My Services.msc :(

Status
Not open for further replies.

Gib

Level 3
Thread author
Verified
Well-known
Forum Veteran
May 23, 2014
113
1,475
168
45
Hello, when I try to change a setting in services.msc, it won't stay that way. I want complete control of services.msc. I turned off a service and disabled it, now it's re-enabled. The FRST abruptly deleted itself.
 
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===


The Farbar program is updated often.
If it's identified as suspicious by your Anti-Virus program trust it if Downloaded from this link:


You can possibly restore the program from the Quarantine folder used by your Virus Protection Software.
<<<>>>

If you need additional help please ask.
 
Thanks, here are the results:
 

Attachments

Hi,

Your logs are clean of malware.

Lets see if we can fix this error.
How to Fix DCOM Error 1084 on Windows 10
<<<>>>


Press the Windows key + r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.

Code:
start

Comment: For your security a new restore point will be created.
CreateRestorePoint:
Comment: We need to close all processes to complete the fix.
CloseProcesses:

Comment: Items from the FRST.TXT log that will be removed from the Registry.
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
S3 cpuz153; \??\C:\WINDOWS\temp\cpuz153\cpuz153_x64.sys [X]


Comment: TCP/IP Reset
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /flushDNS

Comment: To rebuild the performance counter library values.
CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
CMD: "C:\Windows\SysWOW64\lodctr.exe /R"

Comment: Use Farbar routine to delete temp files
C:\Windows\Temp\*.*
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
C:\Program Files (x86)\Temp\*.tmp

cmd: sfc /scannow
cmd: DISM.exe /Online /Cleanup-image /Scanhealth
cmd: DISM.exe /Online /Cleanup-image /Restorehealth

Comment: The system will restart.
Reboot:

End

Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt.

If the problem persists please scan the computer with the Farbar program and post fresh logs log my review.
 
Ok, sorry about that, how do I make my av accept FRST, because I have to download it for the third time?
 

Attachments

  • FRST_concern.png
    FRST_concern.png
    202.9 KB · Views: 5
Nvmd, sorry about that, what I did was I turned off my av (not sure why I didn't think of that before) and downloaded FRST. I also updated my av.
 

Attachments

Hi,

The fixlog looks good. Any remaining issues?

FYI.

When a file is quarantined by the AV it can be recovered.

In the explample you posted I would check the box"IDP.Generic" and accept it. Making sure that the file listed is what I'm looking for.

The file should be de-quarantined and you should be able to run it.
 
Thanks for the information. As far as the service that I stopped and disabled, I did that yesterday. I checked this morning and the settings did not change, however, I checked a minute ago and the setting in services.msc is back to being enabled and manual.
 
Hi,


Letùs reset these services:

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===



Please post the Fixlog.txt and let me know what problem persists.
 

Attachments

This might end up being difficult to nip in the bud. I think that this black hat hacker is determined to manipulate, I really hope that you can
resolve this and outsmart this guy. The FRST failed to update.
 

Attachments

Hi,

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt wait for further instructions.
 

Attachments

Wait a minute, that might not be necessary, because I changed the settings in services.msc and so far it stayed. I will let you know if
there is something I don't like that the hacker is up to.
 
  • Like
Reactions: vtqhtr413
Hello Nasdaq, it's still looking good in my services.msc. You definitely know your stuff, I thought that this issue with my new laptop was going to be long and drawn out. Thanks very much🤓💻
 
  • Like
Reactions: Gandalf_The_Grey
Hi,

What I'm I doing wrong?
Why did you start a new topic here:
 
I'm sorry, you didn't do anything wrong. I was looking near the title and saw that this post was closed for replies, so I'm sorry that I didn't send you a private message.
 
Hello Nasdaq, can you help me?
 
Hi,

Let keep the communications on this topic.

Please post the latest Farbar logs here.

Hello, I do need help with something. I was able to stop any given service from running, however, when I try to disable one in particular, I get a "parameter is incorrect", message. Also, I had a service turned off and disabled and it changed to manual while staying idle.

Can you tell me which services were turned/disabled and then were changed to manual.
I would like to find out if any of these services are normally set by the Operating system.

I will close the there topic.
 
It's the Windows Update. I would stop it from running and disable it and he would change it back. Currently it is turned on and set to Manual, somehow this hacker is getting a big head. Here are the logs:
 

Attachments

Status
Not open for further replies.

You may also like...