Thank you so much for your help. Sorry for my slow response - I had to wait until the weekend so I would have enough time to run the different scans.
—————————————————————————————-
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 2:23:16.17 on Sat 08/15/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1006.294 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Documents and Settings\MSU\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.mcneese.edu/
uInternet Settings,ProxyOverride =
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\adobe acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\common\yhexbmesus.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Version Cue CS2] c:\program files\adobe\adobe version cue cs2\controlpanel\VersionCueCS2Tray.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: Convert link target to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 NaiFsRec;NaiFsRec;c:\windows\system32\drivers\naifsrec.sys [2001-4-30 4512]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-13 335752]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-13 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-13 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-13 298776]
R2 AvSynMgr;AVSync Manager;c:\program files\network associates\virusscan\Avsynmgr.exe [2001-11-26 155665]
R2 prt1xw2k;SEM 11 Mbps Wireless Card NDIS Interface;c:\windows\system32\drivers\PRT1XW2K.SYS [2009-2-24 13056]
R3 McShield;McShield;c:\program files\common files\network associates\mcshield\Mcshield.exe [2001-11-26 225403]
R3 NaiFiltr;NaiFiltr;c:\program files\common files\network associates\mcshield\naifiltr.sys [2001-11-26 23856]
R3 SWLD23;Netopia 802.11b WLAN Cardbus Card;c:\windows\system32\drivers\swld23.sys [2009-2-24 68224]
=============== Created Last 30 ================
2009-08-09 12:16 –d—– c:\program files\Trend Micro
2009-08-01 09:22 410,984 a——- c:\windows\system32\deploytk.dll
2009-08-01 09:22 73,728 a——- c:\windows\system32\javacpl.cpl
2009-07-26 08:46 –d—– c:\program files\MSECache
2009-07-23 08:36 –d—– c:\program files\iPod
==================== Find3M ====================
2009-08-01 09:22 335,752 a——- c:\windows\system32\drivers\avgldx86.sys
2009-07-09 12:16 2,060,288 a——- c:\windows\system32\usbaaplrc.dll
2009-07-09 12:16 39,424 a——- c:\windows\system32\drivers\usbaapl.sys
2009-06-16 09:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 09:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-16 09:55 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-16 09:55 82,432 ——– c:\windows\system32\dllcache\fontsub.dll
2009-06-13 07:21 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-06-03 14:27 1,290,752 a——- c:\windows\system32\quartz.dll
2009-06-03 14:27 1,290,752 ——– c:\windows\system32\dllcache\quartz.dll
============= FINISH: 2:25:32.80 ===============
((((((((((((((((((((((((((((((( Next Report )))))))))))))))))))))))))))))))))))))))))
GMER 1.0.15.15020 [gmer.exe] -
http://www.gmer.net
Rootkit scan 2009-08-15 03:26:26
Windows 5.1.2600 Service Pack 2
—- System - GMER 1.0.15 —-
Code 8695A5A8 ZwEnumerateKey
Code 8695A208 ZwFlushInstructionCache
Code 868B2BFE IofCallDriver
Code 85F1C426 IofCompleteRequest
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs NaiFiltr.sys
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \FileSystem\Fastfat \Fat ECB50C8A
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat NaiFiltr.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- Processes - GMER 1.0.15 —-
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [672] 0x16080000
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1584] 0x16080000
Library C:\Program (*** hidden *** ) @ C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe [2236] 0x16080000
—- Services - GMER 1.0.15 —-
Service C:\WINDOWS\system32\drivers\SKYNETamhiybct.sys (*** hidden *** ) [SYSTEM] SKYNETgixetjlb <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb@imagepath \systemroot\system32\drivers\SKYNETamhiybct.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\[removed] \systemroot\system32\drivers\SKYNETamhiybct.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETfmuwqjol.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETwkwqqltk.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETohiwtosy.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETvksnbaim.dat
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb@imagepath \systemroot\system32\drivers\SKYNETamhiybct.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main@aid 10096
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main@sid 0
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\[removed] \systemroot\system32\drivers\SKYNETamhiybct.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETfmuwqjol.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETwkwqqltk.dat
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETohiwtosy.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETvksnbaim.dat
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\drivers\SKYNETamhiybct.sys 68608 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\SKYNETfmuwqjol.dll 44032 bytes executable
File C:\WINDOWS\system32\SKYNETohiwtosy.dll 20992 bytes executable
File C:\WINDOWS\system32\SKYNETvksnbaim.dat 91 bytes
File C:\WINDOWS\system32\SKYNETwkwqqltk.dat 780224 bytes
File C:\WINDOWS\Temp\SKYNETjgcynmwpmi.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqndxgbxtit.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETuxmjvweiip.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvjpxrorcnn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETvsectplabn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETwdkbrewhtv.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETwpcvkorori.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETwpcynvxufp.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETxdutojutlv.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETyaprpepuqs.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETygxnboteof.tmp 20992 bytes executable
File C:\WINDOWS\Temp\T30DebugLogFile.txt 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\4L5PL4HT 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\4L5PL4HT\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DPFJA2PV 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DPFJA2PV\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\EFEKH1Q9 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\EFEKH1Q9\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat 16384 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KHOWVCJV 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KHOWVCJV\desktop.ini 67 bytes
File C:\WINDOWS\Temp\teredo.txt 108 bytes
File C:\WINDOWS\Temp\Thumbs.db 6144 bytes
File C:\WINDOWS\Temp\uxeventlog.txt 280032 bytes
File C:\WINDOWS\Temp\WebPoolFileFile 261 bytes
File C:\WINDOWS\Temp\_coInst.log 1016 bytes
File C:\WINDOWS\Temp\_scan_buttons.log 1159 bytes
File C:\WINDOWS\Temp\SKYNETjmlfucnhsf.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETjqqdalrjsr.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETkdbynxgade.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETkjenuscexn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETkmwsonlycx.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETlbdworvjki.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETleaxjatqnt.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETljgjxvawui.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETlqmbvgfcpb.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETlyigqyontl.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETmahuymspyl.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETmuidvvummp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETnrfuyrfdax.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETnrhrulmomy.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNEToiorjkiknv.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETopviyqgtel.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETortbfxpesu.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETpmduckppkb.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETprhqcdxbqo.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETptepusfwhq.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpyqrnsmapj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqdrtfnnvnn.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETqelogcofpy.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETapvaxratpw.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETaqslhyvwne.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETbdgcxjkipm.tmp 18944 bytes
File C:\WINDOWS\Temp\SKYNETbrxejfifny.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETbulfxmptcn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETbyfnkwtbru.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETcakoquqlog.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETchutnjwvja.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETcqcjomoiib.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETcsgwgqauyh.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETdfwbwhjfva.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETelercajvdj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETevccrpprrn.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETevrknosdmn.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETfesucvpmta.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETfvnqnsvmti.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETfvtaknvrad.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETgekyjcxjib.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNEThofqoqrljc.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETifxrximird.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETikxsgefuso.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETisvjkpacjr.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETitnvoiwgbg.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETixqfiivxap.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETixvlhmxmdb.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqpxodlccpq.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETqqmdevsjsu.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETqwdfvaqayp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETrirbcjqexj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETroicoecifm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETrpcibmxvpc.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETrppplwtsox.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETsbaohbbcxe.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETscrlckapgi.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETsegickkosj.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETsevpusyapu.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETsmqbvfulmx.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETtalknbpavo.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETtfdxwreewi.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETthqmjsotaf.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETubqresjtuw.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETufxgcixlob.tmp 18944 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.refparser.golive_2.0.0\res\Settings\MarkupGlue\html\chtml\com.adobe.versioncue.controller.imprt.jar 66145 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.refparser.golive_2.0.0\res\Settings\MarkupGlue\html\chtml\META-INF 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.refparser.golive_2.0.0\res\Settings\MarkupGlue\html\chtml\plugin.xml 1386 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\Communicator 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\FileMapping 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\ImportFromPrint 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\InCopy 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\MarkupGlue 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\SiteDesign 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\SiteSettings 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\UserAgentProfile 0 bytes
—- EOF - GMER 1.0.15 —-
(((((((((((((((((((((((((((((((((((((( Next Report )))))))))))))))))))))))))))))))))))))))
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/15 03:29
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
——————-
Name: aujasnkj.sys
Image Path: C:\DOCUME~1\MSU\LOCALS~1\Temp\aujasnkj.sys
Address: 0xECB6C000 Size: 83584 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xEDF89000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7AA9000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xECE27000 Size: 49152 File Visible: No Signed: -
Status: -
Name: SKYNETamhiybct.sys
Image Path: C:\WINDOWS\system32\drivers\SKYNETamhiybct.sys
Address: 0xEE27B000 Size: 163840 File Visible: - Signed: -
Status: Hidden from the Windows API!
Hidden/Locked Files
——————-
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: C:\WINDOWS\system32\SKYNETfmuwqjol.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\SKYNETohiwtosy.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\SKYNETvksnbaim.dat
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\SKYNETwkwqqltk.dat
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETjgcynmwpmi.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETqndxgbxtit.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETuxmjvweiip.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETvjpxrorcnn.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETvsectplabn.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETwdkbrewhtv.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETwpcvkorori.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETwpcynvxufp.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETxdutojutlv.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETyaprpepuqs.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETygxnboteof.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\T30DebugLogFile.txt
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\Temporary Internet Files
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\teredo.txt
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\Thumbs.db
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\uxeventlog.txt
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\WebPoolFileFile
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\_coInst.log
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\_scan_buttons.log
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETjmlfucnhsf.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETjqqdalrjsr.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETkdbynxgade.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETkjenuscexn.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETkmwsonlycx.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETlbdworvjki.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETleaxjatqnt.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETljgjxvawui.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETlqmbvgfcpb.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETlyigqyontl.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETmahuymspyl.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETmuidvvummp.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETnrfuyrfdax.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETnrhrulmomy.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNEToiorjkiknv.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETopviyqgtel.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETortbfxpesu.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETpmduckppkb.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETprhqcdxbqo.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETptepusfwhq.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETpyqrnsmapj.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETqdrtfnnvnn.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETqelogcofpy.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETapvaxratpw.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETaqslhyvwne.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETbdgcxjkipm.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETbrxejfifny.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETbulfxmptcn.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETbyfnkwtbru.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETcakoquqlog.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETchutnjwvja.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETcqcjomoiib.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETcsgwgqauyh.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETdfwbwhjfva.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETelercajvdj.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETevccrpprrn.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETevrknosdmn.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETfesucvpmta.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETfvnqnsvmti.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETfvtaknvrad.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETgekyjcxjib.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNEThofqoqrljc.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETifxrximird.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETikxsgefuso.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETisvjkpacjr.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETitnvoiwgbg.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETixqfiivxap.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETixvlhmxmdb.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETqpxodlccpq.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETqqmdevsjsu.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETqwdfvaqayp.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETrirbcjqexj.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETroicoecifm.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETrpcibmxvpc.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETrppplwtsox.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETsbaohbbcxe.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETscrlckapgi.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETsegickkosj.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETsevpusyapu.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETsmqbvfulmx.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETtalknbpavo.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETtfdxwreewi.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETthqmjsotaf.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETubqresjtuw.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\SKYNETufxgcixlob.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\drivers\SKYNETamhiybct.sys
Status: Invisible to the Windows API!
Path: c:\windows\softwaredistribution\eventcache\{c0869723-c560-4179-9175-e41ada305cd4}.bin
Status: Allocation size mismatch (API: 8, Raw: 0)
Stealth Objects
——————-
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: winlogon.exe (PID: 1256) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: services.exe (PID: 1304) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: lsass.exe (PID: 1316) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETfmuwqjol.dll]
Process: svchost.exe (PID: 1480) Address: 0x008d0000 Size: 57344
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1480) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1584) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1648) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1756) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1940) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: Explorer.EXE (PID: 2044) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: spoolsv.exe (PID: 672) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 336) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: VersionCueCS2.exe (PID: 412) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: AppleMobileDeviceService.exe (PID: 432) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: avgwdsvc.exe (PID: 456) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: Avsynmgr.exe (PID: 548) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: jqs.exe (PID: 164) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1024) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: VsStat.exe (PID: 1216) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: Vshwin32.exe (PID: 1492) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: avgrsx.exe (PID: 1860) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: Avconsol.exe (PID: 928) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: mysqld-nt.exe (PID: 2236) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: Mcshield.exe (PID: 2628) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: alg.exe (PID: 2916) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: hkcmd.exe (PID: 3160) Address: 0x00890000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: SynTPLpr.exe (PID: 3176) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: SynTPEnh.exe (PID: 3192) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: tfswctrl.exe (PID: 3200) Address: 0x00920000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: issch.exe (PID: 3368) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: jusched.exe (PID: 3544) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: VersionCueCS2Tray.exe (PID: 3560) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: avgtray.exe (PID: 3576) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: QTTask.exe (PID: 3584) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: iTunesHelper.exe (PID: 3612) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: ctfmon.exe (PID: 3624) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: DLG.exe (PID: 3664) Address: 0x00d70000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: iPodService.exe (PID: 2032) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 880) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: iexplore.exe (PID: 3816) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: avgnsx.exe (PID: 10692) Address: 0x10000000 Size: 32768
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: RootRepeal.exe (PID: 12088) Address: 0x10000000 Size: 32768
Hidden Services
——————-
Service Name: SKYNETgixetjlb
Image Path: C:\WINDOWS\system32\drivers\SKYNETamhiybct.sys
==EOF==