![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
This is my first time using a forum so sorry if I do something I shouldn't.
Lately AVG (2012 Free Edition) picked up the trojan something to do with C:\Windows\System32\services.exe, so I followed AVG's advice to remove it. However I noticed everytime I restart the computer AVG has another pop up informing me of the exact same problem. I'm not too sure if this has anything to do with it but I thought it would be best if I write it down anyway. Apart from AVG picking up that trojan, when I click on links from Google it redirects me to some unknown site and sometimes there is a black and white pop up box on the bottom right of my screen. When I click close on the black and white pop up it only turns into a small tray with the writing "Recommend for you". Thank you in advance ![]() |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.
For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive. For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive. Plug the flashdrive into the infected PC. Option1: Enter System Recovery Options from the Advanced Boot Options:
Option2: Enter System Recovery Options by using Windows installation disc:
On the System Recovery Options menu you will get the following options: Quote:
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#3
|
|||
|
|||
|
Thank you for such a quick reply here's the file
|
|
#4
|
||||
|
||||
|
We need some additional information so that we can replace an infected system file.
Boot to System Recovery Options and run FRST again. Type the below bolded text in the edit box after "Search:". services.exe Then click the Search button. It will make a log (Search.txt) on the flash drive. Please attach this log to your next reply.
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#5
|
|||
|
|||
|
Here's the log
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Save fixlist.txt to your flash drive.
Now reboot back into the System Recovery Options as you did previously. Run FRST and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt). Please attach this to your next message. (See how to attach) Now boot into normal Windows can continue with the below. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs: * fixlist.txt * C:\MGlogs.zip Make sure you tell me how things are working now!
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#7
|
|||
|
|||
|
After making the fixlog, I rebooted the computer but the screen went blue and something about a physical memory dump. It then went to system restore. When the system restore finished I tried to find the MGtools\GetLogs.bat file but that wasn't anywhere.
![]() |
|
#8
|
||||
|
||||
|
Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
Then attach the below logs: * C:\MGlogs.zip Make sure you tell me how things are working now!
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#9
|
|||
|
|||
|
I haven't got C:\MGtools\GetLogs.bat
|
|
#10
|
||||
|
||||
|
Yes! Because you never have run our full cleaning procedure in the READ & RUN ME FIRST sticky/pinnged thread. Run MGtools as per the below and then attach the C:\MGlog.zip file it creates.
Using MGtools
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Sorry about that
|
|
#12
|
||||
|
||||
|
I am not finding any malware in your logs.
If you are not having any other malware problems, it is time to do our final steps:
Malware removal from a National Chain = $149 Malware removal from MajorGeeks = $0
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#13
|
|||
|
|||
|
Thank you, does this mean my computer is safe to use?
|
|
#14
|
||||
|
||||
|
Yes. And you are welcome.
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| C:\Windows\System32\services.exe";"Trojan horse Dropper.Generic_c.MMI"";"Object is | thernbear | Malware Removal | 3 | 07-22-12 16:15 |
| Removing W32/Patched.UB from C:\Windows\System32\services.exe | Emil Svensson | Malware Removal | 1 | 06-25-12 07:07 |
| Help removing trojan in windows\system32\drivers | Fletch1980 | Malware Removal | 1 | 04-20-12 15:35 |
| Norton can't delete c:\windows\system32\services.exe with W32/Mariofev!mem (Trojan) | dmzasdf | Malware Removal | 12 | 01-29-12 13:37 |
| What is c:\windows\system32\kill1211.exe? Trojan? | Skipswift | Malware Removal | 1 | 03-21-08 18:39 |