This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Yet Another uacinit.dll Problem

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I came across a lot of threads about this particular piece of malware, many of them on this site. Since so many of the threads about this were resolved here, I thought that I'd register and see if I could find help for my problem as well. I'm running WIndows XP, sp 3. I've definitely got an infection. Malwarebytes' Anti-Malware comes up with two items each scan that it can't get rid of: uacinit.dll, and a registry key called HKEY_LOCAL_MACHINE/SOFTWARE\UAC (Malwarebytes has marked them as a trojan.agent and a rootkit.trace, respectively). No amount of scanning has with any utility has gotten rid of either of these files. My computer has been slowed down, and I had definite remote access one night, playing various audio clips. I am periodically presented with an error window cocnerning Google Installer. Also, I can no longer use system restore in any way. I'd post a Hijackthis log, except that I can't install it (double-clicking the icon does nothing, even after I've renamed it). I couldn't even run Malwarebytes until I'd renamed it. If anyone could help me at all, I'd greatly appreciate it.
Hello and :welcome:

My name is Perplexus and I will be helping you fix your computer problem.

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate, so stay with me until given the 'all clear' even if symptoms diminish. Lack of symptoms does not always mean the job is complete.

Before we proceed to clean your computer from malware there are some points you should consider that will make the process go smoother:
  • To make sure that you receive an email when this topic is updated, please click here and check that this topic is listed under Malware Removal and Spyware Removal.
  • Before beginning the fix, read this post completely. If there's anything that you do not understand, please ask your questions before proceeding as you may temporarily be disconnected from the internet. No question is considered dumb here. It's better to be safe than sorry!
  • Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions.
  • It is IMPORTANT that you do not miss a step & perform everything in the correct order/sequence.
  • Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested, as it can be very dangerous and cause harm to your system.
  • When posting logs, please ensure Wordwrap is turned off in Notepad (to check, open Notepad in the menubar click on Format and make sure that Word Wrap is unchecked)
———————————————————————————————

Download Combofix from any of the links below and save it to your desktop. You must rename it to Combo-Fix.exe before saving it.

Link 1
Link 2

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using FireFox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to Always ask me where to Save the files
  • During the download, rename it to Combo-Fix.exe as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important to rename it during the download and not after.
  • Please do not rename it to something other than what was indicated.
  • Make sure to do the following:
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause unpredictable results
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • Warning: ComboFix will disconnect your machine from the internet as soon as it starts.
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  • Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt log so we can continue cleaning the system.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
OK, here's the log:

ComboFix 09-08-30.01 - Kyle 08/30/2009 18:04.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.569 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.dat
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.lan
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.msi
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.par
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.res
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\instance.dat
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\mia.lib
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\Fonts\WPHV07NB.TTF
c:\windows\Installer\WMEncoder.msi
c:\windows\jestertb.dll
c:\windows\run.log
c:\windows\system32\bszip.dll
c:\windows\system32\drivers\UACyvtndpmuje.sys
c:\windows\system32\UACbrqlrulhhb.dll
c:\windows\system32\UACdqvdksrrjk.dll
c:\windows\system32\UACebxnyymnmo.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjtmxewpipx.dll
c:\windows\system32\UACkakjqfopvo.dll
c:\windows\system32\UACwdrexpkela.db

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys
——-\Legacy_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-30 )))))))))))))))))))))))))))))))
.

2009-08-30 20:20 . 2009-08-30 20:20 ——– d—–w- c:\program files\Common Files\LightScribe
2009-08-30 20:10 . 2009-08-30 20:10 ——– d—–w- c:\documents and settings\Kyle\Application Data\Acoustica
2009-08-30 20:09 . 2009-08-30 20:12 ——– d—–w- c:\program files\Acoustica CD Label Maker
2009-08-27 18:19 . 2009-08-27 18:19 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2009-08-22 13:13 . 2009-08-22 13:13 ——– d—–w- c:\documents and settings\Amy Kay Ollila\Application Data\McAfee
2009-08-20 00:13 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-08-19 19:19 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-19 19:17 . 2009-08-19 19:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-19 19:17 . 2009-08-19 19:17 ——– d—–w- c:\program files\Lavasoft
2009-08-19 18:49 . 2009-08-19 18:49 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-19 18:49 . 2009-08-19 18:49 ——– d—–w- c:\program files\Ace Utilities
2009-08-19 18:19 . 2009-08-03 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-19 18:19 . 2009-08-03 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-19 17:36 . 2009-08-19 17:36 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-18 08:04 . 2009-08-18 08:04 ——– d-sh–w- c:\documents and settings\Kyle\IECompatCache
2009-08-18 01:28 . 2009-08-18 01:28 ——– d—–w- c:\documents and settings\Kyle\Application Data\McAfee
2009-08-18 01:28 . 2009-08-18 01:28 127 —-a-w- c:\documents and settings\Kyle\Local Settings\Application Data\fusioncache.dat
2009-08-17 17:31 . 2009-08-17 17:32 ——– d—–w- c:\program files\AVI MPEG RM WMV Joiner
2009-08-17 04:24 . 2009-08-17 04:24 82632 —-a-w- c:\documents and settings\Amy Kay Ollila\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-15 23:02 . 2009-08-15 23:02 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-15 23:02 . 2009-08-15 23:02 ——– d—–w- c:\program files\MSBuild
2009-08-15 23:02 . 2009-08-15 23:02 ——– d—–w- c:\program files\Reference Assemblies
2009-08-15 23:00 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-15 23:00 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-15 23:00 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-15 23:00 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-15 23:00 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-15 23:00 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-15 23:00 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-15 23:00 . 2009-08-15 23:01 ——– d—–w- C:\deb76f555261a90c7710e8acc3d6b5
2009-08-14 06:53 . 2009-08-14 06:53 ——– d—–w- c:\documents and settings\Kyle\Local Settings\Application Data\My Games
2009-08-14 05:13 . 2009-08-14 05:13 ——– d—–w- c:\program files\Firaxis Games
2009-08-11 20:58 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-10 03:20 . 2009-08-11 09:07 ——– d—–w- c:\documents and settings\Kyle\Application Data\Family Project
2009-08-10 03:20 . 2009-08-10 03:19 695578 —-a-w- c:\documents and settings\Kyle\Application Data\Family Project\unins000.exe
2009-08-10 03:20 . 2009-08-08 06:54 647168 —-a-w- c:\documents and settings\Kyle\Application Data\Family Project\FAMILY.exe
2009-08-06 13:52 . 2009-08-06 13:52 152576 —-a-w- c:\documents and settings\Kyle\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-05 09:01 . 2009-08-05 09:01 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-03 04:18 . 2009-08-03 04:19 127872 —-a-w- c:\documents and settings\Kyle\Application Data\Move Networks\uninstall.exe
2009-08-03 04:18 . 2009-08-13 05:45 ——– d—–w- c:\documents and settings\Kyle\Application Data\Move Networks

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-24 22:04 . 2009-07-06 20:13 ——– d—–w- c:\documents and settings\Kyle\Application Data\ATI MMC
2009-08-24 21:01 . 2009-07-06 20:11 ——– d—–w- c:\documents and settings\All Users\Application Data\ATI MMC
2009-08-24 09:03 . 2009-03-09 22:33 ——– d—–w- c:\documents and settings\Kyle\Application Data\uTorrent
2009-08-20 00:38 . 2009-03-09 22:32 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-19 08:49 . 2009-04-23 17:29 ——– d—–w- c:\program files\C-Force
2009-08-18 19:03 . 2009-04-23 17:29 249856 ——w- c:\windows\Setup1.exe
2009-08-18 19:03 . 2009-04-23 17:29 73216 —-a-w- c:\windows\ST6UNST.EXE
2009-08-18 17:50 . 2009-08-18 17:50 784423 —-a-w- c:\windows\system32\xa.tmp
2009-08-18 05:36 . 2009-03-29 17:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Rosetta Stone
2009-08-18 01:28 . 2009-07-19 23:03 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-08-18 01:28 . 2009-03-11 00:08 82632 —-a-w- c:\documents and settings\Kyle\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-14 06:04 . 2005-07-27 13:29 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-06 13:53 . 2005-07-27 13:26 ——– d—–w- c:\program files\Java
2009-08-05 09:01 . 2004-08-10 17:51 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 04:19 . 2009-06-16 06:35 4183416 —-a-w- c:\documents and settings\Kyle\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-07-31 03:24 . 2009-07-27 04:40 ——– d—–w- c:\program files\sische
2009-07-25 10:23 . 2009-03-10 03:06 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-07-20 23:50 . 2009-07-19 23:17 ——– d—–w- c:\program files\McAfee
2009-07-20 23:49 . 2005-07-27 13:49 ——– d—–w- c:\program files\Symantec
2009-07-20 00:11 . 2005-07-27 13:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-19 23:19 . 2009-07-19 23:17 ——– d—–w- c:\program files\Common Files\McAfee
2009-07-19 23:18 . 2009-07-19 23:18 ——– d—–w- c:\program files\McAfee.com
2009-07-17 19:01 . 2004-08-10 17:50 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 15:08 . 2004-08-10 17:51 286720 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-07 08:01 . 2009-07-07 08:01 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-07-07 08:01 . 2009-07-07 08:01 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-07-06 20:02 . 2009-07-06 19:56 ——– d—–w- c:\program files\ATI Multimedia
2009-07-06 19:57 . 2009-07-06 19:57 ——– d—–w- c:\program files\Common Files\ATI
2009-07-06 18:41 . 2009-07-06 18:41 ——– d—–w- c:\documents and settings\Kyle\Application Data\X10 Commander
2009-07-03 17:09 . 2004-08-10 17:51 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-08-10 17:51 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-10 17:51 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-10 17:51 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-10 17:51 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-10 17:51 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-10 17:51 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-10 17:51 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-08-10 17:51 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-10 17:51 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 06:35 . 2009-06-16 06:35 97144 —-a-w- c:\documents and settings\Kyle\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-06-12 12:31 . 2004-08-10 17:51 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-11 07:44 . 2009-06-11 07:44 10134 —-a-r- c:\documents and settings\Kyle\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-10 14:19 . 2004-08-10 18:01 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2004-08-10 17:50 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2004-08-10 17:51 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-10 02:06 . 2009-06-10 02:06 152576 —-a-w- c:\documents and settings\Kyle\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-05 19:46 . 2009-06-17 22:55 2602720 -c–a-w- c:\documents and settings\All Users\Application Data\{AD1633B8-8F63-40E6-8A96-9AF47AC850E1}\Impulse_setup.exe
2009-06-05 14:57 . 2009-06-17 22:50 523120 -c–a-w- c:\documents and settings\All Users\Application Data\{AD1633B8-8F63-40E6-8A96-9AF47AC850E1}\OFFLINE\86D01CB6\597810BF\7za.exe
2009-06-05 14:56 . 2009-06-17 22:50 616696 -c–a-w- c:\documents and settings\All Users\Application Data\{AD1633B8-8F63-40E6-8A96-9AF47AC850E1}\OFFLINE\86D01CB6\597810BF\7z.dll
2009-06-05 14:55 . 2009-06-17 22:50 356352 -c–a-w- c:\documents and settings\All Users\Application Data\{AD1633B8-8F63-40E6-8A96-9AF47AC850E1}\OFFLINE\86D01CB6\757C30BC\ImpulseNow.exe
2009-06-03 19:09 . 2004-08-10 17:51 1291264 —-a-w- c:\windows\system32\quartz.dll
.

——- Sigcheck ——-

[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2004-08-04 10:00 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\ServicePackFiles\i386\TCPIP.SYS
[-] 2009-04-23 17:23 361600 D24EA301E2B36C4E975FD216CA85D8E7 c:\windows\system32\dllcache\TCPIP.SYS
[-] 2009-04-23 17:23 361600 D24EA301E2B36C4E975FD216CA85D8E7 c:\windows\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Google Update"="c:\documents and settings\Kyle\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-26 133104]
"ATI DeviceDetect"="c:\program files\ATI Multimedia\main\ATIDtct.EXE" [2004-07-30 69705]
"ATI Remote Control"="c:\program files\ATI Multimedia\RemCtrl\ATIRW.exe" [2004-07-08 196608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-13 344064]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"mmtask"="c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2004-09-14 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-07-27 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"McAfee Backup"="c:\program files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 4838952]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2005-7-27 156784]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-22 45056]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-7-27 24576]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 21:08 110592 —-a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/19/2009 2:19 PM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
S3 atinysxx;ATI USB 2.0 TV Audio Crossbar;c:\windows\system32\drivers\atinysxx.sys [3/16/2009 11:24 PM 93696]
S3 atinyvxx;ATI TV WONDER USB2.0 Video & Audio;c:\windows\system32\drivers\atinyvxx.sys [3/16/2009 11:24 PM 185344]
S3 ATITUNEP2;ATI TV WONDER USB2.0 TV Tuner;c:\windows\system32\drivers\atinyuxx.sys [3/16/2009 11:24 PM 75776]
S3 ATIUTD;ATI TV WONDER USB2.0 Device Driver;c:\windows\system32\drivers\ATIUTD.sys [3/16/2009 11:24 PM 38912]
S3 TTDec;ATI TV WONDER USB2.0 Teletext Decoder;c:\windows\system32\drivers\atinyttx.sys [3/16/2009 11:24 PM 13824]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-08-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]

2009-08-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1611299190-930597964-4189443988-1006Core.job
- c:\documents and settings\Kyle\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-26 23:58]

2009-08-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1611299190-930597964-4189443988-1006UA.job
- c:\documents and settings\Kyle\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-26 23:58]

2009-07-19 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-07-19 18:32]

2009-08-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-07-19 18:32]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-ATI Launchpad - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 85.131.208.2:3128
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: {CC036844-2068-4C6F-A8A8-F55F89CC8BFD} = 68.87.77.130
FF - ProfilePath - c:\documents and settings\Kyle\Application Data\Mozilla\Firefox\Profiles\j5xm0jzg.default\
FF - prefs.js: browser.startup.homepage - www.stthomas.edu
FF - plugin: c:\documents and settings\Kyle\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Kyle\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-30 18:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = c:\program files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1040)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2009-08-30 18:26
ComboFix-quarantined-files.txt 2009-08-30 23:26

Pre-Run: 1,967,595,520 bytes free
Post-Run: 6,912,602,112 bytes free

280 — E O F — 2009-08-26 06:12
Hi KyGuy196,

Looking better. Is your machine running better?

——————
Step 1:
——————

[external image: Posted Image]Run Malwarebytes' Anti-Malware
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

——————
Step 2:
——————

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

——————
Step 3:
——————

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply

——————
Step 4:
——————

Please post back with the following:
  • How your machine is running
  • MBAM log
  • KasReport.txt
Sorry it took me so long to post again- the Kapersky scan took 7 hours :blush: My computer is running much better now than it was before. I can use system restore, and the google installer has stopped popping up. I'll be at work all day, but I'll be able to post back again once I get home. Malwarebytes: Malwarebytes' Anti-Malware 1.40 Database version: 2719 Windows 5.1.2600 Service Pack 3 8/30/2009 7:21:12 PM mbam-log-2009-08-30 (19-21-12).txt Scan type: Quick Scan Objects scanned: 107847 Time elapsed: 6 minute(s), 0 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\xa.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. Kaspersky: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Monday, August 31, 2009 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, August 31, 2009 03:15:25 Records in database: 2730896 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Objects scanned: 220105 Threats found: 6 Infected objects found: 6 Suspicious objects found: 1 Scan duration: 06:56:11 File name / Threat / Threats count C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\Program Files\Xbox 360 Hack Pack RC1\Resources\Dev Tools\XexTool_v5.2\XexTool.exe Suspicious: Packed.Win32.Black.d 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACyvtndpmuje.sys.vir Infected: Rootkit.Win32.Agent.oxr 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\UACbrqlrulhhb.dll.vir Infected: Trojan.Win32.Tdss.anrc 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\UACdqvdksrrjk.dll.vir Infected: Packed.Win32.TDSS.y 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\UACjtmxewpipx.dll.vir Infected: Trojan.Win32.TDSS.amwo 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\UACkakjqfopvo.dll.vir Infected: Packed.Win32.TDSS.y 1 Selected area has been scanned.
Well done! Your log appears clean! :thumbup:

We're almost done. We need to do some clean up and get you on your way.

——————
Step 1:
——————

We need to remove all the tools that you have used. This is so that should you ever be re-infected, you will download updated versions.

Follow these steps to uninstall Combofix
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]
(This will remove all restore points to rid your machine of saved infected files and create a new restore point)

——————
Step 2:
——————

Download OTC by OldTimer to your desktop and run it

[external image: Posted Image]

  • Click Cleanup! to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.
Now delete any logs that you have left over on your desktop.

——————
Step 3:
——————

Download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
Note: It is a good idea to run TFC to clear out all your temp files every now and again. This helps to keep your computer running more efficiently. It also can assist in getting rid of files that may contain malicious code that could re-infect your computer.

——————
Step 4:
——————

It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Windows Updates are constantly being revised to combat the newest hacks and threats. Microsoft releases security updates that help your computer from becoming vunerable.

Please go to Microsoft's Windows Update and download all the critical updates to help prevent possible re-infection.

It is best if you have these set to download automatically.

Automatic Updates for Windows
  • Click Start.
  • Select Settings and then Control Panel.
  • Select Automatic Updates.
  • Click Automatic (recommended)
  • Choose a day and a time when you know the computer will be on and connected to the internet.
  • Click Apply then OK.

———————————————————————————————

This is a good time to set up protection against further attacks. Read our How Did I Get Infected In The First Place?. You need an antivirus that is continually updated, a good firewall, a spyware blocker, and a real time spyware program to prevent malware intrusions. Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

———————————————————————————————

Anti Spyware

Anti Spyware helps to eliminate certain types of infections. I would recommend getting these and running the scans at least twice a month. Also a real-time protector is beneficial to stop infections before they start. SpywareGuard is an excellent choice here.
Note: If you find your system slows down after installing any of these, just uninstall it, or disable it from running at startup.

———————————————————————————————

Safer Web Browser

Internet Explorer is not the most secure tool for browsing the web. It has been known to be very susceptible to infection, and there are some good free alternatives:
All are faster, safer, more powerful and functional free alternatives to Internet Explorer. It's definitely worth the short period of adjustment to start using one of these.

If you choose FireFox, here are a couple of addons that I recommend:
  • NoScript - for blocking ads and other potential website attacks
  • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must have if you do alot of Google searches.

———————————————————————————————

Other Recommendations

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated. Its important to keep programs up to date so that malware doesn't exploit any old security flaws.

Take Care and Happy Surfing! :wavey:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI