We suggest you to remove UACqqpxthwerx.sys from your computer as soon as possible.
UACqqpxthwerx.sys is Trojan/Backdoor.
Kill the file UACqqpxthwerx.sys and remove UACqqpxthwerx.sys from Windows startup.
Malware dropper: 224-clean.exe
Removed: C:\WINDOWS\system32\drivers\UACqqpxthwerx.sys
-------------------------------------------------------------------------------------
Classification:
Code:
Antivirus Version Last Update Result
F-Secure 8.0.14470.0 2009.10.12 -
Kaspersky 7.0.0.125 2009.10.12 Packed.Win32.TDSS.aa
McAfee 5769 2009.10.12 -
Microsoft 1.5101 2009.10.12 VirTool:Win32/Obfuscator.EW
NOD32 4501 2009.10.12 -
Symantec 1.4.4.12 2009.10.12 -
Additional information
File size: 149504 bytes
MD5 : d88fcacdc357d9b58e748cfe5cd1f43a
SHA1 : 2e5502248a26e9f18c5808121fbfd8da91659f7d
-------------------------------------------------------------------------------------
Installation
When the program is executed, it creates the following registry subkeys and values:
----------------------------------
Keys added:4
----------------------------------
HKLM\SOFTWARE\UAC
HKLM\SOFTWARE\UAC\injector
HKLM\SOFTWARE\UAC\versions
HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys
----------------------------------
Values added:7
----------------------------------
HKLM\SOFTWARE\UAC\injector\*: "uacbbr"
HKLM\SOFTWARE\UAC\affid: "224"
HKLM\SOFTWARE\UAC\type: "av"
HKLM\SOFTWARE\UAC\build: "bbr"
HKLM\SOFTWARE\UAC\subid: "clean"
HKLM\SOFTWARE\UAC\4d4512c1-1c75-4a76-9f64-9e8e6433f0df: ""
HKLM\SOFTWARE\UAC\val: 60 D6 38 9D 21 4C CA 01
----------------------------------
Values modified:4
----------------------------------
HKLM\SYSTEM\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Start: 0x00000002
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Start: 0x00000004
----------------------------------
Files added:7
----------------------------------
C:\Documents and Settings\Administrator\Local Settings\Temp\UAC8935.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\UAC8944.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\UAC8ea3.tmp
C:\WINDOWS\system32\drivers\UACqqpxthwerx.sys
C:\WINDOWS\system32\UACcrigivaswk.dat
C:\WINDOWS\system32\UACldcbnripmb.dll
C:\WINDOWS\system32\UACtbjgerapuy.dll
----------------------------------
Files deleted:1
----------------------------------
C:\sand-box\224-clean.exe
----------------------------------
Files [attributes?] modified:0
----------------------------------
----------------------------------
Folders added:0
----------------------------------
----------------------------------
Folders deleted:0
----------------------------------
----------------------------------
Total changes:23
----------------------------------
-------------------------------------------------------------------------------------
Internet activity:
Code:
HTTP POST http://updateadvanced.org/banner/proxy.p...
-------------------------------------------------------------------------------------
Detected by UnHackMe:
- none -
After first reboot detected by UnHackMe:
Item Name: UACd.sys
Author:
Related File: \systemroot\system32\drivers\UACqqpxthwerx.sys
Type: Services detected by Partizan
Removal Results: Success
Number of reboot: 1
-------------------------------------------------------------------------------------
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com
Removal: uactbjgerapuy.dll is removed by RegRun.
Download RegRun Suite. Click here.
Unzip downloaded file to any folder on your hard drive.
Open an executable file to start program installation.
Follow the installer instructions.
At the end of installing software on your computer you will be prompted
to run "Scan for Viruses".
Wait for a couple seconds to finish scanning.
Click on the "Fix Problems" button.
Is it serious?
|
The
programs is known as malware.
|
Item name:
|
uactbjgerapuy.dll
|
Click on the "Get it out!" button.

We suggest you to reboot your computer to be sure that your computer is
clean now.
Do not hesitate to contact us:
Support center
UnHackMe - Rootkit/Malware killer
Recommended:
RegRun Security Suite Platinum Detects and removes rootkits/malware/adware that your antivirus could not.
Vista Programs - full info...
What is hidden in MSDN?
.NET Secrets Revealed
Why software developers prefer Win32.FreeTechSecrets.com?
All Unix Manuals in Alphabetical Order
C# controls for .NET in 3 simple steps.
Constantly updated. Last update:
March 6 2010
We recommend! Click Here to Update All your PC's Outdated drivers
Would you like to add your opinion?