Computing.Net > Forums > Security and Virus > Winservices, PLEASE HELP ME!!!

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Winservices, PLEASE HELP ME!!!

Reply to Message Icon

Original Message
Name: Kazer0
Date: December 30, 2002 at 21:02:20 Pacific
Subject: Winservices, PLEASE HELP ME!!!
OS: Windows 98se
CPU/Ram: 266mhz / 192 SDRAM
Comment:

I first suspected there was somthing wrong when Norton Antivirus didnt load with windows, but i ignored it. I kept going, but found my PC going slower than usual, and the internet was screwy, like pics missing, pages not loading, slow speeds, downloads stopping.

I was pissed, so I tried to open Norton. It wouldnt open! So i hit CTRL+ALT+DEL and found 2 new things that I have never installed, nor seen b4 (one may be for my mouse, cuz i installed that) they were:

TCPsvs32 -and-
Winservices

So I went to a program I downloaded that turns off things that startup with my pc. I would diable Winserveces (it has a heart .gif next to it), and it just kept re-appearing! It was under two different tabs too!

So i went and downloaded mcafee demo. It wont load! It starts to install, but then just quits with no messages or anything.

So i went to REGEDIT, it popups, stayes there for 3 seconds, and closes too!

I looked and it says its under C:\Windows\System\winservices.exe , So i look there, and there is no such file. I looked in my startup folder too, its not there. I used FIND, its not to be found.

I ran ADWARE, and it didnt find it either! This file is invisible.

So in total, i tried:

Norton Antivirus (Wouldnt load)
McAfee Viruscan (Wouldnt Install)
ADWARE (Coulnt Find It)
Startup Control Panel (Just kept comming back)
REGEDIT (Would close on me)
FIND (Couldnt find it)
Searching throufgh my pc (Not There)


Would someon please help me?


Report Offensive Message For Removal


Response Number 1
Name: Kazer0
Date: December 30, 2002 at 21:10:59 Pacific
Reply: (edit)

Also, I cant close it throgh CTRL+ALT+DEL, it just runs again!


Report Offensive Follow Up For Removal

Response Number 2
Name: hylian_lynk
Date: December 30, 2002 at 23:57:12 Pacific
Reply: (edit)

sorry to say but it seems you have the
W32.Yaha.K@mm worm

have a look http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.k@mm.html

go to srnmicro.com and get a copy of solo antivirus and clean the worm .. you will noit be able to get norton to work .. you will most likely have to do a clean install of it again after you clean your system .. hope it helps


Report Offensive Follow Up For Removal

Response Number 3
Name: Tom41
Date: December 31, 2002 at 00:42:30 Pacific
Reply: (edit)

You will probably have problems trying to install and run any .exe's. To fix this, first go here and download and run exefix08.com. It will repair the .exe file associations. Then follow hylian_lynk's instructions.

http://home.earthlink.net/~rmbox/Reticulated/Only_IE.html


Report Offensive Follow Up For Removal

Response Number 4
Name: Kazer0
Date: December 31, 2002 at 14:09:10 Pacific
Reply: (edit)

I tried both suggestions, and neither worked. Halfway through the symnatech(spelling?), the regestry kept changing itself back, so I still couldnt run the viruscan, or install a new one!

PLEASE HELP ME


Report Offensive Follow Up For Removal

Response Number 5
Name: hylian_lynk
Date: December 31, 2002 at 18:29:39 Pacific
Reply: (edit)

since you can't actually install anything, then get a copy of the F-Prot DOS virus scanner ( check here http://www.f-prot.com/download/ )
then extract it to a folder and then boot into dos and run it .. you can also fit it on a floppy somehow there was a previous poston how to do this. You have to clean the worm other wise you will have to format .. but that would be a last resort.
F-prot should do the job .. i hope it works , take care .. let me know what happens


Report Offensive Follow Up For Removal


Response Number 6
Name: Palival
Date: January 1, 2003 at 00:42:26 Pacific
Reply: (edit)

Hello,

You are infected with New YAHA.K variant. Try Solo antivirus ( www.srnmicro.com ) The only antivirus software works effectively when the virus is active in memory!. Others fails to remove when the virus is active in memory.

Best of luck.


Report Offensive Follow Up For Removal

Response Number 7
Name: Becky
Date: January 1, 2003 at 12:12:41 Pacific
Reply: (edit)

Try the registry thing again, mine changed back a few times as I have just had this virus! but it worked in the end as long as u follow the instructions EXACTLY!!


Report Offensive Follow Up For Removal

Response Number 8
Name: Kazer0
Date: January 1, 2003 at 16:52:30 Pacific
Reply: (edit)

None of these helped me, but I did solve the problem my own way.

For Future Refrence to anyone else who gets this virus:

Instructions to remove the w32.yaha.k@mm worm:

1- Restart your computer in Safe Mode

2- Go to your windows system folder. In windows 9x, this is c:\windows\system\. The folder system32 is NOT the same thing.

3- At the top of the window, go to VIEW > FOLDER OPTIONS. When you get there, click on the tab that says VIEW. Then, click on the radio button labeled "Show All Files" under the Hidden Files category. Click Apply, then Ok.

4- Hit the keys CTRL+ALT+DEL and click on Winservices and hit End Task. Hit CTRL+ALT+DEL again, and click on TCPSVS32 and hit End Task.

5- Look through your Windows System Folder, and delete the files Winservices.exe, Nav32_loader.exe and TCPSVS32.exe. These 3 files should (but may not) have a blue heart as an icon.

6. Go to START > RUN and type in REGEDIT.exe . When this loads, go to HKEY_LOCAL_MACHINE > SOFTWARE > CLASSES > EXEFILE > SHELL > OPEN > COMMAND. (*NOTE* The folder labeled .exe is NOT the same as exefile. Continue to scroll down until you find the exefile folder.) Double Click on the one that says DEFAULT on the right side. Where it says Value Data, erase what it says and put in "%1"%* (quote-percent-one-quote-percent-asertek[star]). Close Regedit.

7- Now run your antivirus software. Make sure it is up to date. It should work now.

8- When the viruscan is done (it may not find any infected files, thats fine.) restart your computer normally.


That is how I fixed the virus. As for Viruscan, I reccommend using McAfee. Also, try Norton Antivirus, although McAfee is better.


Report Offensive Follow Up For Removal

Response Number 9
Name: aashish
Date: January 11, 2003 at 10:35:24 Pacific
Reply: (edit)

I have the same problem as mentioned above. I deleted the three files(Winservices.exe, Nav32_loader.exe and TCPSVS32.exe.)and all .scr files that had a blue heart icon.

Now I seem to face a bigger problem. None of my .exe files run now. I then tried to reinstall windows through my backup. Ironically the setup file itself didnot open as it is a .exe file.

HELP ME!!!! I can't run any of my programs.


Report Offensive Follow Up For Removal

Response Number 10
Name: mackymacmac
Date: January 12, 2003 at 20:31:12 Pacific
Reply: (edit)

After deleteing all these files (Winservice, Tctsvs32 and nav32_loader), Restart windows. Then... While windows is loading... press F8 and start in command Prompt.... then install win98. It should fix the problem... After installing your new windows... run regedit then go to the key with the Winservices then double click it... delete the contents (Note: Dont delete Winservice... just the value of it...) it will work.


Report Offensive Follow Up For Removal

Response Number 11
Name: Max Paswal
Date: January 13, 2003 at 03:17:42 Pacific
Reply: (edit)

Winservices.exe is the Yaha Virus. Get the YahaRemover. It is the best. All others (including McAfee and Symantec tools)did not work for me since the virus had disabled exe file execution on my computer. YahaRemover works brilliantly!

http://www.onlinepcfix.com/virushelp/antivirus.htm

Max


Report Offensive Follow Up For Removal

Response Number 12
Name: Kazer0
Date: January 20, 2003 at 17:20:31 Pacific
Reply: (edit)

A ha! To fix this problem, copy regedit.exe to reg.com

INSTR: Go to dos or a dos prompt. type in copy c:\windows\regedit.exe c:\windows\reg.com

run windows, go to START > RUN and type in c:\windows\reg.com

And follow instruction # 6 taking away the first line.


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software