Security Center is not opening and Windows defender and firewall either

Discussion in 'Malware Help (A Specialist Will Reply)' started by Purplelily, Jul 17, 2012.

  1. Purplelily

    Purplelily Private E-2

    Hi, I have a HP with Windows Vista Home Premium SP2, 64 bit OS. When I click on Windows Security Center on my PC is says, "SC can't be started".
    When I click on the Firewall nothing happens. When I click on Windows defender, messages say Windows Defender application failed to initialize 0x80070006, the handle is invalid.

    So I followed the steps in Vista Malware removal/clean procedure and I have attached the logs.

    Really could use some help! :cry
    Thank you.
     

    Attached Files:

    Last edited: Jul 17, 2012
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need all of the requested logs. You only attached the log from MGtools. We need Malwarebytes, RogueKiller and Hitman logs.

    Also note that according to your MGtools log, Windows Firewall is running.

    You may be having problems because of what you installed. Uninstall PC Tools Browser Defender, Norton Internet Security, and Panda Cloud. Then reboot and see what problems you have. You should never install multiple antivirus programs let alone security suites.
     
  3. Purplelily

    Purplelily Private E-2

    Ok I uninstalled Panda, I don't have the Norton Installed,(not showing in the Uninstall Programs section) and I can not access the PC Tools Browser, I get this message: Runtime error, cannot import dll:c\Program File(x86) PC Tools Sercurity\BDT\DR\SDDRMHelper.dll

    I was not aware I had multiple security suites and since I don't have the Norton and I did not know about the Pc tools I had installed Panda a couple of days ago. I been having this problem for some days now.
    I was not able to attach the logs again when I wrote in this forum because I had attached them in the software forum yesterday. Are you able to access them from there? Thank you.
     
    Last edited: Jul 18, 2012
  4. Purplelily

    Purplelily Private E-2

    After following your instructions and after rebooting I went back and am now able to access the Firewall, it is on! But the Security Center is still saying can't be started.
    What I am concerned about is that i have no antivirus right now.
    Please advise on the next step.
    Thank you.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'll reattach them right here to my my message for you so that we don't have to look at the other thread. ;)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will get a security program on after we first cleanup the mess. Reinstalling one now, would just complicate the mess and the cleanup.
    But it is still installed as you will see in fixes below that will try to clean all this up.

    Okay we will try get rid of this too even though not a malware issue. ;)

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
    O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
    O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
    O2 - BHO: (no name) - {99E00A4C-D35E-11DD-BA95-9B6A56D89593} - (no file)
    O2 - BHO: (no name) - {CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
    O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
    O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
    O3 - Toolbar: (no name) - !{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    O3 - Toolbar: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - (no file)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_24) -
    O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - (no file)
    O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe

    After clicking Fix, exit HJT.

    Now uninstall Java(TM) 6 Update 24 which is a security risk because it is way out of date.

    Now try running Revo Uninstaller that you have installed and see if it is able to uninstall Browser Defender 3.0

    If you have have a problem uninstalling Browser Defender, just continue on.

    Download and save combofix.exe directly on to your Desktop but DO NOT run it.


    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Purplelily

    Purplelily Private E-2

    Ok so I have followed your instructions and have attached requested logs.
    This is what I have found when running Combofix it said AVG Antivirus Free Ed 2012 was detected to be active. I did not find the program and also went to Revo Uninstall and did not find it. What I noticed was that under program data I had them as .exe files to be installed. I deleted them but only after the combo fix ran, because I understood I should not interrupt it.
    Please let me know if it should be run again.

    I can now open Security Center, Windows Defender application still fails to initalize with error 0x80070006.
    When I go to run and type misconfig I get an error message, ( I only tried this again because it was one of my previous problems and still is).

    I think I was able to delete that PC Tools Browser....

    I did see that programs that I have downloaded previously I guess I had saved before downloading are in the computer, should I just delete old programs I no longer want out of there?

    Thank you for reattaching the logs from the previous forum. I take hours to do something because I am very new to all of this and am learning from this AWESOME website! So pardon my ignorance in some things!:confused

    Thank you for your help!:)
     

    Attached Files:

  8. Purplelily

    Purplelily Private E-2

    Just wanted to give you an update, Windows defender is working and on. I still have the UAC account off.

    The misconfig still not taking, and I have a babylon search toolbar that is now popping up and I don't know where it came from. I deleted it from the programs and it still shows up.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You installed it. Either knowingly or with some other junk you downloaded and installed.

    You should unintall anything that you don't use and becareful what you allow to be installed on your PC. Read th license agreements more closely. ;)


    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Purplelily

    Purplelily Private E-2

    Attached the logs.
    Still have the same issues with misconfig and the Babylon toolbar.

    Yes I am learning my lesson from all this, will be more careful with programs. :-o

    I read in the MG tools log that it could not find C:\User\Sams club\Desktop\procoll.txt.
    When I bought the computer from Sams club they did not take off the user or renamed it and I have areas that I can not access because it it Sams club. I have read trying to work with it to no avail. It says access is denied.
    I have even gone into properties to see if I can access it but it doesn't let me change anything.
    Don't know if this info is helpful and if you have any suggestions.:confused

    Thank you.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you talking about with Firefox?

    This is because you do not have the required version of Microsoft .NET Framework installed.

    Since you did not tell me exactly which folders you are referring to, I will have to assume you are trying to access folders that Windows Vista ( and also Windows 7 ) do not allow you to access. For few examples, all of the below are system folders which you are blocked from accessing as you do not need to access them:
    • C:\Documents and Settings
    • C:\System Volume Information
    • C:\Users\Default User
    • C:\Users\Sams club\Application Data
    • C:\Users\Sams club\Cookies
    • C:\Users\Sams club\Local Settings
    • C:\Users\Sams club\My Documents
    • C:\Users\Sams club\NetHood
    • C:\Users\Sams club\PrintHood
    • C:\Users\Sams club\Recent
    • C:\Users\Sams club\Start Menu
    • C:\Users\Sams club\Templates
     
  12. Purplelily

    Purplelily Private E-2

    Yes it is Firefox.
    I will check to install the microsoft.net framework.
    Will that fix the misconfig problem?

    thank you
     
  13. Purplelily

    Purplelily Private E-2

    P.S.
    Could you please tell me how do I find which Microsoft.net I should download? thank you
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought so. We will have to uninstall it it and delete folders from it. DO NOT reinstall until requested. Use Internet Explorer for your browsing.

    No! Spelling it properly will. ;) It is msconfig




    We are going to be uninstalling your current copy of FireFox and installing the new version. So do the below to save bookmarks:
    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla Firefox 14.0.1 Final

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then continue with the next steps

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After further review, it looks like you do have a compatible version. Let's see if it is due to the below not being installed.

    Download and install each of the below. Follow instructions during the installations. Reboot whenever they ask you to reboot.

    http://www.microsoft.com/en-us/download/details.aspx?id=3387

    http://www.microsoft.com/en-us/download/details.aspx?id=21254

    http://www.microsoft.com/en-us/download/details.aspx?id=29

    http://www.microsoft.com/en-us/download/details.aspx?id=15336
     
  16. Purplelily

    Purplelily Private E-2

    I had uninstalled Firefox this morning after getting frustrated with it, (so the part with the browsers I couldn't follow),I also uninstalled Chrome because I realized it also had the Babylon toolbar.

    so I have followed the steps and attached the reports.

    Really appreciate your help!:)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. Purplelily

    Purplelily Private E-2

    OMG I killed my computer somehow! I was starting to celebrate....When it rebooted, it now shows a message saying
    BOOTMGR is missing! At this point I really feel Dumb! :cry

    Is there any hope to recuperate it?
    I am writing from my laptop...
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  20. Purplelily

    Purplelily Private E-2

    I had deleted Chrome, Firefox and other programs I had installed. I then moved some files that showed on the C drive to another file after installing from the links you had sent.
    I am reading from the info you sent, the majority are saying to boot from a CD or DVD. I did not receive either when I bought the computer...
    I will research all the links and see what I can do.

    Thank you.
     
  21. Purplelily

    Purplelily Private E-2

    Well I order the recovery disks I need from HP. All websites say that is what I need.

    Thanks again for all your help!!:)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Could you please clarify this? I don't know what you are saying. You cannot move a file to another file! You can rename a file or you can delete a file. You can also copy files to another hard disk drive. Or you can copy files into another folder. I have no idea what you did and I would like to know exactly what files you are talking about.

    Recovery Disks are not boot disks as far as I know. They are just factory recovery disks to restore the PC to the state it was shipped to you in. They will not help you to just do a repair or recover files. They will cause you to loose all current data in the act of restoring the PC to factory ship state.
     
  23. Purplelily

    Purplelily Private E-2

    The files I moved to another folder were ending in .dll, I don't recall exactly which ones, (sorry) I didn't jot them down. The ones I deleted had to do with programs.

    I thought I needed a recovery disk but as I continued reading I realized what I needed was a bootable disk. I did get a Windows Vista bootable CD and was able to boot the PC and am going to proceed with the instructions for the final steps. ;)
     
  24. Purplelily

    Purplelily Private E-2

    I have followed the final steps and the How to protect yourself from Malware.
    Kudos to MajorGeeks!! Chaslang you are the best!:major Really appreciate all your help! Have an awesome one!
    :wave
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds