not finding that either, tried to manually start windows firewall and it start/stopped. started windows defender but still getting a red ms security essentials saying that the service is stopped
24 replies to this topic
#21
Posted 24 June 2012 - 04:36 PM
#22
Posted 24 June 2012 - 04:50 PM
Just tried uninstalling and reinstalling microsoft sec essentials. It is now saying that it is on and up to date, however windows firewall and windows defender services are still off. here is another log file from Farbar:
Farbar Service Scanner Version: 24-06-2012
Ran by Shmim (administrator) on 24-06-2012 at 16:48:30
Running from "C:\Users\Public"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is OK.
The ImagePath of MpsSvc service is OK.
The ServiceDll of MpsSvc service is OK.
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.
Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
Farbar Service Scanner Version: 24-06-2012
Ran by Shmim (administrator) on 24-06-2012 at 16:48:30
Running from "C:\Users\Public"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is OK.
The ImagePath of MpsSvc service is OK.
The ServiceDll of MpsSvc service is OK.
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.
Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
#23
Posted 25 June 2012 - 12:40 AM
ok I did some research thru the MS forums and was able to fix windows defender and the firewall. It appears that everything is working ok. Is there anything else you would like to look at?
Shmim
Shmim
#24
Posted 25 June 2012 - 03:46 AM
Good work! No, that's all! 
Please run OTL and click on CleanUp button. Next, manually delete Farbar Service Scanner.
Some malware prevention tips:
http://forums.malwar...=0
Safe surfing!
Please run OTL and click on CleanUp button. Next, manually delete Farbar Service Scanner.
Some malware prevention tips:
http://forums.malwar...=0
Safe surfing!
My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here
#25
Posted 30 June 2012 - 05:51 AM
Glad we could help. 
If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.
Other members who need assistance please start your own topic in a new thread. Thanks!
If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.
Other members who need assistance please start your own topic in a new thread. Thanks!
Maurice Naggar
Consumer Support Specialist

Follow us: Twitter, Become a fan: Facebook
I close my threads if there is 5 days without a response.
Consumer Support Specialist

Follow us: Twitter, Become a fan: Facebook
I close my threads if there is 5 days without a response.
Also tagged with one or more of these keywords: trojan
Malwarebytes Anti-Malware Support →
False Positives →
File Detections →
False Positive: Trojan.FakeMS.TTStarted by candystand, 15 Jun 2013 |
|
|
||
Malwarebytes Anti-Malware Support →
False Positives →
File Detections →
Help?Started by IROBotEagle, 15 Jun 2013 |
|
|
||
![]() |
Malware Removal Support →
Malware Removal Help →
Resolved HijackThis Logs →
Laptop Malware - Packer? Zbot? Rootkit.0Access?Started by mosedavid, 09 Jun 2013 |
|
|
|
Malware Removal Support →
Malware Removal Help →
Bug Battling For 2 Weeks & Still Cannot Get It - NEED HELP!Started by ChildPlease, 07 Jun 2013 |
|
|
||
![]() |
Malware Removal Support →
Malware Removal Help →
Resolved HijackThis Logs →
Trojan: PSW.onlinegames4.ALGTStarted by aejulian, 03 Jun 2013 |
|
|
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users



This topic is locked









