need assistance to determine if system is infected.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wario, Mar 26, 2012.

  1. wario

    wario Private E-2

    Hello,
    I need some help determing if my system is infected.
    I found patch.js under Windows/temp folder and I thought it was suspicious I suspect its Norton AV related but can't tell for sure.

    few days ago, I found couple of trojans under Windows/temp but it was successfully removed.

    Please examin MGlogs attached and advise.

    Your assistance is greatly appreciated.
     

    Attached Files:

  2. wario

    wario Private E-2

    attached is patch.js renamed as patch.txt for your review
     

    Attached Files:

  3. thisisu

    thisisu Malware Consultant

    Welcome to Major Geeks, wario! :)

    The logs in MGlogs.zip are clean and I did not see anything malicious in patch.js

    Our full malware removal procedure is listed here: READ & RUN ME FIRST Malware Removal Guide

    Let me know if you need additional help.
     
  4. wario

    wario Private E-2

    Thanks-a-lot thisisu for the quick response.

    Just curious if you are able to make sense of patch.js, i.e it's purpose!

    Regards
     
  5. thisisu

    thisisu Malware Consultant

    No problem, and no - I do not see its purpose.
    Did you already upload it to Virustotal (noticed you had the desktop app installed)?
     
  6. wario

    wario Private E-2

    Yes I uploaded it to virus total as wellas virscan., all shown good status
    the time stamp.on patch.js was awkward as well as other files under windows temp were showing 2009 time stamp even though I formated last year.
    is there a guide you follow to discern these log files or its just experience
     
  7. thisisu

    thisisu Malware Consultant

    No guide, mostly just experience.
     
  8. wario

    wario Private E-2

    The best expiernce is in expiernce for a novice to learn, wonder where to start from!

    One last question do you I need to run Combofix?
     
  9. thisisu

    thisisu Malware Consultant

    Are you going through the Read and Run Me first thread? If not, then there is no need to run ComboFix.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds