Unable to start Windows Security Center Service

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wglmb, Apr 4, 2013.

  1. wglmb

    wglmb Private E-2

    AVG Free detected some malware, and did its best to remove it... but there's still something left. I know because it finds something every time I reboot, and because the Windows Security Centre service is being blocked. I'm getting an Action Centre warning telling me this, but when I try to activate the service, it fails.

    I've gone through the scans in the cleaning procedure, and my logs are attached.

    Any help would be really great. Let me know if any more info will help. I'm running Windows 7.

    Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The registry key has been deleted. We will get to this later. First let's fix the below.

    Re-run RogueKiller and run a scan. After it finishes the scan, select the Registry tab and then select any of the below that exist and then click the Delete button. Only fix the ProxyServer entry if it is not something you knowingly added.

    Then immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in original instructions and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
    Then attach the below logs:
    • the new RogueKiller log
    • C:\MGlogs.zip
     
  3. wglmb

    wglmb Private E-2

    Thanks chaslang.

    Here are the logs. I removed the registry items, but they reappeared after I rebooted. I also removed the proxy entry, and that stayed gone...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Uninstall the below very old versions of software:
    Java(TM) 6 Update 22
    Java(TM) 6 Update 31
    Java(TM) SE Runtime Environment 6

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {f999a48b-1950-4d81-9971-79018f807b4b} - (no file)
    F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,,C:\Users\William\AppData\Local\vxcfjoqo\eetrtrac.exe
    O4 - HKCU\..\Run: [EetRtrac] C:\Users\William\AppData\Local\vxcfjoqo\eetrtrac.exe
    O4 - Startup: eetrtrac.exe

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run it by double clicking on it (Note: if using Vista, Win7, or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Users\William\AppData\Local\vxcfjoqo\eetrtrac.exe
    C:\Users\William\AppData\Local\vxcfjoqo
    C:\Users\William\AppData\Local\*.log
    C:\ProgramData\sloikfya.log
    C:\Windows\temp\*.*
    C:\Users\William\AppData\Local\Temp\eetrtrac.exe
    C:\Users\William\AppData\Local\Temp\vjrmvtcl.exe
    C:\Users\William\AppData\Local\Temp\*.*
    
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "EetRtrac"=-
    [HKEY_USERS\S-1-5-21-3556141506-1870151257-3133043203-1007\Software\Microsoft\Windows\CurrentVersion\run]
    "EetRtrac"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="C:\Windows\system32\userinit.exe,"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{04CA1DBB-78B9-4963-96E6-B7EA4C1F36F8}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{18E9CF3E-2FE3-4AB1-9ED4-1F44FAEDC246}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. wglmb

    wglmb Private E-2

    Done!
    I fixed the first three, but the fourth wasn't there...
    I scanned again after I had clicked Fix, and the middle two reappeared, so I'm not sure whether the fix was successful.

    All done, and here are my logs!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your new MGlogs.zip, you either did not fix anything or you ran things out of order. Your MGlogs.zip shows no sign of anything being fixed. Did you run GetLogs.bat before you finished running OTM? That's what it looks like. OTM.exe is not even showing in the logs and neither is the result of running OTM.
     
  7. wglmb

    wglmb Private E-2

    Sorry chaslang, I don't understand how that happened, since I did everything in order. Could it be because I moved the _OTM folder to a pen drive before running GetLogs.bat? I've disconnected the computer from the internet till it's clean, so I'm transferring the logs to another PC. I'll copy instead of moving in future, in case that's what the problem was.

    I've done all the steps again, and here are my new logs.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is correct. You need to copy files not move them so that I can see the effects from the fixes. Also it may be best if you actually allow the PC to be connected to the internet during the steps so that I can see the effects on your network connection too. It will also simply log retrieval/attachment as long as the internet functions.

    I see more problems than just the Security Center service. I see all of the below service issues:
    Code:
        ---------------------------------------------------------------------------- 
         Windows Backup and Restore Service  -SDRSVC-        is NOT running  
        ----------------------------------------------------------------------------
        Windows Defender service   -WinDefend-               is NOT running  
        ----------------------------------------------------------------------------    
         Windows Security Center service  -wscsvc-           is NOT running  
    [SC] OpenService FAILED 1060:
    The specified service does not exist as an installed service.
        ----------------------------------------------------------------------------
         Windows Update  -wuauserv-                          is NOT running          
            C:\Windows\System32\wuauserv.dll is missing  
        ----------------------------------------------------------------------------
    I'm concerned that AVG may be hindering some of our attempts to remove your malware and to repair various broken registry entries. Please uninstall AVG now before continuing with the next steps below. Do not reinstall it until requested.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,,C:\Users\William\AppData\Local\vxcfjoqo\eetrtrac.exe
    O4 - HKCU\..\Run: [EetRtrac] C:\Users\William\AppData\Local\vxcfjoqo\eetrtrac.exe
    O4 - Startup: eetrtrac.exe

    After clicking Fix, exit HJT.


    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Users\William\AppData\Local\vxcfjoqo\eetrtrac.exe
    C:\Users\William\AppData\Local\vxcfjoqo
    C:\Users\William\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eetrtrac.exe
    C:\Windows\temp\*.*
    C:\Users\William\AppData\Local\Temp\*.*
     
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="C:\Windows\system32\userinit.exe,"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "EetRtrac"=-
    [HKEY_USERS\S-1-5-21-3556141506-1870151257-3133043203-1007\Software\Microsoft\Windows\CurrentVersion\run]
    "EetRtrac"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc]
    "DisplayName"="@%SystemRoot%\\System32\\wscsvc.dll,-200"
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
      32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,4c,6f,63,61,6c,53,65,72,\
      76,69,63,65,4e,65,74,77,6f,72,6b,52,65,73,74,72,69,63,74,65,64,00
    "Start"=dword:00000002
    "Type"=dword:00000020
    "Description"="@%SystemRoot%\\System32\\wscsvc.dll,-201"
    "DependOnService"=hex(7):52,70,63,53,73,00,57,69,6e,4d,67,6d,74,00,00
    "ObjectName"="NT AUTHORITY\\LocalService"
    "ServiceSidType"=dword:00000001
    "RequiredPrivileges"=hex(7):53,65,43,68,61,6e,67,65,4e,6f,74,69,66,79,50,72,69,\
      76,69,6c,65,67,65,00,53,65,49,6d,70,65,72,73,6f,6e,61,74,65,50,72,69,76,69,\
      6c,65,67,65,00,00
    "DelayedAutoStart"=dword:00000001
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
      00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc\Parameters]
    "ServiceDllUnloadOnStop"=dword:00000001
    "ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
      33,32,5c,77,73,63,73,76,63,2e,64,6c,6c,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc\Security]
    "Security"=hex:01,00,14,80,c8,00,00,00,d4,00,00,00,14,00,00,00,30,00,00,00,02,\
      00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
      00,00,02,00,98,00,06,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
      05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
      20,02,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\
      00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,00,00,14,00,00,01,\
      00,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,28,00,15,00,00,00,01,06,00,\
      00,00,00,00,05,50,00,00,00,49,59,9d,77,91,56,e5,55,dc,f4,e2,0e,a7,8b,eb,ca,\
      7b,42,13,56,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,\
      00,00,00
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer][Reboot]
    
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
    We will have more to fix related to the services but I want to start with the above.
     
  9. wglmb

    wglmb Private E-2

    Ok, I uninstalled AVG and enabled the internet connection before doing anything. Then I followed your instructions, and everything seemed to go ok.

    The logs are attached. :)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The fix still did not work properly according to your logs. Many of the items that OTM said it removed are still showing. Did you run GetLogs.bat AFTER OTM had finished and after your PC had been rebooted?

    Let's see if the below will run. There may be something else hiding from view.


    Now download and save a copy of combofix.exe and save it directly onto your Desktop folder.
    • Then right click on it and select Run As Administrator. Do not disturb it by clicking in the window that opens or it may stall.
    • After it finishes, it may reboot your PC. Attach the C:\combofix.txt log that it creates.
    • If after running Combofix you discover none of your programs will open up because you receive the following error:
      • Illegal operation attempted on a registry key that has been marked for deletion
    • Then you will need to reboot your computer which will normally fix this problem.
     
  11. wglmb

    wglmb Private E-2

    Yes, I didn't run getlogs until after OTM was done, and my computer had rebooted. Hmm...

    I downloaded combofix to my desktop and tried to run it. It showed a window for a second, then vanished. I renamed the file to cf.exe and tried again - this time it worked.
    It came up with warning after a while, saying that AVG was running and I should disable it... but AVG is definitely uninstalled, and I couldn't see any AVG processes or services running. So I just clicked ok. It warned me that I'd be proceeding at my own risk, and I clicked ok again... Everything seemed to go ok after that... here's my log!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. wglmb

    wglmb Private E-2

    Right, here are my new logs! Everything ran smoothly... I think Java was up to date, but I reinstalled just in case.

    How do things look in my logs now?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks much better, but how are things working.

    We do need to restore a folder I inadvertantly deleted. We need to restore from the ComboFix quarantine with the below procedure.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named C:\DeQuarantine_log.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\DeQuarantine_log.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. wglmb

    wglmb Private E-2

    Here are my new logs. The security centre service is running now, so that's very promising :) I can't see any evidence of malware any more - although my only other indication before was that AVG kept finding some at startup, and since AVG's uninstalled now, I obviously don't get that...
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.
    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. wglmb

    wglmb Private E-2

    Here are my logs... It didn't take long, probably less than 20 minutes :)

    As before, things now seem ok as far as I can tell...
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  19. wglmb

    wglmb Private E-2

    Wonderful! Thanks so much for your help chaslang, you're brilliant!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks. :)

    Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds