New
#31
Did you get the 'success' message on merging?
Please run the following commands, and post the results.
SC QC SHAREDACCESS
SC QC IPHLPSVC
Did you get the 'success' message on merging?
Please run the following commands, and post the results.
SC QC SHAREDACCESS
SC QC IPHLPSVC
I did, and I rebooted. That's strange...
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\John>SC QC SHAREDACCESS
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\Users\John>SC QC IPHLPSVC
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
Sounds like either your security software is preventing changes, or you still have some kind of infection
Please run a full system scan with (updated) Malwarebytes Anti-Malware - delete everything it finds. (this may trip MSE a few times as well - use MSE to remove anything that finds)
Also, run TDSSKiller and see if it finds anything... http://support.kaspersky.com/5350
I have Malwarebytes run every night, and it hasn't found anything... darn that would stink if there was something still around. I'll download that TDSSKiller now and post the results
Removing malware will not fix windows services.We need to change the permissions.
Please download Rkill by Grinler and save it to your desktop.
- Double-click on the Rkill desktop icon to run the tool.
- If using Vista, right-click on it and Run As Administrator.
- A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
- The log should be saved on the desktop
- Post it here
TDSSKiller did not find anything.
Here are the results from RKill:
Program started at: 03/03/2013 12:43:21 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\Samsung\PanelMgr\SSMMgr.exe (PID: 3588) [WD-HEUR]
* C:\Windows\Samsung\PanelMgr\caller64.exe (PID: 3192) [WD-HEUR]
2 proccesses terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
* HKLM\Software\Classes\exefile\shell\open\command\\IsolatedCommand was changed. It was reset to "%1" %*!
* HKLM\Software\Classes\exefile\shell\runas\command\\IsolatedCommand was changed. It was reset to "%1" %*!
Performing miscellaneous checks:
* ALERT: ZEROACCESS rootkit symptoms found!
* HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32 [ZA Reg Hijack]
Checking Windows Service Integrity:
* Base Filtering Engine (BFE) is not Running.
Startup Type set to: Automatic
* Windows Firewall (MpsSvc) is not Running.
Startup Type set to: Automatic
* iphlpsvc [Missing ImagePath]
* SharedAccess [Missing ImagePath]
* FontCache => %SystemRoot%\system32\svchost.exe -k LocalService [Incorrect ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* No issues found.
Program finished at: 03/03/2013 12:43:33 PM
Execution time: 0 hours(s), 0 minute(s), and 11 seconds(s)
Interesting -
Please run the following commands and post the results.
REG QUERY HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /S
SC QC BFE
SC QUERYEX BFE
SC QC MPSSVC
SC QUERYEX MPSSVC
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\John>REG QUERY HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966fe
abec1} /S
HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}
(Default) REG_SZ MruPidlList
HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32
(Default) REG_SZ C:\Users\John\AppData\Local\{4af788f3-f5ef-bc4a-96b7-
9d1b51f798b7}\n.
ThreadingModel REG_SZ Both
C:\Users\John>SC QC BFE
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: BFE
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceNoNe
twork
LOAD_ORDER_GROUP : NetworkProvider
TAG : 0
DISPLAY_NAME : Base Filtering Engine
DEPENDENCIES : RpcSs
SERVICE_START_NAME : NT AUTHORITY\LocalService
C:\Users\John>SC QUERYEX BFE
SERVICE_NAME: BFE
TYPE : 20 WIN32_SHARE_PROCESS
STATE : 1 STOPPED
WIN32_EXIT_CODE : 5 (0x5)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0
PID : 0
FLAGS :
C:\Users\John>SC QC MPSSVC
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: MPSSVC
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k LocalServiceNoNe
twork
LOAD_ORDER_GROUP : NetworkProvider
TAG : 0
DISPLAY_NAME : Windows Firewall
DEPENDENCIES : mpsdrv
: bfe
SERVICE_START_NAME : NT Authority\LocalService
C:\Users\John>SC QUERYEX MPSSVC
SERVICE_NAME: MPSSVC
TYPE : 20 WIN32_SHARE_PROCESS
STATE : 1 STOPPED
WIN32_EXIT_CODE : 1068 (0x42c)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0
PID : 0
FLAGS :
C:\Users\John>
The MPSSVC service isn't running because the BFE service can't run.
The SPPSVC shouldn't be running either! - and the machine should be complaining.
Please run the following commands, and post the results.
REG QUERY HKLM\SYSTEM\CurrentControlSet\services\spldr /S
REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR /S
REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SLSVC
REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SPPSVC
They may show something
Maybe my computer is a man and doesn't see the need to complain?
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\John>
C:\Users\John>REG QUERY HKLM\SYSTEM\CurrentControlSet\services\spldr /S
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\spldr
DisplayName REG_SZ Security Processor Loader Driver
ErrorControl REG_DWORD 0x3
Start REG_DWORD 0x0
Type REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\spldr\Enum
0 REG_SZ Root\LEGACY_SPLDR\0000
Count REG_DWORD 0x1
NextInstance REG_DWORD 0x1
C:\Users\John>REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR /S
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR
NextInstance REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR\0000
Service REG_SZ spldr
Legacy REG_DWORD 0x1
ConfigFlags REG_DWORD 0x400
Class REG_SZ LegacyDriver
ClassGUID REG_SZ {8ECC055D-047F-11D1-A537-0000F8753ED1}
DeviceDesc REG_SZ Security Processor Loader Driver
Capabilities REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR\0000\Control
ActiveService REG_SZ spldr
C:\Users\John>REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SLSVC
ERROR: The system was unable to find the specified registry key or value.
C:\Users\John>REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SPPSVC
ERROR: The system was unable to find the specified registry key or value.
C:\Users\John>