My issue
Hello, I am making a computer repair to a small, Acer laptop that uses Windows XP Home version 2002, SP3. After installing the malware software (MalwareBytes Anti-Malware) and antivirus software (AVG Free 2011), AVG noticed that a file was infected, and it continues to pop up over and over with no way to clear it. The file in question is
C:\WINDOWS\system32\winlogon.exe
The threat name is
Win32/Patched.FM
What I've done
I have run an otherwise full virus scan, Malware scan, and attempted system restores. I have also recently downloaded ComboFix as I was researching, but decided that, while reading about it, to post the results of the scan where appropriate. I have not yet run the scan via ComboFix.
I have disabled my antivirus
I have closed all windows and browsers
I have no malware scanners running
Included in this help request
AVG scan log
Scan "Whole computer scan" completed.
Infections;"5";"2";"3"
Warnings;"3";"3";"0"
Folders selected for scanning:;"Whole computer scan"
Scan started:;"Monday, November 08, 2010, 1:22:09 PM"
Scan finished:;"Monday, November 08, 2010, 1:59:58 PM (37 minute(s) 48 second(s))"
Total object scanned:;"500470"
User who launched the scan:;"Rita Williams"
Infections
;"File";"Infection";"Result"
;"C:\WINDOWS\system32\winlogon.exe (724)";"Virus identified Win32/Patched.FM";""
;"C:\WINDOWS\system32\winlogon.exe";"Virus identified Win32/Patched.FM";"Object is white-listed (critical/system file that should not be removed)"
;"C:\WINDOWS\system32\winlogon.exe";"Virus identified Win32/Patched.FM";"Object is white-listed (critical/system file that should not be removed)"
;"C:\System Volume Information\_restore{D24A3BE8-4CBB-48D0-81AD-ACAFA6A6C48B}\RP336\A0036122.exe";"Virus identified Win32/Patched.FM";"Moved to Virus Vault"
;"C:\System Volume Information\_restore{D24A3BE8-4CBB-48D0-81AD-ACAFA6A6C48B}\RP330\A0035211.dll";"Trojan horse Generic2_c.BDWK";"Moved to Virus Vault"
Warnings
;"File";"Infection";"Result"
;"C:\Documents and Settings\Rita Williams\Local Settings\Temp\000003D6";"Corrupted executable file";"Moved to Virus Vault"
;"C:\Documents and Settings\Rita Williams\Local Settings\Temporary Internet Files\Content.IE5\1I0B2JC4\iTunesSetup[1].exe";"Corrupted executable file";"Deleted"
;"C:\Documents and Settings\Rita Williams\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000012";"Corrupted executable file";"Moved to Virus Vault"