Windows Security Center can't be started

Discussion in 'Malware Help (A Specialist Will Reply)' started by lzepplin1975, Apr 19, 2013.

  1. lzepplin1975

    lzepplin1975 Private E-2

    Hello,

    My Laptop a few days ago notified me that my Windows Security Center was not turned on and that I should do so. When clicking "Turn on" a message pops up saying "Windows Security Center can't be started. I've gone to multiple sites on how to enabling it but then it disables itself a few seconds later. I've ran the scans you ask for and I have attached them. Hitman Pro found 10 traces (whatever that means).

    Im using Windows 7 Home Premium 64-bit operating system.

    Thanks in advance
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not finding much. Let's do this:

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [TASK][ROGUE ST] 0 : c:\program files (x86)\internet explorer\iexplore.exe -> FOUND
      [TASK][ROGUE ST] 4816 : wscript.exe C:\Users\Taylor\AppData\Local\Temp\launchie.vbs //B -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    Now use windows explorer to find and delete:
    C:\Windows\tasks\tlauzwbdju.job

    Now run Hitman and have it delete all those PUP's.

    Reboot and rerun RogueKiller and Hitman and attach those new logs.
     
  3. lzepplin1975

    lzepplin1975 Private E-2

    Ok I did as you said and here are the logs. I got 2 logs for each scan (before and after). I put them in a zip folder.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-21-3271766646-3921531634-1343325842-1002\$77a265a386b3458593b28c14e072a5c3\n.) [x] -> FOUND
      [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$77a265a386b3458593b28c14e072a5c3\n.) [x] -> FOUND
      [HJ INPROC][ZeroAccess] HKLM\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$77a265a386b3458593b28c14e072a5c3\n.) [x] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Files/folders tab and locate these detections:


    • [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-18\$77a265a386b3458593b28c14e072a5c3\U --> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    Now reboot and rescan with RogueKiller and attach that new log as well. Be sure to tell me how things are running now.
     
  5. lzepplin1975

    lzepplin1975 Private E-2

    Ok here are the logs. I found the items in the registry folder but it didn't find anything in the Files folder. Also Windows Security Center still cant be started.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, that cleared the Zero Access infection. Have you tried uninstalling the Security Center, running CCleaner and reinstalling?
     
  7. lzepplin1975

    lzepplin1975 Private E-2

    I had no idea I could do that. how do I go about this? And also for the past week or so every time I click on a link in google, it doesn't go to the actual link. Instead it goes to random websites that have nothing to do with my search. How do I fix this

    I am using IE 10 and I have no recovery disk just FYI.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rescan with both RogueKiller and Hitman and attach the logs. Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Attach the new C:\MGLogs.zip.
     
  9. lzepplin1975

    lzepplin1975 Private E-2

    Here you go.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the MGLog.zip separately.
     
  11. lzepplin1975

    lzepplin1975 Private E-2

    Here you go
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. However, you need to post in the software forum as per these issues:
    Code:
        Windows Defender service   -WinDefend-               is NOT running  
      
    [SC] OpenService FAILED 1060:
    
    The specified service does not exist as an installed service.
    
        ----------------------------------------------------------------------------    
        ----------------------------------------------------------------------------       
         Windows Security Center service  -wscsvc-           is NOT running  
      
    [SC] OpenService FAILED 1060:
    
    The specified service does not exist as an installed service.
     
  13. lzepplin1975

    lzepplin1975 Private E-2

    ok but what about my internet problem? Is that a software issue too?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attached is bfe.zip

    Inside is:

    * bfe.reg


    Extract bfe.reg to your desktop.
    Double-click bfe.reg and allow it to merge into the registry. If you get a "successfully merged into registry" type of message, reboot your PC and see if you can turn on BFE, or if it is already turned on.

    You can run these commands from the command prompt.

    * net start bfe
    * sc qc bfe

    BFE.zip
     
  15. lzepplin1975

    lzepplin1975 Private E-2

    It says could not be started because of system error 5.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run regedit:
    1. Browse to the location for the BFE service in the registry (HKLM\System\CurrentControlSet\Services\BFE\Parameters\Policy), right click and select permissions. (note: HKLM is short for HKEY_LOCAL_MACHINE_
    2. In the “Permissions for Policy” window, click advanced | Add.
    3. Once the “Select Users, Computers or Group” box appears, change the “From this location:” to point to the local machine name.
    4. After changing the search location, enter “NT Service\BFE” in the “Enter the object name to select” box and click “Check names” – this will allow you to add the BFE account.

    5. Give the following privileges to the BFE account:
    Query Value
    Set Value
    Create Subkey
    Enumerate Subkeys
    Notify
    Read Control

    After adding the BFE account to the registry key, please try to start the Base Filtering Engine service.
     
  17. lzepplin1975

    lzepplin1975 Private E-2

    Ok I got it started and I did the "sc qc bfe" command. Now what?
     
    Last edited: May 2, 2013
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip.
     
  19. lzepplin1975

    lzepplin1975 Private E-2

    Here you go.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That fixed it. Do you have internet now? Your problems will probably best addressed in the software forum from now on.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really. See nwktst.txt which shows
    Code:
    Checking Windows Firewall Service -MpsSvc- State 
    .
       Windows Firewall Service is NOT running  
            C:\Windows\system32\FirewallAPI.dll exists  
    =====================================================================================  
    Checking Windows Firewall Authorization Driver Service -mpsdrv- State 
    .
       Windows Firewall Authorization Driver Service is NOT running  
            C:\Windows\system32drivers\mpsdrv.sys exists  
    Also netinflong shows you the below key is missing:
    Code:
        ----------------------------------------------------------------------------
           **** ERROR: The below registry key is missing and should not be: ****    
                "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc"                                                               
        ----------------------------------------------------------------------------
     
  22. lzepplin1975

    lzepplin1975 Private E-2

    So now what do I do? I posted a thread in the software forum but they say to wait until Im done here.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if the below can automatically repair the broken firewall services and registry key.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  24. lzepplin1975

    lzepplin1975 Private E-2

    Ok so so sorry this is late. I had a lot of stuff happen to me these past 2 months and I totally forgot to get to this to you. I appreciate you both helping me with this and being patient with me. Here is the log you requested.

    It still says "Windows Security center can't be started"
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First run MSconfig and put your PC into Normal Startup mode and remain in this mode.

    Now uninstall DefaultTab. If not found or it will not uninstall, just continue on.


    Now please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    
    :Files
    C:\Users\Taylor\AppData\Roaming\DefaultTab
    C:\Program Files (x86)\Conduit
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc]
    "DisplayName"="@%SystemRoot%\\System32\\wscsvc.dll,-200"
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
      74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
      00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
      6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\
      00,65,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,52,00,65,00,73,00,74,00,\
      72,00,69,00,63,00,74,00,65,00,64,00,00,00
    "Start"=dword:00000002
    "Type"=dword:00000020
    "Description"="@%SystemRoot%\\System32\\wscsvc.dll,-201"
    "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,57,00,69,00,6e,00,\
      4d,00,67,00,6d,00,74,00,00,00,00,00
    "ObjectName"="NT AUTHORITY\\LocalService"
    "ServiceSidType"=dword:00000001
    "RequiredPrivileges"=hex(7):53,00,65,00,43,00,68,00,61,00,6e,00,67,00,65,00,4e,\
      00,6f,00,74,00,69,00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,\
      67,00,65,00,00,00,53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,\
      00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,\
      00,00,00,00
    "DelayedAutoStart"=dword:00000001
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
      00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc\Parameters]
    "ServiceDllUnloadOnStop"=dword:00000001
    "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
      00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
      77,00,73,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc\Security]
    "Security"=hex:01,00,14,80,c8,00,00,00,d4,00,00,00,14,00,00,00,30,00,00,00,02,\
      00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
      00,00,02,00,98,00,06,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
      05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
      20,02,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\
      00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,00,00,14,00,00,01,\
      00,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,28,00,15,00,00,00,01,06,00,\
      00,00,00,00,05,50,00,00,00,49,59,9d,77,91,56,e5,55,dc,f4,e2,0e,a7,8b,eb,ca,\
      7b,42,13,56,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,\
      00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend]
    "DisplayName"="@%ProgramFiles%\\Windows Defender\\MsMpRes.dll,-103"
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
      74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
      00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
      6b,00,20,00,73,00,65,00,63,00,73,00,76,00,63,00,73,00,00,00
    "Start"=dword:00000002
    "Type"=dword:00000020
    "Description"="@%ProgramFiles%\\Windows Defender\\MsMpRes.dll,-1176"
    "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
    "ObjectName"="LocalSystem"
    "ServiceSidType"=dword:00000001
    "RequiredPrivileges"=hex(7):53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,\
      00,6e,00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,\
      65,00,00,00,53,00,65,00,42,00,61,00,63,00,6b,00,75,00,70,00,50,00,72,00,69,\
      00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,\
      74,00,6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,\
      00,00,00,53,00,65,00,44,00,65,00,62,00,75,00,67,00,50,00,72,00,69,00,76,00,\
      69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,68,00,61,00,6e,00,67,\
      00,65,00,4e,00,6f,00,74,00,69,00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,\
      6c,00,65,00,67,00,65,00,00,00,53,00,65,00,53,00,65,00,63,00,75,00,72,00,69,\
      00,74,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\
      53,00,65,00,53,00,68,00,75,00,74,00,64,00,6f,00,77,00,6e,00,50,00,72,00,69,\
      00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,6e,00,63,00,\
      72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,00,72,00,69,\
      00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,41,00,73,00,73,00,\
      69,00,67,00,6e,00,50,00,72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,\
      00,65,00,6e,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\
      00,00
    "DelayedAutoStart"=dword:00000001
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
      00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\Parameters]
    "ServiceDllUnloadOnStop"=dword:00000001
    "ServiceDll"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,69,\
      00,6c,00,65,00,73,00,25,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\
      20,00,44,00,65,00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,6d,00,70,00,73,\
      00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\Security]
    "Security"=hex:01,00,14,80,dc,00,00,00,e8,00,00,00,14,00,00,00,30,00,00,00,02,\
      00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
      00,00,02,00,ac,00,06,00,00,00,00,00,28,00,ff,01,0f,00,01,06,00,00,00,00,00,\
      05,50,00,00,00,b5,89,fb,38,19,84,c2,cb,5c,6c,23,6d,57,00,77,6e,c0,02,64,87,\
      00,0b,28,00,00,00,00,10,01,06,00,00,00,00,00,05,50,00,00,00,b5,89,fb,38,19,\
      84,c2,cb,5c,6c,23,6d,57,00,77,6e,c0,02,64,87,00,00,14,00,fd,01,02,00,01,01,\
      00,00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,\
      05,20,00,00,00,20,02,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,\
      04,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,01,\
      01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\TriggerInfo]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\TriggerInfo\0]
    "Type"=dword:00000005
    "Action"=dword:00000001
    "GUID"=hex:e6,ca,9f,65,db,5b,a9,4d,b1,ff,ca,2a,17,8d,46,e0
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\MpsSvc]
    "DisplayName"="@%SystemRoot%\\system32\\FirewallAPI.dll,-23090"
    "Group"="NetworkProvider"
    "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
      74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
      00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
      6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\
      00,65,00,4e,00,6f,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,00,00
    "Description"="@%SystemRoot%\\system32\\FirewallAPI.dll,-23091"
    "ObjectName"="NT Authority\\LocalService"
    "ErrorControl"=dword:00000001
    "Start"=dword:00000002
    "Type"=dword:00000020
    "DependOnService"=hex(7):6d,00,70,00,73,00,64,00,72,00,76,00,00,00,62,00,66,00,\
      65,00,00,00,00,00
    "ServiceSidType"=dword:00000003
    "RequiredPrivileges"=hex(7):53,00,65,00,41,00,73,00,73,00,69,00,67,00,6e,00,50,\
      00,72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,00,65,00,6e,00,50,00,\
      72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,41,00,75,\
      00,64,00,69,00,74,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,\
      00,00,53,00,65,00,43,00,68,00,61,00,6e,00,67,00,65,00,4e,00,6f,00,74,00,69,\
      00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\
      53,00,65,00,43,00,72,00,65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,\
      00,6c,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,\
      65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,00,61,00,74,00,65,00,50,\
      00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,\
      6e,00,63,00,72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,\
      00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
      00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\MpsSvc\Parameters]
    "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
      00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
      6d,00,70,00,73,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
    "ServiceDllUnloadOnStop"=dword:00000001
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\MpsSvc\Parameters\PortKeywords]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\MpsSvc\Security]
    "Security"=hex:01,00,14,80,b4,00,00,00,c0,00,00,00,14,00,00,00,30,00,00,00,02,\
      00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
      00,00,02,00,84,00,05,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
      05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
      20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\
      00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,00,00,28,00,15,00,\
      00,00,01,06,00,00,00,00,00,05,50,00,00,00,49,59,9d,77,91,56,e5,55,dc,f4,e2,\
      0e,a7,8b,eb,ca,7b,42,13,56,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,\
      00,00,00,05,12,00,00,00
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E24F821A-30E4-4C61-BDC6-2424A3098DEA}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  26. lzepplin1975

    lzepplin1975 Private E-2

    Still says it can't be started.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The first request in my last message was to run MSconfig and put your PC into normal startup mode. You did not do this. You are still in selective startup mode. Please do this now. And then you will need to get another new MGlogs.zip file. ( you have to run GetLogs.bat first to get a new log ).

    While the services are still not running, the last fix did restore all the missing registry entries for them.
     
  28. lzepplin1975

    lzepplin1975 Private E-2

    Sorry, I did the MSconfig but I did not see the "Normal startup" bullet the first time. Did something else by mistake. Here is the new log.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now please download Farbar Service Scanner and run it on the computer with the issue.
    • Put a check mark in each option box on the left side.
    • Click "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach this log to your next reply.
     
  30. lzepplin1975

    lzepplin1975 Private E-2

    Here you go. Also when ever my computer goes to sleep and I log back on, the screen just fades to black after the "Welcome" screen comes up. I'm still in the normal startup mode and this never happened in the previous mode I was in.
     

    Attached Files:

    • FSS.txt
      File size:
      3.7 KB
      Views:
      6
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and save these files to your Desktop >> SharedAccess.reg and iphlpsvc.reg You can get them from the below link/site. The files are sort of alphabetical but the iphlpsvc.reg is in a second list of alpha order. So if you do not see it, keep scrolling down. ;)

    http://download.bleepingcomputer.com/win-services/7

    After saving to your Desktop, right click on them ( one at a time ) and select Merge to add the file to the registry. Approve any prompts you may get about making this change.


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Restart the computer when done.

    Rerun Farbar Service Scanner and attach a new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  32. lzepplin1975

    lzepplin1975 Private E-2

    Here are the logs. I did get a success message on all 3 registry files.
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that fixed several more issues.

    Download and save these files to your Desktop >> wscsvc.reg and wuauserv.reg You can get them from the below link/site. The files are sort of alphabetical but the iphlpsvc.reg is in a second list of alpha order. So if you do not see it, keep scrolling down.

    http://download.bleepingcomputer.com/win-services/7

    After saving to your Desktop, right click on them ( one at a time ) and select Merge to add the file to the registry. Approve any prompts you may get about making this change.

    Now let's run Windows Repair again. Make sure all protection software is disabled before running it.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  34. lzepplin1975

    lzepplin1975 Private E-2

    Windows security center still won't start. Got a success message on both registry files.
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay all the missing registry entries appear to be fixed now, but at a minimum I still see the below services are not running
    • System Restore
    • Windows Defender
    • Windows Security Center

    One more thing I want to try. Uninstall Privatefirewall and then reboot. Is there any change after this?
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's probably okay that Windows Defender and System Restore re not currently running, but Security Center should be running. I hoping that it is only an issue that Privacy Firewall is some how blocking it.
     
  37. lzepplin1975

    lzepplin1975 Private E-2

    No change. I hope my computer is broken because my warranty has already expired.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you meant "isn't". ;)

    Click Start, All Programs, and scroll down to Accessories and click on it to expand what is under it. Then find the black icon for Command Prompt. Right click on it and select Run As Administrator. This will open up a command prompt window. In the command prompt window type the below ( observe the space after sfc, there are no other spaces and observe the direction of the / )

    sfc /scannow

    This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it. After running the above ( even if it does not appear to find anything wrong ) reboot your PC.

    After reboot, please rerun Farbar Service Scanner again and attach a new log.
     
  39. lzepplin1975

    lzepplin1975 Private E-2

    yes I meant "isn't.

    I reloaded MSE and after a while I was able to actually update its virus database without any problems yet WSC wont start. I tried to start Windows Defender but Error 126 came up. I uninstalled MSE before I did the Scannow on the command prompt but I don't have a windows CD. Dell didn't offer it to me when I got the Laptop.
     
  40. lzepplin1975

    lzepplin1975 Private E-2

    Here's the FSS log. Scannow didn't find anything and didn't ask me to insert a CD.
     

    Attached Files:

  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start and in the search box type Services
    You should see it appear in the list above as you type. Once you see the gear icon with Services next to it, right click on it and select Run As Administrator.

    When the Services forum opens up, scroll down to Security Center and double click on it. A new form will open. Try setting the Service type to Automatic (delayed start) and then click the Start button to see if it starts. Tell me exactly what happens. I'm assuming there will be an error message. I need the exact word for word message.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also you can try running Microsoft FixIt.

    http://support.microsoft.com/fixit/

    One of the fixes is for Fix security issues to protect and secure Windows automatically You will have to scroll thru the pages to see it along with other fixes.
     
  43. lzepplin1975

    lzepplin1975 Private E-2

    I have done this tons of times already. It turns on but then the Action center tells me to find an antivirus software and to turn on Windows Defender. I try to turn on Windows Defender via action center but it just takes me to file "C:\Windows\system32".

    When I try to turn on Windows Defender via Services, Error 1297 comes up. Error 1297 says "A privilege that the service requires to function properly does not exist in the service account configuration. You may use the Services Microsoft Management Console (MMC) snap-in (services.msc) and the Local Security Settings MMC snap-in (secpol.msc) to view the service configuration and the account configuration."
     
  44. lzepplin1975

    lzepplin1975 Private E-2

    Fixit didn't fix my firewall. Security center is working now, I reinstalled MSE and PrivateFirewall and everything is back to semi-normal. Windows Defender still wont start but I think PrivateFirewall is doing its job for it. I still would like Windows Defender to work.
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer the same question I ask for the Security Center services. Also please do not translate. Tell me the exact beginning to end error message including the error number. Or did your second message today mean that when you tried starting it from services.msc that it started? Or did MS Fixit correct it?
     
    Last edited: Jun 26, 2013
  46. lzepplin1975

    lzepplin1975 Private E-2

    I did. Security Center is working so there was no Error message.
     
  47. lzepplin1975

    lzepplin1975 Private E-2

    Security Center is working.

    Windows Defender is not.

    MSE is monitoring my computer.

    PrivateFirewall is my only firewall program working right now.

    Fixit did not fix anything.

    There was no error when starting Security Center via Services.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I was working on Windows Security Center not Window Defender because it is not supposed to be running. See the third and fourth questions and answers in the below

    http://answers.microsoft.com/en-us/...sentials/5309cb8d-02e1-40e8-974f-0dcedb9ab9fd

    Back a few messages ago you said security center was still not running and I could see that in your logs too. So if MS Fixit did not do anything and services.msc already showed it running, how did it get started.
     
  49. lzepplin1975

    lzepplin1975 Private E-2

    Again sorry I'm late at responding.

    I don't have any Idea sir. I started Security Center via services and it started right up with no problems. Then I ran Fixit, but thank you for sending that link to those questions. I thought I had to have Windows Defender on. Everything is back to normal now. Thanks again
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Just happy to hear everything is good now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    2. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    3. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds