1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Security Services Driver (x86) service failed to start...

Discussion in 'Malware and Virus Removal Archive' started by alexrozen, 2011/04/01.

  1. 2011/04/01
    alexrozen

    alexrozen Inactive Thread Starter

    Joined:
    2011/04/01
    Messages:
    1
    Likes Received:
    0
    [Inactive] Security Services Driver (x86) service failed to start...

    Hi, everybody: I use Win XP SR2 + Firefox + Thunderbird. It is Pentium 4, 1800 G, 1 G ram, 3 hdd (all 340 G)


    Please help me: either I need to reinstall the whole OS -- or I have some chances to repair it without re-installation?


    The Problem: Computer started behaving strangely, blue death, reboots during downloading (both via Firefox and FlashGet) -- and even without downloading. I often receive a message, that "Internet Explorer failed to start" -- though I practically do not use IE. Installation of IE 8 did not improve anything.

    I have Norton Antivirus + Norton Firewall and update them.

    My comp is never connected to the Internet, unless I need it; after that is disconnected.

    Several times I received an error message immediately after reboot in Event Viewer:
    ----------------------------
    "Event Type: Error
    Event Source: Service Control Manager
    Event Category: None
    Event ID: 7000
    Date: 4/1/2011
    Time: 12:51:37 PM
    User: N/A
    Computer: PEN4
    Description:
    The Security Services Driver (x86) service failed to start due to the following error:
    The system cannot find the file specified. "
    ------------------

    Also I had a strange error message about a strange service SSHNAS. "Event ID: 7023 The SSHNAS service terminated with the following error: The specified module could not be found." I removed it (disabled it). Still comp reboots erratically.

    I tried to check msconfig: disabled all (except MS) -- in this case I do not have any connection to the Web at all.

    My ISProvider's technical assistance also does not know what to do with the problem.

    Google redirected me to your forum.

    It was unexpected to me, as I use Norton antivirus (last update was this week) + Norton FireWall.

    I did all 4 steps you advised:
    Here are logs:

    -----------------
    /*1*/
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5363

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 8.0.6001.18702

    4/1/2011 12:49:15 PM
    mbam-log-2011-04-01 (12-49-15).txt

    Scan type: Quick scan
    Objects scanned: 137033
    Time elapsed: 5 minute(s), 52 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 1
    Registry Keys Infected: 7
    Registry Values Infected: 0
    Registry Data Items Infected: 4
    Folders Infected: 1
    Files Infected: 5

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa (PUP.Wpakill) -> Not selected for removal.
    HKEY_CURRENT_USER\SOFTWARE\ADWare (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\LEO0WTUNO7 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Visicom Media (Adware.KeenValue) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\StimulProfit (Adware.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ( "%1" /S) -> Quarantined and deleted successfully.

    Folders Infected:
    c:\documents and settings\cH_5zo\application data\FieryAds (Adware.FieryAds) -> Quarantined and deleted successfully.

    Files Infected:
    c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
    c:\documents and settings\cH_5zo\application data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
    c:\documents and settings\cH_5zo\application data\fieryads.dat (Adware.FieryAds) -> Quarantined and deleted successfully.
    c:\WINDOWS\Tasks\{35dc3473-a719-4d14-b7c1-fd326ca84a0c}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\winlogon.del (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.


    I also did GMER + mbrcheck + dds

    Thank you in advance
     
  2. 2011/04/01
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Welcome to WindowsBBS :)

    Please post the other logs requested and note .....

    As a new member with less than 10 posts any post you make which contains a URL requires approval (moderation) before it is visible.
     

  3. to hide this advert.

  4. 2011/04/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're using cracked Windows version:
    Unfortunately, I can't help you with your issues.
    You must install legit Windows on your computer.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.