![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi guys and girls I'm hoping someone can help.
AVG(free version) keeps informing me that I have the above trojan in my C:\windows\system32\services.exe folder. As it is an important folder I didn't want to mess around with it. I've read the other posts here regarding this Trojan, ran Combofix and then followed the instructions in your Read Me section, I have attached all the logs as requested below. I was trying to think when this could have happened - when AVG first flagged the trojan I was browsing for some pictures of birds to paint using both Google images and various websites, when I got the flag that a Trojan was detected I shut down Internet Explorer and ran both AVG and Malwarebytes. AVG found it, but it being a systems folder is obviously unable to remove it. I then noticed a new icon on my desktop for a program called "Live Security Platinum" which I did not agree to install. I uninstalled it, re scanned, but the problem remains(I hope I didn't screw up by unistalling it!). After following all the steps in your read me I still have the infection, so I'm posting the logs and hoping for help when someone is able. On a side note, my father has a search engine redirect happening on his laptop which he only just mentioned, apparently that's been there for sometime and as we use a router I'm concerned it might be infected. I haven't been able to fix his redirect either following your steps for it's removal but I'll start a seperate thread for that issue. I didn't want to re-set the router unless you told me to - at this moment I don't to touch anything unless directed to do so. Thankyou so much for your time and experience, regards, Cathy. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive. Plug the flashdrive into the infected PC. Enter System Recovery Options. To enter System Recovery Options from the Advanced Boot Options:
To enter System Recovery Options by using Windows installation disc:
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#3
|
|||
|
|||
|
Thankyou Kestrel13!,
My system is 64 bit. Please find attached the log as requested. Thanks again. |
|
#4
|
||||
|
||||
|
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Attached is fixlist.txt
Now re-enter System Recovery Options. Run FRST64 and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt). Please attach this to your next message. (How to attach) Now attempt to boot normally. ------------------------------------ Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. If you did not deliberately set this proxy yourself then please include it in the HJT fix further below: Quote:
Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished): Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: Quote:
What is inside of these folders? C:\Users\All Users\0C1CFAEF004783B9BA08A775F875F002 C:\Users\Cathy\AppData\Local\826D2194-E317-4BB2-A1DE-47227F1D9C49.aplzod
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
catamongthebats (07-31-12) | ||
|
#5
|
|||
|
|||
|
Thanks Kestrel13!
All the steps ran without issue, please find the logs attached as requested. I am no longer getting the AVG pop up alerting to an infection and a scan no longer shows the infection. (It does show a C:\FRST\Quarantine\services.exe file as a trojan that it has now placed in it's virus vault, please advise if I need to permanently delete this file, I can restore it from the virus vault to it's original position if additional steps need to be taken. I wasn't given a choice by the software, it just moved it.) Otherwise it seems to be running smoothly again. Thank you soooo much for your help it is very much appreciated. with regards, Cathy. |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Nothing needs to be restored! That services.exe was infected. Now it isn't.
![]() And I had asked. Quote:
![]()
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#7
|
|||
|
|||
|
Oops, sorry I misread that question about the folders
,The first folder in the All Users folder contains an .ico file named 0C1CFAEF004783B9BA08A775F875F002.ico. The folder in the App Data\Local contains two Data base files - Alarms.db and Main.db. Thanks, looking forward to the final steps! |
|
#8
|
||||
|
||||
|
Delete these then unless you know what they are for
C:\Users\All Users\0C1CFAEF004783B9BA08A775F875F002 C:\Users\Cathy\AppData\Local\826D2194-E317-4BB2-A1DE-47227F1D9C49.aplzod If you are not having any other malware problems, it is time to do our final steps:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#9
|
|||
|
|||
|
Thank you so much for your help Kestrel13!
|
|
#10
|
||||
|
||||
|
You are *most* welcome.
Safe surfing!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Trojan horse dropper.generic_c.mmi | Lilyannis143 | Malware Removal | 10 | 07-28-12 01:32 |
| Trojan horse Dropper.Generic_c.MMI | hylandertimelord | Malware Removal | 3 | 07-27-12 14:43 |
| Kestrel13!, Help Please. trojan horse dropper.generic_c.mmi Win7 x64 via services.exe | RedJamaX | Malware Removal | 8 | 07-25-12 12:29 |
| Need help to be rid of trojan horse dropper.generic_c.mmi | JackRatbone | Malware Removal | 2 | 07-24-12 21:38 |
| Zero Access/trojan horse dropper.generic_c.mmi | ryanpic | Malware Removal | 14 | 07-21-12 16:03 |