Hi
Read Carefully
You have 2 Infections and we will take care of one at a time. UAC first the the Kungsf hopefully
Take and CD's and DVD's out of your optical drives.
Now go to this thread and download Avenger http://community.norton.com/norton/board/message?board.id=nis_feedback&message.id=53509#M53509
When you get to number 3 on the post use the Script below instead,
3. In the "Input script here:" copy and paste the script between the lines
Drivers to disable:
UACd.sys
gxvxcserv.sys
gaopdxserv.sys
gxvxcserv
Drivers to delete:
UACd.sys
gxvxcserv.sys
gaopdxserv.sys
gxvxcserv
Files to delete:
C:\Autorun.inf
D:\Autorun.inf
C:\WINDOWS\system32\gbnlwyeh.dll
C:\WINDOWS\system32\cpuesjq.dll
c:\WINDOWS\system32\mbjsgsl.dll
C:\WINDOWS\system32\wJQs.exe
C:\WINDOWS\system32\drivers\UACakcfxublxbeheme.sys
C:\RECYCLER\S-1-5-21-583907252-492894223-1343024091-1003\Dc1\UACakcfxublxbeheme.sys
C:\RECYCLER\S-1-5-21-583907252-492894223-1343024091-1003\Dc1\UACakcfxublxbeheme.sys(1)
C:\RECYCLER\S-1-5-21-583907252-492894223-1343024091-1003\Dc1\UACakcfxublxbeheme.sys(2)
C:\RECYCLER\S-1-5-21-583907252-492894223-1343024091-1003\Dc1\UACakcfxublxbeheme.sys(3)
C:\RECYCLER\S-1-5-21-583907252-492894223-1343024091-1003\Dc1\UACakcfxublxbeheme.sys(4)
C:\RECYCLER\S-1-5-21-583907252-492894223-1343024091-1003\Dc1\uachnoverfffpbbojg.dll
C:\RECYCLER\S-1-5-21-583907252-492894223-1343024091-1003\Dc1\uachnoverfffpbbojg.dll(1)
C:\WINDOWS\system32\uacinit.dll
C:\WINDOWS\system32\UACfwqvovmrcwvqxae.log
C:\WINDOWS\system32\UAChnoverfffpbbojg.dll
C:\WINDOWS\system32\UACikjwipoxduxtobi.dll
C:\WINDOWS\system32\uacvymnbtboeayohhs.dll
C:\WINDOWS\system32\uacqciqunodfnlghrv.dll
C:\WINDOWS\system32\UACjhwhfownswugepx.dll
C:\WINDOWS\system32\UACmeuaqmivkbmnyrj.dll
C:\WINDOWS\system32\UACqrmyxiqpfquufol.dat
C:\WINDOWS\system32\UACwordlvukxekdgqo.dll
C:\WINDOWS\system32\UAC5b24.tmperfffpbbojg.dll
C:\WINDOWS\system32\drivers\gxvxcserv.sys
C:\WINDOWS\system32\gxvxccounter
C:\WINDOWS\System32\drivers\gaopdxserv.sys
C:\WINDOWS\system32\gaopdxl.dll
C:\WINDOWS\system32\drivers\gxvxcaithwuhtprrwopxgilalbaobwucrdslx.sys
C:\WINDOWS\system32\gxvxcxkfpxfxurntewmrfttjyqtsmsenqwgiw.dll
C:\WINDOWS\system32\drivers\gxvxcvxmuiisiusdatjuqfpdtmxbuqcecgbdn.sys
C:\Windows\system32\drivers\gxvxcxiearhjspghonrxymbbiyubogpqitydm.sys
C:\WINDOWS\system32\gxvxcbinpbppwhtjxomtyumcthxvnfelpofrx.dll
C:\Windows\system32\drivers\gxvxcxrtfmrhquqmdvrtxediopecmpvcsyenm.sys
C:\WINDOWS\system32\gxvxclglkjccpdximixpvxhosscccyavumnsg.dll
C:\WINDOWS\system32\gxvxcsemsdfpsspjugtwlscubooyseravfcwb.dll
C:\WINDOWS\system32\gxvxctsossroyfpamddlctxslrvqwpvkiweqq.dll
C:\WINDOWS\System32\drivers\gxvxcwcorbswuncunpcjblpdonpfagxrpuqdp.sys
C:\WINDOWS\Temp\UAC5f99.tmp
C:\WINDOWS\Temp\UACcf2c.tmp
C:\WINDOWS\Temp\UACf1b3.tmp
C:\WINDOWS\Temp\UACfa8e.tmp
Folders to delete:
C:\resycled
D:\resycled
E:\resycled
F:\resycled
G:\resycled
H:\resycled
Registry keys to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\UAC
HKEY_LOCAL_MACHINE\SOFTWARE\gaopdx
HKEY_LOCAL_MACHINE\SOFTWARE\gxvxc
HKEY_LOCAL_MACHINE\SYSTEM\currentcontrolset\services\gaopdxserv.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\gxvxcserv.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UACd.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\UACd.sys
Then carry on with the other post from Screenshot and below.
Don't run Malwarebytes though.
I am crossing fingers that will break the UAC infection.
Quads