Reply
Regular Visitor
Taker74
Posts: 9
Registered: ‎07-08-2012

Services.exe issues

This program is being constantly blocked. And it is also reading as a trojan.patchep!sys. I also have a Trojan.zeroaccessB in another file. Neither of which I can seem to remove. Any help would be appreciated.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Services.exe issues

ANY other user other than the thread starter is not to use any instructions, scripts or proceedures,  The work though in cleaning a system is individual and only for that system due to a number of factors.

 


 

Please do not run any tools unless instructed to do so. 

  • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability. Do as the instructions ask nothing extra or run things twice
  • If I ask a Question just answer it, don't run anything unless it states.
  • Major steps used:

1. Find

2. Break

3. Destroy

4. Cleanup  (including system as a whole)

 

Please read every post completely before doing anything. 

  • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.

 

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forum, (sometimes :smileylol:)

  • Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.

 

 

What is your Operating system including if it's 32 bit or 64 bit??

 

Quads

Regular Visitor
Taker74
Posts: 9
Registered: ‎07-08-2012

Re: Services.exe issues

Windows 7 64bit

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Services.exe issues

Do you have a Flash Drive??

 

Quads

Regular Visitor
Taker74
Posts: 9
Registered: ‎07-08-2012

Re: Services.exe issues

No

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Services.exe issues

Please download SystemLook from one of the links below and save it to your Desktop.

 

http://jpshortstuff.247fixes.com/SystemLook.html  the 64 bit version

 

Disable Norton for say 30 mins

 

Double-click SystemLook_v64.exe to run it.

Copy the content of the following codebox into the main textfield:  (don't forget the : in front of :filefind)



:filefind

\n

\@
*.@

services.exe


 

 

Click the Look button to start the scan.

When finished, a notepad window will open with the results of the scan. Please post this log in your next reply (attach to message).

Note: The log can also be found on your Desktop entitled SystemLook.txt

 

Quads

Regular Visitor
Taker74
Posts: 9
Registered: ‎07-08-2012

Re: Services.exe issues

SystemLook 30.07.11 by jpshortstuff
Log created at 15:16 on 14/07/2012 by Josh
Administrator - Elevation successful

========== filefind ==========

Searching for "\n"
No files found.

Searching for "\@"
C:\Users\Josh\AppData\Local\{ff56e231-8c20-23a1-2d0d-003fd383754e}\@    --ahs-- 2048 bytes    [20:03 20/05/2012]    [06:07 14/06/2012] D8E61B9C64C8CF581D2464FA0C6542AA
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003fd383754e}\@    ---hs-- 2048 bytes    [20:03 20/05/2012]    [06:41 17/11/2011] C1DD5DDDDD9A095741B9271EFDF534A4

Searching for "*.@"
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003fd383754e}\U\00000001.@    --a---- 1696 bytes    [16:48 30/06/2012]    [16:48 30/06/2012] B3652DED83AE87449FC9CD698E167B39
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003fd383754e}\U\800000cb.@    --a---- 22016 bytes    [17:11 22/06/2012]    [20:42 08/07/2012] E483D0E283805FA7619E2C23ADCE8D5A

Searching for "services.exe"
C:\Windows\System32\services.exe    --a---- 328704 bytes    [23:19 13/07/2009]    [01:39 14/07/2009] 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe    --a---- 328704 bytes    [23:19 13/07/2009]    [01:39 14/07/2009] 24ACB7E5BE595468E3B9AA488B9B4FCB

-= EOF =-

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Services.exe issues

Disable Norton for say 30 minutes

 

Start OTL,   under   Copy and paste the custom script attached which you open in for instance Notepad,(include the : at the start of :OTL and all the way to the end / bottom)  and run the script. (Red Run Fix Button)

 

The output log, should be placed in the C:\ _OTL folder after.

 

Quads

Regular Visitor
Taker74
Posts: 9
Registered: ‎07-08-2012

Re: Services.exe issues

All processes killed
========== OTL ==========
========== FILES ==========
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003fd383754e}\@ moved successfully.
C:\Users\Josh\AppData\Local\{ff56e231-8c20-23a1-2d0d-003fd383754e}\@ moved successfully.
C:\Users\Josh\AppData\Local\{ff56e231-8c20-23a1-2d0d-003fd383754e}\U folder moved successfully.
C:\Users\Josh\AppData\Local\{ff56e231-8c20-23a1-2d0d-003fd383754e}\L folder moved successfully.
C:\Users\Josh\AppData\Local\{ff56e231-8c20-23a1-2d0d-003fd383754e} folder moved successfully.
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003fd383754e}\U\00000001.@ moved successfully.
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003fd383754e}\U\800000cb.@ moved successfully.
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003fd383754e}\U folder moved successfully.
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003fd383754e}\L folder moved successfully.
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003fd383754e} folder moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56466 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Josh
->Temp folder emptied: 273133493 bytes
->Temporary Internet Files folder emptied: 35023368 bytes
->Java cache emptied: 374592 bytes
->FireFox cache emptied: 436868205 bytes
->Google Chrome cache emptied: 6553751 bytes
->Flash cache emptied: 66983 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 449296630 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 68579157 bytes
RecycleBin emptied: 202279148 bytes
 
Total Files Cleaned = 1,404.00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
->Flash cache emptied: 0 bytes
 
User: Default User
->Flash cache emptied: 0 bytes
 
User: Josh
->Flash cache emptied: 0 bytes
 
User: Public
 
Total Flash Files Cleaned = 0.00 mb
 
 
[EMPTYJAVA]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Josh
->Java cache emptied: 0 bytes
 
User: Public
 
Total Java Files Cleaned = 0.00 mb
 
 
OTL by OldTimer - Version 3.2.54.0 log created on 07142012_203059

Files\Folders moved on Reboot...
C:\Users\Josh\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profiles\foigot6j.default\Cache\_CACHE_001_ moved successfully.
C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profiles\foigot6j.default\Cache\_CACHE_002_ moved successfully.
C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profiles\foigot6j.default\Cache\_CACHE_003_ moved successfully.
C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profiles\foigot6j.default\Cache\_CACHE_MAP_ moved successfully.
C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profiles\foigot6j.default\urlclassifier3.sqlite moved successfully.

PendingFileRenameOperations files...
File C:\Users\Josh\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
File C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profiles\foigot6j.default\Cache\_CACHE_001_ not found!
File C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profiles\foigot6j.default\Cache\_CACHE_002_ not found!
File C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profiles\foigot6j.default\Cache\_CACHE_003_ not found!
File C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profiles\foigot6j.default\Cache\_CACHE_MAP_ not found!
File C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profiles\foigot6j.default\urlclassifier3.sqlite not found!

Registry entries deleted on Reboot...

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Services.exe issues

start attaching logs NOT copy and pasting them.

 

Quads