{"id":189,"date":"2012-12-23T16:08:01","date_gmt":"2012-12-23T21:08:01","guid":{"rendered":"http:\/\/triplescomputers.com\/blog\/?p=189"},"modified":"2012-12-23T16:08:42","modified_gmt":"2012-12-23T21:08:42","slug":"solution-repair-damagedmissing-services-following-malware-infection","status":"publish","type":"post","link":"https:\/\/www.triplescomputers.com\/blog\/casestudies\/solution-repair-damagedmissing-services-following-malware-infection\/","title":{"rendered":"Solution: Repair damaged\/missing services following malware infection"},"content":{"rendered":"<p>Many times, following a nasty infection (such as that of various rogues or rootkits), you might notice that some of the critical Windows services are missing (such as the Security Center or Windows Firewall), or that Windows seems to be devoid of some typically critical functionality (such as Windows Update). \u00a0Apart from the obvious corrective measures that often must be taken post-disinfection (such as reinstalling any security software which might have been damaged), repairing system components can be much tougher.<\/p>\n<p>Today, I&#8217;ll focus specifically on how to detect\/repair some of the most commonly damaged services following an infection. \u00a0The four most commonly-damaged services are:<\/p>\n<ul>\n<li><strong>BITS<\/strong> (The Background Intelligent Transfer Service)<\/li>\n<li><strong>wscsvc<\/strong> (The Windows Security Center Service)<\/li>\n<li><em>(not present on XP)\u00a0<\/em><strong>BFE<\/strong> (The Base Filtering Engine Service)<\/li>\n<li><em>(not present on XP)\u00a0<\/em><strong>MpsSvc<\/strong> (The Windows Firewall Service)<\/li>\n<\/ul>\n<p>It&#8217;s easy to understand why these services specifically are targeted by infections:\u00a0<em>all\u00a0<\/em>of them are potential threats to the malware, as they deal directly with Windows&#8217; ability to protect and update itself.<\/p>\n<p>The easiest way to detect missing or damaged services is to run these commands at the Command Prompt:<\/p>\n<blockquote><p>sc query bits<\/p>\n<p>sc query wscsvc<\/p>\n<p>sc query bfe<\/p>\n<p>sc query mpssvc<\/p><\/blockquote>\n<p>As mentioned above, the bottom two services don&#8217;t exist on XP. \u00a0You can also script this using batch like so:<\/p>\n<pre>echo Checking for damaged Windows services...\r\n\r\nsc query bits|find \"The specified service does not exist as an installed service.\"&gt;nul&amp;&amp;( echo BITS Service [BITS] does not exist )\r\n\r\nsc query wscsvc|find \"The specified service does not exist as an installed service.\"&gt;nul&amp;&amp;( echo Security Center Service [WscSvc] does not exist )\r\n\r\nsc query bfe|find \"The specified service does not exist as an installed service.\"&gt;nul&amp;&amp;( echo Base Filtering Engine Service [bfe] does not exist )\r\n\r\nsc query mpssvc|find \"The specified service does not exist as an installed service.\"&gt;nul&amp;&amp;( echo Windows Firewall Service [MpsSvc] does not exist )<\/pre>\n<p>If any required services return an erroneous response (i.e., &#8220;The specified service does not exist as an installed service.&#8221;) then it&#8217;s pretty clear that damage has been done by the infection which requires repair.<\/p>\n<p>At this point, you have to first check to ensure that the relevant system files for each service are still intact. \u00a0The easiest way to do this is to perform a\u00a0<strong>sfc \/scannow\u00a0<\/strong>operation at the command line (run as Administrator) and ensure that any damaged files were successfully repaired.<\/p>\n<p>Next, it&#8217;s generally as easy as reimporting the default registry keys corresponding with each missing service. \u00a0This isn&#8217;t difficult once you find a reliable location to acquire those keys. \u00a0The best place available is currently <a title=\"BleepingComputer.com's Index of Win-Services\" href=\"http:\/\/download.bleepingcomputer.com\/win-services\/\" target=\"_blank\">BleepingComputer.com&#8217;s Index of Windows Services<\/a>. \u00a0Simply choose the folder which matches your operating system, select the name of the damaged\/missing service, download the file, and import it into your registry.<\/p>\n<p>After this is finished, you&#8217;ll still need to set each service to its default Startup type. \u00a0The easiest way to do this is to simply type each of these commands at the Command Prompt (again, running as Administrator):<\/p>\n<blockquote><p>sc config BITS start= delayed-auto<\/p>\n<p>sc config wscsvc start= delayed-auto<\/p>\n<p>sc config BFE start= auto<\/p>\n<p>sc config MpsSvc start= auto<\/p><\/blockquote>\n<p>Again, it bears repeating: the final two services don&#8217;t exist on XP machines.<\/p>\n<p>After completing these steps,\u00a0<strong>reboot the PC\u00a0<\/strong>and see if everything&#8217;s working again.<\/p>\n<p>In a later post, I&#8217;ll cover Windows Update repair procedures, permissions resets, and plenty more techniques to help repair damaged systems following infection.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Many times, following a nasty infection (such as that of various rogues or rootkits), you might notice that some of the critical Windows services are missing (such as the Security Center or Windows Firewall), or that Windows seems to be &hellip; <a href=\"https:\/\/www.triplescomputers.com\/blog\/casestudies\/solution-repair-damagedmissing-services-following-malware-infection\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,4],"tags":[127,132,131,128,134,129,126,133,130,125],"class_list":["post-189","post","type-post","status-publish","format-standard","hentry","category-casestudies","category-security","tag-reg-files","tag-background-intelligent-transfer-service","tag-base-filtering-engine","tag-default-services","tag-repair","tag-security-center-service","tag-services-repair","tag-the-specified-service-does-not-exist-as-an-installed-service","tag-windows-firewall-service","tag-windows-services"],"_links":{"self":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/comments?post=189"}],"version-history":[{"count":0,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/189\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/media?parent=189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/categories?post=189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/tags?post=189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}