Windows firewall does not stay on - what is SABKUTIL?

Discussion in 'Malware Help (A Specialist Will Reply)' started by JanetE, Sep 9, 2010.

  1. JanetE

    JanetE Private E-2

    I posted "XP SP3 had 177+ bugs - ran MG cleanup - issue with RootRepeal" on 8-21-10, 12:59 regarding my neighbor's infected computer.

    She has received one of those balloon pop-up messages in the tray once or twice since I cleaned her computer, about the Windows firewall not being turned on, but when she went to check the Windows firewall it was on so we crossed our fingers and just kept watching it.

    Now, however, I am really not sure if she is finally free of infections because when we opened Outlook Express and double-clicked on an email with jpg photo attachment sent from a cell phone, we got the same old message about the Windows firewall not being on. But this time when we checked, it was true: the firewall was in fact not on. (We turned it on.)

    The computer has also continued to be very slow, although simple age could adequately explain that. So I don't know how worried to be.

    Today I updated and ran Spybot Search & Destroy in safe mode with networking. It found nothing. She herself updates and runs Super Antispyware and Malwarebytes every day; and yesterday she ran both in safe mode. Also found nothing. (She also runs CCleaner and ATF Cleaner, has a current version of Norton running, and I have Spyware Blaster running there too.)

    I poked around the Event Viewer. Maybe I didn't look in the right place, but I saw no reference to Windows firewall stopping on its own.

    I did see a couple of errors there that keep recurring. One said "The Epson Printer Status Agent2 service failed to start due to the following error: The system cannot find the file specified." This was an old printer that no longer exists and I had tried to uninstall everything associated with it. I figured this was something I missed. So I disabled it from the Event Viewer. Hope that was right?

    A similar-sounding error in Event Viewer referred to SABKUTIL. I ran out of time to work on my neighbor's computer, so tried to research this on my own computer after I came home and am not sure what to make of it. Makes me nervous.

    I also tried to install the FileHippo update checker for her. The app apparently installed OK, but would not run. It said I would need to install V2.0.50727 or V4.0 of .NET Framework first. I have not had time to figure out how to do that yet.

    Questions:

    Maybe we need to contact her ISP (Verizon) to find out if they have any software firewall running that would somehow interfere with the Windows firewall?

    And/or I could install a better firewall like Comodo(?) and then be sure to disable the Windows firewall.

    Or could there be a persistent infection, and do you think I need to start over with the whole MajorGeeks cleanup again?

    Thank you, thank you, thank you in advance!

    Janet
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does she use SUPER Ad Blocker? That's what it relates to.

    You could run our procedures.

    Ideally, especially using XP, there should be a third party firewall installed, yes.

    I would rather you do that, yes, then I can review the logs and check for malware's presence.
     
  3. JanetE

    JanetE Private E-2

    Kestrel13! thank you.

    I do appreciate your kind attention to my logs, attached. I was unable to run RootRepeal in either normal or safe mode (hangs on initialization).

    Before running your procedures I installed the Comodo free firewall and used it to block a few things that I was not sure of, including that Epson Printer service. I have not seen where it has hurt the running of the computer, and it might in fact have helped. It seems faster.

    Re: SABKUTIL - since my last post I noticed that SuperAntiSpyware's publisher is SuperAdBlocker.com (which I do not remember ever seeing before, though maybe I wasn't looking); and yes, she does run SuperAntiSpyware on this computer. I uninstalled and reinstalled it to be sure what I was dealing with.

    Awaiting your response with much gratitude,
    Janet
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Comodo internet security is installed so there is no need to have windows own firewall turned on because comodo will include one in it's suite. However you also have this installed!

    • Norton AntiVirus

    You should decide whether you want to keep Norton or Comodo

    What is this quotes folder all about?

    Anything to do with this?

    Now MGTools did not run to completion, so this time (AFTER uninstalling either norton or comodo) double click the C:\MGTools.exe and this time round when you are prompted to agree to the Trend Micro Hijack this license you need to click agree or accept twice, it's a bug.

    Let MGTools run all the way to completion until you see hit any key to continue.

    Then attach the new C:\Mglogs.zip into your next reply.
     
  5. JanetE

    JanetE Private E-2

    Thank you so much for the help, Kestrel13!

    I didn't think I had Windows' own firewall on. The computer, in Security Center, was telling me that it was turned off. Are my logs telling you different? Because this is where I came in, with the Windows firewall being mysteriously turned on and off.

    The reason I thought I could have both Norton and Comodo running was because the Norton that is running is only an antivirus, and the Comodo is only a firewall. I tried to deselect the antivirus when installing Comodo. Did my logs show you two antiviruses and/or two firewalls running at the same time?

    I don't yet know whether the computer's owner had been receiving a Quote of the Day; I'm waiting for a response from her. But I know she would want to kill anything dangerous, so meanwhile I deselected 'Simple TCP/IP Services' in the Windows Components and rebooted.

    Before rerunning MGTools I did uninstall the Comodo anyway (can always reinstall, or revert to Windows firewall).

    I ran MGTools in normal mode but with no internet connectivity (physically disconnected). Hope this did not interfere, because it never did give me a prompt for the HijackThis license, not yesterday and not today. Today it ran and created a new MGlogs.zip with timestamp 9/11/2010 12:26 PM in the C: drive which I am attaching.

    Previously (see "XP SP3 had 177+ bugs - ran MG cleanup - issue with RootRepeal" 8-21-10, 12:59) when I tried to uninstall HijackThis I wound up with some files that had to be removed manually, possibly because I had renamed the executable and then renamed it back. TimW said I could just go ahead and delete the leftover TrendMicro folder and its backup contents, which I did. Could the way I uninstalled HijackThis be an issue?

    I await your instructions!

    thanks much,
    Janet
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, then you can reinstall the firewall. Do let me know about the "Quotes" folder when your friend gets back to you regarding it.

    I don't know why your logs are incomplete but I am not seeing any malware in your logs. Run the C:\MGTools\analyse.exe do a system scan and save a log file. Attach it to your next post.
     
  7. JanetE

    JanetE Private E-2

    Thanks Kestrel13!

    Firewall:
    I reinstalled the Comodo firewall. I found that the software package I used earlier was not the MG recommended download. MG's choice contained just the firewall; it has no antivirus to be careful not to install. So I downloaded yours this time (installer name has cfw in it, instead of cis). Good catch, thank you. It's less confusing now. Yes, I turned Windows firewall off.

    Comodo crashed on me once tonight while the computer was rebooting; it said it had to close. I restarted again and it seemed okay. The same thing happened once yesterday, first the crash and then okay when I restarted. Crossing my fingers that it will work better than the Windows firewall!

    Quotes:
    My friend says she knows nothing about these quotes. In her email she receives "Daily Quotes" but that's in Outlook Express; it shouldn't have anything to do with a TCP/IP service.

    Yesterday I ran searches for file names containing 'quotes' and found these two, including the one you questioned:
    C:\WINDOWS\SYSTEM32\DRIVERS\ETC\quotes
    C:\I386\QUOTES._
    Both files' properties show that they were last modified 8/29/2002 7:00 AM.

    Today CCleaner picked up an unused file extension '._' (dot underscore, same as the file I had found in the I386 folder above). I only ran a scan for Registry issues just to see, but without fixing them yet, as I didn't want to destroy any evidence.

    HijackThis:
    Trying to run analyse.exe I got Error #75 - Path/File access error. It said my system had denied access to the Hosts file and gave a workaround involving a manual edit. I did not edit the Hosts file yet, preferring to hear from you if I should do that. I was able to run analyse.exe in safe mode. I'm attaching both versions of the log. I guess I will attach the full text of the error message too, though you probably know it by heart.

    Other:
    Before reinstalling the Comodo firewall today I again had issues with Windows firewall being turned off. Once it got turned back on again spontaneously, another time I had to turn it back on manually, but in the process of this when I went to Windows Security Center I got a message that "Due to an unidentified problem, Windows cannot display Windows Firewall settings." The computer, fortunately, was physically disconnected from the Internet this whole time.

    Prior to this I had been in User Account Control changing settings. In the end I put things back the way they had been, but I fooled around with creating a new Administrator account with a password. I was then going to change the user account she's been using to a restricted account. I backed off when I saw that I was going to wipe out whatever passwords might be stored with the account. Instead I deleted the new Administrator account I had just created. Then I tried turning on the Guest account, thinking maybe she could just use that when she has no Admin to do. But I think it was after that I had issues with the firewall turning off. I turned the Guest account back off again. Did something try to take advantage of the Guest account, I wonder?

    By the way, I changed the User Account name today from "Bob & Gin" to "Bob and Gin" because I saw in some of the logs that the special character was causing some kind of truncation. The program was apparently expecting a command to follow the ampersand and didn't find it. I wonder if this could have been responsible for the issues I was having with the MGTools not running to completion? (Or the RootRepeal hanging?)

    One last worry:
    Going back through my notes I see where I found a shortcut in My Documents\My Music.
    The shortcut was named Sample Music, but its properties told me it was pointing to C:\Documents and Settings\All Users\Application Data.
    I deleted the shortcut.
    Then I uninstalled Picasa because I found the executable in a strange place, not with the other programs. It was in c:\Documents and Settings\BOB & GIN D[rest of user name]\Picasa2.
    After that I found a folder on the desktop, created that day, 9/9/10, named %SystemDrive%. It contained a series of nested folders:
    Documents and Settings
    BOB & GIN D[rest of user name]
    Application Data
    Microsoft
    System Certificates
    My
    Certificates
    CRLs
    CTLs
    These last 3 were all in the folder named 'My' and all were empty. I put that whole %SystemDrive% folder in the recycle bin too.

    This was all just before I opened the new thread for help on MajorGeeks. It didn't seem at the time like it was relevant, but boy could I be wrong, so I offer it belatedly with many apologies if I've blindsided you.

    Sorry, I tried to write shorter but couldn't.

    Once again, thank you so much.
    Janet
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's looking like you mayt have to visit the software forum for some issues, let's do this though:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\WINDOWS\SYSTEM32\DRIVERS\ETC\quotes
    C:\I386\QUOTES._
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. JanetE

    JanetE Private E-2

    Kestrel13!, no luck here.

    I created the CFscript.txt using code provided; shut down antivirus/antispyware and firewall; exited all browsers; dragged CFscript.txt onto ComboFix.exe. It started to run but the computer stopped a couple times to ask me whether I wanted to allow it to run or not. It also asked how I wanted to run it, as which user. I accepted the selection of the current user, Bob and Gin D[rest of user name], and unchecked an item on the line below that in the same dialog box (something about disallowing certain functions; in other words I allowed everything).

    The result was a message: Installation failed.

    Should I have tried to run it in safe mode? I have done nothing so far, just turned the antivirus and firewall back on and disconnected cable from Internet while I wait for new instructions.

    Also I did not proceed to run MGtools. Wasn't sure if I should or shouldn't.

    I hope I didn't do anything wrong by placing a line return at the end of the last line of code in the CFscript.txt (to bring the cursor to the next, empty, line).

    Please advise!

    thanks much,
    Janet
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What malware issues are you having?
     
  11. JanetE

    JanetE Private E-2

    Hello TimW,

    Thanks for taking a look!

    The issue up to yesterday has been that the Windows firewall keeps getting mysteriously turned off. I've stamped out over 175 infections on this machine, but am still nervous with not being able to keep the firewall on. Last night I installed a Comodo firewall and turned off the Windows firewall. So far so good with Comodo, but it's too early to really tell.

    I think my other issue is not malware, it's operator error. Today I tried and failed to run ComboFix according to Kestrel13!'s instructions (to go after those two files with 'quotes' in the name). I thought I had stopped Comodo before running ComboFix, but apparently not because I see a lot of executables blocked in Comodo, all seeming to be parts of ComboFix. So probably my fault. Please let me know if I should try again.

    My third problem might be software, not malware. Earlier I could not get MGtools to run to completion, and yesterday analyse.exe would not run correctly. I think I saw a reference somewhere to having to have the right .NET Framework software installed for these to run correctly. I wonder if installing a newer version would help. This machine is not even up to v2.0.

    Hope I've answered the question. Thanks so much for the assist.
    Janet
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Comodo should have taken care of your firewall issues.

    You can download net framework HERE.

    We could try removing those files with Avenger, but I don't think they are an issue. You should be able to just right click them and choose delete.

    Any other issues should probably be addressed in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  13. JanetE

    JanetE Private E-2

    Weelll, I hate to stick my neck out but I have to say right now she's running real sweet, just like a good little computer should. We'll see what tomorrow brings.

    Everything is working per your projections, TimW (gotta love that Comodo firewall), and I am deeply indebted to you and to Kestrel13! for your kind attentions.

    Side note: I've been pondering whether to reinstall my friend's Picasa for her (in the right place this time), and was delighted to find a most useful entry in the Software forum that might allow me to do it: "Picasa + web browser = unusable system (hijackthis log attached)." I thanked scwtech for the artful workaround posted there. Thank you also, TimW, for pointing me in the direction of the Software forum!

    cheers,
    Janet :)
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds