06-10-2009 06:36 PM
Hey Quads,
Do you need the avenger log for anything?
06-10-2009 06:41 PM
Yes Please,
Also can you happen to find a file called "skynet.exe"
Also the zipped avenger folder is in "C:\avenger" could you please upload to http://rapidshare.com/index.html and PM me the link so I can download
The you can see if the likes of Malwarebytes updated and Norton works
Quads
06-10-2009 06:42 PM
Here's the avenger log:
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows NT 6.0 (build 6001, Service Pack 1)
Thu Jun 11 11:22:50 2009
11:22:42: Warning: Skipping potentially dangerous line:
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servi
11:22:50: Error: Execution aborted by user!
//////////////////////////////////////////
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows Vista
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Disablement of driver "SKYNETrdvvtnic" failed!
Status: 0xc0000001 (STATUS_UNSUCCESSFUL)
Error: could not open driver "SKYNETokvviotn.sys"
Disablement of driver "SKYNETokvviotn.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Driver "SKYNETrdvvtnic" deleted successfully.
Error: registry key "\Registry\Machine\System\CurrentControlSet\Servic
Deletion of driver "SKYNETokvviotn.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: could not delete file "C:\WINDOWS\system32\drivers\SKYNETokvviotn.sys"
Deletion of file "C:\WINDOWS\system32\drivers\SKYNETokvviotn.sys" failed!
Status: 0xc0000156
Error: could not delete file "C:\WINDOWS\System32\SKYNETmhxdfufx.dll"
Deletion of file "C:\WINDOWS\System32\SKYNETmhxdfufx.dll" failed!
Status: 0xc0000156
Error: could not delete file "C:\WINDOWS\System32\SKYNETtqsxqrwn.dll"
Deletion of file "C:\WINDOWS\System32\SKYNETtqsxqrwn.dll" failed!
Status: 0xc0000156
Error: could not delete file "C:\Windows\System32\SKYNETcodrxpyq.dat"
Deletion of file "C:\Windows\System32\SKYNETcodrxpyq.dat" failed!
Status: 0xc0000156
Error: file "C:\Windows\System32\SKYNETiuwjpohn.dat" not found!
Deletion of file "C:\Windows\System32\SKYNETiuwjpohn.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETbwqaec
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETbwqaec
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETbxxitn
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETbxxitn
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETcsbrwv
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETcsbrwv
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETevfpdx
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETevfpdx
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETfwtmvq
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETfwtmvq
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETorqwtf
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETorqwtf
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETovwpwd
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETovwpwd
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNEToxbbda
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNEToxbbda
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETqfohup
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETqfohup
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETtmdsve
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETtmdsve
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETvcjher
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETvcjher
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETwptqip
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETwptqip
Status: 0xc0000156
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servi
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\
Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\SKYNET" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\SKYNET" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Completed script processing.
*******************
Finished! Terminate.
06-10-2009 06:54 PM
06-10-2009 06:57 PM
Hi
That is strange
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servi
11:22:50: Error: Execution aborted by user!
06-10-2009 07:00 PM
Use the Windows Search and type in Skynet.exe
Quads
06-10-2009 07:21 PM
I am trying to figure out why Avenger is not allowed to get the files. Did get reg entries and the service, for loading
What Security software do you have installed??
Did you run Avenger as Administrator??
Quads
06-10-2009 07:29 PM
06-10-2009 07:31 PM
I dont think I used it as an administrator. What do I have to do now?
06-10-2009 07:33 PM
