Antivirus software lingering in Security Center

Discussion in 'Software' started by dlb, Jul 18, 2009.

Thread Status:
Not open for further replies.
  1. dlb

    dlb MajorGeek

    XP Home SP2 - Apparently this PC had Defender Pro Internet Security installed on it at some point. It is listed as 'out of date' in the Windows Security Center, but it is not listed in Add/Remove Programs, or in the Start Menu's All Programs list. In C:\Program Files there was an empty Defender Pro folder, and there are numerous listings in the registry for it (why am I not surprised that it's a Kaspersky based program?). How do I remove it from the Windows Security Center? Should I manually remove all its entries from the registry?
     
  2. ITTomas

    ITTomas Private E-2

  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi dlb


    Try this as for now I cannot find the small app that a tech on the Windows Vista test sent me to clean out the WSC listings!

    Open Services and find Windows Management Instrumentation and Stop it, then open the Windows folder and navigate to C:\Windows\System32 and find open the WBEM folder then right click on the repository folder and delete it, then restart the Windows Management Instrumentation service, reboot and check WSC, may need to re-install the Security apps tho
     
  4. dlb

    dlb MajorGeek

    @ITTomas: thanks, but not what I'm after. The link you posted goes to info on how to remove a rogue infection called "Windows Security Suite". This is not the problem I'm having. The PC is virus free. I'm just doing some cleanup and maintenance, and getting everything right. Thanks anyway.

    @ Halo: Thanks! When you find the small app you mentioned, please send me a PM. It sounds like it would come in handy from time to time. I'll take a look at the steps you mentioned.... would simply removing all the DefenderPro entries from the registry help? IIRC, I saw an entry (or two) for DefenderPro in the registry that mentioned Windows Security, I think. :rolleyes I'll have to take a second look.

    If anyone else has anything of help, feel free to post! Thanks!
     
  5. ITTomas

    ITTomas Private E-2

    I do apologize for giving you the wrong info, I'm still in the learning process of all Windows, Linux, and Programming. This forum is also allowing me to learn from the other users as well.
     
  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi dlb

    It may do and would really do no harm if that app has been removed, but the WBEM repository is where the app log is for WSC, and by deleting the files in the folder, it will basically act as a rebuild of the listings for WSC, should in theory list the apps installed and not the ones removed, but you know Windows and "in theory it should work"!



    @ITTomas ~ happens from time to time, dont worry too much.
     
  7. dlb

    dlb MajorGeek

    @ITTomas - no worries ;) We're all here to help and learn.... and welcome to Major Geeks! :major

    @ Halo - thanks again. I'm headed to the WBEM folder right after I remove the dead reg links....
    :-D

    EDIT - Well, I just removed all the related keys from the registry, and browsed to system32\WBEM, and the freekin' folder is EMPTY!!!!
    :confused
    I'll try a reboot and see what happens....
    :banghead
     
    Last edited: Jul 18, 2009
  8. dlb

    dlb MajorGeek

    :-o rolleyes Duh. I was in the wrong folder. Sheeeesh. I'm a stooge. So, the system32\wbem folder is full of all sorts of files, but I don't see anything that screams "Defender Pro Internet Security" in the wbem folder, or in the Repository folder. In the Repository folder, I see one folder called "FS" and a file called "$WinMgt.CFG". The FS folder has two INDEX files, two OBJECTS files, and three MAPPING files (MAPPING, MAPPING1 and MAPPING2). The extensions here are .MAP, .VER, .BTR, and .DATA. Maybe I'll just rename the Repository folder just in case.....
    ?
     
  9. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Don't worry what's in that folder delete the lot, so long as you have the folderci mentioned open, multiple entries maybe from user playing with alot of security apps. WBEM is where the WSC stores it's list.

    Not found that custom app yet but it was written for Vista so could be anywhere in 3 pc's
     
  10. evilfantasy

    evilfantasy Malware Fighter

    This tool? Security Center Reset 1.0

    There is also a quick way to reset it with a .bat file.

    Code:
    @ECHO OFF
    net stop winmgmt
    cd /d %windir%\system32\wbem
    ren repository repository.old
    net start winmgmt
    exit
     
  11. dlb

    dlb MajorGeek

    Well, to be on the safe side, I renamed the Repository folder after turning off the WMI service. I then turned it back on and rebooted. Everything worked out fine, and the WSC is now clean!! :celebrate. I didn't have any security apps installed yet, so I didn't really need to worry about reinstalling anything that may have been altered by the Repository folder. This is a neat 'trick', and could be handy when dealing with malware too. Thanks Halo!

    @ evilfantasy: thanks for the link and BAT. Good stuff! ;)
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds