thanks
Topic Starter
I ran malbytesware, and it removes everything except for uacinit.dll. I ran AVG, McAfee, Avira, and I ran them all in "safe" mode, too, but they haven't been able to remove it. After reading a similar post for this virus, I came across root repeal…here is my root repeal logs, please help, thanks:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/12 13:09
Program Version: Version 1.3.3.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB9EF4000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
——————-
Path: C:\WINDOWS\system32\UACbtdelrumup.dat
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACdethwixoro.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\uacinit.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACkmssblntyx.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACqpwtkvvxai.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACqpxwippatf.db
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACupdpyvymxf.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACvkonqrvrjx.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\UAC6116.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\UAC6b57.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\UAC8400.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\UACdcd3.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\drivers\UACrnirrsklvm.sys
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temp\UACa566.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\IVPBNGAM\backcookie[1].js
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\IVPBNGAM\jump1[5].htm
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\RHTA9DTY\banners[1].js
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\RHTA9DTY\bgcategoriestop[1].jpg
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\RHTA9DTY\bgheader[1].jpg
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\RHTA9DTY\logo[1].jpg
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\adx[1].js
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\backcookie[3].js
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\bighealthtree[1].swf
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\btnsearch[1].jpg
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\btnsubmit[1].jpg
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Jared Goodman\Local Settings\Temporary Internet Files\Content.IE5\XZ9ZTV4W\__utm[4].gif
Status: Visible to the Windows API, but not on disk.
Stealth Objects
——————-
Object: Hidden Module [Name: UACdethwixoro.dll]
Process: winlogon.exe (PID: 628) Address: 0x10000000 Size: 49152
Object: Hidden Module [Name: UACdethwixoro.dll]
Process: services.exe (PID: 676) Address: 0x10000000 Size: 49152
Object: Hidden Module [Name: UACdethwixoro.dll]
Process: lsass.exe (PID: 688) Address: 0x10000000 Size: 49152
Object: Hidden Module [Name: UAC8400.tmpqrvrjx.dll]
Process: svchost.exe (PID: 860) Address: 0x10000000 Size: 217088
Object: Hidden Module [Name: UACdethwixoro.dll]
Process: svchost.exe (PID: 860) Address: 0x00760000 Size: 49152
Object: Hidden Module [Name: UACkmssblntyx.dll]
Process: svchost.exe (PID: 860) Address: 0x00a60000 Size: 73728
Object: Hidden Module [Name: UAC8400.tmpqrvrjx.dll]
Process: svchost.exe (PID: 936) Address: 0x10000000 Size: 217088
Object: Hidden Module [Name: UACdethwixoro.dll]
Process: MsMpEng.exe (PID: 1008) Address: 0x10000000 Size: 49152
Object: Hidden Module [Name: UAC8400.tmpqrvrjx.dll]
Process: svchost.exe (PID: 1064) Address: 0x10000000 Size: 217088
Object: Hidden Module [Name: UAC8400.tmpqrvrjx.dll]
Process: svchost.exe (PID: 1140) Address: 0x10000000 Size: 217088
Object: Hidden Module [Name: UAC8400.tmpqrvrjx.dll]
Process: svchost.exe (PID: 1216) Address: 0x10000000 Size: 217088
Object: Hidden Module [Name: UACdethwixoro.dll]
Process: Explorer.EXE (PID: 196) Address: 0x10000000 Size: 49152
Object: Hidden Module [Name: UACdethwixoro.dll]
Process: ctfmon.exe (PID: 468) Address: 0x10000000 Size: 49152
Object: Hidden Module [Name: UACvkonqrvrjx.dll]
Process: firefox.exe (PID: 1324) Address: 0x10000000 Size: 217088
Object: Hidden Module [Name: UACdethwixoro.dll]
Process: RootRepeal.exe (PID: 380) Address: 0x10000000 Size: 49152
Object: Hidden Module [Name: UACvkonqrvrjx.dll]
Process: Iexplore.exe (PID: 2284) Address: 0x10000000 Size: 217088
Hidden Services
——————-
Service Name: UACd.sys
Image Path: C:\WINDOWS\system32\drivers\UACrnirrsklvm.sys
==EOF==