Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Rootkit/Trojan uacinit.dll Please Help


  • This topic is locked This topic is locked
2 replies to this topic

#1 jmartinich

jmartinich

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:10:48 AM

Posted 21 July 2009 - 02:16 PM

Hello and thanks for any help.

I am the resident IT help at a small law firm. One of our machines running Windows XP Professional SP2 has been infected. Yesterday popups for fake security programs began appearing, one of which asked to uninstall AVG8 and began to after I made the mistake of closing the window, not ignoring it. Shortcuts to porn websites appeared on the desktop and endless popups made working practically impossible.

I disconnected the computer from our network and ran Malwarebytes by installing from a usb drive. I had to rename the install file and the application exe for it to work. After the first scan, restart and re-scan, Malwarebytes showed no infections. I plugged the computer back in, everything came back.

I unplugged the machine from the network again. I ran Malwarebytes in safe mode and regular mode several times. In safe mode, nothing shows up anymore, however, in regular mode, the following items are showing up:

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace)

Files Infected:
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent)

Malwarebytes is not doing the trick. I have the most recent version (I updated yesterday while it was plugged in).
I have a HJT log and the Malwarebytes log attached.

Thank you for any advice, help, etc.

Attached Files



BC AdBot (Login to Remove)

 


#2 jmartinich

jmartinich
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:10:48 AM

Posted 29 July 2009 - 11:52 PM

Resolved. I gave up trying to fix and just reformatted. Didn't have time to wait/research a solution. Thanks to any who tried to find an answer.

#3 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,801 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:01:48 PM

Posted 29 July 2009 - 11:56 PM

Hello

Thank you for letting us know. I'm sorry you had to reformat but glad that your computer problems have been fixed. Since this issue seems to be resolved, this thread will now be closed.

In case you experience any problems with the computer, please start a new topic.

Happy computing,

Orange Blossom :thumbup2:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users