My Services.msc :(

Status
Not open for further replies.

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Hello, when I try to change a setting in services.msc, it won't stay that way. I want complete control of services.msc. I turned off a service and disabled it, now it's re-enabled. The FRST abruptly deleted itself.
 

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===


The Farbar program is updated often.
If it's identified as suspicious by your Anti-Virus program trust it if Downloaded from this link:


You can possibly restore the program from the Quarantine folder used by your Virus Protection Software.
<<<>>>

If you need additional help please ask.
 

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Thanks, here are the results:
 

Attachments

  • FRST.txt
    32.6 KB · Views: 39
  • Addition.txt
    25.5 KB · Views: 36

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

Your logs are clean of malware.

Lets see if we can fix this error.
How to Fix DCOM Error 1084 on Windows 10
<<<>>>


Press the Windows key + r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.

Code:
start

Comment: For your security a new restore point will be created.
CreateRestorePoint:
Comment: We need to close all processes to complete the fix.
CloseProcesses:

Comment: Items from the FRST.TXT log that will be removed from the Registry.
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
S3 cpuz153; \??\C:\WINDOWS\temp\cpuz153\cpuz153_x64.sys [X]


Comment: TCP/IP Reset
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /flushDNS

Comment: To rebuild the performance counter library values.
CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
CMD: "C:\Windows\SysWOW64\lodctr.exe /R"

Comment: Use Farbar routine to delete temp files
C:\Windows\Temp\*.*
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
C:\Program Files (x86)\Temp\*.tmp

cmd: sfc /scannow
cmd: DISM.exe /Online /Cleanup-image /Scanhealth
cmd: DISM.exe /Online /Cleanup-image /Restorehealth

Comment: The system will restart.
Reboot:

End

Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt.

If the problem persists please scan the computer with the Farbar program and post fresh logs log my review.
 

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

Please keep your communications here.

The fix will not touch any of your cache or Histories.
nasdaq
 
  • Like
Reactions: upnorth

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Ok, sorry about that, how do I make my av accept FRST, because I have to download it for the third time?
 

Attachments

  • FRST_concern.png
    FRST_concern.png
    202.9 KB · Views: 5

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Nvmd, sorry about that, what I did was I turned off my av (not sure why I didn't think of that before) and downloaded FRST. I also updated my av.
 

Attachments

  • Fixlog.txt
    23.7 KB · Views: 31

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

The fixlog looks good. Any remaining issues?

FYI.

When a file is quarantined by the AV it can be recovered.

In the explample you posted I would check the box"IDP.Generic" and accept it. Making sure that the file listed is what I'm looking for.

The file should be de-quarantined and you should be able to run it.
 

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Thanks for the information. As far as the service that I stopped and disabled, I did that yesterday. I checked this morning and the settings did not change, however, I checked a minute ago and the setting in services.msc is back to being enabled and manual.
 

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,


Letùs reset these services:

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===



Please post the Fixlog.txt and let me know what problem persists.
 

Attachments

  • Fixlist.txt
    1.7 KB · Views: 29

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
This might end up being difficult to nip in the bud. I think that this black hat hacker is determined to manipulate, I really hope that you can
resolve this and outsmart this guy. The FRST failed to update.
 

Attachments

  • Fixlog.txt
    229.3 KB · Views: 29

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt wait for further instructions.
 

Attachments

  • Fixlist.txt
    442 bytes · Views: 30

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Wait a minute, that might not be necessary, because I changed the settings in services.msc and so far it stayed. I will let you know if
there is something I don't like that the hacker is up to.
 
  • Like
Reactions: vtqhtr413

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Hello Nasdaq, it's still looking good in my services.msc. You definitely know your stuff, I thought that this issue with my new laptop was going to be long and drawn out. Thanks very much🤓💻
 
  • Like
Reactions: Gandalf_The_Grey

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

What I'm I doing wrong?
Why did you start a new topic here:
 

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
I'm sorry, you didn't do anything wrong. I was looking near the title and saw that this post was closed for replies, so I'm sorry that I didn't send you a private message.
 

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

Let keep the communications on this topic.

Please post the latest Farbar logs here.

Hello, I do need help with something. I was able to stop any given service from running, however, when I try to disable one in particular, I get a "parameter is incorrect", message. Also, I had a service turned off and disabled and it changed to manual while staying idle.

Can you tell me which services were turned/disabled and then were changed to manual.
I would like to find out if any of these services are normally set by the Operating system.

I will close the there topic.
 

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
It's the Windows Update. I would stop it from running and disable it and he would change it back. Currently it is turned on and set to Manual, somehow this hacker is getting a big head. Here are the logs:
 

Attachments

  • FRST.txt
    31.7 KB · Views: 27
  • Addition.txt
    20.6 KB · Views: 27
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top