Avast WEBforum

Other => Viruses and worms => Topic started by: REDACTED on February 10, 2016, 07:54:12 AM

Title: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 07:54:12 AM
I found a Win32:Patcher-AK [PUP] yesterday. I've heard that PUP isnt virus, But it can be? Should i be worried?
Title: Re: Win32:Patcher-AK [PUP]
Post by: Pondus on February 10, 2016, 07:59:09 AM
Quote
But it can be?
NO

PUP >> https://www.virusbtn.com/resources/glossary/potentially_unwanted.xml

Malwarebytes PUP Criteria > https://www.malwarebytes.org/pup/

Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 08:09:57 AM
So i shouldn't be worried? But i should maybe delete the PUP?
Title: Re: Win32:Patcher-AK [PUP]
Post by: Pondus on February 10, 2016, 08:15:04 AM
if you want a check, follow instructions and attach requested logs from Malwarebytes and FRST

https://forum.avast.com/index.php?topic=53253.0

Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 08:40:14 AM
so the Win32:Patcher-AK [PUP] isn't dangerous?
Title: Re: Win32:Patcher-AK [PUP]
Post by: Pondus on February 10, 2016, 08:46:03 AM
are you using cracked software?

Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 08:50:58 AM
No, i have a certified windows 7.
Title: Re: Win32:Patcher-AK [PUP]
Post by: Pondus on February 10, 2016, 08:54:07 AM
Win32:Patcher-AK

This is a family of hacktools that are used to patch or "crack" some software so it will run without a valid license or genuine product key.






Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 09:00:09 AM
So if it's named Win:32 Patcher, it will patch my Windows or?
The file was meant to patch a game in my PC.
Title: Re: Win32:Patcher-AK [PUP]
Post by: Pondus on February 10, 2016, 09:02:11 AM
Quote
The file was meant to patch a game in my PC.
you mean crack it


Best way to get infected is to use cracked software, those nice guys that give these away often bundle it with a extra program they dont tell you about

Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 09:05:40 AM
Yeah, that's what i meant :3
So it's dangerous?
Title: Re: Win32:Patcher-AK [PUP]
Post by: Pondus on February 10, 2016, 09:22:24 AM
if you want help, follow instructions and attach requested logs   https://forum.avast.com/index.php?topic=53253.0





Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 09:28:47 AM
Monitoring.
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 10:02:45 AM
if you want help, follow instructions and attach requested logs   https://forum.avast.com/index.php?topic=53253.0







I'll do as soon as i get home! :)
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 03:47:19 PM
Here you go.
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 04:19:16 PM
Hi,

One or more of the identified infections is a rootkit.

This allows hackers to remotely control your computer, steal critical system information, and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Quote
Gæst (S-1-5-21-3545070637-2439424452-1603755923-501 - Limited - Disabled)
Was this user account created by you?

Code: [Select]
Start
CreateRestorePoint:
CloseProcesses:
EmptyTemp:
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {E1C44665-AF03-41B7-89A3-A125F207ED77} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
Task: {FDDE542B-3E97-45AB-A1A6-409EDB85DD0F} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
S3 2819p5U8ntWJ7m; \??\C:\Windows\system32\drivers\2819p5U8ntWJ7m.sys [X]
S3 60S0G2JU2H; \??\C:\Windows\system32\drivers\60S0G2JU2H.sys [X]
S3 7xEKV83l2; \??\C:\Windows\system32\drivers\7xEKV83l2.sys [X]
S3 84Ycwk0T6Cb; \??\C:\Windows\system32\drivers\84Ycwk0T6Cb.sys [X]
S3 8Q5EfbQxFW4x2J; \??\C:\Windows\system32\drivers\8Q5EfbQxFW4x2J.sys [X]
S3 9nlALiZMy; \??\C:\Windows\system32\drivers\9nlALiZMy.sys [X]
S3 Bi4010P3; \??\C:\Windows\system32\drivers\Bi4010P3.sys [X]
S3 eNqywPGAt8; \??\C:\Windows\system32\drivers\eNqywPGAt8.sys [X]
S3 fIjRm27L2IfF65; \??\C:\Windows\system32\drivers\fIjRm27L2IfF65.sys [X]
S3 fZS03y; \??\C:\Windows\system32\drivers\fZS03y.sys [X]
R3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S3 j66uRQpxQh; \??\C:\Windows\system32\drivers\j66uRQpxQh.sys [X]
S3 JS9JRRpcFhcCE5f; \??\C:\Windows\system32\drivers\JS9JRRpcFhcCE5f.sys [X]
S3 jvKq341ou6rJ82; \??\C:\Windows\system32\drivers\jvKq341ou6rJ82.sys [X]
S3 lJ4ef; \??\C:\Windows\system32\drivers\lJ4ef.sys [X]
S3 n8mJU92J; \??\C:\Windows\system32\drivers\n8mJU92J.sys [X]
S3 NNvU7zZpe9; \??\C:\Windows\system32\drivers\NNvU7zZpe9.sys [X]
S3 RX12Cwj01Q1; \??\C:\Windows\system32\drivers\RX12Cwj01Q1.sys [X]
S3 u3Nyymt; \??\C:\Windows\system32\drivers\u3Nyymt.sys [X]
End






