Author Topic: services.exe keeps getting blocked  (Read 4031 times)

0 Members and 2 Guests are viewing this topic.

micepie

  • Guest
services.exe keeps getting blocked
« on: April 03, 2013, 06:49:23 PM »
Avast is coming up worryingly frequently saying C:\windows\system32\services.exe is being blocked. I did a scan and it came up with Threat: Win32:Sirefef-ZT [Trj], but I am unable to do anything about it, because it says it is either being used, or read only.

I've done a little research, but every fix I find has a disclaimer that says the fix is for that system only and could cause problems on other systems.

How do I fix this?

micepie

  • Guest
Re: services.exe keeps getting blocked
« Reply #1 on: April 03, 2013, 07:06:34 PM »
i'm running the scans recommended, will edit and attach when they are done.

EDIT: added logs. someone please help me out?
« Last Edit: April 03, 2013, 07:34:49 PM by micepie »

micepie

  • Guest
Re: services.exe keeps getting blocked
« Reply #2 on: April 03, 2013, 07:51:20 PM »
Can I get a helping hand here? This seems like a pretty serious thing and I'm hesitant to use my computer for anything until it's cleared up. If I've posted the wrong logs or something I'll attach any others that are needed.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: services.exe keeps getting blocked
« Reply #3 on: April 03, 2013, 08:00:32 PM »
A malware removal specialist has been informed of your topic.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: services.exe keeps getting blocked
« Reply #4 on: April 03, 2013, 08:01:08 PM »
Monitoring ...

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: services.exe keeps getting blocked
« Reply #5 on: April 03, 2013, 08:04:38 PM »
Hello and welcome to avast!
---------------------------------

  • I will be working on your Malware issues this may or may not solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • If you don't know or understand something, please don't hesitate to ask.
  • Please refrain from making any further changes to your computer (Install/Uninstall programs, delete files, edit the registry, etc...)
  • Please DO NOT run any other tools or scans whilst I am helping you.
  • It is important that you reply to this thread. Do not start a new topic.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  • Absence of symptoms does not mean that everything is clear.
***********************************

Step#1


Please download Malwarebytes AntiRootkit and save it to your desktop.
http://www.malwarebytes.org/products/mbar/

Full instructions how to use MBAR
http://www.bleepingcomputer.com/virus-removal/how-to-use-malwarebytes-anti-rootkit

    Please note: This is a beta version so please be sure to read the disclaimer and note of it.

  • Unzip/unrar MBAR in a folder to your Desktop
  • Open the folder where the contents were unzipped to run mbar.exe

  • Click on Next > then on Update button to download fresh definitions.
  • When database updates click Next
  • In the following window ensure "Targets" scan for Drivers; Sectors; System are ticked. Then select "Scan button"

  • If an infection/s are found ensure "Create Restore Point" is checked, then select the "Cleanup Button" to remove threats.
    Or if you are sure any entries should not be kept, just untick them. A list of infected files will be listed.

  • The Clean up procedure will be Scheduled for process.
  • When complete pop-up will show you. Select the Yes button and the system should re-boot to complete the cleaning process.
>> Please attach the two following logs from the mbar folder:

system-log.txt
and
mbar-log-year-month-day (hour-minute-second).txt.



-----------------------------------------------------------------
Step#2



> Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this or this Instruction.

How to disable avast:

  • Right-click on the avast! icon in the lower right corner of the screen and choose Open Avast! User Interface.
  • In the window that opens on the top right corner, click Settings.
  • In a new window that opens, choose the option Troubleshooting, Uncheck Enable avast! self-defense, and click OK.

  • Right-click on the avast! icon in the lower right corner of the screen and select avast! shield controls .
  • In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn on this option after the cleaning.



> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.
If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart computer once more.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.


micepie

  • Guest
Re: services.exe keeps getting blocked
« Reply #6 on: April 03, 2013, 09:54:15 PM »
Thanks for getting back to me.

Here are the logs, both programs seemed to run and do everything pretty smoothly and as you described. What's next?


Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: services.exe keeps getting blocked
« Reply #7 on: April 03, 2013, 11:54:39 PM »
 8)







It is necessary to uninstall ComboFix :
  • Click Start (or ) then Run.


    On Windows7 or Vista you may use Start Search field if Run is not available.

  • In the line of text type in (Copy) the following:
Code: [Select]
ComboFix /Uninstall
    Note that there is a space between " ComboFix " and " /Uninstall " .

    • then click OK (or press Enter ).
    Wait for the uninstall process is complete.

    -------------------------------------------



    > Re-run OTL and click on CleanUp! button.

    You will be asked to reboot the machine to finish the cleanup process, choose Yes.
    After the reboot all the tools we used should be gone.
    Note: Some more recently created tools may not yet be removed by OTL. Feel free to manually delete any tools it leaves behind.




    -----------------------------------


    -  Remove ( just delete ) Malwarebytes AntiRootkit becouse it's not a program, its powerfull antirootkit tool

    -  Re-run AdwCleaner and click on [Uninstall]


    ----------------------------------




    I recommended to keep Malwarebytes AntiMalware and to use MCShield if you will.
    You may download MCShield from one of the following links:

    MyCity - MCShield  Official download link
    Softpedija - Mirror download link

    It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
    And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.
    « Last Edit: April 03, 2013, 11:59:13 PM by magna86 »