Windows Security Center Service can't be started

Discussion in 'Malware Help (A Specialist Will Reply)' started by cee3, Jul 16, 2012.

  1. cee3

    cee3 Private E-2

    Hi,

    Running Windows 7 Home Premium 64-bit with Microsoft Security Essentials (MSE). I got a warning from MSE saying I was at risk. When I checked further it told me that the Security Center service wasn't running. When I try to start it I get the error "The Windows Security Center Service can't be started."

    I don't even see that service in the list of services. When I started Googling the errors I found I was being redirected when I tried to click on the links in Google. I cleared my caches, and that seemed to help the redirecting.

    Malwarebytes didn't find anything, but RogueKiller and Hitman did. No action taken on Hitman results, but I did delete the things RogueKiller found. Got to thinking later that maybe I should not have done that. Didn't see anything in the instructions about not doing that. Logs attached.

    Thanks, Chip
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks, cee3 :)

    http://3.bp.blogspot.com/-tH5H1icUyOc/T1XP6r4puoI/AAAAAAAAAQE/jLwmqQECjCg/s1600/hitmanpro.gif - Rescan with HitmanPro, when it finds services.exe - Virus, allow it to Replace by clicking the down arrow next to the detection and choosing Replace.
    Choose to Delete these two files if they are detected:
    • CSM31.tmp - Trojan
    • Desktop.ini - Trojan
    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    __

    http://img205.imageshack.us/img205/1894/otl.gif Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
    Code:
    [COLOR="DarkRed"]:files[/COLOR]
    c:\windows\installer\{86d19e99-bfc1-2b38-5fad-43f00b4edd9a}
    c:\users\chip\appdata\local\{86d19e99-bfc1-2b38-5fad-43f00b4edd9a}
    C:\Windows\assembly\GAC_32\Desktop.ini
    C:\Windows\assembly\GAC_64\Desktop.ini
    dir /s C:\Users\Chip\AppData\Roaming\.oit /c
    type C:\Users\Chip\Desktop\RKreport[2].txt /c
    C:\Users\Chip\Documents\Local Settings\temp\CSM31.tmp
    C:\ProgramData\Norton /d
    [COLOR="DarkRed"]:reg[/COLOR]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
    [COLOR="DarkRed"]:commands[/COLOR]
    [clearallrestorepoints]
    [emptyflash]
    [emptyjava]
    
    Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    __

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below:
    • J2SE Runtime Environment 5.0 Update 3
    • Java(TM) 6 Update 25

    __

    http://img406.imageshack.us/img406/3189/windowsrepair.gif Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to the Start Repairs tab.
    • Press the Start button
    • Create a System Restore point if prompted.
    • In the Repair Options window, choose the following repairs:
      • Reset Registry Permissions
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
    • Place a checkmark in Restart/Shutdown System When Finished
    • Fill in the Restart System bubble
    • Now click the Start button.
    • Be patient while the tool repairs the selected items. Your computer should automatically restart when finished.

    __


    http://3.bp.blogspot.com/-tH5H1icUyOc/T1XP6r4puoI/AAAAAAAAAQE/jLwmqQECjCg/s1600/hitmanpro.gif Once you are back in Windows, run another scan with HitmanPro and then attach the latest hitmanpro.zip log. (How to attach)

    __

    http://img97.imageshack.us/img97/8120/fss.gif Please download Farbar Service Scanner and run it on the computer with the issue.
    • Make sure all the options are checked
    • Press Scan.
    • It will create a log (FSS.txt) in the same directory the tool was run.
    • Please attach FSS.txt to your next message. (How to attach)
     
  3. cee3

    cee3 Private E-2

    Thanks thisisu! This is much appreciated!

    After running the repairs as suggested I'm not able to access the internet on the affected computer :cry. I've attached the OTL and FSS logs. I was not able to rerun HitmanPro again because it apparently needs the internet.

    Thanks!
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    Did you run HitmanPro first? When exactly did you notice that internet was lost?

    __

    Answer the above and also complete these steps:

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  5. cee3

    cee3 Private E-2

    I did first run HitmanPro and replaced services.exe and deleted csm31.tmp and desktop.ini. I first noticed I had no internet after the Windows Repair restart.

    Mglogs.zip attached.

    Thanks!
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    Go inside the C:\MGtools folder
    Locate FixNet.bat
    Right-mouse click FixNet.bat and select Run as administrator
    Your computer will automatically reboot.
    Test for an internet connection upon reboot

    __

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  7. cee3

    cee3 Private E-2

    Still no internet after running FixNet.bat. MG logs.zip attached.

    Thanks!
     

    Attached Files:

  8. thisisu

    thisisu Malware Consultant

    Code:
    Security Center                                         wscsvc                          Auto       Running  
    Looks like Security Center is fixed.. just need to fix your internet.

    http://img205.imageshack.us/img205/1894/otl.gif Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
    Code:
    [COLOR="DarkRed"]:processes[/COLOR]
    killallprocesses
    [COLOR="DarkRed"]:files[/COLOR]
    C:\Users\Chip\AppData\Local\dguxzv.exe
    C:\Users\Chip\AppData\Roaming\.oit /d
    type c:\MGtools\fixnet.txt /c
    ipconfig /flushdns /c
    netsh int ip reset resetlog.txt /c
    netsh winsock reset /c
    
    Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    __

    http://img196.imageshack.us/img196/3557/tdsskiller.gif I want you to read and follow these instructions: TDSSKiller - How to run
     
  9. cee3

    cee3 Private E-2

    Ran OTL and TDSSKiller. Still no internet. Logs attached.

    Thanks again!
     

    Attached Files:

  10. thisisu

    thisisu Malware Consultant

    Uninstall and reinstall your network adapter driver (via Device Manager).
    It should be named: Realtek PCIe GBE Family Controller

    Open the Device Manager

    Collapse the Network Adapters list.
    Right mouse click: Realtek PCIe GBE Family Controller
    Choose "Uninstall".
    You be asked to confirm your actions, choose OK and let it uninstall.
    If it asks you if you want to delete the driver software / files too, say No.
    When you have done this and Realtek PCIe GBE Family Controller is no longer in the Device Manager list -- Press the Scan for hardware changes button (http://img803.imageshack.us/img803/2868/scanhardware.png) or Action -> Scan for hardware changes
    Allow it to reinstall your network adapter.
    Reboot for changes to occur.
    Test internet once you have rebooted.
     
  11. cee3

    cee3 Private E-2

    That worked. I'm now able to access the internet. I'm now able to run HitmanPro, and I attached that log.

    Thanks!
     

    Attached Files:

  12. thisisu

    thisisu Malware Consultant

    Great :)

    __

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)

    __

    Let me know what remaining issues you are experiencing.
     
  13. cee3

    cee3 Private E-2

    MGlogs.zip attached.

    Thanks!
     

    Attached Files:

  14. thisisu

    thisisu Malware Consultant

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  15. cee3

    cee3 Private E-2

    Thanks for all the help thisisu! Things are mostly working now. I'm still having some odd network issues. I'm guessing they're from resetting the network adapter.

    My internet is fine and I can see other computers on the network from the affected computer, but I can't connect to the affected computer from other devices (VNC, Audiotron music player).

    I can see shared files from another computer using UNC (\\computer\c), but I can't ping "computer."

    These are beyond the malware issues so I'll pursue that and let you get back to your job.

    Once again, I really appreciate you taking time to help!
     
  16. thisisu

    thisisu Malware Consultant

    You're welcome.
    Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds