Avira internet security keeps alerting W32/Patched.UB is found in C:\Windows\System32\services.exe and you can’t get rid of it at all? Follow the instruction here to completely remove this virus without coming back.
W32/Patched.UB is high dangerous Trojan that will spread through known software and security vulnerabilities. It will target every computer users that range from individual, educational institutions, up to known organizations. It is shown that this virus can proliferate through malicious websites, spam email messages, unsafe downloads and lots of other means used by attackers.
Users can find this malicious virus while running Avira antivirus. However, it is unable to get rid of it completely as this tricky Trojan is located in C:\Windows\System32\services.exe which belongs to system files that can’t be simply removed. Avira will keep reporting the presence of the virus. It annoys users. When this Trojan is installed, it can download and install more malware infection on the infected computer system. Moreover, it allows cybercriminals to gain remote access and control over the targeted computer. Thus, your personal information and privacy will be in danger. Don’t hesitate to remove this pest from your machine now.
1. Show hidden files and folders.
Open Folder Options by clicking the Start button, clicking Control Panel, clicking Appearance and Personalization, and then clicking Folder Options.
Click the View tab.
Under Advanced settings, click Show hidden files and folders, uncheck Hide protected operating system files (Recommended) and then click OK.
2. Open Registry entries. Find out the malicious files and entries and then delete all.
Attention: Always be sure to back up your PC before making any changes.
a. Press the “Start” button and then choose the option “Run”. In the “Open” field, type “regedit” and click the “OK” button.
b. All malicious files and registry entries that should be deleted:
%Documents and Settings%\[UserName]\Application Data\[random]
%AllUsersProfile%\Application Data\.exe(W32/Patched.UB)
HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s
HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s
If you failed to remove this malware with the instructions above or need any assistant, you are welcome to contact YooCare experts to resolve all the problems completely.
Published by on July 17, 2012 6:32 pm, last updated on July 17, 2012 6:32 pm
Leave a Reply
You must be logged in to post a comment.