Win32:Patched-KX [Trj] prompted me to run R&R

Discussion in 'Malware Help (A Specialist Will Reply)' started by Zwaplat, Sep 11, 2009.

  1. Zwaplat

    Zwaplat Private E-2

    Yesterday I was running a check-up Malwarebytes scan, when Avast warned me it detected a sign of Win32:patched-KX [Trj] (see log attached). -I forgot to turn of the resident scanner before scanning with MBAM.-

    So first thing I did today was to run the entire protocol. SAS and MBAM found nothing, CF seems to have found an infected file (what do I know), RootRepeal and MGTools finished without problems anything problems also.

    Did I have infections ?

    Thanks for your time!
     

    Attached Files:

  2. Zwaplat

    Zwaplat Private E-2

    Logs continued.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    kes13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi, sorry for the delay in a response.

    Please do the below:

    Click Start > Run, and enter cmd and click OK. This will open a command prompt Window. In the command prompt Window, enter the below command in the quote box, followed by the enter key:

    Be patient, and once it has finished, please locate the C:\flist.txt file and attach it into your next reply here.
     
  5. Zwaplat

    Zwaplat Private E-2

    No biggie, I was able to continue with my W7 boot so my XP system didn't change.

    Here's the file requested.

    Thanks.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to this online scanner, choose "browse" and navigate to: c:\windows\system32\calc.exe choose "open" once located calc.exe and hit submit file button.

    Jotti

    Let me know what the various scanner results are for this file!

    Could you please get this: calc.exe into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    The zipped file will be found at C:\collect.zip. Please attach it into your next response here as well as letting me know about the results from jotti.

    Thanks
    Kes13!
     
  7. Zwaplat

    Zwaplat Private E-2

    Result from Jotti: all scanners except for CP Secure found nothing.

    CP secure reported a Troj.W32.Vaklik.cqh


    Collect file attached as requested.

    This is becoming 'interesting'. I really have no idea where I picked this up.

    Thanks for the help, much appreciated.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a problem. You installed Microsoft Calculator Plus which just made your calc.exe file standout as not being the normal file size.
     
  9. Zwaplat

    Zwaplat Private E-2

    Ah, that sounds plausible. Quite comforting as well. So my logs look clean beyond that? Can I clean up?

    Thank you very much!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can cleanup. Just follow the below instructions.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds