hello folks. I have a laptop given to me which came with a grand quota of nasties, and though I think I have probably dealt with most of the problems now, I can't remember how to get the antivirus and spyware software re-enabled.

It is probably a registry value I need to modify I s'pose, and I know I have had and sorted this problem before, but I just can't bring it to mind how I did it... any wise ones here to remind me please?

Dani AI

Generated

Persistent disabling of antivirus and the firewall at every boot — exactly as describes — almost always means something on the machine is actively turning them off during startup. That can be a resident piece of malware, a broken or partially removed security product, or a startup/scheduled task that re-applies the change. is right that you must remove the infection first; the following is a practical, safe sequence to try.

  1. Isolate the laptop: unplug networking and do not log into online accounts.
  2. Work from a clean environment: boot Safe Mode (or better, boot from a known-clean rescue USB/CD) so active nasties have less chance to run.
  3. Run an on-demand antimalware sweep (use a modern on-demand scanner) and an offline rescue scan if anything stubborn remains.
  4. Use a startup inspector (Autoruns or msconfig) to list and disable suspicious Run/RunOnce entries and scheduled tasks; remove anything obviously malicious.
  5. Check Services (Start -> Run -> services.msc) and ensure the Security Center service and the Firewall/ICS service are set to Automatic and are running. For vendor AV, confirm its service is present and running; if it is corrupt, fully uninstall with the vendor’s removal tool and reinstall.

After cleaning, delete old System Restore points (infected points can reintroduce problems), run sfc /scannow if system files look damaged, then reboot and verify the AV/firewall remain enabled. If the machine keeps reverting despite removal attempts, back up user data and do a clean OS reinstall — that is the only reliable way to eliminate deeply hidden persistence. Always export any registry keys before editing, and post startup/service lists if help is needed; they make diagnosis far easier (as suggested).

Recommended Answers

All 3 Replies

uh, you prolly have to install it first. if its installed look for it in the start menu. There are lots of av and anti spware software out there. if you need assistance you gota let us know what you have. if its installed its on the start menu some where. try under "all programs" or "program files"
if you can't find it on the start menu, chances are you dont have any.

oh it's there alright Binary, but each time the machine is booted, the AV and the firewall are set to disabled, even though I have enabled them. It is a common result of infection, like when the system folder disappears, and I ought to know how to fix it - must be an attribute or a reg setting I suppose, but I just can't bring it to mind. Must be getting old... :)

well, if you have spyware and the like still on the machine you need to remove it before you can enable thse things. spyware and virues target these items and turn them off. most of em watch for changes in the program status and turn them off as you try to turn them backon so that wont work.

you will need th following tools:
hijackthis:
winpfind: http://www.bleepingcomputer.com/files/winpfind.php
adware: &tag=top5
spybot: http://www.safer-networking.org/en/mirrors/index.html
process exploer:
rootkit revealer:
nod32:

__online virus scanner __
http://www.pandasoftware.com/activescan/activescan/ascan_2.asp

I would like to see the Hijack this logs and winpfind logs. since were dealing with virus and spyware you will need to post these logs in virus spyware and other nasties forum.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.