Tweaking.com Support Forums

Main Forum => General Computer Support => Topic started by: zellett12 on August 29, 2014, 09:47:16 am

Title: BFE won't start - SOLVED
Post by: zellett12 on August 29, 2014, 09:47:16 am
New Dell laptop, running windows 8. AVG and firewall won't start, can't install any other type of virus protection. Determined that BFE wasn't on/working. Ran MBAM, tried system restore, tried windows all in one from this site, BFE still won't start. When I try to start BFE get a generic "windows can't start BFE on local computer, error 193". Need help!!

Update - noticed a couple of boxes unchecked by default in Windows All in One repair "reset file permissions -2" clicked that and ran repair again. Still unable to install firewall or AV, BFE still won't start. Any help/advice is much appreciated. Thanks!
Title: Re: BFE won't start
Post by: Boggin on August 29, 2014, 03:22:15 pm
Did MBAM find anything as they are typical symptoms of an infection.

Let's see if MSRT will find anything -

Open the Command Prompt as an administrator and enter mrt.exe /F:Y

This will force a Full scan and auto remove any infections - this can take a few hours to run.

When it's done, use this ESET Services Repair Tool to restart services normally disabled by an infection to see if that will get the Firewall and BFE services started again.

http://www.trishtech.com/2013/11/restore-missing-services-after-malware-infection/
Title: Re: BFE won't start
Post by: zellett12 on August 29, 2014, 03:41:29 pm
MBAM only detected 1 object but said wasn't malware. "PUP.optional,serviceprotect" something like that, can't remember exactly. It's my wife's computer, she knows even less than I do about computers so this could be an issue that has gone unnoticed for a while. I ran MBAM a few months ago on it and got a huge list of threats, figured removing them would address any issues they caused. Now I'm thinking it must've happened back then since system restore didn't work (oldest restore point was only a few weeks ago).

Running MSRT now. Will use the service repair tool when done and post an update.

Thanks so much for your help!
Title: Re: BFE won't start
Post by: Boggin on August 29, 2014, 03:49:43 pm
I'm subscribed to the thread so will pick up your update, but that  won't be until tomorrow now as it's 11.45pm here in the UK.

In that ESET link there's also a link to run the ESET Online Scanner, but wasn't sure with AVG disabled etc. whether that would be allowed to run.

It will also do a deep scan when the Advanced button is clicked and all of the boxes checked except the last one - something about Proxy I think.
Title: Re: BFE won't start
Post by: Shane on September 02, 2014, 04:48:05 pm
You do have an infection. My Windows Repair program puts back the registry keys for the bfe service and others, and if they go missing again afterwards then you know you have an infection that is deleting it.

Normally I would have you try combofix but they havent added support for 8 yet. I use to use the malwarebytes anti rootkit a LOT, and it would find a lot of things. But lately over the last couple of months it hasnt found crap on the infected machines I have ran it on. Combofix always did the trick, but I need to find something new to use in my toolbox. I dont know if it is just me or not but malwarebytes really seems to be slipping.

Shane
Title: Re: BFE won't start
Post by: zellett12 on September 02, 2014, 05:04:00 pm
Boggin, tried the full scan and ESET, still no BFE. So I lost it and pulled all my files off the laptop and set it back to factory settings, BFE is back on. All seems well.
Shane, I had done the basic MBAM scan, I will try the root kit to see if it finds anything just to feel a bit more secure.

Thanks for all your help!!
Title: Re: BFE won't start
Post by: Boggin on September 03, 2014, 01:03:12 am
I have the manual steps for that ESET services repair procedure which includes download links for BFE and the Firewall, but a factory reset is as good as a reformat/reinstall so you will now be virus free and if when a system is badly damaged following an infection, either usually is the best option.