Microsoft.Windows.SecurityCenter.Firewallbypass

Discussion in 'Malware Help (A Specialist Will Reply)' started by liveNlearn, Dec 3, 2008.

  1. liveNlearn

    liveNlearn Private E-2

    I've always thought that I was careful about surfing, what I looked at, where I went, etc. Unfortunately I clicked on a link and got my computer infected. I thought I had gotten rid of everything, but I did not. I came across your website with the information pertaining to the Microsoft.Windows.SecurityCenter.Firewallbypass (which was one of the problems that kept coming back after I had removed it with Spybot), so I proceeded to follow all the instructions on your forum to clean my computer. I was unable to download MGtools.exe. I ran everything up till that point and found I had alot more 'crap' on my computer than I realized. I do have two others that use my computer, and it would appear we are all guilty of getting 'crap on the computer. I have Antivirus protection and a firewall, but apparently I am still doing something wrong. Please assist me, I need to post my logs for someone to look at and to download the MGtools.exe.
     
  2. liveNlearn

    liveNlearn Private E-2

    Here are three of my logs. I will attach others soon. I appreciate your input and assistance. Thank you very much.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need the log from running the C:\MGTools.exe --> C:\MGLogs.zip
     
  4. liveNlearn

    liveNlearn Private E-2

    Sorry about that, here it is.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Actually you look good. The scans took care of the malware.

    Just use windows explorer to find and delete:
    C:\WINDOWS\SYSTEM32\ren34.tmp
    C:\WINDOWS\SYSTEM32\ren35.tmp

    Tell me if you are still having problems. :)
     
  6. liveNlearn

    liveNlearn Private E-2

    Thank you, Tim. Everything seems to be fine at this time. If you don't mind me asking, what where those two files you had me delete? Also, should I remove all the recent software I installed to clean up my computer? Is there one that I should keep? What would you recommend that I have installed to better protect myself? I know it takes more than software to protect yourself, but I would like some pointers on what is best, and what I need to be doing. After viewing my information do you have any advice or pointers? I'm also having trouble accessing the system Administrator account. Is that a question I should address the software team? I truly appreciate your time and assistance.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The files were just temp files that did not need to be in your system32 folder.

    This should answer your questions ..though the admin account issue can be pursued in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  8. liveNlearn

    liveNlearn Private E-2

    Thanks again, Tim. I really appreciate your time and assistance. :)
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...safe surfing. :)
     
  10. liveNlearn

    liveNlearn Private E-2

    Unfortunately, we encountered another Trojan. I am attaching logs for your review. I think the AVG caught it in a somewhat timely manner. I tried to completely disable the AVG while running the other scans but it would not completely disable. You assistance is greatly appreciated.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What did AVG "catch" ....( which is what it is supposed to do )?
     
  12. liveNlearn

    liveNlearn Private E-2

    RKHit.sys - a rootkit. Sorry I attached the wrong combofix log. AVG is my antivirus and alot of things seem to make it past it :(
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do a search to see if this still exists:
    c:\windows\system32\drivers\RKHit.sys

    If you find any instance of RKHit.sys --> delete it and let me know the exact path to it.

    Then go to start / run / typse 'services.msc" without quotes and see if it is listed. If so, click it and disable it. Again let me know.
     
  14. liveNlearn

    liveNlearn Private E-2

    The only place I located it at was under C:\Qoobox\Quaratine\C\WINDOWS\SYSTEM32\Drivers, I
    didn't locate it anywhere other than there.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good, that is where it should be. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  16. liveNlearn

    liveNlearn Private E-2

    What is tcpip.reg? It seems to keep showing up. Could you please take a look at these logs for me. I'd sincerely appreciate it. If there is anything you need, please let me know.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's not something to worry about. Just run the final steps.

    I apologize for the delay....my isp took a 4 day dump.
     
  18. liveNlearn

    liveNlearn Private E-2

    Thank you, Tim. I appreciate your assistance. :)
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing. :)
     
  20. liveNlearn

    liveNlearn Private E-2

    Tim,

    Recently, in the last few days, my computer had become extremely slow. I couldn’t load my windows updates, and had a hard time loading updates to SuperAntiSpyware and Malwarebytes’ Anti-Malware. I could see there were more processes running on my system than usual, all with similar names. I finally got the updates to load for the AntiSpyware and Anti-Malware applications. I ran all the scans, and I am attaching all of the log files. The ComboFix Log has a message that states, , “c:\windows\system32\appmgmts.dll ... is missing !!”, and a Trojan was detected by the SuperAntiSpyware. Please take a look at everything when you get a chance, and let me know what I need to do.

    Thank you,
    liveNlearn
     

    Attached Files:

  21. liveNlearn

    liveNlearn Private E-2

    Tim,

    Also, what are all of those files that ComboFix deleted. I was looking at the ComboFix Quarantine file and some of those files date back to June 2008. I guess I'm a bit confused because looking at the times I've posted logs here in the past, these things were never detected by previous scans.

    Leslie
     
  22. liveNlearn

    liveNlearn Private E-2

    I realize you are probably pretty busy. Somehow, while we have been waiting, some other strange things have been going on. I don't know if it's new, or part of the previous problem. Whatever is going on has completely blocked the SuperAntiSpyware application. It wouldn't open, or if it did, it would close immediately. I was contemplating on purchasing this application, but now I am quite leery. Which is better, the SuperAntiSpyware or the Malwarebytes' AntiMalware (as far as purchasing). Whatever is going on, has also been messing with my firewall settings. It was messing with the running of ComboFix, when I clicked on My Computer I couldn't see anything (none of the drives or folders) and I couldn't see anything in my Control Panel under Add/Remove Applications. I had to disconnect my network connection, and then was able to run ComboFix, and then I was able to access everything again. There are only certain web sites we frequent regularly, and very occasionally do we actually 'surf.' This is very frustrating. I am attaching new logs, there appears to be something new/different on the ComboFix log. What is PEV.exe, it appears to have shown up on 8/12/09. Also, I am attaching a Bug.txt, what is this? It apparently showed up last night when I was having problems with everything.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All the logs you attached are clean. The previous log for SAS shows the infection in the system restore folders...which would have gone away if you had followed my previous cleanup instructions and toggled system restore.

    You need to uninstall Black Ice!

    Then you need to go to start / run / and type:
    sfc /scannow

    Have your xp cd handy and run it twice.

    Pev.exe is part of ComboFIx.

    You are also allowing all users to have Admin. privileges! A very bad idea! You need to run SAS on each user account and only allow one to have Admin. privileges. As to MBAM, you may just have to uninstall it and download the latest version.

    Any other issue you have should be addressed in the software forum.
     
  24. liveNlearn

    liveNlearn Private E-2

    I honestly did that, I wouldn't just leave them there. I actually went through the whole process again, but thank you for your assistance.
     
    Last edited: Aug 19, 2009
  25. liveNlearn

    liveNlearn Private E-2

    I have always followed all of the steps you have given me. I wouldn't intentionally waste your time or mine. Those files were not located previously by any scans that I had done. I have posted between now and then, and those files were never in any logs that I attached, until this most recent time. Thank you for your time and assistance.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you run the sfc/scannow command? Did you uninstall Black Ice? What issues are you having?

    Have you done an online scan with either TrendMicro, Bitdefender or kasperski? Did they find anything?
     
  27. liveNlearn

    liveNlearn Private E-2

    I did everything you suggested, and I ran an online scan with Kaspersky. It didn't find anything. Everything seems to be running fine at this time.
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.....If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds