Author Topic: Services.exe infected, but unable to do anything?  (Read 1936 times)

0 Members and 1 Guest are viewing this topic.

DanManPan

  • Guest
Services.exe infected, but unable to do anything?
« on: September 12, 2012, 08:03:10 PM »
Hello, so after finishing the scan i attempted to delete all the infected files however one file will not let me do anything, unsure what to do and would like to remove it as it has been causing me trouble for a number of weeks. The file is located at C:\Windows\System32\services.exe, and the virus status is Win32:Patched-AKC [Trji]Any help would be brill.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Services.exe infected, but unable to do anything?
« Reply #1 on: September 12, 2012, 08:05:12 PM »
Hi there lets remove that for you and see what remains

  • Download RogueKiller  and save it on your desktop.
     
    NOTE: If using IE8 or better Smartscreen Filter will need to be disabled

  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ... 
  •     Click on Scan
   
 
  • Wait for the end of the scan. 
  • The report has been created on the desktop. 
  • Click on the Delete button.
     
  • The report has been created on the desktop.
  • Next click on the ShortcutsFix   

  • The report has been created on the desktop.
Please post:    All RKreport.txt text files located on your desktop.

THEN

Download OTL  to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
qmgr.dll
/md5stop
%systemdrive%\$Recycle.Bin|@;true;true;true
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS /s
CREATERESTOREPOINT


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Attach both logs