Server service access denied

Discussion in 'Software' started by LordDragonDan, Aug 31, 2006.

  1. LordDragonDan

    LordDragonDan Private E-2

    I can't start the server service. I get "error 5: access denied." My kid surfed some sites with the web filtering off (my fault). Fixed some other major problems, but this one has me stumped. I am the administrator. Any ideas?

    HP PC
    Pentium 4 1.8 Ghz, 384 MB RAM
    Windows XP Pro Version 2002 SP2

    Avast home AV, ZoneAlarm Pro, SpywareGuard, Spybot S&D, Ad-Aware

    Thanks,

    Dan
     
  2. yank101

    yank101 Private First Class

    Error 5 is most likely something is not giving you permission ‘no duh’.
    make sure you are logged on using an account that has permission to view the shares on the remote computer. ie. is log on an admin still there? “meaning your not a guest on your on pc!”.
    1. Kill fire wall, ‘try this frist' !
    2 . Change settings in your IE browser to default 'optional'
    some small simple things to try w/o messing up more stuff, good luck, hope you get better help then me!!!! cheers jeff
     
  3. erikske

    erikske Sergeant

    For clarity: which server do you mean? Do you mean the 'Server' service listed in the system services? Normally this service starts automatically and you don't have to start it, unless you or windows decided to turn it off first. The startup type for 'Server' should be set to automatic.
    As for firewall settings: svchost.exe should always be granted FULL access to everything, else your internet won't work.
     
  4. LordDragonDan

    LordDragonDan Private E-2

    I can't start the server service. I get "error 5: access denied." Yes the server service. I am the administrator. I've tried turning off all the security. I've also tried everything else I can find. This is the only service I can't start. It is set to automatic but does not start.
     
  5. LordDragonDan

    LordDragonDan Private E-2

    Just to clarify I ran this.
    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    C:\Documents and Settings\Dan>net localgroup administrators
    Alias name administrators
    Comment Administrators have complete and unrestricted access to the compu
    ter/domain

    Members

    -------------------------------------------------------------------------------
    Administrator
    Dan
    The command completed successfully.


    C:\Documents and Settings\Dan>
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Question ....are you trying to access this from an account that doesn't have a password on the account (blank password?).
     
  7. erikske

    erikske Sergeant

    First, verify that File and printer sharing is enabled for your network connection.
    Second, check that the path to the Server service is set to '%systemroot%\System32\svchost.exe -k netsvcs'
     
  8. LordDragonDan

    LordDragonDan Private E-2

    It is a password protect administrator account. I have file and print sharing on. I can't find Server under HKLM\SYSTEM\CurrentControlSet\Services
    I've kind of suspected the key is missing but am not sure. Some thing delete the keys for windows installer. I've fixed that already.Other services do have the path '%systemroot%\System32\svchost.exe -k netsvcs'.
    I'm still on dial-up. I will have DSL in a few days. I don't know for sure how long ago this problem started. I think April. Is there any way I can open my registry back ups to check, other than importing them into the current registry? This is very frustrating since I can (and have) fix almost anything on my PC. MS forums have been useless, when there even working.
     
  9. erikske

    erikske Sergeant

    The 'Server' registry key is located at HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver
    This key may have gone bad. Export it as a text file and post it here. I'll see if i can find any errors then.
    Other cases of this problem have been solved by replacing the lanmanserver key by one from a 'healthy' computer. If you decide to try this, make sure to backup your own key first.
     
  10. LordDragonDan

    LordDragonDan Private E-2

    Here it is. I my wife has XP home, this machine has Pro. Not sure if the keys would be the same.

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver
    Class Name: <NO CLASS>
    Last Write Time: 9/1/2006 - 9:00 AM
    Value 0
    Name: Type
    Type: REG_DWORD
    Data: 0x120
    Value 1
    Name: Start
    Type: REG_DWORD
    Data: 0x2
    Value 2
    Name: ErrorControl
    Type: REG_DWORD
    Data: 0x1
    Value 3
    Name: ImagePath
    Type: REG_EXPAND_SZ
    Data: %SystemRoot%\system32\svchost.exe -k netsvcs
    Value 4
    Name: DisplayName
    Type: REG_SZ
    Data: Server
    Value 5
    Name: ObjectName
    Type: REG_SZ
    Data: LocalSystem
    Value 6
    Name: Description
    Type: REG_SZ
    Data: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\AutotunedParameters
    Class Name: <NO CLASS>
    Last Write Time: 8/30/2006 - 11:27 PM
    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\DefaultSecurity
    Class Name: <NO CLASS>
    Last Write Time: 8/30/2006 - 11:27 PM
    Value 0
    Name: SrvsvcConfigInfo
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 c8 00 00 00 - d4 00 00 00 00 00 00 00 ....È...Ô.......
    00000010 14 00 00 00 02 00 b4 00 - 08 00 00 00 01 00 18 00 ......´.........
    00000020 17 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 25 02 00 00 01 00 14 00 - 16 00 0f 00 01 01 00 00 %...............
    00000040 00 00 00 05 07 00 00 00 - 01 00 14 00 16 00 0f 00 ................
    00000050 01 01 00 00 00 00 00 01 - 00 00 00 00 00 00 18 00 ................
    00000060 17 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000070 20 02 00 00 00 00 14 00 - 01 00 00 00 01 01 00 00 ...............
    00000080 00 00 00 05 07 00 00 00 - 00 00 14 00 01 00 00 00 ................
    00000090 01 01 00 00 00 00 00 01 - 00 00 00 00 00 00 18 00 ................
    000000a0 17 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    000000b0 23 02 00 00 00 00 14 00 - 17 00 0f 00 01 01 00 00 #...............
    000000c0 00 00 00 05 12 00 00 00 - 01 01 00 00 00 00 00 05 ................
    000000d0 12 00 00 00 01 01 00 00 - 00 00 00 05 12 00 00 00 ................

    Value 1
    Name: SrvsvcTransportEnum
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 8c 00 00 00 - 98 00 00 00 00 00 00 00 ................
    00000010 14 00 00 00 02 00 78 00 - 05 00 00 00 00 00 18 00 ......x.........
    00000020 17 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 20 02 00 00 00 00 18 00 - 17 00 0f 00 01 02 00 00 ...............
    00000040 00 00 00 05 20 00 00 00 - 25 02 00 00 00 00 14 00 .... ...%.......
    00000050 17 00 0f 00 01 01 00 00 - 00 00 00 05 12 00 00 00 ................
    00000060 00 00 18 00 03 00 00 00 - 01 02 00 00 00 00 00 05 ................
    00000070 20 00 00 00 23 02 00 00 - 00 00 14 00 01 00 00 00 ...#...........
    00000080 01 01 00 00 00 00 00 05 - 0b 00 00 00 01 01 00 00 ................
    00000090 00 00 00 05 12 00 00 00 - 01 01 00 00 00 00 00 05 ................
    000000a0 12 00 00 00 ....
    Value 2
    Name: SrvsvcConnection
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 7c 00 00 00 - 88 00 00 00 00 00 00 00 ....|...........
    00000010 14 00 00 00 02 00 68 00 - 04 00 00 00 00 00 18 00 ......h.........
    00000020 01 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 20 02 00 00 00 00 18 00 - 01 00 0f 00 01 02 00 00 ...............
    00000040 00 00 00 05 20 00 00 00 - 25 02 00 00 00 00 18 00 .... ...%.......
    00000050 01 00 00 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000060 26 02 00 00 00 00 18 00 - 01 00 00 00 01 02 00 00 &...............
    00000070 00 00 00 05 20 00 00 00 - 23 02 00 00 01 01 00 00 .... ...#.......
    00000080 00 00 00 05 12 00 00 00 - 01 01 00 00 00 00 00 05 ................
    00000090 12 00 00 00 ....
    Value 3
    Name: SrvsvcServerDiskEnum
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 4c 00 00 00 - 58 00 00 00 00 00 00 00 ....L...X.......
    00000010 14 00 00 00 02 00 38 00 - 02 00 00 00 00 00 18 00 ......8.........
    00000020 01 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 20 02 00 00 00 00 18 00 - 01 00 0f 00 01 02 00 00 ...............
    00000040 00 00 00 05 20 00 00 00 - 25 02 00 00 01 01 00 00 .... ...%.......
    00000050 00 00 00 05 12 00 00 00 - 01 01 00 00 00 00 00 05 ................
    00000060 12 00 00 00 ....
    Value 4
    Name: SrvsvcFile
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 64 00 00 00 - 70 00 00 00 00 00 00 00 ....d...p.......
    00000010 14 00 00 00 02 00 50 00 - 03 00 00 00 00 00 18 00 ......P.........
    00000020 11 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 20 02 00 00 00 00 18 00 - 11 00 0f 00 01 02 00 00 ...............
    00000040 00 00 00 05 20 00 00 00 - 25 02 00 00 00 00 18 00 .... ...%.......
    00000050 11 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000060 23 02 00 00 01 01 00 00 - 00 00 00 05 12 00 00 00 #...............
    00000070 01 01 00 00 00 00 00 05 - 12 00 00 00 ............
    Value 5
    Name: SrvsvcShareFileInfo
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 8c 00 00 00 - 98 00 00 00 00 00 00 00 ................
    00000010 14 00 00 00 02 00 78 00 - 05 00 00 00 00 00 18 00 ......x.........
    00000020 13 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 20 02 00 00 00 00 18 00 - 13 00 0f 00 01 02 00 00 ...............
    00000040 00 00 00 05 20 00 00 00 - 25 02 00 00 00 00 18 00 .... ...%.......
    00000050 13 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000060 23 02 00 00 00 00 14 00 - 01 00 00 00 01 01 00 00 #...............
    00000070 00 00 00 01 00 00 00 00 - 00 00 14 00 01 00 00 00 ................
    00000080 01 01 00 00 00 00 00 05 - 07 00 00 00 01 01 00 00 ................
    00000090 00 00 00 05 12 00 00 00 - 01 01 00 00 00 00 00 05 ................
    000000a0 12 00 00 00 ....
    Value 6
    Name: SrvsvcSharePrintInfo
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 a4 00 00 00 - b0 00 00 00 00 00 00 00 ....¤...°.......
    00000010 14 00 00 00 02 00 90 00 - 06 00 00 00 00 00 18 00 ................
    00000020 13 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 20 02 00 00 00 00 18 00 - 13 00 0f 00 01 02 00 00 ...............
    00000040 00 00 00 05 20 00 00 00 - 25 02 00 00 00 00 18 00 .... ...%.......
    00000050 13 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000060 26 02 00 00 00 00 18 00 - 13 00 0f 00 01 02 00 00 &...............
    00000070 00 00 00 05 20 00 00 00 - 23 02 00 00 00 00 14 00 .... ...#.......
    00000080 01 00 00 00 01 01 00 00 - 00 00 00 01 00 00 00 00 ................
    00000090 00 00 14 00 01 00 00 00 - 01 01 00 00 00 00 00 05 ................
    000000a0 07 00 00 00 01 01 00 00 - 00 00 00 05 12 00 00 00 ................
    000000b0 01 01 00 00 00 00 00 05 - 12 00 00 00 ............
    Value 7
    Name: SrvsvcShareAdminInfo
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 8c 00 00 00 - 98 00 00 00 00 00 00 00 ................
    00000010 14 00 00 00 02 00 78 00 - 05 00 00 00 00 00 18 00 ......x.........
    00000020 13 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 20 02 00 00 00 00 18 00 - 02 00 00 00 01 02 00 00 ...............
    00000040 00 00 00 05 20 00 00 00 - 25 02 00 00 00 00 18 00 .... ...%.......
    00000050 02 00 00 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000060 23 02 00 00 00 00 14 00 - 01 00 00 00 01 01 00 00 #...............
    00000070 00 00 00 01 00 00 00 00 - 00 00 14 00 01 00 00 00 ................
    00000080 01 01 00 00 00 00 00 05 - 07 00 00 00 01 01 00 00 ................
    00000090 00 00 00 05 12 00 00 00 - 01 01 00 00 00 00 00 05 ................
    000000a0 12 00 00 00 ....
    Value 8
    Name: SrvsvcShareConnect
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 8c 00 00 00 - 98 00 00 00 00 00 00 00 ................
    00000010 14 00 00 00 02 00 78 00 - 05 00 00 00 00 00 18 00 ......x.........
    00000020 03 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 20 02 00 00 00 00 18 00 - 03 00 0f 00 01 02 00 00 ...............
    00000040 00 00 00 05 20 00 00 00 - 25 02 00 00 00 00 18 00 .... ...%.......
    00000050 03 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000060 27 02 00 00 00 00 14 00 - 01 00 00 00 01 01 00 00 '...............
    00000070 00 00 00 01 00 00 00 00 - 00 00 14 00 01 00 00 00 ................
    00000080 01 01 00 00 00 00 00 05 - 07 00 00 00 01 01 00 00 ................
    00000090 00 00 00 05 12 00 00 00 - 01 01 00 00 00 00 00 05 ................
    000000a0 12 00 00 00 ....
    Value 9
    Name: SrvsvcShareAdminConnect
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 64 00 00 00 - 70 00 00 00 00 00 00 00 ....d...p.......
    00000010 14 00 00 00 02 00 50 00 - 03 00 00 00 01 00 18 00 ......P.........
    00000020 03 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 25 02 00 00 00 00 18 00 - 03 00 0f 00 01 02 00 00 %...............
    00000040 00 00 00 05 20 00 00 00 - 20 02 00 00 00 00 18 00 .... ... .......
    00000050 03 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000060 27 02 00 00 01 01 00 00 - 00 00 00 05 12 00 00 00 '...............
    00000070 01 01 00 00 00 00 00 05 - 12 00 00 00 ............
    Value 10
    Name: SrvsvcStatisticsInfo
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 60 00 00 00 - 6c 00 00 00 00 00 00 00 ....`...l.......
    00000010 14 00 00 00 02 00 4c 00 - 03 00 00 00 00 00 18 00 ......L.........
    00000020 01 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 20 02 00 00 00 00 18 00 - 01 00 0f 00 01 02 00 00 ...............
    00000040 00 00 00 05 20 00 00 00 - 25 02 00 00 00 00 14 00 .... ...%.......
    00000050 01 00 00 00 01 01 00 00 - 00 00 00 02 00 00 00 00 ................
    00000060 01 01 00 00 00 00 00 05 - 12 00 00 00 01 01 00 00 ................
    00000070 00 00 00 05 12 00 00 00 - ........
    Value 11
    Name: AnonymousDescriptorsUpgraded
    Type: REG_DWORD
    Data: 0x1
    Value 12
    Name: PreviousAnonymousRestriction
    Type: REG_DWORD
    Data: 0x0
    Value 13
    Name: SrvsvcSessionInfo
    Type: REG_BINARY
    Data:
    00000000 01 00 04 80 78 00 00 00 - 84 00 00 00 00 00 00 00 ....x...........
    00000010 14 00 00 00 02 00 64 00 - 04 00 00 00 00 00 18 00 ......d.........
    00000020 13 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000030 20 02 00 00 00 00 18 00 - 13 00 0f 00 01 02 00 00 ...............
    00000040 00 00 00 05 20 00 00 00 - 25 02 00 00 00 00 18 00 .... ...%.......
    00000050 13 00 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000060 23 02 00 00 00 00 14 00 - 01 00 00 00 01 01 00 00 #...............
    00000070 00 00 00 05 0b 00 00 00 - 01 01 00 00 00 00 00 05 ................
    00000080 12 00 00 00 01 01 00 00 - 00 00 00 05 12 00 00 00 ................

    Value 14
    Name: SessionSecurityDescriptorRegenerated
    Type: REG_DWORD
    Data: 0x1

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Linkage
    Class Name: <NO CLASS>
    Last Write Time: 8/30/2006 - 11:27 PM
    Value 0
    Name: Bind
    Type: REG_MULTI_SZ
    Data: \Device\NwlnkNb
    \Device\NwlnkIpx
    \Device\NetbiosSmb
    \Device\NetBT_Tcpip6_{966AD9E7-6E4B-418B-877B-6BEBF63D10E5}
    \Device\NetBT_Tcpip6_{FDECAC9E-FAEC-4EB6-8065-9F22334221A4}
    \Device\NetBT_Tcpip_{966AD9E7-6E4B-418B-877B-6BEBF63D10E5}
    \Device\NetBT_Tcpip_{DF121A31-E114-464C-9CDC-8BA5CCA6C98A}
    \Device\NetBT_Tcpip_{02E82768-60E7-4F2B-887A-065ADD37BA87}
    \Device\NetBT_Tcpip_{1B27249C-DCBF-4A4D-BE52-531436BBDC8F}
    \Device\NetBT_Tcpip_{AE0A1C61-2121-41FB-97D3-B741273B69B7}
    Value 1
    Name: Route
    Type: REG_MULTI_SZ
    Data: "NwlnkNb"
    "NwlnkIpx"
    "NetbiosSmb"
    "NetBT" "Tcpip6" "{966AD9E7-6E4B-418B-877B-6BEBF63D10E5}"
    "NetBT" "Tcpip6" "{FDECAC9E-FAEC-4EB6-8065-9F22334221A4}"
    "NetBT" "Tcpip" "{966AD9E7-6E4B-418B-877B-6BEBF63D10E5}"
    "NetBT" "Tcpip" "NdisWanIp"
    Value 2
    Name: Export
    Type: REG_MULTI_SZ
    Data: \Device\LanmanServer_NwlnkNb
    \Device\LanmanServer_NwlnkIpx
    \Device\LanmanServer_NetbiosSmb
    \Device\LanmanServer_NetBT_Tcpip6_{966AD9E7-6E4B-418B-877B-6BEBF63D10E5}
    \Device\LanmanServer_NetBT_Tcpip6_{FDECAC9E-FAEC-4EB6-8065-9F22334221A4}
    \Device\LanmanServer_NetBT_Tcpip_{966AD9E7-6E4B-418B-877B-6BEBF63D10E5}
    \Device\LanmanServer_NetBT_Tcpip_{DF121A31-E114-464C-9CDC-8BA5CCA6C98A}
    \Device\LanmanServer_NetBT_Tcpip_{02E82768-60E7-4F2B-887A-065ADD37BA87}
    \Device\LanmanServer_NetBT_Tcpip_{1B27249C-DCBF-4A4D-BE52-531436BBDC8F}
    \Device\LanmanServer_NetBT_Tcpip_{AE0A1C61-2121-41FB-97D3-B741273B69B7}

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters
    Class Name: <NO CLASS>
    Last Write Time: 9/1/2006 - 9:03 AM
    Value 0
    Name: autodisconnect
    Type: REG_DWORD
    Data: 0xf
    Value 1
    Name: enableforcedlogoff
    Type: REG_DWORD
    Data: 0x1
    Value 2
    Name: enablesecuritysignature
    Type: REG_DWORD
    Data: 0x0
    Value 3
    Name: requiresecuritysignature
    Type: REG_DWORD
    Data: 0x0
    Value 4
    Name: NullSessionPipes
    Type: REG_MULTI_SZ
    Data: COMNAP
    COMNODE
    SQL\QUERY
    SPOOLSS
    LLSRPC
    browser
    Value 5
    Name: NullSessionShares
    Type: REG_MULTI_SZ
    Data: COMCFG
    DFS$
    Value 6
    Name: ServiceDll
    Type: REG_EXPAND_SZ
    Data: %SystemRoot%\System32\srvsvc.dll
    Value 7
    Name: Lmannounce
    Type: REG_DWORD
    Data: 0x0
    Value 8
    Name: Size
    Type: REG_DWORD
    Data: 0x1
    Value 9
    Name: Guid
    Type: REG_BINARY
    Data:
    00000000 a5 6a 5b 2f 50 37 68 49 - a1 f9 90 17 d5 a5 2e af ¥j[/P7hI¡ù..Õ¥.¯

    Value 10
    Name: AdjustedNullSessionPipes
    Type: REG_DWORD
    Data: 0x1

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Security
    Class Name: <NO CLASS>
    Last Write Time: 8/30/2006 - 11:27 PM
    Value 0
    Name: Security
    Type: REG_BINARY
    Data:
    00000000 01 00 14 80 90 00 00 00 - 9c 00 00 00 14 00 00 00 ................
    00000010 30 00 00 00 02 00 1c 00 - 01 00 00 00 02 80 14 00 0...............
    00000020 ff 01 0f 00 01 01 00 00 - 00 00 00 01 00 00 00 00 ÿ...............
    00000030 02 00 60 00 04 00 00 00 - 00 00 14 00 8d 01 02 00 ..`.............
    00000040 01 01 00 00 00 00 00 05 - 0b 00 00 00 00 00 18 00 ................
    00000050 9d 01 02 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ............ ...
    00000060 23 02 00 00 00 00 18 00 - ff 01 0f 00 01 02 00 00 #.......ÿ.......
    00000070 00 00 00 05 20 00 00 00 - 20 02 00 00 00 00 14 00 .... ... .......
    00000080 fd 01 02 00 01 01 00 00 - 00 00 00 05 12 00 00 00 ý...............
    00000090 01 01 00 00 00 00 00 05 - 12 00 00 00 01 01 00 00 ................
    000000a0 00 00 00 05 12 00 00 00 - ........

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Shares
    Class Name: <NO CLASS>
    Last Write Time: 8/30/2006 - 11:27 PM
    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Shares\Security
    Class Name: <NO CLASS>
    Last Write Time: 8/30/2006 - 11:27 PM
    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Enum
    Class Name: <NO CLASS>
    Last Write Time: 9/1/2006 - 9:00 AM
    Value 0
    Name: 0
    Type: REG_SZ
    Data: Root\LEGACY_LANMANSERVER\0000
    Value 1
    Name: Count
    Type: REG_DWORD
    Data: 0x1
    Value 2
    Name: NextInstance
    Type: REG_DWORD
    Data: 0x1

    Thanks,

    Dan
     
    Last edited: Sep 1, 2006
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Someone correct me if I'm wrong, but in order to take possession of a file, don't you need to turn off file sharing?:confused:
     
  12. erikske

    erikske Sergeant

    This may be your error. The value marked in red should be 0x20 and not 0x120. To change it: run regedit, navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver and change the Type value to 0x20 (decimal 32).

    More info on Service registry keys.
     
    Last edited: Sep 1, 2006
  13. LordDragonDan

    LordDragonDan Private E-2

    Ok tried it, no luck. I thought maybe this key since is different from other security keys on services that work.

    HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver\Security

    0000 01 00 14 80 90 00 00 00
    0008 9C 00 00 00 14 00 00 00
    0010 30 00 00 00 02 00 1C 00
    0018 01 00 00 00 02 80 14 00
    0020 FF 01 0F 00 01 01 00 00
    0028 00 00 00 01 00 00 00 00
    0030 02 00 60 00 04 00 00 00
    0038 00 00 14 00 8D 01 02 00
    0040 01 01 00 00 00 00 00 05
    0048 0B 00 00 00 00 00 18 00
    0050 9D 01 02 00 01 02 00 00
    0058 00 00 00 05 20 00 00 00
    0060 23 02 00 00 00 00 18 00
    0068 FF 01 0F 00 01 02 00 00
    0070 00 00 00 05 20 00 00 00
    0078 20 02 00 00 00 00 14 00
    0080 FD 01 02 00 01 01 00 00
    0088 00 00 00 05 12 00 00 00
    0090 01 01 00 00 00 00 00 05
    0098 12 00 00 00 01 01 00 00
    00A0 00 00 00 05 12 00 00 00
    00A8
     
  14. LordDragonDan

    LordDragonDan Private E-2

    Last edited: Sep 2, 2006
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if either of these are in your registry:
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup]

    and writes the key

    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Nocana]
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Also look for these:
    Presence of the following file in %SYSTEM% folder (86,016 bytes):
    SYSPOLY32.EXE
    SYSANA32.EXE

    Presence of the following file in Program Files folder (108,336 bytes):
    MSWINSCK.OCX

    Presence of any of the following files in %SYSTEM% folder (137,651 bytes each):
    ANACON.EXE
    BUILD.EXE
    FORCE.EXE
    SCAN.EXE
    RUNTIME.EXE
    HANGUP.EXE
    HUNGRY.EXE
    THINGS.EXE
    AGAINST.EXE
    WARS.EXE

    Presence of the next registry keys:

    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"Nocana"]
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"PowerManagement"]
     
  17. LordDragonDan

    LordDragonDan Private E-2

    None of these are present on my system. Could have been removed by AV and anti-spy ware after the damage was done.

    Thanks
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  19. LordDragonDan

    LordDragonDan Private E-2

    Interesting but no help on this.

    Thanks,

    dan
     
  20. erikske

    erikske Sergeant

    Just a quick thought. Did you reboot the computer after you modified that registry key i said was wrong?
     
  21. LordDragonDan

    LordDragonDan Private E-2

    Yes, several times now. No luck.
     
  22. me.g33k

    me.g33k Private E-2

  23. StenCZ

    StenCZ Private E-2

    Just working on the same problem. Server service (and probably others) crashes when network is first time accessed (MSIE started or Explore network performed) - there is rastapi.dll related error in Application log. After that Server service could not be started (access denied). Could you check your apps event log to confirm similar error?
     
  24. StenCZ

    StenCZ Private E-2

    Short update - in my case the RasMon is iniciator of this crash - when I disabled this service (not sure about the english name, could be Remote access administrator ?) crash doesnt occure.. but its just workaround.
     
  25. SushilVanve

    SushilVanve Private E-2


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds