virus - Windows 7 UAC (user access control) is being disabled on every reboot

08
2014-07
  • Christian Thamer

    To put it simply, I noticed UAC was disabled so I enabled it. I was prompted to reboot the computer for the changes to take effect. Upon my reboot I checked the settings again as I hadn't disabled UAC in the first place. It was again set to off (never notify). For the heck of it I repeated the process a couple of more times. Same result each time.

    I have Microsoft Security Essentials running a full scan nightly so I should be protected from viruses. I also did an on demand scan with the online tool at www.antivirus.com. Nothing was found.

    Other than the fact that UAC is being disabled on each reboot I have no other reason to suspect a virus.

    So my question is does anyone have insight into if this is a possible problem with a virus or other malware changing my UAC settings on each boot or is it possibly a problem with Windows and UAC itself? If it is malware are there suggestions for other products outside of the ones I have used to detect and remove it.

  • Answers
  • Christian Thamer

    I finally figured out the cause of my problem. It was in fact malware. Unfortunately none of the various antivirus, malware and rootkit scanners I tried detected it so I had to figure it out through lots of googling.

    In my case the offender seems to be Hoax.Win32.BadJoke.Formatter.ct or something similar. It doesn't do any harm other than turning off UAC and eating up all my bandwidth by creating background connections to youtube and various google IPs.

    Further details can be found here. http://greatis.com/blog/how-to-remove-malware/removed-regsrv-exe-stdrt-exe.htm


  • Related Question

    uac - Change Windows 7 user account control settings for a particular program
  • Phenom

    Possible Duplicate:
    Elevated Priviliges for Startup Applications in Vista

    I have a particular program that whenever I run it the screen dims and a message appears saying that the program wants to make changes to the computer and should I allow it. I can make the message go away by lowering the user account control settings but I don't want to do it. If other programs try to make changes to my computer, I want to be alerted. However, I want to make an exception for this program so that it runs without having to alert me. Is there a way to do that?


  • Related Answers