed: -
Path: C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090814.004\EraserUtilRebootDrv.sys
Status: Locked to the Windows API!
#: 123 Function Name: NtOpenProcessToken
Status: Hooked by "<unknown>" at address 0x89b1eb80
#: 129 Function Name: NtOpenThreadToken
Status: Hooked by "<unknown>" at address 0x89b12a98
#: 228 Function Name: NtSetInformationProcess
Status: Hooked by "<unknown>" at address 0x89d77df0
Service Name: SKYNETksrtlwos
Image Path: C:\WINDOWS\system32\drivers\SKYNETsrssnkap.sys