<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Malware problem in globalroot\systemroot (UAC) in Norton Internet Security / Norton AntiVirus</title>
    <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106452#M55798</link>
    <description>&lt;p&gt;Could you please post the Avenger log??  oh my bad, I see it. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I will spend time looking over the Avenger log and new rootrepeal log, looks like anothee .sys file, (different name)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I will also script the .exe file you stated, the Exe file might be reloading the rootkit, with new names. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Quads on &lt;/span&gt;&lt;span class="local-date"&gt;06-11-2009&lt;/span&gt;&lt;span class="local-time"&gt; 10:22 AM&lt;/span&gt;&lt;/div&gt;</description>
    <pubDate>Wed, 10 Jun 2009 22:22:48 GMT</pubDate>
    <dc:creator>Quads</dc:creator>
    <dc:date>2009-06-10T22:22:48Z</dc:date>
    <item>
      <title>Re: Malware problem in globalroot\systemroot</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106272#M55729</link>
      <description>&lt;p&gt;Quad,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I ran the rootrepeal and got a log which I have given below. Also I have pasted the log from GMER in &lt;a target="_blank" href="http://pastebay.com/21223"&gt;http://pastebay.com/21223&lt;/a&gt;. I did not get a luck yesterday to login to my system as the login screen did not come up at all. I like to give the exact name of UAC*.dll but I could not login and scan through Symantec Antivirus.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The log from rootrepeal is&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;ROOTREPEAL (c) AD, 2007-2008&lt;br&gt;==================================================&lt;br&gt;Scan Time:   2009/06/07 19:43&lt;br&gt;Program Version:  Version 1.2.3.0&lt;br&gt;Windows Version:  Windows XP SP2&lt;br&gt;==================================================&lt;/p&gt;&lt;p&gt;Drivers&lt;br&gt;-------------------&lt;br&gt;Name: dump_atapi.sys&lt;br&gt;Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys&lt;br&gt;Address: 0xAA87B000 Size: 98304 File Visible: No&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: dump_WMILIB.SYS&lt;br&gt;Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS&lt;br&gt;Address: 0xF7AFF000 Size: 8192 File Visible: No&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: rootrepeal.sys&lt;br&gt;Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys&lt;br&gt;Address: 0xA8C90000 Size: 45056 File Visible: No&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: UACdnkfrxllrmowqjk.sys&lt;br&gt;Image Path: C:\WINDOWS\system32\drivers\UACdnkfrxllrmowqjk.sys&lt;br&gt;Address: 0xAAAD1000 Size: 81920 File Visible: -&lt;br&gt;Status: Hidden from Windows API!&lt;/p&gt;&lt;p&gt;Stealth Objects&lt;br&gt;-------------------&lt;br&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: winlogon.exe (PID: 916) Address: 0x00790000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: winlogon.exe (PID: 916) Address: 0x006d0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: services.exe (PID: 964) Address: 0x00730000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: services.exe (PID: 964) Address: 0x00800000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: lsass.exe (PID: 976) Address: 0x00760000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: lsass.exe (PID: 976) Address: 0x00850000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACyirwbwwostypehq.dll]&lt;br&gt;Process: svchost.exe (PID: 1144) Address: 0x00c10000 Size: 69632&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: svchost.exe (PID: 1144) Address: 0x00730000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: svchost.exe (PID: 1144) Address: 0x007e0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UAC5040.tmpwaboulhcsxt.dll]&lt;br&gt;Process: svchost.exe (PID: 1144) Address: 0x00ae0000 Size: 200704&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: svchost.exe (PID: 1144) Address: 0x02740000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACsfsqwaboulhcsxt.dll]&lt;br&gt;Process: svchost.exe (PID: 1144) Address: 0x028e0000 Size: 200704&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: svchost.exe (PID: 1144) Address: 0x02ab0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACmpcxxnpkbpondir.dll]&lt;br&gt;Process: svchost.exe (PID: 1144) Address: 0x02b50000 Size: 53248&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: svchost.exe (PID: 1220) Address: 0x00730000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: svchost.exe (PID: 1220) Address: 0x007e0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: svchost.exe (PID: 1264) Address: 0x00730000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: svchost.exe (PID: 1264) Address: 0x007e0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: EvtEng.exe (PID: 1324) Address: 0x00ca0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: EvtEng.exe (PID: 1324) Address: 0x00d60000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: S24EvMon.exe (PID: 1416) Address: 0x00e10000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: S24EvMon.exe (PID: 1416) Address: 0x00ed0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: WLKeeper.exe (PID: 1472) Address: 0x00f10000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: WLKeeper.exe (PID: 1472) Address: 0x00fd0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: SR_Service.exe (PID: 1536) Address: 0x00b10000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: SR_Service.exe (PID: 1536) Address: 0x00bd0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: SR_WatchDog.exe (PID: 