Forefront Client Security Malware Technology and Response ForumDiscussions and questions on the malware/signature response process© 2009 Microsoft Corporation. All rights reserved.Thu, 26 Nov 2009 02:20:10 Zb2e00868-23e1-4fbe-8b13-77f319fbdb14http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/61203670-1571-43cf-8d23-64c32069ebf2http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/61203670-1571-43cf-8d23-64c32069ebf2SergioTorreshttp://social.technet.microsoft.com/Profile/en-US/?user=SergioTorresMSFCS Not detecting malwareI installed MSFCS with <span style="font-family:Calibri;font-size:small">clientsetup /nomom option in a remote windows 2003 server (leased from GoDaddy).<br/><br/>I have received 13 emails in the last 3 days with a zip attachment asking the receipient to install a file that exists inside the attachment.<br/><br/>MSFCS does not detect any threats in those emails (Real Tiime Protection is on).<br/><br/>If I run a manual scan, the result is the same: No threats.<br/><br/>I decided to send a sample to Microsoft Malware Protection Center.<br/>They answered:<br/><br/>If you were to scan the files you submitted using Microsoft's Forefront Client Security product, you would      see relevant detection information similar to what is displayed below.<br/>The detection results for the file(s) in your submission are as follows:<br/>Submitted Files<br/>=============================================<br/>B0001714884-nws1.msg [Trojan:Win32/Oficla.E]<br/>+---(part0002_module.zip) [Trojan:Win32/Oficla.E]<br/>+---utility.ex_ [Trojan:Win32/Oficla.E]<br/><br/>I checked my MSFCS setup and everything seems to be ok. <br/>     Real time protection is on. <br/>     Antivirus definition version is 1.71.26.0<br/>     Check for updated definitions before scanning is checked.<br/>     Scan the contents of archived files and folder for potential threats is checked.<br/>I checked and both the Antimalware and State Assesment services are running.<br/><br/>The emails are being filtered by my mail server as spam, so I have access to the original files.<br/><br/>The messages are in files with the .msg extention.<br/><br/>I copied them to a new folder and ran a manual scan again. MSFCS says there is no threat in any of the 13 files.<br/><br/>As you can imagine, this is worrying me, a lot.<br/><br/>Any ideas about what can be the problem?<br/><br/>Thanks,</span>Thu, 19 Nov 2009 16:57:08 Z2009-11-21T00:15:56Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/7425a003-c08a-4b31-8891-58c278f28473http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/7425a003-c08a-4b31-8891-58c278f28473gavigahttp://social.technet.microsoft.com/Profile/en-US/?user=gavigamsmpeng.exe causing bad builds for isdev.exe (InstallShield)My company recently replaced MacAfee AV with MS Forefront.  Since that moment, whenever I try to build an install in InstallShield (using v7 or 2010), the resulting install gets corrupted so that when it runs it produces a -5006 error.  If I add isdev.exe to the “Do not scan files accessed by these processes:” option or kill the antimalware component msmpeng.exe, the install builds and runs fine.  It does <span style="text-decoration:underline">not</span> help if I use the “Do not scan these files or locations:” option as the antimalware component seems to ignore this option.  Has anyone else experienced this issue?  Is there any possibility that MS will change the antimalware component so that this will not occur? <div><br/></div> <div>Thanks - Gary Gavin</div>Wed, 18 Nov 2009 14:58:32 Z2009-11-26T02:20:10Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/b6178d3b-c365-4005-bdba-b1a82432e718http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/b6178d3b-c365-4005-bdba-b1a82432e718andreasjanhttp://social.technet.microsoft.com/Profile/en-US/?user=andreasjanFCS slow removal?<span style="font-family:'Times New Roman';font-size:23px"> <div style="color:#000000;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:67%;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Hi,</div> <div style="color:#000000;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:67%;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">We have FCS deployed in our network and recently we found a virus conficker. From the FCS log I can find that it took about 11-12 minutes for the FCS to take action:Remove. Please refer to the log below (in the log you can find 2 domain users, meaning on 2 different computers). </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">We wonder why it took a while for the FCS to take Remove action and it did not immediately take Remove action once it detects the virus. Kindly advise. Thank you.</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Regards,</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Januar</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">10/27/2009 10:39:55 PM 3005  Microsoft Forefront Client Security Real-Time Protection agent has taken action to protect this machine </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">from spyware or other potentially unwanted software.</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">For more information please see the following:</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">http://go.microsoft.com/fwlink/?linkid=37020&amp;name=Worm:Win32/Conficker.B&amp;threatid=2147618124</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Scan ID: {76D6031E-8FAE-40F2-89C1-F5396A93205E}</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">User: Domain-name\domain-user1</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Name: Worm:Win32/Conficker.B</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">ID: 2147618124</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Severity: Severe</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Category: Worm</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Alert Type: Spyware or other potentially unwanted software</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Action: Remove  </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">10/27/2009 10:39:50 PM 3005  Microsoft Forefront Client Security Real-Time Protection agent has taken action to protect this machine </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">from spyware or other potentially unwanted software.</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">For more information please see the following:</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">http://go.microsoft.com/fwlink/?linkid=37020&amp;name=Worm:Win32/Conficker.B&amp;threatid=2147618124</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Scan ID: {7762C745-71DB-45B2-A861-9AB93802F541}</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">User: Domain-name\domain-user2</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Name: Worm:Win32/Conficker.B</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">ID: 2147618124</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Severity: Severe</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Category: Worm</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Alert Type: Spyware or other potentially unwanted software</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Action: Remove  </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">10/27/2009 10:27:47 PM 3004  Microsoft Forefront Client Security Real-Time Protection agent has detected changes. Microsoft </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">recommends you analyze the software that made these changes for potential risks. You can use information about how these programs </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">software publisher. Microsoft Forefront Client Security can't undo changes that you allow.</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">For more information please see the following:</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">http://go.microsoft.com/fwlink/?linkid=37020&amp;name=Worm:Win32/Conficker.B&amp;threatid=2147618124</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Scan ID: {5EBC84F0-DD38-41AA-BA83-B9E4C9EEDC19}</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Agent: Application Registration</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">User: Domain-name\domain-user1</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Name: Worm:Win32/Conficker.B</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">ID: 2147618124</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Severity: Severe</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Category: Worm</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Path Found: file:C:\WINNT\tasks\At1.job;file:C:\WINNT\system32\uhcguem.sf;taskscheduler:C:\WINNT\tasks\At1.job</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Alert Type: Spyware or other potentially unwanted software</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Process Name: </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Detection Type: Concrete</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Status:  </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">10/27/2009 10:27:39 PM 3004  Microsoft Forefront Client Security Real-Time Protection agent has detected changes. Microsoft </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">recommends you analyze the software that made these changes for potential risks. You can use information about how these programs </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">software publisher. Microsoft Forefront Client Security can't undo changes that you allow.