My first time every getting something I shouldn't have gotten, lol! Hope you can help. I clicked on a link to a web page, that I shouldn't have and got a popup saying I needed to update my Adobe. It looked good and I clicked away, thinking all was ok! When I did that another popup came and said I may be infected and it wanted me to click on their link, which of coarse I didn't! Instead I tried closing the windows, even with Ctrl-Alt-Del, it wouldn't let me. Then upon returning to my desktop, McAfee said something was trying to access and if I wanted to allow. Again, I said NO! The only way out seemed to reboot, which took some time to shutdown. When the system came back on I got a window saying Google installer had a problem and had to close, never had that before. It did have a "more info" link, which I clicked and a new window opened up saying something about UACD.SYS & WJQS.EXE! I knew I had a problem. After running McAfee, it said something about NTOSKRNL-HOOK and Generic RootKit.d!RootKit. Needless to say it didn't clean it and that started my online search. I would continue to get that popup, about Google Installer needing to close. Also when I did a search and would click on a link I would get the "WindowsClick" and was redirected to another web page.
Ok, try to make it short now,
I know a little about computing and tried a lot, nothing seemed to help until I read here and ran ComboFix, it seemed to work! Had to note some files "UAC******.dll and one UAC******.dat another was Service_Uac.sys, "*" equals random letters. I also ran Kaspersky Online Scan 7.0 and my McAfee again. Everything seems great; system is running normal and no more redirecting. Also, the two file listed in the Registry "UACD.SYS" and "WJQS.EXE" are both gone. Also, one of the programs, not sure which had placed those files I had to write down into a folder called C:\Qoobox\Quarantine.
I have the log file from ComboFix; I was hoping that someone could check it for me. Also, I was hoping to be able to just delete the whole directory "C:\Qoobox\”, not sure if that is acceptable. I read here a lot about different things I needed to do, it was also very helpful and informative. The firewall setting, the privacy setting, disabling the restore point before doing all this stuff. You guys are really great! I started out in the old days with my Commodore Vic-20; things have come a long way!
I know I should have talked with you guys before doing everything on my own. But I don't save any passwords on my computer and didn't want to take a chance accessing my email until I believed I was clean. So I couldn't join without opening my email. Also, I'm hoping that this Malware wasn't able to fully install, because I rebooted the system without clicking and I kept getting that Google Installer popup. Well that's it, I'll post the log file as soon as I am directed to!
Again, thank you guys so very much for being here and taking the time to help us less understanding people. I look forward to hearing back from you, have a great night.