1652) Address: 0x009b0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: SR_WatchDog.exe (PID: 1652) Address: 0x00a70000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: svchost.exe (PID: 1712) Address: 0x00730000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: svchost.exe (PID: 1712) Address: 0x007e0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: svchost.exe (PID: 1808) Address: 0x00730000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: svchost.exe (PID: 1808) Address: 0x007e0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: ccSetMgr.exe (PID: 140) Address: 0x00720000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: ccSetMgr.exe (PID: 140) Address: 0x007e0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: ccEvtMgr.exe (PID: 256) Address: 0x00670000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: ccEvtMgr.exe (PID: 256) Address: 0x00730000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: spoolsv.exe (PID: 504) Address: 0x009b0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: spoolsv.exe (PID: 504) Address: 0x00a80000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: svchost.exe (PID: 572) Address: 0x00730000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: svchost.exe (PID: 572) Address: 0x007e0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: CdfSvc.exe (PID: 620) Address: 0x00740000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: CdfSvc.exe (PID: 620) Address: 0x00800000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: DefWatch.exe (PID: 640) Address: 0x009a0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: DefWatch.exe (PID: 640) Address: 0x00a70000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: NICCONFIGSVC.exe (PID: 820) Address: 0x00a00000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: NICCONFIGSVC.exe (PID: 820) Address: 0x00ad0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: RadeSvc.exe (PID: 1100) Address: 0x00b20000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: RadeSvc.exe (PID: 1100) Address: 0x00be0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: RegSrvc.exe (PID: 1456) Address: 0x00780000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: RegSrvc.exe (PID: 1456) Address: 0x00850000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: SavRoam.exe (PID: 1548) Address: 0x00730000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: SavRoam.exe (PID: 1548) Address: 0x00800000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: Rtvscan.exe (PID: 1588) Address: 0x00eb0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: Rtvscan.exe (PID: 1588) Address: 0x00f80000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: WLTRYSVC.EXE (PID: 1508) Address: 0x00a40000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: WLTRYSVC.EXE (PID: 1508) Address: 0x00980000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: bcmwltry.exe (PID: 1900) Address: 0x00e30000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: bcmwltry.exe (PID: 1900) Address: 0x00f00000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: Explorer.EXE (PID: 2800) Address: 0x009c0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: Explorer.EXE (PID: 2800) Address: 0x00d10000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: wmiprvse.exe (PID: 2936) Address: 0x00870000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: wmiprvse.exe (PID: 2936) Address: 0x00960000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: SR_GUI.Exe (PID: 3096) Address: 0x00c40000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: SR_GUI.Exe (PID: 3096) Address: 0x00f20000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: WLTRAY.exe (PID: 3188) Address: 0x00bc0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: WLTRAY.exe (PID: 3188) Address: 0x00c80000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: stsystra.exe (PID: 3196) Address: 0x00aa0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: stsystra.exe (PID: 3196) Address: 0x00b70000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: quickset.exe (PID: 3216) Address: 0x00e30000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: quickset.exe (PID: 3216) Address: 0x00f00000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: hkcmd.exe (PID: 3268) Address: 0x009d0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: hkcmd.exe (PID: 3268) Address: 0x00a90000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: igfxpers.exe (PID: 3348) Address: 0x00a40000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: igfxpers.exe (PID: 3348) Address: 0x00980000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: ctfmon.exe (PID: 3476) Address: 0x009b0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: ctfmon.exe (PID: 3476) Address: 0x00a80000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: igfxsrvc.exe (PID: 3516) Address: 0x00990000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: igfxsrvc.exe (PID: 3516) Address: 0x00a50000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: ccApp.exe (PID: 3544) Address: 0x008d0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: ccApp.exe (PID: 3544) Address: 0x009a0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: VPTray.exe (PID: 3664) Address: 0x009b0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: VPTray.exe (PID: 3664) Address: 0x00a80000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: jusched.exe (PID: 3740) Address: 0x00cc0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: jusched.exe (PID: 3740) Address: 0x00bf0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: ZCfgSvc.exe (PID: 3992) Address: 0x00f80000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: ZCfgSvc.exe (PID: 3992) Address: 0x01040000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: ifrmewrk.exe (PID: 4016) Address: 0x00e80000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: ifrmewrk.exe (PID: 4016) Address: 0x00f40000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: DoScan.exe (PID: 152) Address: 0x00980000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: DoScan.exe (PID: 152) Address: 0x00a40000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: realsched.exe (PID: 208) Address: 0x009a0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: realsched.exe (PID: 208) Address: 0x00a60000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: StartFX.exe (PID: 332) Address: 0x00970000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: StartFX.exe (PID: 332) Address: 0x00a30000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: NMBgMonitor.exe (PID: 1568) Address: 0x00990000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: NMBgMonitor.exe (PID: 1568) Address: 0x00a50000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: TosBtMng.exe (PID: 2508) Address: 0x00e70000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: TosBtMng.exe (PID: 2508) Address: 0x00f40000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: Dot1XCfg.exe (PID: 3528) Address: 0x00d50000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: Dot1XCfg.exe (PID: 3528) Address: 0x00ea0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: TosA2dp.exe (PID: 2296) Address: 0x00c60000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: TosA2dp.exe (PID: 2296) Address: 0x00d30000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: TosBtHid.exe (PID: 2324) Address: 0x003f0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: TosBtHid.exe (PID: 2324) Address: 0x00a40000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: TosBtHsp.exe (PID: 2280) Address: 0x00cb0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: TosBtHsp.exe (PID: 2280) Address: 0x00d90000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: iexplore.exe (PID: 2088) Address: 0x00a30000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: iexplore.exe (PID: 2088) Address: 0x00b00000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: svchost.exe (PID: 3044) Address: 0x00730000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: svchost.exe (PID: 3044) Address: 0x007e0000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: Iexplore.exe (PID: 2816) Address: 0x00a30000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: Iexplore.exe (PID: 2816) Address: 0x00b00000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: iexplore.exe (PID: 3640) Address: 0x00a30000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: iexplore.exe (PID: 3640) Address: 0x00b00000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: iexplore.exe (PID: 2212) Address: 0x00a30000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: iexplore.exe (PID: 2212) Address: 0x00b00000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: RootRepeal.exe (PID: 2256) Address: 0x00c10000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: RootRepeal.exe (PID: 2256) Address: 0x10000000 Size: 45056&lt;/p&gt;&lt;p&gt;Hidden Services&lt;br&gt;-------------------&lt;br&gt;Service Name: UACd.sys&lt;br&gt;Image Path: C:\WINDOWS\system32\drivers\UACdnkfrxllrmowqjk.sys&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Wed, 10 Jun 2009 08:56:22 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106272#M55729</guid>
      <dc:creator>gally</dc:creator>
      <dc:date>2009-06-10T08:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106274#M55730</link>
      <description>&lt;p&gt;Hi Gally, &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It is just about My bed time, I will study the logs, and tomorrow morning New Zealand time create the script and take it from there.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font face="courier new,courier" size="1" color="#ff0000"&gt;&lt;strong&gt;&amp;lt;&amp;lt;Edit: Edited the request to move the message to a new thread.&amp;gt;&amp;gt;&lt;/strong&gt;&lt;/font&gt; &lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="local-time"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by TomV on &lt;/span&gt;&lt;span class="local-date"&gt; 06-10-2009&lt;/span&gt;&lt;span class="local-time"&gt; 02:25 AM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Wed, 10 Jun 2009 09:25:44 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106274#M55730</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-10T09:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106276#M55731</link>
      <description>Thanks Quad</description>
      <pubDate>Wed, 10 Jun 2009 09:17:04 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106276#M55731</guid>
      <dc:creator>gally</dc:creator>
      <dc:date>2009-06-10T09:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106306#M55744</link>
      <description>&lt;p&gt;Maybe I will get to bed now,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I have 2 scripts to create now, to grab all the rootkit files,  .sys, .dll, .log, tmp, and reg entries&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Wed, 10 Jun 2009 11:24:26 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106306#M55744</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-10T11:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106424#M55787</link>
      <description>&lt;p&gt;Hi&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Funny, solved already&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;If you have Spybot S&amp;amp;D uninstall it &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Now  go to this post, Download Avenger &lt;a target="_blank" href="http://community.norton.com/norton/board/message?board.id=nis_feedback&amp;amp;message.id=53509#M53509"&gt;http://community.norton.com/norton/board/message?board.id=nis_feedback&amp;amp;message.id=53509#M53509&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;When you get to Number 3. use the script below&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;3. In the &amp;quot;Input script here:&amp;quot; copy and paste the script between the lines&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;p&gt;Drivers to disable:&lt;/p&gt;&lt;p&gt;UACd.sys&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Drivers to delete:&lt;/p&gt;&lt;p&gt;UACd.sys&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Files to delete:&lt;/p&gt;&lt;p&gt;C:\Autorun.inf&lt;/p&gt;&lt;p&gt;D:\Autorun.inf&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\wJQs.exe&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\drivers\UACakcfxublxbeheme.sys &lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\drivers\UACdnkfrxllrmowqjk.sys&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\uacinit.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACfwqvovmrcwvqxae.log&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UAChnoverfffpbbojg.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACikjwipoxduxtobi.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\uacvymnbtboeayohhs.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\uacqciqunodfnlghrv.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACjhwhfownswugepx.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACmeuaqmivkbmnyrj.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACqrmyxiqpfquufol.dat&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACwordlvukxekdgqo.dll &lt;/p&gt;&lt;p&gt;C:\Documents and Settings\user\Local Settings\Temp\UAC8ff7.tmp&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\drivers\UACdnkfrxllrmowqjk.sys&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACfoasddwfxtmqvpx.dat &lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UAClwmkyhhientbiem.log&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACmpcxxnpkbpondir.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACprqrqrqvsqjpwcv.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACsfsqwaboulhcsxt.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACxjpfmkusfwiswns.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACyirwbwwostypehq.dll &lt;/p&gt;&lt;p&gt;C:\WINDOWS\Temp\UAC5040.tmp&lt;/p&gt;&lt;p&gt;C:\WINDOWS\Temp\UACa4bb.tmp&lt;/p&gt;&lt;p&gt;C:\WINDOWS\Temp\UACa93c.tmp&lt;/p&gt;&lt;p&gt;C:\WINDOWS\Temp\UACe204.tmp&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACpragfvramewsyfs.log&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACjpbdqtxaqanyrcb.log                                                                                                           &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Registry keys to delete:&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SOFTWARE\UAC&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UACd.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\UACd.sys&lt;/p&gt;&lt;hr&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;p&gt;Then carry on with the other post from the screenshot and below&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Quads on &lt;/span&gt;&lt;span class="local-date"&gt;06-11-2009&lt;/span&gt;&lt;span class="local-time"&gt; 08:37 AM&lt;/span&gt;&lt;/div&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Quads on &lt;/span&gt;&lt;span class="local-date"&gt;06-11-2009&lt;/span&gt;&lt;span class="local-time"&gt; 08:42 AM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Wed, 10 Jun 2009 20:42:49 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106424#M55787</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-10T20:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106433#M55789</link>
      <description>&lt;p&gt;Our users know already that when Quads shows up the problem is SOLVED. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The original poster does have the option of changing his solved solution to the one that was most helpful.&lt;/p&gt;</description>
      <pubDate>Wed, 10 Jun 2009 20:46:53 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106433#M55789</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2009-06-10T20:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106449#M55796</link>
      <description>&lt;p&gt;Quads,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; I did as you told and saw lot of files got deleted. After that I ran a quick scan by my Symantec Antivirus. It detected a virus&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;c:\windows\system32\adptifn.exe.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I could see the particular file in that path but I am not sure if I can delete it. Also I rerun the rootrepeal and found the following log&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;ROOTREPEAL (c) AD, 2007-2008&lt;br&gt;==================================================&lt;br&gt;Scan Time:   2009/06/11 03:26&lt;br&gt;Program Version:  Version 1.2.3.0&lt;br&gt;Windows Version:  Windows XP SP2&lt;br&gt;==================================================&lt;/p&gt;&lt;p&gt;Drivers&lt;br&gt;-------------------&lt;br&gt;Name: aujasnkj.sys&lt;br&gt;Image Path: C:\DOCUME~1\user\LOCALS~1\Temp\aujasnkj.sys&lt;br&gt;Address: 0xA8EFF000 Size: 81664 File Visible: No&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: dump_atapi.sys&lt;br&gt;Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys&lt;br&gt;Address: 0xAA79D000 Size: 98304 File Visible: No&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: dump_WMILIB.SYS&lt;br&gt;Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS&lt;br&gt;Address: 0xF7AF3000 Size: 8192 File Visible: No&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: ezcak.sys&lt;br&gt;Image Path: C:\WINDOWS\system32\drivers\ezcak.sys&lt;br&gt;Address: 0xF77DD000 Size: 61440 File Visible: No&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: rootrepeal.sys&lt;br&gt;Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys&lt;br&gt;Address: 0xA8FFE000 Size: 45056 File Visible: No&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: UACdnkfrxllrmowqjk.sys&lt;br&gt;Image Path: C:\WINDOWS\system32\drivers\UACdnkfrxllrmowqjk.sys&lt;br&gt;Address: 0xAAABB000 Size: 81920 File Visible: -&lt;br&gt;Status: Hidden from Windows API!&lt;/p&gt;&lt;p&gt;Stealth Objects&lt;br&gt;-------------------&lt;br&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: winlogon.exe (PID: 944) Address: 0x00790000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: winlogon.exe (PID: 944) Address: 0x006d0000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: services.exe (PID: 992) Address: 0x00730000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: services.exe (PID: 992) Address: 0x00800000 Size: 49152&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACprqrqrqvsqjpwcv.dll]&lt;br&gt;Process: lsass.exe (PID: 1004) Address: 0x00760000 Size: 45056&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: UACxjpfmkusfwiswns.dll]&lt;br&gt;Process: lsass.exe (PID: 1004) Address: 0x00850000 Size: 49152&lt;/p&gt;&lt;p&gt;Hidden Services&lt;br&gt;-------------------&lt;br&gt;Service Name: UACd.sys&lt;br&gt;Image Path: C:\WINDOWS\system32\drivers\UACoijxikibfsvravy.sys&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Also I run the GMER and it highlighted one virus in red. It is&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Service         system32\drivers\UACoijxikibfsvravy.sys (*** hidden *** )                                                           [SYSTEM] UACd.sys                                                                                          &amp;lt;-- ROOTKIT !!!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I have attached the log of Avenger in the following path&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a target="_blank" href="http://pastebay.com/21394"&gt;http://pastebay.com/21394&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Is some serious virus still there in my system?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Gally&lt;/p&gt;</description>
      <pubDate>Wed, 10 Jun 2009 22:10:32 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106449#M55796</guid>
      <dc:creator>gally</dc:creator>
      <dc:date>2009-06-10T22:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106452#M55798</link>
      <description>&lt;p&gt;Could you please post the Avenger log??  oh my bad, I see it. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I will spend time looking over the Avenger log and new rootrepeal log, looks like anothee .sys file, (different name)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I will also script the .exe file you stated, the Exe file might be reloading the rootkit, with new names. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Quads on &lt;/span&gt;&lt;span class="local-date"&gt;06-11-2009&lt;/span&gt;&lt;span class="local-time"&gt; 10:22 AM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Wed, 10 Jun 2009 22:22:48 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106452#M55798</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-10T22:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106454#M55799</link>
      <description>&lt;p&gt;Delphinium,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I am new to this community and I thought that the green Solution button is having some link to solution and I clicked that. I am happy to tick the original solution post once my problem is resolved.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;But I am not sure still how to do that&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Gally&lt;/p&gt;</description>
      <pubDate>Wed, 10 Jun 2009 22:18:33 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106454#M55799</guid>
      <dc:creator>gally</dc:creator>
      <dc:date>2009-06-10T22:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106455#M55800</link>
      <description>&lt;p&gt;Quad,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The avenger log is present in the path&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a target="_blank" href="http://pastebay.com/21394"&gt;http://pastebay.com/21394&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Gally&lt;/p&gt;</description>
      <pubDate>Wed, 10 Jun 2009 22:24:15 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106455#M55800</guid>
      <dc:creator>gally</dc:creator>
      <dc:date>2009-06-10T22:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106457#M55801</link>
      <description>Yeah I updated my post just above above, my fault</description>
      <pubDate>Wed, 10 Jun 2009 22:26:04 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106457#M55801</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-10T22:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106474#M55808</link>
      <description>&lt;p&gt;Quads,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Its almost 5 in the morning here and I haven't sleep still as I want to remove this virus desperately. Also I will be out of station for 3 days this weekend. I will be available only tommorrow.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Can you please advice me if there is anything else needs to be done. I will look at it in the morning and take action.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Gally&lt;/p&gt;</description>
      <pubDate>Wed, 10 Jun 2009 23:11:45 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106474#M55808</guid>
      <dc:creator>gally</dc:creator>
      <dc:date>2009-06-10T23:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Malware problem in globalroot\systemroot (UAC)</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106504#M55815</link>
      <description>&lt;p&gt;Hi&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I have added the other &amp;quot;C:\WINDOWS\system32\drivers\UACoijxikibfsvravy.sys&amp;quot; file to the script and the &amp;quot;C:\windows\system32\adptifn.exe&amp;quot; file that seems to be a backdoor somewhat.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;This is what Avenger deleted from the first script&lt;/p&gt;&lt;hr&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;Driver &amp;quot;UACd.sys&amp;quot; deleted successfully&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\system32\drivers\UACdnkfrxllrmowqjk.sys&amp;quot; deleted successfully.&lt;/span&gt; &lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\system32\uacinit.dll&amp;quot; deleted successfully&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\Documents and Settings\user\Local Settings\Temp\UAC8ff7.tmp&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\system32\drivers\UACdnkfrxllrmowqjk.sys&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\system32\UACfoasddwfxtmqvpx.dat&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\system32\UAClwmkyhhientbiem.log&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\system32\UACmpcxxnpkbpondir.dll&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\system32\UACprqrqrqvsqjpwcv.dll&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\system32\UACsfsqwaboulhcsxt.dll&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\system32\UACxjpfmkusfwiswns.dll&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\system32\UACyirwbwwostypehq.dll&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\Temp\UACa4bb.tmp&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\Temp\UACa93c.tmp&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;File &amp;quot;C:\WINDOWS\Temp\UACe204.tmp&amp;quot; deleted successfully.&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;Registry key &amp;quot;HKEY_LOCAL_MACHINE\SOFTWARE\UAC&amp;quot; deleted successfully.&lt;/span&gt; &lt;/p&gt;&lt;hr&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Here is the new updated script&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;p&gt;Drivers to disable:&lt;/p&gt;&lt;p&gt;UACd.sys&lt;/p&gt;&lt;p&gt;UACdnkfrxllrmowqjk.sys&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Drivers to delete:&lt;/p&gt;&lt;p&gt;UACd.sys&lt;/p&gt;&lt;p&gt;UACdnkfrxllrmowqjk.sys&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Files to delete:&lt;/p&gt;&lt;p&gt;C:\Autorun.inf&lt;/p&gt;&lt;p&gt;D:\Autorun.inf&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\adptifn.exe&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\wJQs.exe&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\drivers\UACoijxikibfsvravy.sys&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\drivers\UACakcfxublxbeheme.sys &lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\drivers\UACdnkfrxllrmowqjk.sys&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\uacinit.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACfwqvovmrcwvqxae.log&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UAChnoverfffpbbojg.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACikjwipoxduxtobi.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\uacvymnbtboeayohhs.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\uacqciqunodfnlghrv.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACjhwhfownswugepx.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACmeuaqmivkbmnyrj.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACqrmyxiqpfquufol.dat&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACwordlvukxekdgqo.dll &lt;/p&gt;&lt;p&gt;C:\Documents and Settings\user\Local Settings\Temp\UAC8ff7.tmp&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\drivers\UACdnkfrxllrmowqjk.sys&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACfoasddwfxtmqvpx.dat &lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UAClwmkyhhientbiem.log&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACmpcxxnpkbpondir.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACprqrqrqvsqjpwcv.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACsfsqwaboulhcsxt.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACxjpfmkusfwiswns.dll&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACyirwbwwostypehq.dll &lt;/p&gt;&lt;p&gt;C:\WINDOWS\Temp\UAC5040.tmp&lt;/p&gt;&lt;p&gt;C:\WINDOWS\Temp\UACa4bb.tmp&lt;/p&gt;&lt;p&gt;C:\WINDOWS\Temp\UACa93c.tmp&lt;/p&gt;&lt;p&gt;C:\WINDOWS\Temp\UACe204.tmp&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACpragfvramewsyfs.log&lt;/p&gt;&lt;p&gt;C:\WINDOWS\system32\UACjpbdqtxaqanyrcb.log&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Registry keys to delete:&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SOFTWARE\UAC&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UACd.sys&lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\UACd.sys&lt;/p&gt;&lt;div&gt;&lt;hr&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Quads &lt;/div&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Thu, 11 Jun 2009 00:31:01 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Re-Malware-problem-in-globalroot-systemroot/m-p/106504#M55815</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-11T00:31:01Z</dc:date>
    </item>
  </channel>
</rss>

