can't access windows defender - vista

Discussion in 'Software' started by JoeyBats, Aug 29, 2013.

  1. JoeyBats

    JoeyBats Private E-2

    Hi guys,

    Kestrel13! helped me in the malware forum regarding the zeroaccess trojan on my laptop. It's all cleaned now and I can access the items in the security center except windows defender. The message I get is: "Application failed to initialize: 0x80070006. The handle is invalid."

    The other thing I am experiencing is a black screen with a white mouse pointer for ~35 seconds after logging in.

    I appreciate your help, thanks.

    Cheers,
     
  2. falconattack

    falconattack Command Sergeant Major

    Hi my friend , do you installed any antivirus programme in your machine ? Do you disable Windows Defender ? If you have antivirus with Windows Defender enable there is a conflict between them :wave
     
  3. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Launch Windows Defender and go to Tools -> Options.
    There will be a list of configuration options.
    Scroll down to the end of the list to Administrator options.
    Deselect the Use Windows Defender box and press the Save button.
    Now you will receive a notification saying that "Windows Defender is turned off".
    Click on Close.

    If you are not able to access Windows Defender, do the following:
    Go to Start > Run and type services.msc
    Now look for the service named Windows Defender,
    Double click to bring up the Properties window.
    Click the Stop button to stop Windows Defender services and set the Startup type Disabled
    Click Apply and then click OK.
    Close Services/Local window
     
  4. JoeyBats

    JoeyBats Private E-2

    Hey plodr, thanks for your help, I appreciate it.


    Windows defender is not to be found in the list of services. It's not there. I can see the icon in the following places: control panel, typing "windows defender" at the start-run-search field, in security center, c:drive windows defender etc.

    All was well before the laptop was infected with the zeroaccess rootkit trojan. I posted logs in the malware forum. Not sure if they would help you.

    Thanks
     
  5. JoeyBats

    JoeyBats Private E-2

    Not sure if the following helps, but in "problems reports and solutions," the following are listed under windows defender:

    Problem signature
    Problem Event Name: MpTelemetry
    Problem Signature 01: 8024402c
    Problem Signature 02: EndSearch
    Problem Signature 03: Search
    Problem Signature 04: 1.1.1600.0
    Problem Signature 05: MpSigDwn.dll
    Problem Signature 06: 1.1.1600.0
    Problem Signature 07: Windows Defender
    OS Version: 6.0.6002.2.2.0.768.3
    Locale ID: 4105

    Problem signature
    Problem Event Name: MpTelemetry
    Problem Signature 01: 8024402c
    Problem Signature 02: EndSearch
    Problem Signature 03: Search
    Problem Signature 04: 1.1.1600.0
    Problem Signature 05: MpSigDwn.dll
    Problem Signature 06: 1.1.1600.0
    Problem Signature 07: Windows Defender
    OS Version: 6.0.6002.2.2.0.768.3
    Locale ID: 4105
     
