Solved Base Filtering Engine could not be started. Error 5: Acess is denied

rusl07cl08

New member
Local time
7:46 AM
Messages
19
Every time I start the service from Services, I always get this error:

Windows could not start the Base Filtering Engine service on Local computer.
Error 5: Access is denied.

I tried this code: Reg Query "HKLM\SYSTEM\CurrentControlSet\Services\BFE"> 0 & notepad 0
and this is the outcome:

Code:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
    DisplayName    REG_SZ    Base Filtering Engine
    Group    REG_SZ    NetworkProvider
    ImagePath    REG_EXPAND_SZ    %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
    Description    REG_SZ    @%SystemRoot%\system32\bfe.dll,-1002
    ObjectName    REG_SZ    NT AUTHORITY\LocalService
    ErrorControl    REG_DWORD    0x1
    Start    REG_DWORD    0x2
    Type    REG_DWORD    0x20
    DependOnService    REG_MULTI_SZ    RpcSs
    ServiceSidType    REG_DWORD    0x3
    RequiredPrivileges    REG_MULTI_SZ    SeAuditPrivilege
    FailureActions    REG_BINARY    805101000000000000000000030000001400000001000000C0D4010001000000E09304000000000000000000

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE\Parameters

I already uninstalled McAfee before and used McAfee removal tool (MCPR.exe). By the way, my anvtivirus is ESET Smart Security 5.
What can I do? Thanks for any advice.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Ultimate x64 7600 Multiprocessor Free
CPU
Pentium(R) Dual-Core CPU T4500 @2.30GHz, 2300 MHz, 2 Core(s)
Motherboard
TOSHIBA Portable PC
Memory
3.00 GB
Graphics Card(s)
Mobile Intel(R) 45 Express Chipset Family(Microsoft-WDDM1.1)
Sound Card
High Defition Audio Device (Microsoft)
Monitor(s) Displays
Mobile PC Display
Screen Resolution
1366 x 768
Hard Drives
Hitachi HTS545032B9A300 ATA Device
PSU
Microsoft Composite Battery
Keyboard
Standard PS/2 Keyboard
Mouse
Synaptics PS/2 Port Touchpad
Internet Speed
100.0 Mbps
Antivirus
ESET Smart Security Version 5.2.9.1
Browser
Google Chrome
Other Info
has Bluetooth Radios
BIOS: InsydeH2O Version 1.40

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ACER ASPIRE 5742G
OS
Microsoft Windows 7 Home Premium 64-bits 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer Aspire 5742G
Memory
4,00 GB
Graphics Card(s)
ATI Mobility Radeon HD 5400 Series
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
WDC WD5000BEVT-22ZAT0
Run Trojan Remover (http://www.simplysup.co.uk/download/dl/trjsetup691.exe), it will check for infections and also it will replace any missing or corrupt service. for every detection it will give you a pop-up with the details of detected object and will ask you to select an action for the detected object (action selected by default is recommended).
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell Vostro 2520
OS
Windows 10 Tech Preview
CPU
Intel i5 (3rd Gen)
Motherboard
Intel® Mobile HM75 Express chipset
Memory
4GB
Graphics Card(s)
Intel HD Graphics 4000
Hard Drives
500GB
Keyboard
onboard keypad, USB keyboard
Mouse
touchpad, USB mouse, wireless muse
Internet Speed
4 Mbps
Antivirus
No
Browser
IE, chrome, firefox

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Ultimate x64 7600 Multiprocessor Free
CPU
Pentium(R) Dual-Core CPU T4500 @2.30GHz, 2300 MHz, 2 Core(s)
Motherboard
TOSHIBA Portable PC
Memory
3.00 GB
Graphics Card(s)
Mobile Intel(R) 45 Express Chipset Family(Microsoft-WDDM1.1)
Sound Card
High Defition Audio Device (Microsoft)
Monitor(s) Displays
Mobile PC Display
Screen Resolution
1366 x 768
Hard Drives
Hitachi HTS545032B9A300 ATA Device
PSU
Microsoft Composite Battery
Keyboard
Standard PS/2 Keyboard
Mouse
Synaptics PS/2 Port Touchpad
Internet Speed
100.0 Mbps
Antivirus
ESET Smart Security Version 5.2.9.1
Browser
Google Chrome
Other Info
has Bluetooth Radios
BIOS: InsydeH2O Version 1.40
You simply recreated HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE\Parameters ?
Any idea why it was missing???? Can be due to virus or virus removal.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ACER ASPIRE 5742G
OS
Microsoft Windows 7 Home Premium 64-bits 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer Aspire 5742G
Memory
4,00 GB
Graphics Card(s)
ATI Mobility Radeon HD 5400 Series
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
WDC WD5000BEVT-22ZAT0
You simply recreated HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE\Parameters ?
Any idea why it was missing???? Can be due to virus or virus removal.

Yeah I did it manually. I think its because of rootkit, as I have run rkill. What do you advice?
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Ultimate x64 7600 Multiprocessor Free
CPU
Pentium(R) Dual-Core CPU T4500 @2.30GHz, 2300 MHz, 2 Core(s)
Motherboard
TOSHIBA Portable PC
Memory
3.00 GB
Graphics Card(s)
Mobile Intel(R) 45 Express Chipset Family(Microsoft-WDDM1.1)
Sound Card
High Defition Audio Device (Microsoft)
Monitor(s) Displays
Mobile PC Display
Screen Resolution
1366 x 768
Hard Drives
Hitachi HTS545032B9A300 ATA Device
PSU
Microsoft Composite Battery
Keyboard
Standard PS/2 Keyboard
Mouse
Synaptics PS/2 Port Touchpad
Internet Speed
100.0 Mbps
Antivirus
ESET Smart Security Version 5.2.9.1
Browser
Google Chrome
Other Info
has Bluetooth Radios
BIOS: InsydeH2O Version 1.40
You simply recreated HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE\Parameters ?
Any idea why it was missing???? Can be due to virus or virus removal.

Yeah I did it manually. I think its because of rootkit, as I have run rkill. What do you advice?
Why didn't you tell that in previous posts!?
I didn't make rkill and don't know what it did fix. http://www.sevenforums.com/tutorials/783-elevated-command-prompt.html
Code:
sfc/scannow
To test the integrity of exe and dll files. Post results.
Eventlog is also a good starting point to detect problems.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ACER ASPIRE 5742G
OS
Microsoft Windows 7 Home Premium 64-bits 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer Aspire 5742G
Memory
4,00 GB
Graphics Card(s)
ATI Mobility Radeon HD 5400 Series
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
WDC WD5000BEVT-22ZAT0
You simply recreated HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE\Parameters ?
Any idea why it was missing???? Can be due to virus or virus removal.

Yeah I did it manually. I think its because of rootkit, as I have run rkill. What do you advice?
Why didn't you tell that in previous posts!?
I didn't make rkill and don't know what it did fix. http://www.sevenforums.com/tutorials/783-elevated-command-prompt.html
Code:
sfc/scannow
To test the integrity of exe and dll files. Post results.
Eventlog is also a good starting point to detect problems.

Oh I'm sorry. This is the result of sfc/ scannow: Windows Resource Protection did not find any integrity violations.
Sorry for the delay of the result because operation fails many times until it successfully done. Thanks!

Oh, btw, I have run Trojan Remover (http://www.simplysup.co.uk/download/dl/trjsetup691.exe) as Mayank Parmar advised.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Ultimate x64 7600 Multiprocessor Free
CPU
Pentium(R) Dual-Core CPU T4500 @2.30GHz, 2300 MHz, 2 Core(s)
Motherboard
TOSHIBA Portable PC
Memory
3.00 GB
Graphics Card(s)
Mobile Intel(R) 45 Express Chipset Family(Microsoft-WDDM1.1)
Sound Card
High Defition Audio Device (Microsoft)
Monitor(s) Displays
Mobile PC Display
Screen Resolution
1366 x 768
Hard Drives
Hitachi HTS545032B9A300 ATA Device
PSU
Microsoft Composite Battery
Keyboard
Standard PS/2 Keyboard
Mouse
Synaptics PS/2 Port Touchpad
Internet Speed
100.0 Mbps
Antivirus
ESET Smart Security Version 5.2.9.1
Browser
Google Chrome
Other Info
has Bluetooth Radios
BIOS: InsydeH2O Version 1.40
Any detection in trojan remover?
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell Vostro 2520
OS
Windows 10 Tech Preview
CPU
Intel i5 (3rd Gen)
Motherboard
Intel® Mobile HM75 Express chipset
Memory
4GB
Graphics Card(s)
Intel HD Graphics 4000
Hard Drives
500GB
Keyboard
onboard keypad, USB keyboard
Mouse
touchpad, USB mouse, wireless muse
Internet Speed
4 Mbps
Antivirus
No
Browser
IE, chrome, firefox
Please follow the Windows Update Posting Instructions and post the requested data
If the file is too large (8MB compressed), remove the older CBSPersist cab files until the final file is below the limit - you can always post them separately after zipping them. (the forum doesn't allow the upload of bare CAB files, for a number of reasons)
Also...

Open Event Viewer
click on the Windows logs entry in the left pane to expand it.
Now click on the Application entry - wait while it loads.
Click on 'File' in the menu bar and select Save...
Save the file as Appevt.evtx
Repeat for the System log
then zip both, and upload them.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Back
Top