07-20-2012 01:38 PM
Hello and thank you in advance for your support.
I am running Windows 7 64bit and I do have a flash drive.
I have run Norton scans and gotten the Trojan.patchep!sys virus from the services.exe and it must be removed manually. I understand each case is different from the others, so I am waiting for the instructions on how to get this removed.
Thank you,
Jack
Solved! Go to Solution.
07-20-2012 02:40 PM
In Windows 7 and Vista
Go to Start Menu and Inside the Search box type CMD.
Now at the Top side if the Start menu you can see one file Called CMD.
Right Click on that one and Select the Option RUN AS ADMINISTRATOR
In Windows XP
Go to Run and type "cmd" to open the command prompt
Now you will get a black Window. Inside that black window type the above commands.
Type or copy & paste "sfc /scanfile=c:\windows\system32\services.exe"
and press enter
. Restart your computer
This will replace the infected services.exe with the original.
07-20-2012 08:04 PM
Sreedharram wrote:In Windows 7 and Vista
Go to Start Menu and Inside the Search box type CMD.
Now at the Top side if the Start menu you can see one file Called CMD.
Right Click on that one and Select the Option RUN AS ADMINISTRATOR
In Windows XP
Go to Run and type "cmd" to open the command promptNow you will get a black Window. Inside that black window type the above commands.
Type or copy & paste "sfc /scanfile=c:\windows\system32\services.exe"
and press enter. Restart your computer
This will replace the infected services.exe with the original.
And what about the rest of the infection??
Quads
07-20-2012 08:10 PM
Sure we can fix that one one by one. I am not telling this is the end of the troubleshoting.... Our main problem now is Trojan.patchep!sys. First we need to fix it in a simple way. After that we can run the other tools and check the Logs........
Thank you.......
07-20-2012 08:17 PM
There is a reason why Malware removalists like myself do things the way we do.
Your instructions as a whole don't work I have tried it.
Dumb instructions is why malware removal forums are protected from this.
There is also areason why I have been notified that the likes of ESET is using the approch I use. by not touching services.exe first up.
Quads
07-21-2012 12:25 PM
I appreciate the advice.
@Quads: I have done nothing as of yet as I wish to remove all problems and not just part of it. Please advise.
Thanks,
Jack
07-21-2012 07:20 PM - edited 07-21-2012 07:23 PM
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)
Read Slowly and all of it.
Please download http://www.bleepingcomputer.com/download/farbar-re
Transfer it on to the Flash Drive / portable Hard Drive.
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
Quads
07-21-2012 09:58 PM
Thanks for the assistance. The reply is attached.
07-22-2012 01:03 AM - edited 07-22-2012 01:05 AM
You are lucky you didn't follow the other users instructions as you are infected by more than just zeroaccess
I am going to get more data
Download the script attached, needs to be the same file name as well (fixlist.txt), Copy across to flash drive
NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Now please enter System Recovery Options again. Like previously
Quads
07-22-2012 08:18 AM
Ok. Steps taken and fixlog is attached.
Thanks again
