Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > Can't Start Automatic Update Service

Reply
Thread Tools Display Modes

Can't Start Automatic Update Service

 
 
Rascal
Guest
Posts: n/a

 
      04-11-2009
First let me say that I am working on a friend's computer that I know has the
Vundo trojan. I've read many posting and tried many tools (MalwareBytes,
Microsoft Malicious etc, Super Anti Spware, Rootkit Revealer...etc) and most
of them find things and clean them but the just come back.

So, yes, they let their anti virus subcription expire and, yes, they have
themselves to blame, and yes, I nag them about it, but sick puppies still end
up coming back.

I also know that this is not a microsoft issue, per se - and I have posted
logs on bleeping computer and am currently patiently waiting and hoping that
my issue will attract someone's attention.

The reason for this post is, while I'm waiting I'm trying to learn, I'd like
to get insight from this community on one particular aspect of the infection.
The windows update service will not start - I get 'access denied'. And I
notice that the path to the executable begins with %fystem% ...etc - (the f
is not a typo). That can't be good.

What do you think?


 
Reply With Quote
 
 
 
 
Shenan Stanley
Guest
Posts: n/a

 
      04-11-2009
Rascal wrote:
> First let me say that I am working on a friend's computer that I
> know has the Vundo trojan. I've read many posting and tried many
> tools (MalwareBytes, Microsoft Malicious etc, Super Anti Spware,
> Rootkit Revealer...etc) and most of them find things and clean them
> but the just come back.
>
> So, yes, they let their anti virus subcription expire and, yes,
> they have themselves to blame, and yes, I nag them about it, but
> sick puppies still end up coming back.
>
> I also know that this is not a microsoft issue, per se - and I have
> posted logs on bleeping computer and am currently patiently waiting
> and hoping that my issue will attract someone's attention.
>
> The reason for this post is, while I'm waiting I'm trying to learn,
> I'd like to get insight from this community on one particular
> aspect of the infection. The windows update service will not start
> - I get 'access denied'. And I notice that the path to the
> executable begins with %fystem% ...etc - (the f is not a typo).
> That can't be good.
>
> What do you think?


Time to format. ;-)

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html


 
Reply With Quote
 
Rascal
Guest
Posts: n/a

 
      04-11-2009


"Shenan Stanley" wrote:

> Rascal wrote:
> > First let me say that I am working on a friend's computer that I
> > know has the Vundo trojan. I've read many posting and tried many
> > tools (MalwareBytes, Microsoft Malicious etc, Super Anti Spware,
> > Rootkit Revealer...etc) and most of them find things and clean them
> > but the just come back.
> >
> > So, yes, they let their anti virus subcription expire and, yes,
> > they have themselves to blame, and yes, I nag them about it, but
> > sick puppies still end up coming back.
> >
> > I also know that this is not a microsoft issue, per se - and I have
> > posted logs on bleeping computer and am currently patiently waiting
> > and hoping that my issue will attract someone's attention.
> >
> > The reason for this post is, while I'm waiting I'm trying to learn,
> > I'd like to get insight from this community on one particular
> > aspect of the infection. The windows update service will not start
> > - I get 'access denied'. And I notice that the path to the
> > executable begins with %fystem% ...etc - (the f is not a typo).
> > That can't be good.
> >
> > What do you think?

>
> Time to format. ;-)
>
> --
> Shenan Stanley
> MS-MVP
> --
> How To Ask Questions The Smart Way
> http://www.catb.org/~esr/faqs/smart-questions.html
>
>
>


Ha! I'm pretty much assuming that. Thought I'd try other avenues first just
for the heck of it.

Maybe this time they will learn their AV lesson...

tks
 
Reply With Quote
 
Volstag
Guest
Posts: n/a

 
      04-14-2009
Reformatting and reinstalling might be a little overkill.

Search the registry for fystemroot. Change permissions on the key if
necessary (malware likes to make it read only). Change it to the correct
value (systemroot). Repeat for as many occurances of fystemroot that you
find.

-V

"Rascal" wrote:

>
>
> "Shenan Stanley" wrote:
>
> > Rascal wrote:
> > > First let me say that I am working on a friend's computer that I
> > > know has the Vundo trojan. I've read many posting and tried many
> > > tools (MalwareBytes, Microsoft Malicious etc, Super Anti Spware,
> > > Rootkit Revealer...etc) and most of them find things and clean them
> > > but the just come back.
> > >
> > > So, yes, they let their anti virus subcription expire and, yes,
> > > they have themselves to blame, and yes, I nag them about it, but
> > > sick puppies still end up coming back.
> > >
> > > I also know that this is not a microsoft issue, per se - and I have
> > > posted logs on bleeping computer and am currently patiently waiting
> > > and hoping that my issue will attract someone's attention.
> > >
> > > The reason for this post is, while I'm waiting I'm trying to learn,
> > > I'd like to get insight from this community on one particular
> > > aspect of the infection. The windows update service will not start
> > > - I get 'access denied'. And I notice that the path to the
> > > executable begins with %fystem% ...etc - (the f is not a typo).
> > > That can't be good.
> > >
> > > What do you think?

> >
> > Time to format. ;-)
> >
> > --
> > Shenan Stanley
> > MS-MVP
> > --
> > How To Ask Questions The Smart Way
> > http://www.catb.org/~esr/faqs/smart-questions.html
> >
> >
> >

>
> Ha! I'm pretty much assuming that. Thought I'd try other avenues first just
> for the heck of it.
>
> Maybe this time they will learn their AV lesson...
>
> tks

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Automatic Updates Service won't start - Error 2 shamrin Windows Update 12 06-01-2010 05:04 PM
Unable to Start Automatic Updates Service gt3ch Windows Update 7 10-07-2009 09:20 PM
0x8024d007 Automatic Update Service won't start kkkwj Windows Update 4 11-16-2007 03:40 AM
could not start automatic updates service Jeffrey G Windows Update 1 11-04-2005 10:46 PM
Automatic Updates Service Fails To Start? Brian K Windows Update 0 12-01-2004 07:39 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59