This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] hijack this for a probably common trojan (guessing from

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I appreciate that forums of this nature exist. Thanks for any assistance in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:27:58 PM, on 7/27/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PMSveH.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\PMHandler.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauthe.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\IBM ThinkVantage\Client Security Solution\pwmgre.exe
c:\progra~1\common~1\instal~1\update~1\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PMHandler] C:\WINDOWS\system32\PMHandler.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [cssauthe] "C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauthe.exe" silent
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/us/en/
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.avsystemcare.com
O15 - Trusted Zone: *.onerateld.com
O15 - Trusted Zone: *.safetydownload.com
O15 - Trusted Zone: *.trustedantivirus.com
O15 - Trusted Zone: *.virusremover2008.com
O15 - Trusted Zone: *.virusschlacht.com
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: lfjood.dll,tocdbn.dll
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PMSveH - Lenovo - C:\WINDOWS\system32\PMSveH.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe

–
End of file - 9245 bytes
Hi,

Please do the following:

Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hello CatByte, thanks for your assistance. I've run into a small problem and wondering how you'd like me to proceed. I was able to run the first program and get the dds and attach text files. The second program was problematic. I unzipped it and ran the scan as instructed. At some point during the scan my computer flashed the "Windows blue screen of death" and the machine completely shut down. This wasn't a one time thing, it happened three times. Below is the data from the first two text files, but I would like to know how you'd like me to handle the gmer scan report. Also, if you'd prefer these files as attachments to a post please let me know. Thanks again. DDS: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 20:17:16.64 on Tue 07/28/2009 Internet Explorer: 8.0.6001.18241 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.138 [GMT -4:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\PMSveH.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\PMHandler.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauthe.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe C:\WINDOWS\system32\dlcccoms.exe C:\Program Files\IBM ThinkVantage\Client Security Solution\pwmgre.exe c:\progra~1\common~1\instal~1\update~1\isuspm.exe C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\RENSYS06\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\RENSYS06\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local mSearchAssistant = hxxp://www.google.com/ie BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\rensys06\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [TPWAUDAP] c:\program files\lenovo\hotkey\TpWAudAp.exe mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPHKMGR.exe mRun: [suScheduler] c:\program files\thinkvantage\systemupdate\UCLauncher.exe /SCHEDULER mRun: [SoundMan] SOUNDMAN.EXE mRun: [PMHandler] c:\windows\system32\PMHandler.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [cssauthe] "c:\program files\ibm thinkvantage\client security solution\cssauthe.exe" silent mRun: [Corel Photo Downloader] c:\program files\corel\corel photo album 6\MediaDetect.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [DLCCCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCCtime.dll,_RunDLLEntry@16 mRun: [dlccmon.exe] "c:\program files\dell photo aio printer 924\dlccmon.