Regards,
Valinorum
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 07:32:22 PM
Thanks for your help!

I don't remember making that user account. I might have, but i can't remember.
Here's the 2 log files :)
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 07:40:58 PM
Looks good. How is your system?
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 08:00:12 PM
Nothing is going slow. I don't get redirected or anything. Everything is normal so far.
Thank you so much for your time and help! :)
I'll write if anything happens!
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 08:01:17 PM
Perusing your logs, I see no infection currently present in your system. Unless you are having any issue(s), the machine appears to be Malware-free as we speak.



♣ Removal of Tools and Quarantined Files ♣



Despite the tools we have used are clean, they are powerful removal tools and made in a way so that they carry out any commands given to them without (most cases) asking for a confirmation. In the hands of an inept person, they can make the machine un-bootable -- a scenario we do not wish to see. Also, we need to remove the quarantined files/folders from your system as a dormant malware can be as bad as an active one if given the proper environment. I shall now give you the guidelines to remove the tools and the quarantined files from your system.



♣ Prevention and Future Guidelines ♣



Prevention is better than cure -- goes the old saying. As much as we love to see you visit our site, we do not want to see you having your PC infected by malwares again.

My help is free but if you feel like making my day you may donate any amount you wish by clicking the 'donate' button. I really appreciate your kindness.
(https://www.paypalobjects.com/en_US/i/btn/btn_donate_SM.gif) (https://www.paypal.com/cgi-bin/webscr?cmd=_donations&business=valinorum%40gmail%2ecom&lc=US&item_name=Malware%20Removal%20Assistance&item_number=avast%21&currency_code=USD&bn=PP%2dDonationsBF%3abtn_donateCC_LG%2egif%3aNonHosted)

Regards,
Valinorum
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 10, 2016, 10:33:38 PM
I think's somethings wrong. My windows pc won't start now, i rebooted it and puf, i come to the login screen, but when i write my code, it just says "Welcome" and stay there..
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 11, 2016, 05:27:49 AM
Is this a one-time event? When did it start? Can you boot into Safe Mode and restore it prior to FRST fix. A restore point was created by FRST.
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 11, 2016, 10:29:17 AM
It isn't a one time event. I happened 5 times in a row. I come to the password screen, i write it and i says "welcome" in 10 minutes. I can then press CTRL+ALT+DEL and start windows job list. With help from the job list, i can get the desktop to show itself. All the processes are shut down, expect the ones, that keep the pc running. My network driver won't work, i can't troubleshoot anything. I can only open some programs and i can open my control panel. I can boot into safe mode and i can restore it. I remember seeing the restore point with FRST. So i'll try that.
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 11, 2016, 10:54:49 AM
Tell me how it goes.
Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 11, 2016, 12:49:47 PM
Maybe malware/virus took over my pc?
Title: Re: Win32:Patcher-AK [PUP]
Post by: Pondus on February 11, 2016, 12:57:53 PM
Maybe malware/virus took over my pc?
Malware want your computer to work, if it dont work it can`t do the malicious deeds it was created to do
Most likely a file was damaged by the malware or damaged during the cleaning process

Follow instructions given by Valinorum

Title: Re: Win32:Patcher-AK [PUP]
Post by: Pondus on February 11, 2016, 01:03:04 PM
some info to red ...

The complexity of finding, preventing, and cleanup from malware
https://forums.malwarebytes.org/index.php?/topic/130154-the-complexity-of-finding-preventing-and-cleanup-from-malware/

Title: Re: Win32:Patcher-AK [PUP]
Post by: REDACTED on February 11, 2016, 04:00:46 PM
Maybe malware/virus took over my pc?
Let's get your PC in working condition first. :)