Major Problem: Services.msc won't open!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Aerion Of The Shadows, Apr 13, 2005.

  1. Aerion Of The Shadows

    Aerion Of The Shadows Private E-2

    I'm attempting to follow the removal steps for most major spyware/adware (http://forums.majorgeeks.com/showthread.php?t=35407) but when I run services, nothing happens. At all. Sometimes, a window will appear for a split second, but then it disappears.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What OS are you running? And do you have an about:blank or HSA hijacker problem? If not, you should not be running that step.
     
  3. Aerion Of The Shadows

    Aerion Of The Shadows Private E-2

    Windows XP

    about? HS? I don't know specifically what these are, but there is so much wrong with my computer that I wanted to take care of everything. Plus, doesn't the fact that I can't run services mean there is a major problem?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If could be! At any rate since you cannot run services.msc, just complete the remaining steps and let me know the results (like what is found, fixed and not fixed). And what problems remain when finished.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing the remaining steps of the READ ME FIRST, if you still have a problem, carefully follow the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  6. Aerion Of The Shadows

    Aerion Of The Shadows Private E-2

    Here It is!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Look in Add/Remove progams for WinTools and uninstall if found. Then continue with the below.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {55562F7B-99E7-CD4E-E81A-BFEE8DFDBDCA} - C:\WINDOWS\system32\ayi.dll
    O2 - BHO: ZToolbar Activator Class - {FFF5092F-7172-4018-827B-FA5868FB0478} - C:\WINDOWS\system32\azesearch.ocx (file missing)
    O3 - Toolbar: (no name) - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - (no file)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
    O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MusicAccess/ie/bridge-c445.cab
    O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
    O16 - DPF: {99802379-7362-40E2-9D28-8A3B9AF880B7} - http://hotsearchbar.com/toolbar2/winhot32.cab
    O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/bgn/partners/wildgames/stx/install.cab
    O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} (CParamWr Class) - http://toolbar.azesearch.com/install/azesearch.cab
    O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\ayi.dll
    C:\Program Files\Common Files\WinTools <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. Aerion Of The Shadows

    Aerion Of The Shadows Private E-2

    Still won't let me run services... could it be a registry setting, perhaps?

    Though, a noticeable improvement on behalf of the computer... Here is new log file.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run HijackThis click on the "Open the Misc Tools Section" button on the open page. Then select "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK:

    WinTools for IE service

    If that does not work try entering the short name: WinToolsSvc

    Then reboot into safe mode.

    While in safe mode, see if you can run services.msc

    Then reboot to normal mode and post a new HJT log.
     
  10. Aerion Of The Shadows

    Aerion Of The Shadows Private E-2

    Works perfectly now. Thanks a lot!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds