SFC error message

barleysinger

Distinguished
Sep 27, 2013
35
2
18,530
Running WIN XP PRO (SP3)

I was reading an old thread. It was asking how to get explore.exe replaced with a proper version. The thread said to use the Command (in a CMD.exe window)

c:\>sfc /scannow

I tried this and got this error message :

Windows File Protection could not initiate a scan of protected system files.

The specific error code is 0x000004dd [The operation being requested was not performed because the user has not logged on to the network. The specified service does not exist.].

This user HAS "admin" privileges!


*** THE REASON FOR DOING THIS ***

I wanted to try this because of two things :

1) from time to time my PC seriously slows down. I can fix this by killing the process explorer.exe

2) I wanted to see if there was evidence that I was infected. At one point I had checked the CBL site, and they (but no other similar site) said I was part of a botnet (based on my IP address which does not tend to change). I checked out each (you never know) but the programs which are supposed to find and remove the things they claim I have - never find a thing. ..yet the "CBL" keeps saying that my IP address is involved in a spam botnet (or some other claim which varies from day to day). The CBL also can't seem to be consistent. They have claimed I have infections from all sorts of things. I then use a program from a trustworthy source - try and find and remove it - and NOT ONCE has anything been found.

This includes claims of

ZeuS trojan, AKA "Zbot" aka "WSNPoem
ZeroAccess root kit
s_smart12
(and others)

Now I use MALWAREBYTES (paid version), unhackme and AVG. I also periodically use: Microsoft Safety Scanner, Microsoft Malicious Software Removal Tool, SpyHunter, RogueKiller, mbam. I have also used (to try and remove things that apparently were not even there) : kaspersky zbotkiller, ESETSirefefCleaner, and quite a few others.

I have tried to fix this (if there even is a problem) by doing everything I was asked to do on BLEEPINGCOMPUTER. They are wonderful, but "No dice so far".


*** ANYWAY **

I think perhaps my explorer.exe could be at least a PART of the problem, or it could be that this is an OLD beast (Dell Optiplex) and XP PRO is far from perfect.

However I can't use the sfc command line program (see above) for some reason.
 
Solution
I have installed/reinstalled Windows XP many times on different computers and have run SFC /Scannow tenths of times without a single problem and without ever having touched the RPC Service startup setting. BTW my systems all show the RPC Service in Automatic startup (Remote Procedure Call (RPC) Locator) is the one in Manual. So, if you mean the RPC Service ends up in manual in all your installations, you may have to investigate what causes it.

One thing you haven't mentioned is if you have checked the HOSTS file has the default text. If it has been infected it may cause what you're experiencing. You may also replace it with the MVPS Hosts from:
http://msmvps.com/blogs/hostsnews/archive/2014/01/08/1920344.aspx...
Well, that "some" reason is most likely the cause you can't run SFC /Scannow... some infections can't be detected with regular security software... and some even infect the antivirus so it can't act against them... You could try a RootKit remover... there is a AVG Rootkit freeware, Avira antivirus I believe scans for rootkits... you can also run Online virus scanns which are more likely to detect something if your antivirus and antimalwares are infected. You can also program your antivirus to do a boot scan when the malicious apps and bugs are disabled. You should also uninstall Spy Hunter, RogueKiller and all other securit programs you have installed and leave only the best known programs such as the antivirus and malwarebytes... this because Spy Hunter doesn't enjoy a good reputation and some unknown antispywares are in reality disguised malware and virus installers, so it's better to stick with the best known and recognized security programs such as Malwarebytes Anti-Malware, ComboFix, HijackThis, Super Antispyware, Spyware Terminator, Emisisoft Anti-Malware...

Time ago a list of all known rogue antispyware was published and regularly updated. I can't recall how they named the list or how to locate it... but this Wikipedia list should give you an idea of how many malicious applications disguise as antimalware.

List of rogue security software
http://en.wikipedia.org/wiki/List_of_rogue_security_software
 

barleysinger

Distinguished
Sep 27, 2013
35
2
18,530


The reson for that "sfc /scannow" error is the most common one - the stupidity of Microsoft in how they install things. On install, the RPC service (needed by 'sfc') is set to 'manual'. It has to be set to 'automatic' for 'sfc' to work. This is a lot like putting an engine and a drive train in your car at the factory, but not connecting them.

Also, every item I have installed to deal with this, was strongly recomended by professionals who do this all the time. I got most of my help from BLEEPINGCOMPUTER (who have a very good reputation).

As for rootkit removers, I have run rootkit removers. Quite a few of them (all of them are well vetted).

* kaspersky _ zbotkiller.exe
* Rkill 2.6.1 by Lawrence Abrams (Grinler) http://www.bleepingcomputer.com/
* Junkware Removal Tool (JRT) by Thisisu, Version: 6.0.8 (11.05.2013:1)
* Free Win32ZeroAccess Removal Tool
* BDRemovalToolLauncher_sirefef_sfc_x86.exe
* tdsskiller.exe
* trjsetup688.exe (Trojan Remover by Simply Super Software)
* mbam 1.75.0.1300
* NPE (Norton Power Eraser)
* ESETSirefefCleaner

- and others....

nothing has ever been found
 
I have installed/reinstalled Windows XP many times on different computers and have run SFC /Scannow tenths of times without a single problem and without ever having touched the RPC Service startup setting. BTW my systems all show the RPC Service in Automatic startup (Remote Procedure Call (RPC) Locator) is the one in Manual. So, if you mean the RPC Service ends up in manual in all your installations, you may have to investigate what causes it.

One thing you haven't mentioned is if you have checked the HOSTS file has the default text. If it has been infected it may cause what you're experiencing. You may also replace it with the MVPS Hosts from:
http://msmvps.com/blogs/hostsnews/archive/2014/01/08/1920344.aspx
http://winhelp2002.mvps.org/hosts2.htm

Also, have you tried removing your IP from the CBL List? For details, click the link and check under "What to do if you're listed/How do I get delisted?"
http://cbl.abuseat.org/

The article also explains how your IP may have made the CBL list... without your system necessarily being infected:
Quote: "The CBL does NO probes. In other words, the CBL NEVER makes connections to other machines to "test" anything".
http://cbl.abuseat.org/
 
Solution

barleysinger

Distinguished
Sep 27, 2013
35
2
18,530
I eventually had found enough traces left behind of old virus problems, that I just gave in and reinstalled Windows (and lost software I cannot ever get back).

also - I am aware that the CBL does not advertise itself as foolproof. People do get listed who have no actual virus on their machine. However many site use the CBL (and other blacklist site lists) as if they were perfect and use the IP address lists to block access to their sites (despite a direct statement on the CBL site that this is an abuse of their list).

This bad habit (banning those on the lists) includes some people who ought to know better - like the primary support forum sites for official large projects (like "forum.videolan.org" which is the support site for "VLC media player"). Theses sites ban people because they are on a list, and some of them use many lists.

The trouble is some of those black listing sites ban entire IP address ranges; so everyone on your entire ISP can get banned...and stay banned forever.

This is *not* the desire of the folks at the CBL. They warn people not to do this, but they do it anyway.