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL Trusted Zone: amaena.com Trusted Zone: avsystemcare.com Trusted Zone: onerateld.com Trusted Zone: safetydownload.com Trusted Zone: trustedantivirus.com Trusted Zone: virusremover2008.com Trusted Zone: virusschlacht.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4.2/jinstall-142-win.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: ACNotify - ACNotify.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll Notify: tphotkey - tphklock.dll AppInit_DLLs: lfjood.dll,tocdbn.dll SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll LSA: Authentication Packages = msv1_0 nwprovau ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\rensys06\applic~1\mozilla\firefox\profiles\ni3owowq.default\ FF - prefs.js: browser.startup.homepage - hxxp://mlive.com/sports FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - plugin: c:\documents and settings\rensys06\application data\mozilla\firefox\profiles\ni3owowq.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll FF - plugin: c:\documents and settings\rensys06\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2006-7-20 11520] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-7-19 327688] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-7-19 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-7-19 108552] R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2006-7-20 6016] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-7-19 298776] R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [2005-12-21 12544] R2 smi2;smi2;c:\program files\smi2\smi2.sys [2005-12-21 3968] S0 ANCSQ;ANCSQ;c:\windows\system32\drivers\ancsq.sys –> c:\windows\system32\drivers\ANCSQ.sys [?] =============== Created Last 30 ================ 2009-07-28 20:16 –d-h— c:\windows\PIF 2009-07-27 18:27 –d—– c:\program files\Trend Micro 2009-07-26 20:09 61,440 a——- c:\windows\system32\drivers\muoj.sys 2009-07-26 00:13 5,427 a——- c:\windows\EGATHDRV.TMP 2009-07-19 08:35 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-07-19 08:35 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-07-19 08:35 327,688 a——- c:\windows\system32\drivers\avgldx86.sys 2009-07-19 08:35 –d—– c:\windows\system32\drivers\Avg 2009-07-06 19:16 –d—– c:\program files\Mobile Systems ==================== Find3M ==================== 2009-07-26 00:13 5,427 a——- c:\windows\system32\EGATHDRV.SYS 2009-07-13 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-13 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys ============= FINISH: 20:19:35.79 =============== Attach.txt UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 8/17/2006 5:19:13 AM System Uptime: 7/26/2009 12:13:53 AM (68 hours ago) Motherboard: LENOVO | | HEL00 Processor: Intel® Celeron® M processor 1.50GHz | JCPU1A | 1496/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 70 GiB total, 48.022 GiB free. D: is CDROM (CDFS) ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP210: 6/12/2009 8:18:33 PM - System Checkpoint RP211: 6/12/2009 8:18:35 PM - System Checkpoint RP212: 6/12/2009 8:18:36 PM - System Checkpoint RP213: 6/12/2009 8:18:38 PM - System Checkpoint RP214: 6/12/2009 8:18:41 PM - System Checkpoint RP215: 6/12/2009 8:18:42 PM - Installed Microsoft Calculator Plus RP216: 6/12/2009 8:18:42 PM - Installed Windows Internet Explorer 8. RP217: 6/12/2009 8:18:43 PM - System Checkpoint RP218: 6/12/2009 8:18:44 PM - System Checkpoint RP219: 6/12/2009 8:18:44 PM - System Checkpoint RP220: 6/12/2009 8:18:44 PM - System Checkpoint RP221: 6/12/2009 8:18:44 PM - System Checkpoint RP222: 6/12/2009 8:18:45 PM - System Checkpoint RP223: 6/12/2009 8:18:48 PM - System Checkpoint RP224: 6/12/2009 8:18:49 PM - System Checkpoint RP225: 6/12/2009 8:18:51 PM - System Checkpoint RP226: 6/12/2009 8:18:54 PM - System Checkpoint RP227: 6/12/2009 8:18:56 PM - System Checkpoint RP228: 6/12/2009 8:18:58 PM - System Checkpoint RP229: 6/12/2009 8:18:59 PM - System Checkpoint RP230: 6/12/2009 8:19:01 PM - System Checkpoint RP231: 6/12/2009 8:19:03 PM - System Checkpoint RP232: 6/12/2009 8:19:04 PM - System Checkpoint RP233: 6/12/2009 8:19:04 PM - System Checkpoint RP234: 6/12/2009 8:19:05 PM - System Checkpoint RP235: 6/12/2009 8:19:06 PM - System Checkpoint RP236: 6/12/2009 8:19:07 PM - System Checkpoint RP237: 6/12/2009 8:19:07 PM - System Checkpoint RP238: 6/12/2009 8:19:07 PM - System Checkpoint RP239: 6/12/2009 8:19:08 PM - System Checkpoint RP240: 6/12/2009 8:19:08 PM - System Checkpoint RP241: 6/12/2009 8:19:08 PM - System Checkpoint RP242: 6/12/2009 8:19:09 PM - System Checkpoint RP243: 6/12/2009 8:19:09 PM - System Checkpoint RP244: 6/12/2009 8:19:09 PM - System Checkpoint RP245: 6/12/2009 8:19:10 PM - System Checkpoint RP246: 6/12/2009 8:19:10 PM - System Checkpoint RP247: 6/12/2009 8:19:10 PM - System Checkpoint RP248: 6/12/2009 8:19:10 PM - System Checkpoint RP249: 6/12/2009 8:19:11 PM - System Checkpoint RP250: 6/12/2009 8:19:11 PM - Advanced Registry Optimizer - Before Installation RP251: 6/12/2009 8:19:11 PM - Advanced Registry Optimizer - Before Installation RP252: 6/12/2009 8:19:11 PM - ADVANCED REGISTRY OPTIMIZER - FIRST RUN RP253: 6/12/2009 8:19:11 PM - Advanced Registry Optimizer Fri, Apr 24, 09 22:21 RP254: 6/12/2009 8:19:12 PM - Installed Java™ 6 Update 13 RP255: 6/12/2009 8:19:12 PM - Removed AVG 8.0 RP256: 6/12/2009 8:19:12 PM - Installed AVG 8.0 RP257: 6/12/2009 8:19:12 PM - System Checkpoint RP258: 6/12/2009 8:19:13 PM - System Checkpoint RP259: 6/12/2009 8:19:13 PM - System Checkpoint RP260: 6/12/2009 8:19:13 PM - System Checkpoint RP261: 6/12/2009 8:19:13 PM - System Checkpoint RP262: 6/12/2009 8:19:14 PM - System Checkpoint RP263: 6/12/2009 8:19:14 PM - System Checkpoint RP264: 6/12/2009 8:19:14 PM - System Checkpoint RP265: 6/12/2009 8:19:14 PM - System Checkpoint RP266: 6/12/2009 8:19:14 PM - System Checkpoint RP267: 6/12/2009 8:19:15 PM - Installed muvee Plugin 1.0 RP268: 6/12/2009 8:19:15 PM - System Checkpoint RP269: 6/12/2009 8:19:16 PM - System Checkpoint RP270: 6/12/2009 8:19:16 PM - System Checkpoint RP271: 6/12/2009 8:19:16 PM - System Checkpoint RP272: 6/12/2009 8:19:16 PM - System Checkpoint RP273: 6/12/2009 8:19:17 PM - System Checkpoint RP274: 6/12/2009 8:19:17 PM - System Checkpoint RP275: 6/12/2009 8:19:17 PM - System Checkpoint RP276: 6/12/2009 8:19:17 PM - System Checkpoint RP277: 6/12/2009 8:19:17 PM - System Checkpoint RP278: 6/12/2009 8:19:18 PM - System Checkpoint RP279: 6/12/2009 8:19:18 PM - System Checkpoint RP280: 6/12/2009 8:19:18 PM - System Checkpoint RP281: 6/12/2009 8:19:18 PM - System Checkpoint RP282: 6/12/2009 8:19:19 PM - Removed Diskeeper Lite RP283: 6/12/2009 8:19:19 PM - Removed Lenovo Care RP284: 6/12/2009 8:19:19 PM - Removed Message Center RP285: 6/12/2009 8:19:19 PM - Removed Presentation Director RP286: 6/12/2009 8:19:19 PM - Removed Small Business Center RP287: 6/12/2009 8:19:19 PM - Removed WordPerfect Office 12 RP288: 6/12/2009 8:19:20 PM - System Checkpoint RP289: 6/12/2009 8:19:20 PM - System Checkpoint RP290: 6/12/2009 8:19:20 PM - System Checkpoint RP291: 6/12/2009 8:19:20 PM - System Checkpoint RP292: 6/12/2009 8:19:20 PM - System Checkpoint RP293: 6/12/2009 8:19:20 PM - System Checkpoint RP294: 6/12/2009 8:19:21 PM - System Checkpoint RP295: 6/12/2009 8:19:21 PM - System Checkpoint RP296: 6/12/2009 8:19:21 PM - System Checkpoint RP297: 6/12/2009 8:19:21 PM - System Checkpoint RP298: 6/12/2009 8:19:21 PM - System Checkpoint RP299: 6/12/2009 8:19:21 PM - System Checkpoint RP300: 6/12/2009 8:19:22 PM - System Checkpoint RP301: 6/12/2009 8:19:22 PM - System Checkpoint RP302: 6/12/2009 8:19:22 PM - System Checkpoint RP303: 6/12/2009 8:19:22 PM - System Checkpoint RP304: 6/12/2009 8:19:23 PM - System Checkpoint RP305: 6/12/2009 8:19:23 PM - System Checkpoint RP306: 6/12/2009 8:19:23 PM - System Checkpoint RP307: 6/12/2009 8:19:23 PM - System Checkpoint RP308: 6/12/2009 8:19:23 PM - System Checkpoint RP309: 6/13/2009 6:30:22 PM - System Checkpoint RP310: 6/14/2009 6:39:00 PM - System Checkpoint RP311: 6/15/2009 7:39:00 PM - System Checkpoint RP312: 6/16/2009 8:34:58 PM - System Checkpoint RP313: 6/17/2009 8:36:03 PM - System Checkpoint RP314: 6/18/2009 9:17:23 PM - System Checkpoint RP315: 6/19/2009 9:34:57 PM - System Checkpoint RP316: 6/20/2009 10:35:01 PM - System Checkpoint RP317: 6/22/2009 1:17:32 AM - System Checkpoint RP318: 6/23/2009 2:08:53 AM - System Checkpoint RP319: 7/6/2009 7:16:18 PM - System Checkpoint ==== Installed Programs ====================== 3ivx MPEG-4 5.0.1 Decoder (remove only) ABBYY FineReader 6.0 Sprint Access Help Ad-Aware SE Personal Adobe AIR Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Photoshop CS Adobe Reader 7.0 Apple Software Update AVG Free 8.5 Broadcom 802.11 Network Adapter Dell Photo AIO Printer 924 FileZilla Client 3.1.2 Google Chrome Help Center HijackThis 2.0.2 Hotfix for Windows XP (KB893357) Hotfix for Windows XP (KB894686) Hotfix for Windows XP (KB903250) Hotfix for Windows XP (KB909667) Hotfix for Windows XP (KB952287) Hotkey Features Setup IBM 32-bit Runtime Environment for Java 2, v1.4.2 Intel® Graphics Media Accelerator Driver for Mobile InterVideo WinDVD Jasc Paint Shop Photo Album 5 Jasc Paint Shop Pro Studio, Dell Editon Java™ 6 Update 13 Lenovo Care Supplement Macromedia HomeSite 5 Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft Calculator Plus Microsoft Office Professional Edition 2003 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.0.11) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) muvee Plugin 1.0 On Screen Display Opera 9.52 PM Driver Pocket Oxford Spanish Dictionary QuickTime Realtek AC'97 Audio REALTEK Gigabit and Fast Ethernet NIC Driver Rescue and Recovery Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Soft Data Fax Modem with SmartCP Sony Noise Reduction Plug-In 2.0h Sony Sound Forge 9.0 Spybot - Search & Destroy Synaptics Pointing Device Driver ThinkPad PC Card Power Policy ThinkVantage Access Connections ThinkVantage System Update ThinkVantage Technologies Welcome Message Trillian TweetDeck Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB951072-v2) Update for Windows XP (KB955839) Wallpapers WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Beta 2 Windows Media Connect Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB883517 Windows XP Hotfix - KB883523 Windows XP Hotfix - KB884020 Windows XP Hotfix - KB884868 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885894 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888239 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB889315 Windows XP Hotfix - KB889673 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB896613 XP Themes ==== Event Viewer Messages From Past Week ======== 7/27/2009 12:17:09 PM, error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 7/26/2009 12:15:28 AM, error: Service Control Manager [7034] - The TVT Scheduler service terminated unexpectedly. It has done this 1 time(s). 7/26/2009 12:15:20 AM, error: DCOM [10005] - DCOM got error "%1055" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820} 7/26/2009 12:15:00 AM, error: Dhcp [1002] - The IP address lease 192.168.1.106 for the Network Card with network address 0014A5C09199 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message). ==== End Of File ===========================
Hi,

Please run this rootkit scanner instead:

Please download Sysprot Antirootkit from here

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select all items.
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to.
  • Open the text file and copy/paste the log here.
Whatever virus I have isn't interested in complying with the tasks you're setting forth. Again I got to the point where I was running the scan and again my computer flashes the blue screen and reboots. I await further instruction.
Here is the gmer.txt file that was run in safe mode…..

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-31 23:16:00
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

Code 8223B378 ZwEnumerateKey
Code 8223B340 ZwFlushInstructionCache
Code 8223B3AE IofCallDriver
Code 822381BE IofCompleteRequest

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \FileSystem\Fastfat \Fat B9DA6C8A

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\drivers\SKYNETveudwjos.sys (*** hidden *** ) [SYSTEM] SKYNETyqivwwrk <– ROOTKIT !!!
Service system32\drivers\TDSSxeuu.sys (*** hidden *** ) [SYSTEM] TDSSserv.sys <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk@imagepath \systemroot\system32\drivers\SKYNETveudwjos.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\main\connections
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\[removed] \systemroot\system32\drivers\SKYNETveudwjos.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\[removed] \systemroot\system32\SKYNETaqbyulny.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\[removed] \systemroot\system32\SKYNETycyxlovd.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\[removed] \systemroot\system32\SKYNETogbmerjb.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETyqivwwrk\[removed] \systemroot\system32\SKYNETkrgdnjsl.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@imagepath \systemroot\system32\drivers\TDSSxeuu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@TDSSserv \systemroot\system32\drivers\TDSSxeuu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@TDSSl \systemroot\system32\TDSSktao.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssservers \systemroot\system32\TDSSwupe.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssmain \systemroot\system32\TDSSirxy.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdsslog \systemroot\system32\TDSSravu.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssadw \systemroot\system32\TDSSocun.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssinit \systemroot\system32\TDSSqqon.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdsserrors \systemroot\system32\TDSSehys.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@TDSSproc \systemroot\system32\TDSSwrhd.log
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk@imagepath \systemroot\system32\drivers\SKYNETveudwjos.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\main
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\main@aid 10096
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\main@sid 0
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\main\connections
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\main\delete
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\main\injector
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\main\tasks
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\modules
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\[removed] \systemroot\system32\drivers\SKYNETveudwjos.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\[removed] \systemroot\system32\SKYNETaqbyulny.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\[removed] \systemroot\system32\SKYNETycyxlovd.dat
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\[removed] \systemroot\system32\SKYNETogbmerjb.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETyqivwwrk\[removed] \systemroot\system32\SKYNETkrgdnjsl.dat
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys@imagepath \systemroot\system32\drivers\TDSSxeuu.sys
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules@TDSSserv \systemroot\system32\drivers\TDSSxeuu.sys
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules@TDSSl \systemroot\system32\TDSSktao.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules@tdssservers \systemroot\system32\TDSSwupe.dat
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules@tdssmain \systemroot\system32\TDSSirxy.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules@tdsslog \systemroot\system32\TDSSravu.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules@tdssadw \systemroot\system32\TDSSocun.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules@tdssinit \systemroot\system32\TDSSqqon.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules@tdsserrors \systemroot\system32\TDSSehys.log
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules@TDSSproc \systemroot\system32\TDSSwrhd.log

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\SKYNETveudwjos.sys 69632 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\SKYNET.dat 93 bytes
File C:\WINDOWS\system32\SKYNETaqbyulny.dll 44544 bytes executable
File C:\WINDOWS\system32\SKYNETkrgdnjsl.dat 91 bytes
File C:\WINDOWS\system32\SKYNETogbmerjb.dll 20992 bytes executable
File C:\WINDOWS\system32\SKYNETycyxlovd.dat 661050 bytes
File C:\WINDOWS\Temp\SKYNETawmhpbdqjy.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETngrqeyfjdc.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETnkvrrixfwy.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETnmecbvdfes.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETnoghukfnmf.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETnptetynemn.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETnsifucvrao.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETntsiycbosg.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETnvikpcvnfk.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETnwkvipmbiq.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETnxtauccupj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETnyvpntnhlk.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETocdbhjpggw.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETodhpwwrvgi.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETodmhuupoaf.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETogajypkgtc.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETogqqbyfnwj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETogyjfcpdal.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNEToipoqmijjn.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETompwiseonm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNEToojaaahbuf.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETopcvbvrxtf.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETopcwxwrtfw.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETopelxgtplj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETyjhvftokig.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETyjygraerkq.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETylpcynemqx.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETyntvlqnauc.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETypdrtixvbv.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETyqhxrxvbdw.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETyqnnfwjqkf.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETyqvrbguuwa.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETyvosnqhqop.tmp 20992 bytes executable
File C:\WINDOWS\Temp\Temporary Internet Files 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\3YWJWRBK 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\3YWJWRBK\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\73A2S634 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\73A2S634\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat 32768 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\MZ2F8A9X 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\MZ2F8A9X\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ZQDM67GZ 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ZQDM67GZ\desktop.ini 67 bytes
File C:\WINDOWS\Temp\tmp73.exe 0 bytes
File C:\WINDOWS\Temp\tmp73.tmp 0 bytes
File C:\WINDOWS\Temp\tmp833.tmp 0 bytes
File C:\WINDOWS\Temp\tvttemp.txt 12064 bytes
File C:\WINDOWS\Temp\WGAErrLog.txt 255 bytes
File C:\WINDOWS\Temp\WGANotify.settings 409 bytes
File C:\WINDOWS\Temp\_avast4_ 0 bytes
File C:\WINDOWS\Temp\SKYNETdygnunwsgh.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETebqvdxdtep.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETeejcbqoffe.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETejkgxujfqk.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETekskkflsvw.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETelwrmuguua.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETeqvnmdeobv.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETescjodrivt.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETesswoyrrsq.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETfggbjkbgxi.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETfhemlbblad.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETfhfenqrscu.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETfhyeaffphk.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETfjyboveyvg.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETfomnqgudls.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETfubbhvyprn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETfuytbcwsem.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETfyabwulnsd.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETaaxnwcptvd.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETaduoapsfvm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETadwkptyxlj.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETaectvbtbrq.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETaeiyrkydnn.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETafkenyjngg.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETaggjcvofia.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETaggkymnvkv.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETahvnftjtpf.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETaklntamxwl.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETancabdrykg.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETanymxnfjpi.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETapegcdpmkp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETapulqipyra.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETasoghfpuju.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETattcgpkafp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETavxdffssqn.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETrujxbpcexx.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETrwuvvwdirt.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETrxrxslvldf.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETrytedlwcyj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETryxwfihvub.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETsbwulnsemp.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETsdpcqxtwdy.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETsflkjcmgqo.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETshtohsmuvh.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETsmpfymxuit.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETsqnruojfgy.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETsqulhlereu.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETssiuwidkxo.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETsvobysmvti.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETswfbsrpaaj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETswhplehsqu.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETtahngtfxko.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETkcmbuphcbc.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETkeaihufewe.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETkfaxhakgcr.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETkinnjefmdl.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETkmbxvqsopw.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETkmxgkrlhmi.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETkokouujswt.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETkotmbmexcc.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETkpmnsvjuyu.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETkpoomanpix.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETkramkdhruo.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETktppbcmeyk.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETkxfibficxb.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETlcjivfkjpv.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETlcskisqvek.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETljfvwlchlq.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETlkrubhauyj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETlqouuyfnfe.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETlracbihfkq.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETlskcndmxuw.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETlthpyyebfp.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETlvpxdicsix.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETlwttpojhex.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETlxjipmexun.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETmbsyefxlim.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETmcrsixcimm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETmeyecpbewm.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETwamqfqamnq.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETwbgamkxemp.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETwentspibii.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETwfnbwcwchv.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETwhjvrunfil.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETwhnulfqexi.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETwitrpiyeon.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETwjojsxjhli.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETwjollfswok.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETwjrhwdqyji.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETwkprxhkekr.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETwlhmptfdsm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETwlxmvgwdqp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETwojstgjvjj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETwpsspvnmxr.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETwryaevofkn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETwscjaaxjqx.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETwxrpoyyvdr.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETwysppwjkow.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETxbrvulenus.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETxchslskkod.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETxdtikorcnp.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETbadnpcydqh.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETbawqiudgpu.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETbciyqfuwqq.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETbfsofrrwgf.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETbfudmcsitc.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETbfwepplqar.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETbjcuvbwptb.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETbkibesdvkh.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETblovrdykio.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETbmioebldea.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETbniuhatoas.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETbqkfmcgunh.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETbqmbeqqhwr.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETbqtbspkjes.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETbskgdspabp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETbsrddmiqyc.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETbvpdgwivtn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETbwgswsvtks.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETbwxprkpnjm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETcextxsxqgy.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETchtlsxuewi.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETciridvuwym.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNEThpaxwhnmyd.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNEThpvrocfwca.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNEThqlebfucfa.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNEThsiplfkgop.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNEThtbegspsfs.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNEThtdenvhvha.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNEThufhxnqdnt.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNEThxrifucdwx.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNEThxwbgdcpeh.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNEThycxiqigbo.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNEThyivullsxd.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETidgpnvfuxm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETidpllgeteu.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETiflityenyf.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETigpxivewjp.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETigwtxnwrow.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETinqmkjnirp.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETiouobyqdmd.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETiryprhilfp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETitueqdcxnm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqhosixrnfv.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqixcpugkbc.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETqkctvbqogh.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqkmcluitwh.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETqlkebbidfb.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETqlnybmgejs.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETqmemmvohae.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETqmykokajhh.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETqnbmhxrgmc.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqompudylbd.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETqqefrtjohh.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETqqhyenvugs.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETqrkqhhgrqj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqyhijelhip.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETqyyvvfhllc.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETrbefxckaxp.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETrclwvdwpok.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETrdnagthfop.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETrhpqoesxgm.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETrillytuysg.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETriycvbyfqq.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETrjtpsrutak.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETrnkrimeitl.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETrpieifouwo.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETrpiporkexq.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETrpiwureifh.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETrsnjxuhebs.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETrtsinjondk.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETuobnptmfex.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETuohjajqcfx.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETurnqjdqaeg.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETusaiwmdmsq.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETuvxlyximqa.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETuxfvxmjria.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETuxkppehspj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETuybocfxoyl.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvadkqakplb.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvarseawqem.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvauajjocke.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETvcakpjnbet.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvdrgqetreb.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETvipcpcejda.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETvkqybwpfhs.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvmfrjvxihv.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETvnecputwbq.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETvnyyqxoqmb.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETvpxahahwcu.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvrevuvxxgt.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETvsohpbamau.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETvstuwitblh.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvtynsvfexs.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETvyanjaoalq.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETvyevrjivjj.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETmprbkktdvi.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETmqdnpspyxm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETmryxibovug.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETmspasijsbv.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETmtndiwejxg.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETmtnxofqwmc.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETmubnnfvutj.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETmuinwagnlg.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETmunujpunts.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETmupfcguklq.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETmuwjljurlx.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETmwhmuymhyg.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETmyfgdpsppv.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETnaecycbixw.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETnahiepflea.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETnaklfkxnft.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETnbcfbcwdjl.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETnbeqshynlg.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETnewtwwwtib.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETxfrfumdfrp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETxilrnmbfnf.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETxjsqdolrem.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETxlqptqwqge.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETxmjvfjyxpp.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETxoapbhjvna.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETxshmvwgqwn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETxtpuyxdrik.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETxtqsbfgexn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETxunjowsuls.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETxvkpyrbvpq.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETxxsngpfmym.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETxxyktudjex.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETxyergamgwr.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETycrtmwodcl.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETyevhhjaklh.tmp 519 bytes
File C:\WINDOWS\Temp\SKYNETygwuttbojo.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETyhhkyvpjjv.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETyhsbmxyxdw.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETgdrtkfitjo.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETgffgwwqypk.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETgfmirhconc.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETgjfqdltagb.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETglorclivqg.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETglrhtsahdr.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETgmxprrxext.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETgrycogsuxm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETgsdkrjmhwk.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETgsebxfsdsh.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETgtfrmsyebs.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETgxoaafpmnj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETgxtwnurrjk.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNEThakjtwcceq.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNEThkaorarfrd.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNEThkogrkbdpx.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNEThlnmsjdndk.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETorenwixdmm.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETorxbafcoey.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNEToshnfwspej.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETpbvpfsdpkv.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETpciynejtpd.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpdqgtbfubg.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpeovjplxme.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpeyftfnmcs.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETpftiqdcxnl.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETphcqmktddr.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETphrqichcld.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpidipnfbjv.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETplaxnadcys.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETpmuxhfxwbj.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETpnpvthxrpv.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETpodgyugtdp.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpqfganokig.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpqqeivctjy.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpqrprpqxxy.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETprdweubgdr.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpudxetycri.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETputilhluxh.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpuxxtaphpf.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpwkrtyiiaw.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpwofujtilt.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpylqbvfwki.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqfgbibhniw.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqfgcrrllsm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETclwgdqrcfx.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETcnovvtsyld.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETcqjpqelohp.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETcqkocpskbk.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETcqowqpuymb.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETcsurixloli.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETdbukiqgrdv.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETdceubousfm.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETdeenmumobm.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETdibadccriv.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETdkecgnujcp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETdmtfxompnd.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETdtidpjcwcp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETdtlesfsmrx.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETdupntrxjkk.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETdvfambpbkf.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETdvjdqbettk.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETdwvwjfhwtk.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETdxdgogvpqg.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETiwqvtksvbv.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETiwyfmtqibo.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETixpnmgqbux.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETjapuadwmpq.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETjdbnnuwcdf.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETjfyvvygbft.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETjhsweucswi.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETjhupxaunbh.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETjjifflvxbu.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETjmrrjcfipw.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETjpcshnkevm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETjpgjfehyik.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETjtovpogqht.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETjuxosljdgk.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETjvojelatpk.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETjxpexyyotm.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETjywxbxnpej.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETclhldoecge.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETdxiobvgljp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETgcjtfbswha.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNEThovktldxws.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETiwdphnnxnh.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETkcidxmxemm.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETmmlipcegql.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETnftpdhvxis.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNEToqnymtgrjd.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqhfnujnunf.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETrucjiaxadc.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETtatvthvbkx.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETuidgslrurf.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvyktepfgwf.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETxekngdhryp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETyijyufefvw.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETtdentlkrox.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETtdxfjhrxaj.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETtfgnbvtnee.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETthhmfxmhkw.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETtkbfgqdrtt.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETtkpfvnnkbs.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETttqmgnldoc.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETttyvxflvel.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETtuoymdmlsm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETtuqgyrdkrc.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETtxgodvlskl.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETtydsdlloor.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETuasdaxxhbr.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETucqblnaknr.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETugncwetmtt.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETuhmdfaqlxc.tmp 18944 bytes executable

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI