![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Sep 2009
Posts: 2
OS: Windows 98
|
uacinit.dll
My AVG found a trojan horse this morning and couldn't get rid of it, so after doing a little online research I found Malwarebytes, which then found uacinit.dll. I did a little more research and found ComboFix which I ran. After it rebooted the log read:
ComboFix 09-09-03.02 - Meghan Harrison 09/03/2009 21:39.2.1 - NTFSx86 Running from: c:\documents and settings\Meghan Harrison\My Documents\download\Combo-Fix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\MEGHAN~1\LOCALS~1\Temp\catchme.dll c:\documents and settings\Meghan Harrison\Local Settings\temp\catchme.dll c:\windows\system32\Drivers\ksqzk.sys . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_lmrnkq ((((((((((((((((((((((((( Files Created from 2009-08-04 to 2009-09-04 ))))))))))))))))))))))))))))))) . 2009-09-03 19:05 . 2009-09-03 19:05 -------- dc----w- c:\program files\FileASSASSIN 2009-09-03 13:20 . 2009-09-03 13:20 -------- dc----w- c:\documents and settings\Meghan Harrison\Application Data\Malwarebytes 2009-09-03 13:19 . 2009-08-03 17:36 38160 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-03 13:19 . 2009-09-03 13:19 -------- dc----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-09-03 13:19 . 2009-09-03 13:20 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware 2009-09-03 13:19 . 2009-08-03 17:36 19096 -c--a-w- c:\windows\system32\drivers\mbam.sys 2009-08-29 22:59 . 2009-09-03 16:54 -------- dc----w- c:\program files\Common Files\Uninstall 2009-08-12 07:01 . 2009-08-12 07:01 -------- dc----w- c:\windows\ServicePackFiles . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-09-03 13:15 . 2005-05-06 03:10 -------- dc----w- c:\program files\Spybot - Search & Destroy 2009-09-02 19:19 . 2009-02-07 18:06 -------- dc----w- c:\documents and settings\All Users\Application Data\avg8 2009-08-19 13:10 . 2009-02-07 18:07 11952 -c--a-w- c:\windows\system32\avgrsstx.dll 2009-08-19 13:10 . 2009-02-07 18:07 335240 -c--a-w- c:\windows\system32\drivers\avgldx86.sys 2009-08-19 13:10 . 2009-02-07 18:07 27784 -c--a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-08-14 21:42 . 2005-05-08 04:48 -------- dc----w- c:\program files\Common Files\Palo Alto Software 2009-08-14 21:42 . 2005-05-08 04:47 -------- dc----w- c:\program files\Quicken 2009-08-05 09:11 . 2004-08-04 11:00 204800 -c--a-w- c:\windows\system32\mswebdvd.dll 2009-07-17 18:55 . 2004-08-04 11:00 58880 -c--a-w- c:\windows\system32\atl.dll 2009-07-13 14:08 . 2004-08-04 11:00 286720 -c--a-w- c:\windows\system32\wmpdxm.dll 2009-07-08 20:16 . 2006-11-14 02:17 -------- dc----w- c:\documents and settings\Meghan Harrison\Application Data\U3 2009-06-26 15:59 . 2004-08-04 11:00 668160 -c----w- c:\windows\system32\wininet.dll 2009-06-26 15:59 . 2004-08-04 11:00 81920 -c--a-w- c:\windows\system32\ieencode.dll 2009-06-16 14:55 . 2004-08-04 11:00 82432 -c--a-w- c:\windows\system32\fontsub.dll 2009-06-16 14:55 . 2004-08-04 11:00 119808 -c--a-w- c:\windows\system32\t2embed.dll 2009-06-12 11:50 . 2004-08-04 11:00 76288 -c--a-w- c:\windows\system32\telnet.exe 2009-06-10 14:21 . 2004-08-04 11:00 84992 -c--a-w- c:\windows\system32\avifil32.dll 2009-06-10 06:32 . 2006-11-17 08:02 132096 -c--a-w- c:\windows\system32\wkssvc.dll . ((((((((((((((((((((((((((((( SnapShot@2009-09-03_21.40.25 ))))))))))))))))))))))))))))))))))))))))) . - 2005-03-21 12:31 . 2009-09-03 21:34 53436 c:\windows\SYSTEM32\PERFC009.DAT + 2005-03-21 12:31 . 2009-09-03 21:44 53436 c:\windows\SYSTEM32\PERFC009.DAT + 2005-03-21 12:31 . 2009-09-03 21:44 381692 c:\windows\SYSTEM32\PERFH009.DAT - 2005-03-21 12:31 . 2009-09-03 21:34 381692 c:\windows\SYSTEM32\PERFH009.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AIM"="c:\program files\AIM\aim.exe" [2005-08-05 67160] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 36975] "IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184] "DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 86016] "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592] "mmtask"="c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2004-09-14 53248] "RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-03-21 26112] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035] "WinampAgent"="c:\program files\Winamp\Winampa.exe" [2002-04-26 12288] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928] "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688] "PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-12-04 406016] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 57344] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048] "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-02-12 188416] "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-02-12 77824] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-19 2007832] c:\documents and settings\Meghan Harrison\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2006-2-12 1425424] HotSync Manager.lnk - c:\program files\Sony Handheld\HOTSYNC.EXE [2005-3-25 299008] QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-08-19 13:10 11952 -c--a-w- c:\windows\SYSTEM32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\AIM\\aim.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [2/7/2009 2:07 PM 335240] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [2/7/2009 2:07 PM 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2/7/2009 2:07 PM 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2/7/2009 2:06 PM 297752] S2 lxalh;lxalh;c:\windows\system32\drivers\wyovvs.sys --> c:\windows\system32\drivers\wyovvs.sys [?] . Contents of the 'Scheduled Tasks' folder 2009-09-02 c:\windows\Tasks\Spybot - Search & Destroy.job - c:\progra~1\SPYBOT~1\SpybotSD.exe [2003-03-16 16:43] . . ------- Supplementary Scan ------- . uStart Page = hxxp://engwebmail.bu.edu/ mStart Page = hxxp://www.dell4me.com/myway uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Meghan Harrison\Application Data\Mozilla\Firefox\Profiles\08ks8hz4.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - plugin: c:\documents and settings\Meghan Harrison\Application Data\Mozilla\Firefox\Profiles\08ks8hz4.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07100121.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava11.dll FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava12.dll FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava13.dll FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava14.dll FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava32.dll FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMGWRAP.DLL FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-09-03 21:48 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\ . ------------------------ Other Running Processes ------------------------ . c:\program files\Lavasoft\Ad-Aware\aawservice.exe c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe c:\program files\Java\jre1.5.0_02\bin\jucheck.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Cisco Systems\VPN Client\cvpnd.exe c:\windows\SYSTEM32\wdfmgr.exe c:\windows\SYSTEM32\LVComS.exe c:\program files\AVG\AVG8\avgrsx.exe c:\progra~1\AVG\AVG8\avgnsx.exe c:\program files\AVG\AVG8\avgcsrvx.exe c:\program files\iPod\bin\iPodService.exe c:\windows\SYSTEM32\WSCNTFY.EXE . ************************************************************************** . Completion time: 2009-09-04 21:54 - machine was rebooted ComboFix-quarantined-files.txt 2009-09-04 01:53 ComboFix2.txt 2009-09-03 21:43 Pre-Run: 5,826,666,496 bytes free Post-Run: 5,722,808,320 bytes free 178 --- E O F --- 2009-08-26 07:00 I don't think it got rid of all the UAC components, what should I do next? Thanks. |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#3 (permalink) | |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,697
OS: 2000 Pro; XP Pro; XP Home
|
Re: uacinit.dll
Thanks for letting us know.
A Reminder....we do not want members to run Combofix on their own. As seen in Post #2 of our sticky topic 'NEW INSTRUCTIONS Read this Before Posting For Malware Removal Help' Quote:
Surf Safely, and Think Prevention! Since this issue is resolved, this topic will be archived.
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
| Thread Tools | |
|
|