Windows Security Service Center can't be started

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jennybelle, Nov 20, 2012.

  1. jennybelle

    jennybelle Private E-2

    I got a message from System Tray saying to Turn on Windows Security Center. When I try, it says the Windows Security Center can't be started.

    I've run the steps as you specify, and there were some bad files found.

    Thank you.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This does not appear to be a malware problem. Your logs are clean. Your Security Center service is just stopped according to your logs. You can try the below, but starting it from what you did should have done the same.

    First disable all protection and make sure that UAC is still disabled as requested in the READ & RUN ME because per your logs, you never disabled it. You must reboot after disabling it to make it take effect.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now reboot and see if it worked.
     
  3. jennybelle

    jennybelle Private E-2

    Hi,

    Well, when I signed in, yesterday I found that my Avast! had isolated a Trojan virus. I don't understand your reply, because the Hitman Pro report I attached in my initial message shows 2 threats found. I took no action, per instructions, when Hitman showed 2 threats after I ran it.

    Also, I did disable the UAC before running the reports, and enabled it after.

    I'm not sure if I should proceed with your instructions now, because there was a threat? Is there more I should do first?

    Avast screen shot attached, showing Trojan moved to vault.

    Thanks.
     

    Attached Files:

    Last edited: Nov 22, 2012
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I was not convinced that Media Tools was malware since it had a publisher name of Microsoft. Did some additional research and I don't see anyone removing this. Perhaps it is a new issue. It seems to show up with MegaCodec Pack quite frequently. Let's remove it and also apply the registry patch but we will do it differntly.



    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\ProgramData\Microsoft\Media Tools\temp\tmp30CE.exe
    c:\programdata\Microsoft\Media Tools\MediaIconsOverlays.dll
    c:\programdata\Microsoft\Media Tools
    :Reg
    [-HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\0MediaIconsOerlay]
    [-HKEY_CLASSES_ROOT\CLSID\{1EC23CFF-4C58-458f-924C-8519AEF61B32}]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc]
    "DisplayName"="@%SystemRoot%\\System32\\wscsvc.dll,-200"
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
    74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
    00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
    6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\
    00,65,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,52,00,65,00,73,00,74,00,\
    72,00,69,00,63,00,74,00,65,00,64,00,00,00
    "Start"=dword:00000002
    "Type"=dword:00000020
    "Description"="@%SystemRoot%\\System32\\wscsvc.dll,-201"
    "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,57,00,69,00,6e,00,\
    4d,00,67,00,6d,00,74,00,00,00,00,00
    "ObjectName"="NT AUTHORITY\\LocalService"
    "ServiceSidType"=dword:00000001
    "RequiredPrivileges"=hex(7):53,00,65,00,43,00,68,00,61,00,6e,00,67,00,65,00,4e,\
    00,6f,00,74,00,69,00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,\
    67,00,65,00,00,00,53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,\
    00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,\
    00,00,00,00
    "DelayedAutoStart"=dword:00000001
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
    00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc\Parameters]
    "ServiceDllUnloadOnStop"=dword:00000001
    "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
    00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
    77,00,73,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc\Security]
    "Security"=hex:01,00,14,80,c8,00,00,00,d4,00,00,00,14,00,00,00,30,00,00,00,02,\
    00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
    00,00,02,00,98,00,06,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
    05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
    20,02,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\
    00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,00,00,14,00,00,01,\
    00,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,28,00,15,00,00,00,01,06,00,\
    00,00,00,00,05,50,00,00,00,49,59,9d,77,91,56,e5,55,dc,f4,e2,0e,a7,8b,eb,ca,\
    7b,42,13,56,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,\
    00,00,00 
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. jennybelle

    jennybelle Private E-2

    Okay. Sorry for the delay, I've been unwell and wanted to be 'alert' when doing this.

    I've completed the instructions, and attached the logs.

    A note: I see that I am no longer getting a notification on my taskbar that Windows Security Center is not working.

    Thanks for your help, chaslang. :)


    EDIT: checked Windows Secuity Center, and it shows that all features are "on". I am using the Private Firewall 7.0 that is recommended here, and not my Windows firewall (FYI).
     

    Attached Files:

    Last edited: Nov 24, 2012
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. A couple more services/drivers need to be repaired.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. jennybelle

    jennybelle Private E-2

    Hi.

    I d/l and ran Windows Repair, following the instructions. It did not take very long, and did not restart the system when it finished (though I had double checked before running, and had clicked the appropriate boxes to Restart/Shutdown system and checked the Restart System radio button you indicated). So I checked the Task Manager to make sure it was no longer running, and rebooted.

    Next, ran MGtools per instructions. Log is attached.

    Note: When I first started up this morning, and was checking my mail before doing this, my pc shut down (just the tower, though the power lights on the monitor and keyboard were still on) and would not start up, so I unplugged it and waited 5 minutes.

    I also checked my Avast! sheilds, and it shows infected files. I don't know if this is helpful, but I've attached a screen shot of same.

    Was able to restart and perform the above operations.

    Thanks.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not appear to have worked properly. Please try again but do it from Safe Boot mode.

    Nothing useful there at all. It just shows what shields Avast has. It does not show any infections.
     
  9. jennybelle

    jennybelle Private E-2

    Hi!

    On sunday, I read your reply, and planned to follow your instructions after I checked my email and pm's.

    In the midst of doing that my PC shut down. Waited 5 mins, and was able to power up,

    truth be told, I called a friend who lives across the country, and her husband is an IT specialist. they helped me.

    FYI - this might be useful for you, so I'm sharing. :)

    Couldn't uninstall my Avast - it was corrupted. When I checked it, showed many files corrupted.

    So I went into safe mode, and was able to uninstall Avast. Then I ran malwarebytes.

    Went back into my acct, and installed the new microsoft free malware, and did a detailed scan. All seems to be well.

    I hope my experience was helpful to you. Damn, these viruses that attack and attach to our anti-malware software are so devious.!!

    I appreciate the help of majorgeeks so much, and thank you, chaslang, for giving your time and helping us. xoxoxo
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes it is quite common that we also have people uninstall their antivirus or other protection software too. Sometimes we do this because the protection software is corrupted and other times we do it because the protection software is simply getting in the way of malware cleanup and is doing nothing to help in the removal of the infections.

    In your last logs, you still had problems with Windows Firewall not running properly, but it think all is fine now continue with the below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. jennybelle

    jennybelle Private E-2

    Thanks, I have followed your instructions and the steps in READ ME, but was waiting a couple days to do "toggle system restore". My windows updates are not coming in automatically, and I can't change those settings. So running malwarebytes plus a scan with my MD daily for a couple of days, as the instruction noted, just to be sure and see if anything else happens. Perhaps this will correct itself with the updates.

    And yes, I will work through the safety link. This infection was my own fault, and have learned a few lessons through this process.

    Thank you! :)

    EDIT: I just checked my Windows Firewall and can't turn it on. Error Code: 80070424. I was sent to a site (by my system) that says to download Microsoft FixIt and run in order to fix this problem.

    the url is: http://support.microsoft.com/mats/windows_firewall_diagnostic/

    Is this legit?

    Thanks.
     
    Last edited: Dec 4, 2012
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's do some more checking. Not sure if you picked up anything new in the last 6 days.

    Yes. Give this a run and then reboot. Let me know if it fixes the firewall problem or not.


    Also copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. jennybelle

    jennybelle Private E-2

    Hi,

    I ran the MS file Fixit, and it said I am running PrivateFirewall, so can't turn on the Windows Firewall. What I'm noticing, is that I'm not getting my Windows updates automatically, even though I have that option selected. Maybe I should be running Windows Firewall since I am using their ME package?

    I merged the registry files per your instructions, and got the message that it was successful.

    Ran MGTools with UAP off, as Administrator, and log is attached.

    Things seem to have been fine, though I haven't run Malwarebytes for a couple days, and will do so today, just to check.

    My computer (tower only) did shut down again while I was writing this letter. I left it off for 5 minutes, and then powered it up, no problems rebooting. I am thinking that the power source fan may be overheating (yes, the tower feels warm), this could be a hardware problem? (which is warranted, so an easy fix if so).

    Thank you so much! :)
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the last registry patch fixed what we need to fix. You logs are clean. If you are still having problems with Windows Update, you may want to try disabling or uninstall Privacy Firewall to make sure you are not somehow blocking updates. Also make sure you use Internet Explorer for updating.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  15. jennybelle

    jennybelle Private E-2

    That's great. I uninstalled PrivateFirewall (it was blocking Windows Update) and switched to the Windows Firewall. Next, I deleted the fixme.reg and reenabled UAC.

    There was no MGclean.bat file in the C:\MGtools folder (checked several times) - there is one called DebugMGT.bat - ? I didn't use that, as the name is different. Has the name been changed, or am I missing something?

    I also followed the procedures in step 6 to flush Restore Points, rebooted and Enabled system restore.

    I'll work on step 9 "How to Protect yourself from malware!"

    Thanks again, Chaslang!

    :)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Yes there was. It even showed in the last logs you attached.
     
  17. jennybelle

    jennybelle Private E-2

    Okay, I found the MGClean.bat file and ran it. Sorry, I looked several times before.

    Thanks again for your help.

    :)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds