Fix it now
Error 1058 is ERROR_SERVICE_DISABLED, published as the service not being startable because it is disabled or has no enabled devices associated with it. When it names an AVG service, your antivirus has not been running at boot. Check the startup type before anything else, then find out what set it.
sc query "<servicename>"
sc config "<servicename>" start= auto
sc start "<servicename>"
- Open
services.msc, find the AVG entries and read the Startup type column. Anything showing Disabled is your answer. - Set it to Automatic and start it. Note the space after the equals sign in
start= auto; without it the command fails. - If it will not start, open Event Viewer, then Windows Logs, then System, and read the Service Control Manager entries around boot time for a more specific reason.
- Use AVG’s own repair option from its settings, which resets its files and permissions.
- Restart and confirm the service is running and AVG reports protection as active.
Find out what disabled it. A tuning utility, a policy, a failed uninstall or malware are the realistic candidates, and if you do not find the cause the setting comes back.
If AVG starts on its own after a restart you can stop here. If not, the next section explains what each of the four codes is telling you.
Why it happens
All four of these are Windows system error codes with published text, which makes this one of the more tractable antivirus problems. 1058 is ERROR_SERVICE_DISABLED: the service cannot be started, either because it is disabled or because it has no enabled devices associated with it. That is unambiguous. Something set the start type, and that something is worth finding.
1053 is ERROR_SERVICE_REQUEST_TIMEOUT: the service did not respond to the start or control request in a timely fashion. Note that it covers control requests as well as start requests, so a service that hangs on a stop or a pause reports the same number. That points at something slow or blocked rather than at configuration.
1070 is ERROR_SERVICE_START_HANG: after starting, the service hung in a start-pending state. It is 1053’s near neighbour, one stage further along – the service was launched, told the Service Control Manager it was starting, and then stopped making progress. And error 5 is ERROR_ACCESS_DENIED, “Access is denied”, which on a service means either the account it runs under lost rights, or permissions on its files, registry keys or drivers were changed.
Access denied is the one that arrives on hardened machines. A security baseline or a permissions cleanup script that tightens the wrong tree will stop a security product starting just as effectively as it stops anything else, and tracing exactly which permission changed is usually slower than repairing or reinstalling the product to recreate them.
The start type was set to disabled
You have this one if services.msc shows the AVG service with Startup type Disabled.
- Open the service’s Properties, set Startup type to Automatic, and click Start.
- If the console will not allow it, run it elevated, or use
sc config "<servicename>" start= autofrom an elevated prompt. The space after the equals sign is required. - Start it with
sc start "<servicename>". - Restart and confirm it starts on its own.
The documented values for start= are boot, system, auto, demand, disabled and delayed-auto. Anything else is rejected.
Permissions on the service or its files were changed
You have this one if The access-denied code, often on a machine that has had a hardening baseline or a permissions cleanup applied.
- Check the service’s Log On tab and confirm it uses the account AVG installed it with.
- Run
sfc /scannowto repair damaged Windows files that may be involved. - Use AVG’s repair option, which resets its own file and registry permissions.
- If repair fails, remove with AVG Clear and reinstall, which recreates the service with correct permissions.
The service times out or hangs at boot
You have this one if The timeout or start-hang code, on a machine that is slow to start or has many services competing.
- Read the Service Control Manager entries in Event Viewer, then Windows Logs, then System, and note whether other services time out too.
- Reduce what starts at boot from Task Manager’s startup apps list.
- Check disk health; a failing drive makes everything time out at boot.
- If only AVG times out and the machine is otherwise healthy, repair or reinstall it.
The service start timeout can be extended through a registry value. That hides the symptom rather than fixing it, and on a security product it means protection starts later than everything else.
The service entry itself is damaged
You have this one if The service does not appear in services.msc at all, or appears with no description and refuses to start.
- Export
HKLM\SYSTEM\CurrentControlSet\Servicesbefore looking at anything. - Check whether the AVG service key exists and read its Start value: 2 is automatic, 3 manual, 4 disabled.
- Do not hand-build a missing service key. Remove AVG with AVG Clear in Safe Mode and reinstall so the installer recreates it.
- Restart and confirm the service is present and running.
A dependency or a driver failed to load
You have this one if The service reports that it depends on another which failed to start, or the machine logs driver failures at boot.
- Read the System log at boot time for driver and Service Control Manager errors.
- Confirm the Windows services AVG depends on are running, starting with Remote Procedure Call.
- If AVG’s kernel drivers are failing to load, repair or reinstall rather than trying to fix a driver by hand.
- Restart into Safe Mode, run AVG Clear, restart and reinstall from the full offline installer.
Full reference
The four codes, precisely
| Code | Constant | Published text |
|---|---|---|
1058 |
ERROR_SERVICE_DISABLED | The service cannot be started, either because it is disabled or because it has no enabled devices associated with it |
1053 |
ERROR_SERVICE_REQUEST_TIMEOUT | The service did not respond to the start or control request in a timely fashion |
1070 |
ERROR_SERVICE_START_HANG | After starting, the service hung in a start-pending state |
0x00000005 |
ERROR_ACCESS_DENIED | Access is denied |
Service commands and where to look
| Item | What it does |
|---|---|
services.msc |
Where service startup type and state are set |
sc query "<servicename>" |
Shows the current state of a service |
sc config "<servicename>" start= auto |
Sets a service to start automatically; the space after the equals sign is required |
sc config "<servicename>" start= delayed-auto |
Starts it automatically a short time after the other automatic services |
sc start "<servicename>" |
Starts a service immediately |
| Event Viewer, Windows Logs, System | Where the Service Control Manager records start failures and timeouts |
Get-MpComputerStatus |
Shows whether Microsoft Defender’s real-time protection is currently active |
What is protecting the machine meanwhile
Microsoft documents that Defender goes into Disabled mode automatically when a third-party antivirus registers, and that where it was disabled automatically it can be re-enabled automatically if that product expires, is uninstalled, or otherwise stops providing real-time protection. A disabled AVG service is exactly that last case, so in most cases Defender has already taken over.
Confirm rather than assume. Get-MpComputerStatus in an elevated PowerShell prompt shows whether real-time protection is on right now, and Windows Security, then Virus and threat protection, shows the same thing in a form you can put in front of a user. If neither says anything is scanning, turn Defender’s real-time protection on before you carry on troubleshooting.
Before you go near HKLM\SYSTEM\CurrentControlSet\Services, export the key or take a restore point. A wrong value under that tree can stop Windows booting, and a missing service key is a reason to reinstall the product rather than to build one by hand.
Finding what disabled it
- Check whether a system tuning or optimiser utility is installed. Disabling security services to “speed up boot” is a standard behaviour for that class of software.
- Check Group Policy and any management tool for a service configuration policy naming the product.
- Look at the Application and System logs around the date the service first failed to start.
- Consider malware seriously. Disabling security software is a common step in an infection, so once AVG is running again, run a full scan.
- If you have real doubt, scan with a second on-demand scanner from separate media rather than trusting the product that was switched off.
When to stop and reinstall
- The service key is missing entirely from the registry.
- The access-denied code persists after a repair.
- Setting the start type sticks until the next restart and then reverts, with no policy or utility to blame.
- The product’s drivers appear in the System log as failing to load.
- Two or more of the four codes appear across different restarts, which usually means the installation rather than the configuration is damaged.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
1058 |
ERROR_SERVICE_DISABLED: the service cannot be started, either because it is disabled or because it has no enabled devices associated with it | Microsoft Learn |
1053 |
ERROR_SERVICE_REQUEST_TIMEOUT: the service did not respond to the start or control request in a timely fashion | Microsoft Learn |
0x00000005 |
ERROR_ACCESS_DENIED: access is denied, to the service, its files or its registry keys | Microsoft Learn |
1070 |
ERROR_SERVICE_START_HANG: after starting, the service hung in a start-pending state | Microsoft Learn |
Confirm the fix worked
services.mscshows the AVG service Running with Startup type Automatic.- AVG reports all protection components as active.
- Restart and confirm the service starts without intervention.
- The System log shows no new Service Control Manager errors after that restart.
Get-MpComputerStatusreflects whichever product you intend to be protecting the machine.
Questions people ask about this
Is this because my AVG subscription ran out?
No. An expired subscription changes which features you get, not whether a Windows service is allowed to start. A disabled or access-denied service is a configuration or permissions problem and costs nothing to fix.
Something disabled my antivirus. Should I assume malware?
Consider it seriously. Disabling security software is a common step in an infection. Once AVG is running again, run a full scan, and if you have real doubt scan with a second on-demand scanner from separate media.
Why does sc config fail when I type it?
Almost always the space. Microsoft’s documented syntax requires a space between the option and its value – start= auto, not start=auto – and without it the operation fails.
Am I protected in the meantime?
Probably by Microsoft Defender. Microsoft documents that it re-enables itself automatically when a third-party product stops providing real-time protection, which is what a disabled service amounts to. Confirm with Get-MpComputerStatus rather than assuming.
Can I just reinstall straight away?
You can, and it often works. Checking the start type first takes half a minute and tells you whether something is switching it off, which a reinstall would not reveal – and that something would switch the new installation off too.