  6. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Here is the reg file that will restore Windows Defender to the Registry and services for Vista and 7 only
    Code:
    Windows Registry Editor Version 5.00
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend]
    "DisplayName"="Windows Defender"
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
      74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
      00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
      6b,00,20,00,73,00,65,00,63,00,73,00,76,00,63,00,73,00,00,00
    "Start"=dword:00000004
    "Type"=dword:00000020
    "Description"="@%ProgramFiles%\\Windows Defender\\MsMpRes.dll,-1176"
    "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
    "ObjectName"="LocalSystem"
    "ServiceSidType"=dword:00000001
    "RequiredPrivileges"=hex(7):53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,\
      00,6e,00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,\
      65,00,00,00,53,00,65,00,42,00,61,00,63,00,6b,00,75,00,70,00,50,00,72,00,69,\
      00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,\
      74,00,6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,\
      00,00,00,53,00,65,00,44,00,65,00,62,00,75,00,67,00,50,00,72,00,69,00,76,00,\
      69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,68,00,61,00,6e,00,67,\
      00,65,00,4e,00,6f,00,74,00,69,00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,\
      6c,00,65,00,67,00,65,00,00,00,53,00,65,00,53,00,65,00,63,00,75,00,72,00,69,\
      00,74,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\
      53,00,65,00,53,00,68,00,75,00,74,00,64,00,6f,00,77,00,6e,00,50,00,72,00,69,\
      00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,6e,00,63,00,\
      72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,00,72,00,69,\
      00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,41,00,73,00,73,00,\
      69,00,67,00,6e,00,50,00,72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,\
      00,65,00,6e,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\
      00,00
    "DelayedAutoStart"=dword:00000001
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
      00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\Parameters]
    "ServiceDllUnloadOnStop"=dword:00000001
    "ServiceDll"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,69,\
      00,6c,00,65,00,73,00,25,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\
      20,00,44,00,65,00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,6d,00,70,00,73,\
      00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\Security]
    "Security"=hex:01,00,14,80,dc,00,00,00,e8,00,00,00,14,00,00,00,30,00,00,00,02,\
      00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
      00,00,02,00,ac,00,06,00,00,00,00,00,28,00,ff,01,0f,00,01,06,00,00,00,00,00,\
      05,50,00,00,00,b5,89,fb,38,19,84,c2,cb,5c,6c,23,6d,57,00,77,6e,c0,02,64,87,\
      00,0b,28,00,00,00,00,10,01,06,00,00,00,00,00,05,50,00,00,00,b5,89,fb,38,19,\
      84,c2,cb,5c,6c,23,6d,57,00,77,6e,c0,02,64,87,00,00,14,00,fd,01,02,00,01,01,\
      00,00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,\
      05,20,00,00,00,20,02,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,\
      04,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,01,\
      01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\TriggerInfo]
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\TriggerInfo\0]
    "Type"=dword:00000005
    "Action"=dword:00000001
    "GUID"=hex:e6,ca,9f,65,db,5b,a9,4d,b1,ff,ca,2a,17,8d,46,e0
    Rather than typing all that in, you can download the registry file
    http://file.walagata.com/w/perk/Windefend.reg
    and double click it to merge with your registry.

    Note: after you download it and before you install it, please make a backup of your registry. That way, if it doesn't work, you can revert back to the registry before the merge.
     
  7. JoeyBats

    JoeyBats Private E-2

    Plodr! You rock buddy! It worked!!! Thank you so much!

    It set on disable, but I'm happy I can see it in the list of services.

    Any thoughts regarding the black screen with a movable mouse pointer after the login page? It stays like that for ~35 seconds. It never did that before. Should I start a new thread?

    Thank you.
    Cheers,
     
  8. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Glad you at least can now change the settings. If you disable it, be sure you load another av program in its place.

    As far as the black screen with a delay...
    maybe a vestige of some malware starting up that was removed.

    This happens after you log in correct?
    If so, open up msconfig (type it in the run box).
    See what is running at Startup (one of the tabs in the box that opens).
    List everything showing in the first two columns Item and Manufacturer. There might be something in there trying to start that has been removed and is causing the delay.
     
  9. JoeyBats

    JoeyBats Private E-2

    Hey plodr,

    I attached a screen shot of the first two columns of the startup pane. The last item which is not that visible is zune - microsoft.

    Thanks,
     

    Attached Files:

  10. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    I don't see anything suspicious there.
    If I were you, I'd disable Java and turn off the auto updater for that.
    It won't have an effect on the 35 second delay showing your desktop.
    I'm not sure why it takes Windows Explorer so long to have your desktop appear.
     
  11. JoeyBats

    JoeyBats Private E-2

  12. JoeyBats

    JoeyBats Private E-2

    I ran sfc /scannow four times last night before it fixed the problem. I rebooted this morning and the desktop loaded instantly! I wanted to share that with you and say thanks again for all of your help plodr. The team here is awsome! ;)

    cheers,
     
  13. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Sorry, Vista is the only version of Windows I never installed so I don't give advice in trying to fix or tweak it because I have zero experience with it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds