Trojan Patched.c and Generic help

Discussion in 'Malware Help (A Specialist Will Reply)' started by ejaym, Aug 18, 2013.

  1. ejaym

    ejaym Private E-2

    Hello,

    Not only am I new to this, but I'm not totally computer savvy either. Attached are the logs and zip you've requested, but I have a few more things I'll add on a reply just in case I either made a mistake or because I'm the noob that I am.

    My problem is that nearly a week ago, my AVG detected a few Trojans including the Patched.c_ADKY and the Generic Drops. I think there were 4 or 5 altogether -Hitman detected 14 threats. That same day, I had irregular debit card activity; I'm assuming it was because of the Trojan. Can these Trojans pick up accounts that are cached in the computer somehow, or just after the point of infection? Am I vulnerable for any site I log into with a password at this point?

    I'm not even sure I did everything right here -some instructions were not so clear. Anyway, thanks for the help. Hopefully this can be solved.
     

    Attached Files:

  2. ejaym

    ejaym Private E-2

    Here are other logs -maybe they're the same, but I don't want to leave anythin out just in case.

    Again, thanks for your help.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    There are no signs of malware in your logs. I just see some junk search engine stuff. I cannot comment on exactly what the infections you had detected may have been. If they really were Sirefef.c type infections it is possible that they could have been stealing info, but I doubt that is what you had because AVG would not fix these. No antivirus program does. Manual steps are always required.

    The below may repair the rest of the junk search engine items I mentioned:

    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  4. ejaym

    ejaym Private E-2

    Hi, thanks for taking a look-see, and for the welcome.

    So according to your analysis, the computer should be fine then? With all the scanners/tools I downloaded should I be keeping those, or do you suggest recycling them?

    And I guess I'll throw in one more question: I only have the AVG 2009 Free ed. anti-virus; Is that good enough, or do you recommend better/more protection?

    Thanks a bunch.
     

    Attached Files:

    • JRT.txt
      File size:
      3.8 KB
      Views:
      1
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Yes.

    See final instructions below.

    No it is way too out of date. You need to keep your protection software current. Either update to the current version of AVG ( see >>> AVG AntiVirus Free Edition 2013 13.0 Build 3392a6523 ) or use a current version of another antivirus.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  6. ejaym

    ejaym Private E-2

    Thanks for the help!

    Now with the last part about Disable/Re-enable System Restore, the picture on the instruction page is not working so I screen shot what System Protection showed me. I'm not sure if I'm supposed to untick (C), although it doesn't say drive, it's the only thing there that's checked.

    Please advise.

    Thanks
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes drive C is what you need to uncheck to remove restore points. C is the letter of the drive partition. When you recheck it, a new restore point is created along with reenabling system restore.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds