Forum Home
Press F1
 
Thread ID: 128819 2013-01-17 07:45:00 windows 7 security centre disabled... cannot turn on anglokiwi (16988) Press F1
Post ID Timestamp Content User
1323226 2013-01-17 07:45:00 I have a limited ability but not for the sake of trying . . . .

I see the security centre is turned off . . . don't know when or how it came about . . . .

have followed several paths but no luck so far . . .

have SC properties dialogue box . . . states startup type disabled

C:\Windows\System32\svchost . exe -k LocalServiceNetworkRestricted
am not sure as to why restricted . . . .

any ideas please?
anglokiwi (16988)
1323227 2013-01-17 19:25:00 Have you scanned the computer for malware / viruses??

Get farbar service scanner, run it as admin. (www.bleepingcomputer.com) Tick all the options except the last one. Copy and paste what comes up in here. We'll see if any services are missing
Speedy Gonzales (78)
1323228 2013-01-17 19:58:00 thanks will do anglokiwi (16988)
1323229 2013-01-17 20:04:00 thanks will do anglokiwi (16988)
1323230 2013-01-17 20:05:00 have run farbar as supplied... how to as admin??

here is log

Farbar Service Scanner Version: 16-01-2013
Ran by Guest (ATTENTION: The logged in user is not administrator) on 18-01-2013 at 08:51:28
Running from "C:\Users\Guest\Downloads"
Windows 7 Professional Service Pack 1 (X86)
Boot Mode: Normal
************************************************** **************

Internet Services:
============

Connection Status:
==============
Attempt to access Local Host IP returned error: Localhost is blocked: Other errors
LAN connected.
Attempt to access Google IP returned error. Other errors
Attempt to access Google.com returned error: Other errors
Attempt to access Yahoo IP returned error. Other errors
Attempt to access Yahoo.com returned error: Other errors


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============
SDRSVC Service is not running. Checking service configuration:
The start type of SDRSVC service is OK.
The ImagePath of SDRSVC service is OK.
The ServiceDll of SDRSVC service is OK.

VSS Service is not running. Checking service configuration:
The start type of VSS service is OK.
The ImagePath of VSS service is OK.


System Restore Disabled Policy:
========================


Action Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is set to Disabled. The default start type is Auto.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is set to Disabled. The default start type is Auto.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Disabled. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Other Services:
==============


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****

thanks
anglokiwi (16988)
1323231 2013-01-17 20:21:00 Can you log in as admin, since it looks like you're logged in as a guest. Then run it again as admin (right mouse on the file you downloaded) then select run as admin. Looks like something may have added something to the hosts file

Go to c:\windows\system32\drivers\etc folder. Open the hosts file with notepad. Copy and paste whats in there in here.

Another thing you can try is get trojan remover install it. (simplysup1.com) <- direct link. Then update it then click on scan. If it finds anything suss, tell it to remove it. Then select all of the options under the utils menu. So it resets everything. Then reboot then see if windows security works
Speedy Gonzales (78)
1