Help Service.exe all procedure done log in post

Discussion in 'Malware Help (A Specialist Will Reply)' started by patrick182, May 5, 2013.

  1. patrick182

    patrick182 Private E-2

    Hi everyone looking to know what to do now (main computer) infected im working with it. Here is the log files i have after completed the Windows 7 procedure here: http://forums.majorgeeks.com/showthread.php?t=139681

    So im looking to know what i should/must do to clean out everything. Will be a good lesson for me next time i will save back C driver and just format its out of my knowledge so..please help :cry

    Thanks for all guys/girls
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You have a Zero Access infection.

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. patrick182

    patrick182 Private E-2

    cannot go in recovery mode this way i think im gonna need windows 7 cd or something else to enter in this mode usb is ready to work. Just need another way to go there if you have some feel free (main computer on gigabyte motherboards)
     
  4. patrick182

    patrick182 Private E-2

    Ive done a recovery disk and here is the log.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows and continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. patrick182

    patrick182 Private E-2

    First things work great in my opinion but second thing (mglogs) stop like beore i say ok and then you will probably see in logs.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good. Just cleanup all the junk in the below folder.

    C:\Users\Patrick\AppData\Local\Temp

    CCleaner should clean a bunch of it but you may need to clean manually. There are quite a few questionable files in this folder. Other than that, time for final instructions.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  8. patrick182

    patrick182 Private E-2

    Only things now is when session load up screen stay in black or 30-60 seconds then turn into my desktop with icon never happen beore infection. What do i do now? All scan are ok
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is likely due to what you are loading/running at startup. For example, from your last logs I noted the below running
    Code:
    postgres.exe  2184       4        8   0 Patrick-PC\postgres
    postgres.exe  2320       3        8   0 Patrick-PC\postgres
    postgres.exe  2380       2        8   0 Patrick-PC\postgres
    postgres.exe  2388       2        8   0 Patrick-PC\postgres
    postgres.exe  2396       2        8   0 Patrick-PC\postgres
    postgres.exe  2404       2        8  24 Patrick-PC\postgres
    Why does it need to run at all and why 6 times?

    Also AVG can be a bit of a hog and while it is getting loaded up and possibly updating, it can cause delays in your desktop being loaded.

    Also all the below services are starting up and this causes delay too:
     
  10. patrick182

    patrick182 Private E-2

    Postgres is a database i need but 1 times is ok i gest dont know why it load 24 times, and also how i clear other programs that i dont wanna run at start up except when i double-click on like steam etc..? thanks for all info
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    6 times not 24. I would uninstall it and then reinstall. Or check with the creator as to why it is running some many times. Did you have any database files open when you ran the scans? Why is this running as a service? Is this PC used as a server?

    You will have to decide what you use and what you need. We cannot do that for you. But uninstall anything that you don't use. Then you can use a program like below to try and control others.

    Microsoft Autoruns 11.50
     
  12. patrick182

    patrick182 Private E-2

    Booting seem fine now ive done nothing. Will try to unistall holdem manager 2 later and reinstall to see..thanks for all
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds