View Full Version : Security Centre disabled
ERICBRAD
25-05-2009, 07:07 PM
If I go to the security centre, via control panel, it always says "security centre has not started or was stopped". When I go to services, it shows that the security centre is disabled.
In security centre properties I set it to automatic and click the start button, which switches it back on, with firewall,automatic updates and virus protection showing as on in control panel.
However it seems that when I reboot, the security centre is disabled again.
Any idea what is causing this, and could it be caused by Norton Antivirus?.
The Underdog
25-05-2009, 08:28 PM
Sounds like you go an infection tbh :(.
ERICBRAD
25-05-2009, 09:21 PM
I did think that might be a possibility, although norton antivirus and spybot both show the system is safe, so how do I get rid of it?
I was looking at the list of startup Items via msconfig last week, and I googled one of them called "msmsgs"and it said that it was a virus,spyware,trojan or worm. Could that have anything to do with it?
The Underdog
25-05-2009, 09:37 PM
Try disabling it and find out... experiment :D.
ERICBRAD
27-05-2009, 04:11 PM
I did a search for `msmsgs.exe` found it and deleted it, but the security centre is still being disabled every time I reboot.
I have searched and found 6 more `msmsgs files (although these are not `msmsgs.exe) and they are
C:\WINDOWS\$NTServicePack Uninstall$
C:\WINDOWS\$NTUninstallKB887472$
C:\WINDOWS\I386\MMSSETUP.CAB
C:\WINDOWS\ServicePackFiles\i386
C:\WINDOWS\$hf_mig$\KB887472\SP2QFE
C:\WINDOWS\ServicePackFiles\ServicePackCache\i386
They are all prefixed msmsgs, but I presume it`s only msmsgs.exe that are dangerous
Do I need to keep these files or should I delete them?
Nip into control panel - system - computer name tab -
Look where it say's Full computer name then the line below
Does it say Workgroup : workgroup
or something different ?
/edit.. P.s msmsgs = Windows Messenger ;)
ERICBRAD
27-05-2009, 07:24 PM
It says `WORKGROUP`
AeroFX
27-05-2009, 07:38 PM
there are some viruses that interfere with the Security Centre, it is also possible that a group policy setting could have been changed, that is overriding what you see in Services.MSC
the latter is only likely if you've changed group policy settings.
darn... hoping you were going to say Domain.
Its deffo being forced overridden in that case.
try checking the following registry entry...
Microsoft.WindowsSecurityCenter_disabled
Settings HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\wscsvc\Start!=W=2
ERICBRAD
27-05-2009, 07:49 PM
I have always used Norton Antivirus since the computer was new, and have more recently added Spybot Search and Destroy. They`ve not stopped the viruses though.
Baggpuss
27-05-2009, 08:04 PM
Thats because norton is rubbish :-P
ERICBRAD
27-05-2009, 08:31 PM
I tried checking that registry entry,when I open wscscv the only 3 entries it reveals are ENUM,PARAMETERS, AND SECURITY.
But `start` appears in the right hand main window as shown below.
START - - -REG_DWORD 0X00000004 (4)
change the 4 to a 2 see if solves it or not.
ERICBRAD
28-05-2009, 10:24 AM
I had another look this morning and it now says - START - REG_DWORD 0X00000002(2)
I was certain that it ended with(4) yesterday because I wrote it down straight away, but it has changed to (2) with no input from me.
I start windows security centre every time I switch the PC on now, because it is always in disabled mode otherwise.
Get MalwareBytes (http://www.malwarebytes.org/)and run a scan with it and see if it detects anything.
ERICBRAD
28-05-2009, 05:08 PM
I have installed Windows Defender, and did a full system scan. It found two "severe alert level" objects.One was called `backdoor` and the other `trojan downloader`.I deleted them both but the security centre is still being disabled every time I reboot.
I also installed ZoneAlarm 8.0 Firewall, which is a better one than the WSC firewall.
The Underdog
28-05-2009, 05:27 PM
Doesn't sound good mate, let me explain:
A backdoor means it will hide in your system undetected (it sounds like it has been for some time successfully), feeding another machine possibly critical information (eg passwords).
A trojan downloader basically downloads more backdoors and other programs you don't want which will gradually or quickly (depends what gets downloaded) rape your pc and get as much from it as it can. Tbh at this point I would consider a huge format and reinstall but I'm sure someone here could help you to remove them successfully as an alternative.
Problem with viruses and such like is even though you can attempt to sort, your usually left with a PC in naff state because you have nuked essential files to other programs & windows whilst nuking the viruses blah blagh blah.
As mentioned re-install is best - then ditch nortons and go with something Like Avast
Use Firefox instead of Explorer & also install Spyware Terminator'.
That along with your ADSL or routers basic firewall should essentially keep you safe.
Not had any nasties for several years now using that combo.
I have done cleanups for friends one had over 1000 Nasties on it :OMG:
and the only way to do it is slave it up to another machine else you have no chance
because many have the ability to evade & hide & re-implement & turn off and nobble anti-virus programs.
So essentially you could download a program - install and the virus will nobble it you scan your system it fails to find the cleaver ones becuase they hae already took the necessary action to evade.
If you want to at the mo... you could try ' Spybot search and Distroy' and 'Ad-Aware'
If I remember right CCleaner os also a good one.
ERICBRAD
28-05-2009, 07:36 PM
So are you saying that Windows Defender,having deleted these two Items and now showing "No unwanted or harmfull software detected", only means that it can`t find anything because they are evading detection?
If that`s the case, then Spybot,Ad-Aware, and CCleaner could give the same misleading results, so that means that no spyware detector can do the job it`s intended for.
Your also at the mercy of the program makers to keep on top of the game so to speak - you might be ok... you might be not.
Nortons = epic fail
There is honestly no 100% fool proof method.
Also - Check to see if your Windows Updates is still intact - that can get disabled as well.
It maybe the case you only got some basic non cleaver stuff - but as you have realised you would never know if that was true or not.
If you take it into a shop there basic course of action is nuke it and clean install
more so in the fact its quicker to do that than spend all day tracking everything down and manually sorting it.
The Underdog
28-05-2009, 08:51 PM
Wow I got it right :D. Go me :P. Thx for the backup PMM (I was sure you'd come to the rescue :)) but the problem with nuking it means you have to do backups etc.
ERICBRAD
29-05-2009, 03:01 PM
Yeah, nuking it sounds like a big job. I `d have to buy an xp Install disc for a start as mine came preloaded. I suppose I could try doing full scans with several spyware cleaners in the hope that one of them will find something.
ERICBRAD
08-06-2009, 03:51 PM
I decided to try uninstalling Norton AntiVirus, and `HEY PRESTO`, the security centre now stays on. So it was Norton that was overriding, or disabling WSC, and not a virus or trojan, it would appear.
I don`t know if Norton is supposed to do this, but that`s what was happening.
I now have more security than Fort Knox, with Windows Defender, AVG free Antivirus, ZoneAlarm Firewall, Malwarebytes scanner, and WSC.
Overall, I found the following - - 1 x backdoor, 1 x trojan downloader, and 3 x trojan agents
My only question now is, Is AVG free antivirus as good a product as a paid for virus program such as Norton Antivirus? Although in my experience Norton has been useless and I won`t be installing it again.
sharpapotheosis
08-06-2009, 04:06 PM
yes it is as good as most paid for, and a lot better than norton. I personally used avira antvir, which is very good, but then i got iolo, which is even better. my only problem with AVG is that it takes ages to download/scan and is really system intensive when doing either.
The Underdog
08-06-2009, 04:31 PM
I would recommend Avast over AVG anyway - system never had an issue with it compared to AVG Free which I've never not had an issue with :(.
Powered by vBulletin® Version 4.1.10 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.