?
Solved

Base Filtering Engine and Windows Firewall Services Missing on Server 2008 R2

Posted on 2015-02-04
5
Medium Priority
?
722 Views
Last Modified: 2015-02-06
We are working on a Windows Server 2008 R2 machine, and found that the Windows Firewall and BFE services are missing in services.msc. We've tried the following to get them back:

- Ran sfc /scannow
- Checked the registry permissions as directed here. When we try to give permissions to the NT Service\BFE account, it says the account cannot be found.
- I found a tool called Tweaking.com Windows Repair that was recommended to fix this issue, but it appears to be for WIndows workstations rather than servers, so I don't know if that will fix this.
0
Comment
Question by:PIMSupport
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 44

Expert Comment

by:Darr247
ID: 40590218
Usually it's serious malware infections that do the kind of damage described... is this machine allowed to be used for general surfing access? With Internet Explorer?

Because if it is, I would recommend wiping it and restoring the backup image... that would be faster than trying to fix it. You're not even sure what all has been damaged; the lack of the base filtering engine stopping other services from starting is just the symptom you noticed first.

If you don't have a backup image, I suggest referring to this EE article to start.
i.e. run RogueKiller, and when it finishes its initial scan, minimize it without telling it to fix anything (during its initial scan it will kill any processes it thinks are virus-like, and which may prevent other cleaners from starting), then run a full scan with MalwareBytes AntiMalware (follow the 'how to use' directions on that page).
0
 
LVL 43

Accepted Solution

by:
Davis McCarn earned 2000 total points
ID: 40590873
From Tweaking.com:
"For Windows XP, 2003, Vista, 2008, 7, 8, 8.1, 2012 (32 & 64 Bit)"
http://www.tweaking.com/content/page/windows_repair_all_in_one.html

But; as Darr247 suggested, those services were almost undoubtedly deleted by malware and I use 3 tools to detect and remove:
http://www.bleepingcomputer.com/download/roguekiller/ (I let it scan and clean what it finds)
http://www.bleepingcomputer.com/download/tdsskiller/ (finds Trojans embedded in driver files)
http://www.bleepingcomputer.com/download/adwcleaner/  ( I haven't had to run this on a server yet; but, it has never yet hurt matters!)

Run all 3 of the tools and then an antivirus scan before running the repair tool.  You want it to be clean, first!
0
 
LVL 44

Expert Comment

by:Darr247
ID: 40591345
But within 2 weeks, you will very-likely find other stuff that was damaged, too... and those other damages typically provide vectors for re-infection without having to return to the site of the original infection.

If you don't have a backup image of a clean install, you should start working on a clean install on a secondary machine so you can make a backup image for the next time this or something similar happens.
0
 
LVL 43

Expert Comment

by:Davis McCarn
ID: 40591756
Darr247,
I have been servicing PC's for 38 years now and have seen in excess of 150,000 problems. The process I outlined cleans 95+% of the PC's I see on a regular basis and Tweaking.com's repair tool has rescued hundreds from otherwise irreparably damaged Windoze installations by restoring the defaults existant prior to the malware's infestation.
I, in fact, don't consider a "reinstall" to be fixing the PC and have only had to do 3 in the last three years.

P.S. You forgot to mention that the "clean install on a secondary machine" must be a hardware match for the target PC.
0
 
LVL 44

Expert Comment

by:Darr247
ID: 40593822
Yes, well any "production" server should have a 'hardware match' backup, AND a backup image.  Not to mention production servers should have severely limited user access to prevent precisely the type of problem with which this thread deals.  If it's not a production server, then I suggest they should have bought Home Server 2011, instead.
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question