This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

services.exe malware

2 min read

This thread's last reply is from December 12, 2012, 7:48 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

I recently opened a program which contained a malware. It locked away my Windows Security Centre. I followed this Malware removal guide here: http://www.selectrealsecurity.com/malware-removal-guide but seems like none of the programs were able to get rid of the actual malware. AVG alerts me every few minutes that svchost.exe is a threat.

I've since got Windows Security Centre working. But Windows Update isn't functioning. These are the three anti-malware programs I ran. I've ran them multiple times and restarted and each time, they still detect the same problems. Any help would be appreciated! Thanks!

Malwarebytes

Files Detected: 3
C:\Windows\Installer\{287d593f-28e0-2648-82f0-7755076a5120}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.
C:\Windows\Installer\{287d593f-28e0-2648-82f0-7755076a5120}\U\000000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\Windows\Installer\{287d593f-28e0-2648-82f0-7755076a5120}\U\80000032.@ (Rootkit.0Access) -> Quarantined and deleted successfully.


TDSSKiller

13:26:57.0612 6988 Detected object count: 1
13:26:57.0612 6988 Actual detected object count: 1
13:28:03.0439 6988 C:\Windows\system32\services.exe - copied to quarantine
13:28:06.0430 6988 C:\Windows\assembly\GAC_32\desktop.ini - copied to quarantine
13:28:06.0450 6988 C:\Windows\assembly\GAC_64\desktop.ini - copied to quarantine
13:28:06.0450 6988 C:\Windows\installer\{287d593f-28e0-2648-82f0-7755076a5120}\@ - copied to quarantine
13:28:06.0465 6988 C:\Windows\installer\{287d593f-28e0-2648-82f0-7755076a5120}\L\00000004.@ - copied to quarantine
13:28:06.0470 6988 C:\Windows\installer\{287d593f-28e0-2648-82f0-7755076a5120}\L\201d3dde - copied to quarantine
13:28:06.0470 6988 C:\Windows\installer\{287d593f-28e0-2648-82f0-7755076a5120}\U\00000004.@ - copied to quarantine
13:28:06.0470 6988 C:\Windows\installer\{287d593f-28e0-2648-82f0-7755076a5120}\U\80000000.@ - copied to quarantine
13:28:06.0470 6988 C:\Windows\installer\{287d593f-28e0-2648-82f0-7755076a5120}\U\80000064.@ - copied to quarantine
13:29:03.0854 6988 Backup copy not found, trying to cure infected file..
13:29:03.0854 6988 C:\Windows\system32\services.exe - Cure failed (FFFFFFFF)
13:29:03.0854 6988 C:\Windows\system32\services.exe - processing error
13:29:03.0854 6988 C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - User select action: Cure

Hitman Pro
C:\Windows\assembly\GAC_32\Desktop.ini -> PendingDelete
Size . . . . . . . : 4,608 bytes
Age . . . . . . . : 3.6 days (2012-12-07 23:13:50)
Entropy . . . . . : 3.9
> G Data . . . . . . : Win32:Sirefef-PL [Rtk]
> Ikarus . . . . . . : Backdoor.Win32.ZAccess!IK
Fuzzy . . . . . . : 119.0

C:\Windows\assembly\GAC_64\Desktop.ini -> PendingDelete
Size . . . . . . . : 6,144 bytes
Age . . . . . . . : 3.6 days (2012-12-07 23:13:49)
Entropy . . . . . : 3.4
> G Data . . . . . . : Win32:Sirefef-PL [Rtk]
> Ikarus . . . . . . : Trojan.Win64!IK
Fuzzy . . . . . . : 119.0

C:\Windows\system32\services.exe -> DeleteFailed
Size . . . . . . . : 329,216 bytes
Age . . . . . . . : 1246.3 days (2009-07-14 06:19:46)
Entropy . . . . . : 6.2
SHA-256 . . . . . :
> G Data . . . . . . : Win32:Sirefef-ZT [Trj]
> Ikarus . . . . . . : Trojan.Patched_c!IK
Fuzzy . . . . . . : 172.0