• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove windowsclick.com redirect [UACd.sys trojan]

Myantispyware team January 24, 2009    

Redirect to windowsclick.com site is a result of UACd.sys trojan activity. The trojan horse may represent security risk for the infected computer and uses rootkit-specific techniques designed to hide the software presence in the system.

Once infected, UACd.sys trojan blocks user access to security websites, search results in Google, Yahoo, MSN and other redirect you to windowsclick.com and other non related sites.

Use the following instructions to remove UACd.sys trojan.

Step 1: Disable UACd.sys trojan driver.

  • Right click the My computer icon. If you are using the non classic Start menu, then right click My computer icon on your Start button menu.
  • Click Properties.
  • Click Hardware Tab.
  • Click Device Manager.
  • In the top menu, click View and click Show Hidden Drivers.
  • Scroll down to non Plug and Play drivers.
  • Click + at left.
  • In the list of drivers right click UACd.sys.
  • Click Disable.
  • Click YES for confirm.
  • Close all windows and reboot your computer.

Step 2: Delete UACd.sys trojan driver and malware files.

  • Download Avenger from here and unzip to your desktop.
  • Run Avenger, copy,then paste the following text in Input script Box:

    Drivers to delete:
    UACd.sys

    Files to delete:
    C:\WINDOWS\system32\wJQs.exe

    Then click on ‘Execute’.

  • You will be asked Are you sure you want to execute the current script?. Click Yes.
  • You will now be asked First step completed — The Avenger has been successfully set up to run on next boot. Reboot now?. Click Yes.
  • Your PC will now be rebooted.

Step 3: Remove UACd.sys trojan files and any associated malware.

  • Download Malwarebytes Anti-Malware (MBAM). The program designed to quickly detect, destroy and prevent malware, spyware, trojans.
  • Once downloaded, close all programs and Windows on your computer (including this one).
  • Double-click on the icon named mbam-setup.exe to install the application.
  • When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select “Perform Quick Scan”, then click Scan.
  • MBAM will now start scanning your computer for malware. This process may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • MBAM will now delete all of the files and registry keys and add them to the quarantine.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

UACd.sys trojan creates the following files.

%System%\uacinit.dll
%System%\drivers\UAC[RANDOM CHARACTERS].sys
%System%\UAC[RANDOM CHARACTERS].dll
%System%\UAC[RANDOM CHARACTERS].log
%System%\UAC[RANDOM CHARACTERS].dat
%Temp%\tmp[RANDOM NUMBERS].tmp

If you need help with the instructions, then post your questions in our Spyware Removal forum.

Trojan Tutorials - HowTo

 Previous Post

How to remove Antivirus XP Pro (Delete instructions)

Next Post 

How to remove System Guard 2009 (Delete instructions)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

400 Comments

  1. Ace
    ― July 20, 2009 - 8:29 pm  Reply

    If you had a Paypal link for donations I would send you $10, all I can afford as a student.

    Your solution worked with a few bumps along the way.

    I spent “only” about 2 hours with other fixes til I found yours.

    Thanks!

  2. Patrik
    ― July 21, 2009 - 5:27 am  Reply

    Glad to help you 🙂

  3. Mo
    ― July 21, 2009 - 12:33 pm  Reply

    Patrik, can you please help me:

    Ok so..i couldnt do step 1, Because I could’nt find the filed that were stated.

    Step two worked well, after reboot however i got a message “Exception processing message c00000013 Paramerers 75b6bf7c 4 75 blah blah”
    And i just clicked cancel.

    My UACd still showed though (You see i have a Google Installer error, which is apparently a UACd.)

    Im stuck on the (MBAM) i downloaded it, but it wont open. I tried downloading the other one, didn’t work. I did close all windows, even restarted and the first thing i did was double click on the setup icon. But still it wont open, it just has that timer near mouse pointer and then nothing.

    Any help please?

    Regards,

    Mo

  4. Patrik
    ― July 21, 2009 - 10:35 pm  Reply

    Mo, ask for help at our Spyware removal forum.

  5. Jenni
    ― July 22, 2009 - 10:08 am  Reply

    Thank you so much!!!!!! This is amazing!!!!

  6. lp
    ― July 22, 2009 - 3:03 pm  Reply

    i followed the steps, and when i scanned, i keep getting the same results, and it tells me to restart. then i restart and scan again, and the same results show up again.

    how do i permanently get rid of it? =
    thanks in advance 🙂

  7. Deep
    ― July 22, 2009 - 7:28 pm  Reply

    If I download Avenger will it delete songs in itunes and delete word documents and pictures?

  8. Patrik
    ― July 22, 2009 - 10:24 pm  Reply

    “it tells me to restart” – whats it ? MBAM or Avenger ? Make a new topic at our Spyware removal forum.

  9. Patrik
    ― July 22, 2009 - 10:27 pm  Reply

    Deep, NO. Avenger will remove only malware files and drivers.

  10. Ryan Houston
    ― July 23, 2009 - 6:48 pm  Reply

    Thanks so much for this infrmation

    it is really helpful nd im really greatful

  11. Margaret
    ― July 23, 2009 - 7:57 pm  Reply

    THANK YOU!! This worked great! If you were here I would hug you!

  12. Big Dutchman
    ― July 24, 2009 - 6:49 am  Reply

    I have struggled with this too. Ran Avenger and now re-running MalwareBytes, so we’ll see.

    I was having the trouble with the trojan blocking the running (executing) of malwarebytes and other anti-crap software. I renamed the folders from the default during installation and went back & renamed the executible (m_bam.exe versus default of mbam.exe in the renamed MalwareBytes folder and it ran without issue.

  13. Joe Li
    ― July 29, 2009 - 9:02 am  Reply

    I have the Virus but I cant find it in the Device Manager. Does UACd.sys have another name?

  14. Patrik
    ― July 29, 2009 - 9:18 am  Reply

    Joe, skip first step.

  15. Joe Li
    ― July 29, 2009 - 9:26 am  Reply

    ok.

  16. Krupa
    ― July 29, 2009 - 9:47 am  Reply

    Hi, I have followed all the above instructions, and, after running the Malwarebytes scan it said to restart so it could remove the virus. Upon restart all was good, BUT THEN next morning i switch on comp and the same virus is back! it says Trojen.Agent – C:\WINDOWS\system32\uacinit.dll
    what can i do?
    Thanks

  17. Joe Li
    ― July 29, 2009 - 9:49 am  Reply

    Thanks a lot Patrik. My computer is now working all because of you. Your the best!! 🙂

  18. Patrik
    ― July 29, 2009 - 10:18 am  Reply

    Krupa, ask for help at our Spyware removal forum.

  19. cosmoe e
    ― July 30, 2009 - 11:19 pm  Reply

    Thanks three days of sheer confusion this is coldest trojan horse ive ever rode suggestions worked i was going nuts Malwarebytes frist progam worth paying for

  20. Casey
    ― July 31, 2009 - 4:16 pm  Reply

    Had to do second step because I don’t have the UACd.sys driver listed. Didn’t work.

  21. Casey
    ― July 31, 2009 - 5:36 pm  Reply

    I tried malwarebytes and I got the blue screen of death about 45 minutes into the scan. Avenger didn’t do anything. I use Trend Micro antivirus and it can’t find it. There’s nothing named UAC… anywhere in the registry or and device drivers. But I get problems when I try to open programs (they usually eventually open). Boxes pop up with the following three .dll’s:

    UACenjcvorlfpwrbqipf.dll
    UACmrfxxtjphbsufoebr.dll
    UACvtiobmqhdxerjkevd.dll

    I really have no idea what to do at this point. Any help is greatly appreciated.

  22. Patrik
    ― July 31, 2009 - 8:42 pm  Reply

    Casey, try to repeat step 2. Also you can ask for help at our Spyware removal forum.

  23. Joel
    ― August 2, 2009 - 9:50 am  Reply

    My computer is randonly playing ads and audio clips from the internet. How do I stop this?

    Also, I have installed Malware and tried to run it. I have renamed the mbam.exe file to other names as suggested above, but it still will not run.

    Help please!

  24. Patrik
    ― August 2, 2009 - 10:17 am  Reply

    Joel, if above instructions does not help you, than ask for help at our Spyware removal forum.

  25. Al
    ― August 4, 2009 - 9:20 am  Reply

    Thank you so much. Very good instructions and you helped people all the way. Works so well. I had a lot of malware so again thank you. 😀

  26. John
    ― August 4, 2009 - 11:55 am  Reply

    Worked perfectly! Saved my work computer. Thanks for the info!

  27. Matt
    ― August 5, 2009 - 4:21 pm  Reply

    This Windowsclick virus had me angry for a couple days. I thought i would have to reformat(and dont have a disk). Found this site/help quickly and.. poof,.,. gone like the wind! Thank you sooo much for the removal software. I feel safe again.LOL
    *after downloading, program wouldn’t open. I restarted the machine and everything went smooth. Thanks again!

  28. Robsta
    ― August 6, 2009 - 3:41 pm  Reply

    Wow I having huge issues with this and im pretty neat with PCs, could not load malabytes or antispyware to kill the malaware, kept redirecting me to websites i did not want. Loaded avanger and followed the command even though the first stage i never had that exact file in my non plug and play list, and it worked i can now install malaware and antispyware to kill any threat

    awesome job guys 100% genuine deal here, im happy

  29. Mario
    ― August 7, 2009 - 1:37 pm  Reply

    Step 1 didn’t work for me so I went on to the following steps and it seems that it worked. The only thing is that I couldn’t run MBAM after I download it. So I rebooted my machine and I did it in safe mode.
    Thanks so much for your help.

  30. Jeff
    ― August 7, 2009 - 11:03 pm  Reply

    Per the instruction in step 2, after I type the script to be run, before I click “execute” should I have any of the boxes checked? The “Scan for rootkits” box was checked by default. Should I leave it checked? What about the other box “Automatically disable any rootkits found”, should this be checked as well? I’m wondering if this might be why some people had problems and others didn’t after running step 2.

« Previous 1 … 9 10 11 12 13 14 Next »

Leave a Reply to Suny329 Cancel reply

New Guides

scam alert
Remove Searchernow.com Redirect: Chrome, Edge, Firefox
Avoid the ExLig.com Bitcoin Scam: Insights on Promo Code Frauds
scam alert
Denwex.com Review: Bitcoin Promo Codes as a Scam
scam alert
CEFOLEX.com Review: A Closer Look at the Bitcoin Promo Code Scam
The Bigexcoin.com Bitcoin Promo Code Scam: How to Stay Safe

Follow Us

Search

Useful Guides

Managed by your organization chrome virus
Chrome Managed by your organization malware removal guide
Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]
How to remove pop-up ads [Chrome, Firefox, IE, Opera, Edge]
adwcleaner
AdwCleaner – Review, How to use, Comments
Smart Captcha Virus redirect
What is a Virus that Redirects Web Pages? A Comprehensive Guide

Recent Guides

How to remove Antivirus XP Pro (Delete instructions)
How to remove Spyware Protect 2009 (Delete instructions)
How to remove Spyware Guard 2009 (Delete instructions)
How to remove Flash Disinfector protection (autorun.inf folder)
How to remove Conficker worm (Downadup or Kido)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.