I noticed that Jat90 - helper was helping "djseanpc" with almost the same problem I am having with the difference that I've run iOrbit 360 as well as almost every function of Advance System Care. I also use CCleaner (I've found this file to be very helpful in the past) - it finds a lot of "dust" so to speak. Anyway I was following along with Jat90's instructions for djseanpc until the thread ended.
My scans have verified that I have uacinit.dll - trojan (there were more but I quarantined them & they seem to have disappeared. I've restarted my computer after every scan & finding - in hopes that the antivirus did it's job with no avail - this is one "Tough" bug! My computer if it starts up - sometimes takes me cold booting 3 or 4 times - gives me that blue screen of death. Most of the time the error message is:
The driver is attempting to access memory beyond the end of the allocation.
--- However last night I received this one: IRQL_NOT_LESS_OR_EQUAL ** only the once though.
The only way I can "get into" my computer is through the various safe modes - I'm currently using safe mode with networking. I really don't want to reformat as I have absolutely no CD's with this computer - I bought it a yard sale last summer. It's a cheap Lenovo 3000 J Series - came with Vista - but I down graded (to keep my family happy) to Windows XP home Edition - bought the CD from one of those 2nd hand thrift stores - the drive won't read it anymore. Also when it did it contained Windows XP - the registration key & drivers and stuff for a Dell Inspiron. I did the downgrade Last Aug. /08 - everything worked up until the last 3 weeks.
I ran this "RootRepeal" tool as per Jat90's instructions for djseanpc and here's the results from that scan:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Time: 2009/07/04 08:56
Program Version: Version 1.3.0.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF6AA7000 Size: 49152 File Visible: No Signed: -
Status: -
Name: UACfrkdlitpstvymnboy.sys
Image Path: C:\WINDOWS\system32\drivers\UACfrkdlitpstvymnboy.sys
Address: 0xF736F000 Size: 81920 File Visible: - Signed: -
Status: Hidden from Windows API!
Hidden/Locked Files
-------------------
Path: C:\WINDOWS\system32\wuapi(2).dll
Status: Locked to the Windows API!
Path: C:\WINDOWS\system32\uacinit.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACiioyobjcttdmoldvi.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACjlipyisbyxcbpyetl.dat
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACmjapqeqeegreveyik.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACnitbakxisoreqvabn.db
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACsmpjfjptwhdrdtbsw.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\uactmp.db
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACxjblfcdlxlcxjaofe.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACykypawyltuhapdgxv.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\UAC9ad8.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\UACa5d5.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\UACa7a9.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\UACa8d2.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\UACa95f.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\UACa9fb.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\drivers\UACfrkdlitpstvymnboy.sys
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Joey\Local Settings\Temp\UACbcfb.tmp
Status: Invisible to the Windows API!
Path: c:\documents and settings\joey\local settings\temp\~df1634.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\joey\local settings\temp\~dffd6c.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: C:\Documents and Settings\Joey\Local Settings\Temporary Internet Files\Content.IE5\ZXVA5GEC\UAC_Telus[1].gif
Status: Invisible to the Windows API!
Path: c:\documents and settings\joey\local settings\application data\mozilla\firefox\profiles\2elsk4rq.default\cache\_cache_002_
Status: Size mismatch (API: 2768014, Raw: 2763918)
Path: C:\Documents and Settings\Joey\Local Settings\Application Data\Microsoft\Messenger\bobo-139@hotmail.com\SharingMetadata\flanagan_25@hotmail.com\DFSR\Staging\CS{23F11F13-087F-098D-5799-30753509E8E5}\01\10-{23F11F13-087F-098D-5799-30753509E8E5}-v1-{EF528CC3-E11D-4662-B6E7-A438E1DC5942}-v10-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Joey\Local Settings\Application Data\Microsoft\Messenger\kooljustindude@hotmail.com\SharingMetadata\bobbymcconnell66@msn.com\DFSR\Staging\CS{C8369811-54C7-5DC3-134B-1BD6D2723361}\01\10-{C8369811-54C7-5DC3-134B-1BD6D2723361}-v1-{147D6044-BC2D-4ED4-B4C0-9782C6CE3E73}-v10-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Joey\Local Settings\Application Data\Microsoft\CD Burning\New Folder\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\App_LocalResources\AppConfigHome.aspx.resx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Joey\Local Settings\Application Data\Microsoft\CD Burning\New Folder\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\App_LocalResources\AppConfigHome.aspx.resx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Stealth Objects
-------------------
Object: Hidden Module [Name: UACykypawyltuhapdgxv.dll]
Process: svchost.exe (PID: 1156) Address: 0x01010000 Size: 196608
Object: Hidden Module [Name: UACmjapqeqeegreveyik.dll]
Process: svchost.exe (PID: 1156) Address: 0x01320000 Size: 45056
Object: Hidden Module [Name: UACxjblfcdlxlcxjaofe.dll]
Process: svchost.exe (PID: 1156) Address: 0x013c0000 Size: 49152
Object: Hidden Module [Name: UACa7a9.tmpobjcttdmoldvi.dll]
Process: svchost.exe (PID: 1156) Address: 0x10000000 Size: 73728
Object: Hidden Module [Name: UACxjblfcdlxlcxjaofe.dll]
Process: Explorer.EXE (PID: 1184) Address: 0x00cd0000 Size: 49152
Object: Hidden Module [Name: UACmjapqeqeegreveyik.dll]
Process: Explorer.EXE (PID: 1184) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACxjblfcdlxlcxjaofe.dll]
Process: ctfmon.exe (PID: 1596) Address: 0x00a40000 Size: 49152
Object: Hidden Module [Name: UACmjapqeqeegreveyik.dll]
Process: ctfmon.exe (PID: 1596) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACxjblfcdlxlcxjaofe.dll]
Process: vzlogin.exe (PID: 1868) Address: 0x00dc0000 Size: 49152
Object: Hidden Module [Name: UACmjapqeqeegreveyik.dll]
Process: vzlogin.exe (PID: 1868) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACxjblfcdlxlcxjaofe.dll]
Process: IObit Security 360.exe (PID: 1940) Address: 0x010d0000 Size: 49152
Object: Hidden Module [Name: UACmjapqeqeegreveyik.dll]
Process: IObit Security 360.exe (PID: 1940) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACxjblfcdlxlcxjaofe.dll]
Process: IS360tray.exe (PID: 1980) Address: 0x00e60000 Size: 49152
Object: Hidden Module [Name: UACmjapqeqeegreveyik.dll]
Process: IS360tray.exe (PID: 1980) Address: 0x10000000 Size: 45056
Object: Hidden Module [Name: UACmjapqeqeegreveyik.dll]
Process: AWC.exe (PID: 212) Address: 0x01210000 Size: 45056
Object: Hidden Module [Name: UACxjblfcdlxlcxjaofe.dll]
Process: AWC.exe (PID: 212) Address: 0x01370000 Size: 49152
Object: Hidden Module [Name: UACmjapqeqeegreveyik.dll]
Process: firefox.exe (PID: 1224) Address: 0x00b90000 Size: 45056
Object: Hidden Module [Name: UACxjblfcdlxlcxjaofe.dll]
Process: firefox.exe (PID: 1224) Address: 0x00c40000 Size: 49152
Object: Hidden Module [Name: UACykypawyltuhapdgxv.dll]
Process: firefox.exe (PID: 1224) Address: 0x10000000 Size: 196608
Hidden Services
-------------------
Service Name: hjgruiuiyqbpjx
Image Path: C:\WINDOWS\system32\drivers\hjgruijcbrqpfx.sys
Service Name: UACd.sys
Image Path: C:\WINDOWS\system32\drivers\UACfrkdlitpstvymnboy.sys
==EOF==
Are you able to help help - or at least point me in the right direction? I really do appreciate any & all time & assistance with this. This is the only computer I have and if it goes ... well hopefully we can work together & get it fixed.
In the meantime I'm going to do some research on this trojan & keep the forum files open.