Can't remove services.exe virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ilovetechnology, Jun 12, 2013.

  1. Ilovetechnology

    Ilovetechnology Private E-2

    Hi Major Geeks,

    First time using a forum here, so please bear with me. I got some strange virus on my computer a couple of weeks ago trying to figure out how to stream TV on my computer and got a little too click happy and downloaded something. I tried to remove the trojans/viruses from online help. Everything seems to be fine but I can't seem to remove this "suspicious" services.exe file. I followed all of the steps in the "read me first" link and everything went well except for the Hitman Pro scan found that services.exe "suspicious" file. I will attach all of my logs for review but please note when I tried to run the MGtools.exe program I got an error message and it said to note that a log was not created. I tried to save it but the black screen disappeared when trying to take a screenshot of it.

    One other thing... I am not able to turn on my firewall. I tried to attach a screenshot of it but it's too big. Basically what happens is when I go to turn it off or on there is a button that says "use recommended settings" but when I click it, nothing happens and it can't see what the recommended settings are.

    I am using Windows 2003 and I have a 64bit version.

    Thanks for your help!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let Hitman fix the suspicious services.exe file. Then re run and scan only... attach new log.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  3. Ilovetechnology

    Ilovetechnology Private E-2

    Hi Kestrel13!

    Thank you for your reply. I ran Hitman Pro a couple of times. The first time I ran it I tried to "Quarantine" the services.exe file and it failed. The second time I tried to "replace" the file that that failed too. The only other option is to "ignore" it and I did not try that option. I ran a log of Hitman Pro and I have attached it with both of the txt files to requested. Thanks for your help and I'll wait to hear from you about next steps.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  5. Ilovetechnology

    Ilovetechnology Private E-2

    Hi Kestrel13,

    Sorry for the delay in responding. For some reason your message went into my spam folder. I ran the next set of steps and I have attached the log you requested.

    Thank you,
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We need some additional information so that we can replace an infected system file.

    Boot to System Recovery Options and run FRST again.
    Type the below bolded text in the edit box after "Search:".

    services.exe

    Then click the Search button.

    It will make a log (Search.txt) on the flash drive. Please attach this log to your next reply.
     
  7. Ilovetechnology

    Ilovetechnology Private E-2

    Hi TimW,

    I ran the FRST in system recovering mode again but typed services.exe in the search box before running the scan. Here is the log.

    Thank you
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That's not the log we need.
     
  9. Ilovetechnology

    Ilovetechnology Private E-2

    Sorry about that. I think this is the correct file.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Save fixlist.txt to your flash drive.

    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.

    Running MGTools.
     

    Attached Files:

  11. Ilovetechnology

    Ilovetechnology Private E-2

    I ran the program you requested and attached the .txt log. I also ran the MG tools file and wasn't sure if you needed that log or not but attached it too.

    Thanks
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  13. Ilovetechnology

    Ilovetechnology Private E-2

    Thanks for the speedy response. Here you go!
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun both RogueKiller and Hitman and attach the logs, please.
     
  15. Ilovetechnology

    Ilovetechnology Private E-2

    Here are the two logs you have requested. I don't want to jump the gun but maybe it worked (yay!!!) as the services.exe file didn't show up as a threat when I ran Hitman Pro (which has always been the case).

    Thank you,
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  17. Ilovetechnology

    Ilovetechnology Private E-2

    Yay!!! It looks like everything has been fixed. I followed all of your instructions in your last post. It seems that my firewall is working again as well (that was my other original concern). Everything looks great!!!


    Thanks again for all of your help!!!!
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds