This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] uacinit.dll remove

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I ran malbytesware, and it removes everything except for uacinit.dll. I ran AVG, McAfee, Avira, and I ran them all in "safe" mode, too, but they haven't been able to remove it. After reading a similar post for this virus, I came across root repeal…here is my root repeal logs, please help, thanks: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/08/12 13:09 Program Version: Version 1.3.3.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xB9EF4000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: C:\WINDOWS\system32\UACbtdelrumup.dat Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\UACdethwixoro.dll Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\uacinit.dll Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\UACkmssblntyx.dll Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\UACqpwtkvvxai.dll Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\UACqpxwippatf.db Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\UACupdpyvymxf.dll Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\UACvkonqrvrjx.dll Status: Invisible to the Windows API! Path: C:\WINDOWS\Temp\UAC6116.tmp Status: Invisible to the Windows API! Path: C:\WINDOWS\Temp\UAC6b57.tmp Status: Invisible to the Windows API! Path: C:\WINDOWS\Temp\UAC8400.tmp Status: Invisible to the Windows API! Path: C:\WINDOWS\Temp\UACdcd3.tmp Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\drivers\UACrnirrsklvm.sys Status: Invisible to the Windows API! Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temp\UACa566.tmp Status: Invisible to the Windows API! Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\IVPBNGAM\backcookie[1].js Status: Invisible to the Windows API! Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\IVPBNGAM\jump1[5].htm Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\RHTA9DTY\banners[1].js Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\RHTA9DTY\bgcategoriestop[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\RHTA9DTY\bgheader[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\RHTA9DTY\logo[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\adx[1].js Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\backcookie[3].js Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\bighealthtree[1].swf Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\btnsearch[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\btnsubmit[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\__utm[4].gif Status: Visible to the Windows API, but not on disk. Stealth Objects ——————- Object: Hidden Module [Name: UACdethwixoro.dll] Process: winlogon.exe (PID: 628) Address: 0x10000000 Size: 49152 Object: Hidden Module [Name: UACdethwixoro.dll] Process: services.exe (PID: 676) Address: 0x10000000 Size: 49152 Object: Hidden Module [Name: UACdethwixoro.dll] Process: lsass.exe (PID: 688) Address: 0x10000000 Size: 49152 Object: Hidden Module [Name: UAC8400.tmpqrvrjx.dll] Process: svchost.exe (PID: 860) Address: 0x10000000 Size: 217088 Object: Hidden Module [Name: UACdethwixoro.dll] Process: svchost.exe (PID: 860) Address: 0x00760000 Size: 49152 Object: Hidden Module [Name: UACkmssblntyx.dll] Process: svchost.exe (PID: 860) Address: 0x00a60000 Size: 73728 Object: Hidden Module [Name: UAC8400.tmpqrvrjx.dll] Process: svchost.exe (PID: 936) Address: 0x10000000 Size: 217088 Object: Hidden Module [Name: UACdethwixoro.dll] Process: MsMpEng.exe (PID: 1008) Address: 0x10000000 Size: 49152 Object: Hidden Module [Name: UAC8400.tmpqrvrjx.dll] Process: svchost.exe (PID: 1064) Address: 0x10000000 Size: 217088 Object: Hidden Module [Name: UAC8400.tmpqrvrjx.dll] Process: svchost.exe (PID: 1140) Address: 0x10000000 Size: 217088 Object: Hidden Module [Name: UAC8400.tmpqrvrjx.dll] Process: svchost.exe (PID: 1216) Address: 0x10000000 Size: 217088 Object: Hidden Module [Name: UACdethwixoro.dll] Process: Explorer.EXE (PID: 196) Address: 0x10000000 Size: 49152 Object: Hidden Module [Name: UACdethwixoro.dll] Process: ctfmon.exe (PID: 468) Address: 0x10000000 Size: 49152 Object: Hidden Module [Name: UACvkonqrvrjx.dll] Process: firefox.exe (PID: 1324) Address: 0x10000000 Size: 217088 Object: Hidden Module [Name: UACdethwixoro.dll] Process: RootRepeal.exe (PID: 380) Address: 0x10000000 Size: 49152 Object: Hidden Module [Name: UACvkonqrvrjx.dll] Process: Iexplore.exe (PID: 2284) Address: 0x10000000 Size: 217088 Hidden Services ——————- Service Name: UACd.sys Image Path: C:\WINDOWS\system32\drivers\UACrnirrsklvm.sys ==EOF==
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

NEXT

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI