06-10-2009 07:57 PM
ancp41 wrote:I dont think I used it as an administrator. What do I have to do now?
Ok when you clicked "Avenger.exe" did you use the right click menu and select "Run as adminstrator"??
Also, if on turn off the windows Firewall.
Quads
06-10-2009 08:01 PM
Windows firewall is off. And no.. I didnt right click and run as administrator. Sorry. I didnt know I was supposed to. Do I turn off the firewall on norton? And I still cant find the skynet.exe file. My search engine keeps saying No Search results.
06-10-2009 08:06 PM
Don't worry about the file you can't find as that is good.
Avenger with Vista need to run with Administrator rights See if that works
Right click "Avenger.exe" and click "Run as Administrator" then Avenger will start like before but with admin priviledges the you can place the script in again.
Quads
06-10-2009 08:14 PM
Ok... here's the new avenger log:
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows Vista
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Disablement of driver "SKYNETrdvvtnic" failed!
Status: 0xc0000001 (STATUS_UNSUCCESSFUL)
Error: could not open driver "SKYNETokvviotn.sys"
Disablement of driver "SKYNETokvviotn.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Driver "SKYNETrdvvtnic" deleted successfully.
Error: registry key "\Registry\Machine\System\CurrentControlSet\Servic
Deletion of driver "SKYNETokvviotn.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: could not delete file "C:\WINDOWS\system32\drivers\SKYNETokvviotn.sys"
Deletion of file "C:\WINDOWS\system32\drivers\SKYNETokvviotn.sys" failed!
Status: 0xc0000156
Error: could not delete file "C:\WINDOWS\System32\SKYNETmhxdfufx.dll"
Deletion of file "C:\WINDOWS\System32\SKYNETmhxdfufx.dll" failed!
Status: 0xc0000156
Error: could not delete file "C:\WINDOWS\System32\SKYNETtqsxqrwn.dll"
Deletion of file "C:\WINDOWS\System32\SKYNETtqsxqrwn.dll" failed!
Status: 0xc0000156
Error: could not delete file "C:\Windows\System32\SKYNETcodrxpyq.dat"
Deletion of file "C:\Windows\System32\SKYNETcodrxpyq.dat" failed!
Status: 0xc0000156
Error: file "C:\Windows\System32\SKYNETiuwjpohn.dat" not found!
Deletion of file "C:\Windows\System32\SKYNETiuwjpohn.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETbwqaec
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETbwqaec
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETbxxitn
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETbxxitn
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETcsbrwv
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETcsbrwv
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETevfpdx
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETevfpdx
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETfwtmvq
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETfwtmvq
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETorqwtf
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETorqwtf
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETovwpwd
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETovwpwd
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNEToxbbda
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNEToxbbda
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETqfohup
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETqfohup
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETtmdsve
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETtmdsve
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETvcjher
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETvcjher
Status: 0xc0000156
Error: could not delete file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETwptqip
Deletion of file "C:\Users\ahah\AppData\Local\Temp\Low\SKYNETwptqip
Status: 0xc0000156
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servi
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\SKYNET" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\SKYNET" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Completed script processing.
*******************
Finished! Terminate.
06-10-2009 08:33 PM
looks like it is time for me to CFScript with a kill switch. ti target those files.
Read from this message onwards on how myself and anothe poster used a CFScript to tartget files So you understand.
http://community.norton.com/norton/board/message?b
I will get scipting, it's slightly different.
Quads
06-10-2009 08:56 PM
Hi Quads...
When I went to the slingshot link for the CFScript.txt, it said ERROR page not found. what do I do?
06-10-2009 08:57 PM - edited 06-10-2009 08:58 PM
I have / am having to make you yor own script
Quads
06-10-2009 09:16 PM
I have PM ed you the script (yellow envelope)
You have to Copy everything between the lines then open Notepad, and paste it
Then save the .txt file as "CFScript.exe" and do the drag and drop it on top of Combofix.exe.
When combofix is running do not move the mouse to inside the box
Quads
06-10-2009 10:06 PM
Ok... i did the combofix thingy. I just wanted to know if it was normal that after it does what it needs to do it changes your background? But here's the combofix log.
ComboFix 09-06-09.06 - ahah 06/11/2009 14:52.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3002.1900 [GMT 10:00]
Running from: c:\users\ahah\Desktop\ComboFix.exe
Command switches used :: c:\users\ahah\Desktop\CFScript.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
SP: Norton Internet Security *disabled* (Updated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
06-10-2009 10:07 PM
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\IEToolbar
c:\windows\system32\drivers\SKYNETokvviotn.sys
c:\windows\system32\SKYNETcodrxpyq.dat
c:\windows\system32\SKYNETgcepqmpx.dat
c:\windows\system32\SKYNETixaxndrs.dat
c:\windows\system32\SKYNETmhxdfufx.dll
c:\windows\system32\SKYNETpwxtbpbn.dll
c:\windows\system32\SKYNETqxcoirod.dll
c:\windows\system32\SKYNETsigxirmp.dat
c:\windows\system32\SKYNETtqsxqrwn.dll
c:\windows\system32\SKYNETtvxectjx.dll
D:\Desktop.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETrdvvtnic
((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 )))))))))))))))))))))))))))))))
.
2009-06-11 04:55 . 2009-06-11 04:56 -------- d-----w- c:\users\ahah\AppData\Loca
2009-06-11 04:20 . 2009-06-11 04:54 -------- d---a-w- \Qoobox
2009-06-11 01:27 . 2009-06-11 03:11 -------- d-----w- \Avenger
2009-06-10 07:52 . 2009-06-10 07:52 -------- d-----w- c:\users\ahah\AppData\Roam
2009-06-10 07:52 . 2009-05-26 03:20 40160 ----a-w- c:\windows\system32\drivers\m
2009-06-10 07:52 . 2009-06-10 07:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-10 07:52 . 2009-06-10 07:52 -------- d-----w- c:\progra~2\Malwarebytes
2009-06-10 07:52 . 2009-05-26 03:19 19096 ----a-w- c:\windows\system32\drivers\m
2009-06-10 07:42 . 2009-06-10 07:42 -------- d-----w- c:\program files\Trend Micro
2009-06-10 06:52 . 2009-06-10 06:56 -------- d-sh--w- \Config.Msi
2009-06-10 05:55 . 2009-06-10 05:55 -------- d-----w- c:\users\ahah\AppData\Roam
2009-06-10 05:52 . 2009-06-10 06:56 -------- d-----w- c:\program files\Norton Internet Security
2009-06-10 05:50 . 2009-06-10 06:54 124464 ----a-w- c:\windows\system32\drivers\
2009-06-10 05:50 . 2009-06-10 06:54 -------- d-----w- c:\program files\Symantec
2009-06-10 05:44 . 2009-06-10 06:56 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-08 13:58 . 2009-06-08 13:58 -------- d-----w- c:\users\ahah\AppData\Loca
2009-06-08 07:36 . 2009-06-08 07:36 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-06-07 23:04 . 2006-10-26 09:58 30512 ----a-w- c:\windows\system32\mdimon.dl
2009-06-07 22:59 . 2009-06-07 22:59 -------- d-----w- c:\program files\Microsoft.NET
2009-06-07 22:56 . 2009-06-07 22:56 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-06-07 22:53 . 2009-06-07 22:53 -------- d--h--r- C:\MSOCache
2009-06-07 22:53 . 2009-06-07 22:53 -------- d--h--r- \MSOCache
2009-06-05 07:40 . 2009-06-05 07:40 -------- d-----w- c:\users\Administrator
2009-06-05 07:20 . 2009-06-05 07:20 -------- d-----w- c:\program files\iPod
2009-06-05 07:20 . 2009-06-05 07:20 -------- d-----w- c:\program files\iTunes
2009-06-05 07:18 . 2009-06-05 07:18 -------- d-----w- c:\program files\QuickTime
2009-06-05 07:15 . 2009-06-05 07:15 -------- d-----w- c:\users\ahah\AppData\Roam
2009-06-05 05:52 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocarda
2009-06-05 05:52 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\Presenta
2009-06-05 05:52 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt
2009-06-05 05:52 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\Presentat
2009-06-05 05:52 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.
2009-06-05 05:52 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\Presenta
2009-06-05 05:52 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\Presenta
2009-06-05 05:44 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dl
2009-06-05 05:44 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf
2009-06-05 05:44 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.
2009-06-05 05:44 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier
2009-06-05 05:44 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.
2009-06-05 05:41 . 2009-06-05 05:41 -------- d-----w- c:\users\ahah\AppData\Loca
2009-06-04 06:35 . 2009-06-05 08:40 -------- d-----w- c:\users\ahah\AppData\Roam
2009-05-26 03:28 . 2009-05-26 03:28 -------- d-----w- c:\progra~2\PlayFirst
2009-05-26 03:28 . 2009-05-26 03:28 -------- d-----w- c:\users\ahah\AppData\Roam
2009-05-26 03:26 . 2009-05-26 03:26 16 ----a-w- c:\windows\popcinfo.dat
2009-05-24 01:36 . 2009-05-24 01:36 -------- d-----w- c:\users\ahah\AppData\Roam
2009-05-16 00:36 . 2008-12-05 04:32 428544 ----a-w- c:\windows\system32\EncDec.d
2009-05-16 00:36 . 2008-12-05 04:32 293376 ----a-w- c:\windows\system32\psisdecd
2009-05-15 03:45 . 2009-05-17 01:58 -------- d-----w- c:\users\ahah\AppData\Loca
2009-05-15 03:02 . 2009-06-05 06:31 5972 ----a-w- c:\users\ahah\AppData\Local\d3
2009-05-15 00:27 . 2009-05-29 04:49 -------- d-----w- c:\users\ahah\AppData\Loca
2009-05-14 13:41 . 2009-05-14 13:41 -------- d-----w- c:\progra~2\LightScribe
2009-05-14 12:31 . 2008-10-22 01:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-05-14 12:27 . 2009-05-14 12:27 -------- d-----w- c:\program files\MSXML 4.0
2009-05-14 11:17 . 2008-12-16 05:31 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-05-14 11:17 . 2008-12-16 05:31 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-05-14 11:17 . 2008-12-16 03:29 8147456 ----a-w- c:\windows\system32\wmploc.
2009-05-14 11:15 . 2009-02-13 08:49 1255936 ----a-w- c:\windows\system32\lsasrv.
2009-05-14 11:15 . 2009-02-13 08:49 72704 ----a-w- c:\windows\system32\secur32.d
2009-05-14 11:15 . 2009-03-17 03:38 13824 ----a-w- c:\windows\system32\apilogen.
2009-05-14 11:15 . 2009-03-17 03:38 24064 ----a-w- c:\windows\system32\amxread.d
2009-05-14 11:15 . 2008-08-28 03:40 425472 ----a-w- c:\windows\system32\PhotoMet
2009-05-14 11:15 . 2008-08-28 03:40 347136 ----a-w- c:\windows\system32\WindowsC
2009-05-14 11:15 . 2008-08-28 03:40 712704 ----a-w- c:\windows\system32\WindowsC
2009-05-14 11:15 . 2008-11-01 03:44 28672 ----a-w- c:\windows\system32\Apphlpdm.
2009-05-14 11:15 . 2008-11-01 01:21 4240384 ----a-w- c:\windows\system32\GameUXL
2009-05-14 11:14 . 2008-11-27 04:43 268288 ----a-w- c:\windows\system32\schannel
2009-05-14 11:14 . 2008-06-23 01:59 2868736 ----a-w- c:\windows\system32\mf.dll
2009-05-14 11:14 . 2008-06-23 01:59 996352 ----a-w- c:\windows\system32\WMNetMgr
2009-05-14 11:14 . 2008-06-23 01:58 94720 ----a-w- c:\windows\system32\logagent.
2009-05-14 11:11 . 2009-02-09 03:10 2033152 ----a-w- c:\windows\system32\win32k.
2009-05-14 10:55 . 2008-09-18 04:56 125952 ----a-w- c:\windows\system32\wersvc.d
2009-05-14 10:55 . 2008-09-18 04:56 147456 ----a-w- c:\windows\system32\Faultrep
2009-05-14 10:42 . 2008-09-05 05:14 1191936 ----a-w- c:\windows\system32\msxml3.
2009-05-14 10:33 . 2008-08-12 03:39 443392 ----a-w- c:\windows\system32\win32spl
2009-05-14 10:32 . 2008-12-16 02:42 288768 ----a-w- c:\windows\system32\drivers\
2009-05-14 10:24 . 2008-10-21 05:25 1645568 ----a-w- c:\windows\system32\connect
2009-05-14 10:13 . 2008-10-22 03:57 241152 ----a-w- c:\windows\system32\Portable
2009-05-14 10:13 . 2008-12-06 04:42 376832 ----a-w- c:\windows\system32\winhttp.
2009-05-14 10:13 . 2008-10-21 05:25 296960 ----a-w- c:\windows\system32\gdi32.dl
2009-05-14 10:12 . 2008-08-27 01:05 212480 ----a-w- c:\windows\system32\drivers\
2009-05-14 10:12 . 2008-06-06 03:27 38912 ----a-w- c:\windows\system32\xolehlp.d
2009-05-14 10:12 . 2008-06-06 03:27 562176 ----a-w- c:\windows\system32\msdtcprx
2009-05-14 06:05 . 2008-09-10 03:40 1334272 ----a-w- c:\windows\system32\msxml6.
2009-05-13 17:11 . 2009-05-16 06:41 -------- d-----w- c:\users\ahah\AppData\Loca
2009-05-13 17:11 . 2009-05-13 17:11 -------- d-----w- c:\users\ahah\AppData\Roam
2009-05-13 17:11 . 2009-05-13 17:11 -------- dc----w- c:\windows\system32\DRVSTO
2009-05-13 17:11 . 2009-03-19 06:32 23400 ----a-w- c:\windows\system32\drivers\G
2009-05-13 17:11 . 2008-04-17 02:12 107368 ----a-w- c:\windows\system32\GEARAspi
2009-05-13 17:10 . 2009-05-13 17:11 -------- d-----w- c:\progra~2\{8CD7F5AF-ECFA
2009-05-13 17:10 . 2009-05-13 17:10 -------- d-----w- c:\program files\Bonjour
2009-05-13 17:09 . 2009-05-13 17:10 -------- d-----w- c:\progra~2\Apple Computer
2009-05-13 17:09 . 2009-05-13 17:09 -------- d-----w- c:\users\ahah\AppData\Loca
2009-05-13 17:09 . 2009-05-13 17:09 -------- d-----w- c:\program files\Apple Software Update
2009-05-13 17:08 . 2009-06-05 07:20 -------- d-----w- c:\program files\Common Files\Apple
2009-05-13 17:08 . 2009-05-13 17:08 -------- d-----w- c:\progra~2\Apple
2009-05-13 16:47 . 2009-06-09 02:55 -------- d-----w- c:\users\ahah\AppData\Roam
2009-05-13 15:37 . 2009-06-11 02:31 -------- d-----w- c:\users\ahah\AppData\Loca
2009-05-13 14:50 . 2009-05-13 14:50 -------- d-----w- c:\users\ahah\AppData\Roam
2009-05-13 14:18 . 2009-06-11 03:11 -------- d-----w- c:\users\ahah\Tracing
2009-05-13 14:17 . 2009-05-13 14:17 -------- d-----w- c:\program files\Microsoft
2009-05-13 14:16 . 2009-05-13 14:16 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-05-13 14:16 . 2009-05-13 14:17 -------- d-----w- c:\program files\Windows Live
2009-05-13 14:08 . 2009-05-13 14:08 -------- d-----w- c:\program files\Common Files\Windows Live
2009-05-13 13:43 . 2008-10-16 21:13 1809944 ----a-w- c:\windows\system32\wuaueng
2009-05-13 13:43 . 2008-10-16 21:09 51224 ----a-w- c:\windows\system32\wuauclt.e
2009-05-13 13:43 . 2008-10-16 21:09 43544 ----a-w- c:\windows\system32\wups2.dll
2009-05-13 13:43 . 2008-10-16 20:56 1524736 ----a-w- c:\windows\system32\wucltux
2009-05-13 13:43 . 2008-10-16 21:12 561688 ----a-w- c:\windows\system32\wuapi.dl
2009-05-13 13:43 . 2008-10-16 21:08 34328 ----a-w- c:\windows\system32\wups.dll
2009-05-13 13:43 . 2008-10-16 20:55 83456 ----a-w- c:\windows\system32\wudriver.
2009-05-13 13:43 . 2008-10-16 04:08 162064 ----a-w- c:\windows\system32\wuwebv.d
2009-05-13 13:43 . 2008-10-16 03:56 31232 ----a-w- c:\windows\system32\wuapp.exe
2009-05-13 09:52 . 2009-06-10 07:47 -------- d-----w- c:\users\ahah\AppData\Loca
2009-05-13 09:51 . 2009-05-13 09:51 -------- d-----w- c:\users\ahah\AppData\Roam
2009-05-13 09:51 . 2009-06-07 23:06 106944 ----a-w- c:\users\ahah\AppData\Local\
2009-05-13 09:45 . 2009-05-13 09:45 -------- d-----w- c:\users\ahah\AppData\Roam
