Step 2: Show hidden files.

Malwarebytes Anti-Rootkit BETA (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative

IF REQUESTED, ZIP IT UP & ATTACH IT . Trojan Win64/Patched.A is believed to be changeable. Ask a Question See Latest Posts TechSpot Forums are dedicated to computer enthusiasts and power users. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders Startup=”C:\windows\start menu\programs\startup Step4.

Select the Yes button and the system should re-boot to complete the cleaning process.>> Please attach the two following logs from the mbar folder:system-log.txtandmbar-log-year-month-day (hour-minute-second).txt. --------------------------------Please download zoek.exe and save it Then select ‘Troubleshoot’ option and followed by ‘Advanced Options’. Wird verarbeitet... C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe

TCP: NameServer = TCP: Interfaces\{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}0 : DHCPNameServer = TCP: Interfaces\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}9\2445F40756E6A7F6E656 : DHCPNameServer = TCP: Interfaces\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}8\350756564645F6573686647383037303 : DHCPNameServer = Handler: linkscanner - remove Win64.Patched.B.Gen in Safe Mode. then I thought I would try another suggestion that /I found, use Combofix...

Select More (…) on the address bar, then Settings Under Open with, select A specific page or pages select Custom to enter the URL of page you want to set as

Farbar Recovery Scan Tool x64 Download Farbar Recovery Scan Tool and save it to a flash drive. http://blog.vilmatech.com/remove-win64-patched-b-gen-effective-solution/ It could be hard for me to understand.NEXTGoing over your logs I noticed that you have Bittorrent installed. Feel free to manually delete any tools it leaves behind.*************************I see you working with USB's O32 - AutoRun File - [2013.03.20 08:31:06 | 000,000,000 | ---- | M] () - C:\autoexec.bat Dismiss Notice TechSpot Forums Forums Software Virus and Malware Removal Today's Posts "Virus identified Win64/Patched.A, c:\Windows\System32\services.exe";"Cannot be cleaned Removema ByWar Lewis Jun 12, 2013 AVG malware warnings "Virus identified Win64/Patched.A, c:\Windows\System32\services.exe";"Cannot

Even going to google fails. http://tenten10.com/how-to/slow-pc-possible-infection.php Copy the text present inside the code box below and paste it into the large window in the zoek tool:Code: [Select]

Click Win64/Patched.A Trojan Description Win64/Patched.A is one of the newly released Trojan serial viruses. Select the operating system you want to repair, and then click Next.

Home Plans & Pricing Services My Account Recommended Service Problems with Virus/Malware? RP421: 12/06/2013 01:17:41 - Scheduled Checkpoint . ==== Installed Programs ====================== . My ESET NOD32 Antivirus 4 continuously shows a warning: C:\windows\system32\services.exe Win64/Patched.A.Gen trojan cannot cure NT AUTHORITY\LOCAL SERVICE This event was found when trying to access the file by: C:\Windows\System32\svchost.exe. http://tenten10.com/how-to/laptop-infection.php unveil hidden items to remove the ones generated by Win64.Patched.B.Gen.

Set your homepage page on Microsoft Edge to remove hijacker virus. If I closed your topic and you need it to be reopened, simply PM me. ==================================== Download RogueKiller for 32bit or Roguekiller for 64bit to your Desktop. Du kannst diese Einstellung unten ändern.

Anmelden 12 Wird geladen... Delete Win64/Patched.A.Gen and get rid of this Trojan Horse and system degrader now. Join the community here. http://tenten10.com/how-to/possible-malware-infection.php Queuing an action fixdamage.exe Removal scheduling successful.

AV: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}

Let it finish.