</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">For more information please see the following:</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">http://go.microsoft.com/fwlink/?linkid=37020&amp;name=Worm:Win32/Conficker.B&amp;threatid=2147618124</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Scan ID: {2D8E3473-C5DA-46D2-8C87-63E14B8F2EAB}</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Agent: Application Registration</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">User: Domain-name\domain-user2</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Name: Worm:Win32/Conficker.B</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">ID: 2147618124</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Severity: Severe</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Category: Worm</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Path Found: file:C:\WINNT\tasks\At1.job;file:C:\WINNT\system32\uhcguem.sf;taskscheduler:C:\WINNT\tasks\At1.job</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Alert Type: Spyware or other potentially unwanted software</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Process Name: </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Detection Type: Concrete</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Status:  </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">10/27/2009 10:26:48 PM 3004  Microsoft Forefront Client Security Real-Time Protection agent has detected changes. Microsoft </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">recommends you analyze the software that made these changes for potential risks. You can use information about how these programs </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"><br/></div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">software publisher. Microsoft Forefront Client Security can't undo changes that you allow.</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">For more information please see the following:</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">http://go.microsoft.com/fwlink/?linkid=37020&amp;name=Worm:Win32/Conficker.B&amp;threatid=2147618124</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Scan ID: {204EC5C2-0BBF-415B-95F2-251383DAD752}</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Agent: On Access</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">User: NT AUTHORITY\SYSTEM</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Name: Worm:Win32/Conficker.B</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">ID: 2147618124</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Severity: Severe</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Category: Worm</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Path Found: file:C:\WINNT\system32\uhcguem.sf</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Alert Type: </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Process Name: </div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Detection Type: Concrete</div> <div style="background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px">Status: Suspend  </div> <div><span style="font-size:12px"><br/></span></div> </div> </span>Mon, 02 Nov 2009 05:57:28 Z2009-11-17T18:21:55Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/fa6d09bd-68e3-4368-a4ea-3d74d5942676http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/fa6d09bd-68e3-4368-a4ea-3d74d5942676RojALhttp://social.technet.microsoft.com/Profile/en-US/?user=RojALAntivirus System PRO Infection could not be removed by MSFF clientMy computer got infected by Antivirus system PRO which every few minutes pushed porno pages on to the screen.  I ran Microsoft forefront client security program installed on the laptop and it just showed my system is working fine.  I had to google to find out how to manually remove the infected software and had to remove it the hard way. Does it mean that MSForefront is not good enough?Sat, 07 Nov 2009 03:06:05 Z2009-11-16T18:26:35Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/31f98374-ae94-40e5-ab34-cf9a72b8690ahttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/31f98374-ae94-40e5-ab34-cf9a72b8690ailhan1980http://social.technet.microsoft.com/Profile/en-US/?user=ilhan1980error code 0x80070643i can t install microsoft security essentials error code 0x80070643Thu, 12 Nov 2009 06:26:02 Z2009-11-19T08:35:31Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/cb55d01d-4055-4405-ad39-a08ed4eb882fhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/cb55d01d-4055-4405-ad39-a08ed4eb882fparamatihttp://social.technet.microsoft.com/Profile/en-US/?user=paramatiis it a virus or malware?hey guys hope you all ok. am kindly asking, is &quot;desktop .ini&quot; a virus or malware? its been on my pc for ages. i have tried to remove it but it still comes back. my pc is advent 5712 and the anti virus that i have is avg. kindly help please and thanks in advanceFri, 06 Nov 2009 10:24:15 Z2009-11-13T07:28:21Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/3cb48972-b7f4-485a-9959-c8b66fe8a078http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/3cb48972-b7f4-485a-9959-c8b66fe8a078A b d a l l Ahttp://social.technet.microsoft.com/Profile/en-US/?user=A%20b%20d%20a%20l%20l%20Awhy those options not included at FCS<p class=MsoNormal style="margin:0in 0in 10pt"><span style="font-size:small;font-family:Times New Roman"> </span><span style="font-size:8pt;color:black;line-height:115%;font-family:'Verdana','sans-serif'">i wonder if can i confute FCS to take action as <br/>if detect Virus/spyware so First action to <strong>clean</strong> then <strong>delete/</strong><span style="font-size:8pt;color:black;line-height:115%;font-family:'Verdana','sans-serif'"><strong>quarantine</strong> <br/></span><br/>i don't need <strong>manual interaction response</strong> when malware detected <br/>i need FCS to automatically clean any Infected files <br/>why user must right click and chick <em>smart clean</em> or apply Action <br/><br/>any AV have this option, did MS not trust itself and need client to take action or FCS are not good enough to know Malware from false positive <br/>where is shell integration<span style="font-size:8pt;color:black;line-height:115%;font-family:'Verdana','sans-serif'"> and why when we ask about any AV option MS say at FCS v2, <br/>MS should make a <strong>hot fixes</strong> for this or it will lose market because customer will not wait until their environment be infected.</span></span></p> <p class=MsoNormal style="margin:0in 0in 10pt"><strong>waiting ur answer badly<br/></strong></p>Sat, 28 Mar 2009 12:16:49 Z2009-11-04T01:45:51Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/f4cf1ae5-35e3-43d8-8b53-affe27ac1e16http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/f4cf1ae5-35e3-43d8-8b53-affe27ac1e16Sysgenhttp://social.technet.microsoft.com/Profile/en-US/?user=SysgenTrojanDropper:Win32/Ilomo.CAnyone have a problem with this one? It keeps coming back again and again and again, well you get the idea. <br /><br />And from the same list of computers. It reports it as Successfully Responded and then a couple of days later it will come back with the same message. <br /><br />Then I get this <br /><br /><span lang="EN"> <p>Source:&nbsp; Microsoft Forefront Client Security Threat ID = 2147621724<br />Name:&nbsp; <strong>Re-Infected Computer</strong> (Alert Level 5)<br />Description:&nbsp; Client Security has detected that the computer has been infected several times by the following threat:<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; - Threat name: TrojanDropper:Win32/Ilomo.C<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; - Window start time: 10/12/2009 12:10:00 PM<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; - Window end time: 10/15/2009 12:10:00 PM<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; - Reported infection instances: 4<br /><br />This happens on computers that are doing nothing!! We have a computer that is used for scanning only and one day I received this same alert from this computer and no one was using it ??<br /><br />Here are the details of the event <br /><br />Microsoft Forefront Client Security Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Microsoft Forefront Client Security can't undo changes that you allow.<br />For more information please see the following:<br /><a href="http://go.microsoft.com/fwlink/?linkid=37020&amp;name=TrojanDropper:Win32/Ilomo.C&amp;threatid=2147621724">http://go.microsoft.com/fwlink/?linkid=37020&amp;name=TrojanDropper:Win32/Ilomo.C&amp;threatid=2147621724</a><br />Scan ID: {ADC00520-598E-4BD5-AC81-2D4084B63624}<br />Agent: On Access<br />User: NT AUTHORITY\SYSTEM<br />Name: TrojanDropper:Win32/Ilomo.C<br />ID: 2147621724<br />Severity: Severe<br />Category: Trojan Dropper<br />Path Found: file:C:\WINDOWS\system32\2.exe<br />Alert Type: <br />Process Name: <br />Detection Type: Concrete<br />Status: Suspend <br /><br />How could I track how it's getting in?<br /><br />Thanks</p> </span>Fri, 16 Oct 2009 15:01:25 Z2009-10-27T19:56:27Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/27f9551b-18a6-4309-bff7-21ecfdc87638http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/27f9551b-18a6-4309-bff7-21ecfdc87638ParrotHeadhttp://social.technet.microsoft.com/Profile/en-US/?user=ParrotHead"Windows PC Defender" Malware Not Detected<p class=MsoPlainText style="margin:0in 0in 0pt"><span style="font-size:small"><span style="font-family:Consolas">I have a user who has managed to get infected with the Windows PC Defender malware.</span></span></p> <p class=MsoPlainText style="margin:0in 0in 0pt"><span style="font-family:Consolas;font-size:small"> </span></p> <p class=MsoPlainText style="margin:0in 0in 0pt"><span style="font-size:small"><span style="font-family:Consolas">She's running as a standard user, so I'm assuming the damage will be minimal. However, her machine is running the latest version of FCS with the latest definitions.</span></span></p> <p class=MsoPlainText style="margin:0in 0in 0pt"><span style="font-family:Consolas;font-size:small"> </span></p> <p class=MsoPlainText style="margin:0in 0in 0pt"><span style="font-size:small"><span style="font-family:Consolas">How is it that FCS allowed this software to install? And why, when I run a full scan of the system, is no malware detected?</span></span></p>Mon, 21 Sep 2009 14:19:15 Z2009-10-24T11:24:15Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/fbe998b2-c1c3-4fbc-900a-0fdd45300d41http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/fbe998b2-c1c3-4fbc-900a-0fdd45300d41JoniB2009http://social.technet.microsoft.com/Profile/en-US/?user=JoniB2009I received a message from Skype saying that I had a serious issue that needed immediate attention<p>Here is the message that I received &quot;Impact of Vulnerability: Remote Code Execution / Virus Infection /<br/>Unexpected shutdowns&quot;    <br/><br/>It told me to download a file immediately? <br/><br/>[4:47:12 PM] Scan Alert says: WINDOWS REQUIRES IMMEDIATE ATTENTION<br/>=============================</p> <p>ATTENTION ! Security Center has detected<br/>malware on your computer !</p> <p>Affected Software:</p> <p>Microsoft Windows Vista<br/>Microsoft Windows XP<br/>Microsoft Windows 2000<br/>Microsoft Windows Server 2003</p> <p>Impact of Vulnerability: Remote Code Execution / Virus Infection /<br/>Unexpected shutdowns</p> <p>Recommendation: Users running vulnerable version should install a repair utility immediately</p> <p>Your system IS affected, download the patch from the address below !<br/>Failure to do so may result in severe computer malfunction.</p> <p><a href="http://www.securityreg.org/">http://www.securityreg.org/</a></p> <p>For the link to become active, please click on 'Add to contacts' skype button or type it in manually into your web browser !</p> <p> </p> <p>Please let me know what I should do and if I should get off of my computer immediately?  I am very worried!!! </p>Fri, 10 Jul 2009 22:11:12 Z2009-10-19T21:42:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/e58fbf3f-ab11-412b-a68f-a5b4cc543d10http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/e58fbf3f-ab11-412b-a68f-a5b4cc543d10Ron_ghttp://social.technet.microsoft.com/Profile/en-US/?user=Ron_gWorm:Win32/Conficker.B virus<p>Hi All,</p> <p>I have <a style="cursor:pointer;color:#3264c8" tabindex=10>Worm:Win32/Conficker.B</a> virus in my network, I have WSUS 3.0 deploy defintion+security+critial updates to all my clients and FCS managed by Forefront Managment Console.</p> <p>I deployed Microsoft Removal Malicious Software Removal Tool last version to all my client via GPO.</p> <p>The worm keep showing at clients that already removed the worm. The clients are fully update, AntiVirus-AntiSpyware definition - 1.49.2577.</p> <p>How to remove the worm completely from my network?</p> <p> </p> <p>Thanks.</p>Tue, 27 Jan 2009 14:06:12 Z2009-09-30T10:12:15Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/90542a52-226f-47d5-9968-d2a3c16d450fhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/90542a52-226f-47d5-9968-d2a3c16d450fchuckster45http://social.technet.microsoft.com/Profile/en-US/?user=chuckster45softsafeness virussoftsafeness has invaded mywindows security center on my vista computer can't remove it. can anyone give me some help.Mon, 14 Sep 2009 20:40:01 Z2009-09-22T02:14:57Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/d6f49f2f-773d-457d-bc91-785428d1e4a2http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/d6f49f2f-773d-457d-bc91-785428d1e4a2MGMNVAhttp://social.technet.microsoft.com/Profile/en-US/?user=MGMNVAConficker.B - Where to find threat Source?<p> How do I determine the threat source that is attacking other computers? McAfee will report the &quot;threat source&quot;, which makes dealing with an issue much easier. I have not been able to find the &quot;threat source&quot; data in Forefront. Can anyone shed some light on where to find the &quot;threat source&quot; data in Forefront. <br/><br/> As you all probably know, this is critical information for fighting outbreaks.</p>Thu, 30 Jul 2009 18:15:06 Z2009-09-03T16:10:54Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/13664500-8cc6-4e9e-a3ed-e358c51e0cf4http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/13664500-8cc6-4e9e-a3ed-e358c51e0cf4fishohttp://social.technet.microsoft.com/Profile/en-US/?user=fishofirst windows installer pops up then microsoft.net framework then they stay in middle of framestop shoving updates i don,t want doun my throatMon, 31 Aug 2009 04:06:15 Z2009-09-08T06:25:04Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/3cc6cf3d-f35d-4684-8e89-fc7d252a8f83http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/3cc6cf3d-f35d-4684-8e89-fc7d252a8f83lclaudiohttp://social.technet.microsoft.com/Profile/en-US/?user=lclaudioSupported topologies for FCS SP1Hello Team,<br/>I have a quick question.  In the product documentation, there are six supported configurations listed.  We have decided to go with a three server configuration with the management server on one server, the distribution server on a WSUS server, and the remaining roles and databases on a seperate SQL server.  Is this a supported configuration?<br/>LC-JWed, 26 Aug 2009 18:40:27 Z2009-09-01T04:56:28Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/8e27d414-179b-4b01-bac3-af3c6bf1347fhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/8e27d414-179b-4b01-bac3-af3c6bf1347fSandy Woodhttp://social.technet.microsoft.com/Profile/en-US/?user=Sandy%20WoodSeek App discovered on one system - not detected by FCSWe recently discovered a virus on one of our XP systems called Seek App. The filename on the system was seekapp149.exe and it was attached to IE. It appears to be the same as this <br/><br/><a href="http://www.threatexpert.com/report.aspx?md5=f74708da4f2d06c8114b1077f957dc68">http://www.threatexpert.com/report.aspx?md5=f74708da4f2d06c8114b1077f957dc68</a><br/><br/>Is there a way to add this one to the FCS defs?<hr class="sig">Orange County District AttorneyFri, 28 Aug 2009 17:56:33 Z2009-09-07T02:22:12Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/0f285e26-4810-4a51-887f-9ffd99a9674ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/0f285e26-4810-4a51-887f-9ffd99a9674eAndrewm1972http://social.technet.microsoft.com/Profile/en-US/?user=Andrewm1972Red X will not go away!Good day!<br/><br/>Forefront Managed Systems<br/>Full Scans once a week.  No Quick Scans.<br/>No End User Access (locked down)<br/>Fully Managed by System Admin<br/>Virus detected- Icon turned from green check mark to Red X.<br/>Red X will not clear up.  Been about a week now.<br/><br/>Anything I can do besides editing the Policy and giving End Users access to Forefront settings?<br/>I was under the assumption this would automatically clear up (automatically Smart-Clean).<br/><br/><br/>Regards-<br/><br/>AndrewWed, 19 Aug 2009 21:12:09 Z2009-08-24T12:19:16Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/58e65125-4992-44d3-8a4f-a9cd709a3496http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/58e65125-4992-44d3-8a4f-a9cd709a3496troyswift5http://social.technet.microsoft.com/Profile/en-US/?user=troyswift5I have vista-getting a pop-up that w32.paysee.c has infected my computer. Personal virus icon is viewed I cannot delete it.<span style="font-family:Arial;font-size:13px;white-space:pre">I have vista-getting a pop-up that w32.paysee.c has infected my computer. Personal virus icon is viewed I cannot delete it.</span> <div><span style="font-family:Arial;font-size:small"><span style="font-size:13px;white-space:pre"><br/></span></span></div> <div><span style="font-family:Arial;font-size:small"><span style="font-size:13px;white-space:pre">Do not know what to do...</span></span></div>Sat, 22 Aug 2009 10:04:12 Z2009-08-31T01:51:15Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/9d389306-6704-439a-9022-b2daa54a0869http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/9d389306-6704-439a-9022-b2daa54a0869Mike Tanishttp://social.technet.microsoft.com/Profile/en-US/?user=Mike%20TanisHow do I learn if and when Forefront definitions will catch a particular virus threat?<p>One of my technically astute AutoCAD engineers forwarded a link from Webroot about an AutoCAD specific vulnerability.<br/><br/><a href="http://blog.webroot.com/2009/07/01/autocad-adware-trojans-target-techies/">http://blog.webroot.com/2009/07/01/autocad-adware-trojans-target-techies/</a><br/><br/>We are using Forefront 1.0sp1 for our client machine malware and virus protection. How can I determine if Forefront will protect against this threat? And if so, which definitions do I need? Although this issue hasn't arisen for me before I can imagine a boss wanting to see proof that a specific product protects against a specific threat.<br/><br/>Any pointers would be appreciated.<br/><br/>-Mike Tanis</p>Fri, 14 Aug 2009 15:22:26 Z2009-08-21T10:08:51Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/c1c0ba18-36bc-4086-839a-8b3efda5c007http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/c1c0ba18-36bc-4086-839a-8b3efda5c007mislahttp://social.technet.microsoft.com/Profile/en-US/?user=mislaExploit MDAC ActiveX code execution (type 183) and JS/Downloader.AgentI was surfing on the web and AVG notified me of the following malware:<br/><br/>Exploit MDAC ActiveX code execution (type 183)<br/>JS/Downloader.Agent<br/><br/>What are these and how can I get rid of them?  AVG had no options in the results column of Web Shield.<br/><br/>Thank you!Mon, 10 Aug 2009 06:11:47 Z2009-08-18T02:00:30Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/d0d28107-dcc1-40c5-8720-e62ed7b64d03http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/d0d28107-dcc1-40c5-8720-e62ed7b64d03Edgarc2010http://social.technet.microsoft.com/Profile/en-US/?user=Edgarc2010Forefront made nothing with gadislugu virusHI, everybody, my computer has a gadislugu virus but forefront not make nothing about it.  Why?Tue, 11 Aug 2009 16:55:58 Z2009-08-20T03:36:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/71f6197c-2e7d-4dda-9d7b-46e5b70210c6http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/71f6197c-2e7d-4dda-9d7b-46e5b70210c6ReghuMhttp://social.technet.microsoft.com/Profile/en-US/?user=ReghuMForefront doesnt clean virus W32.Bancos in some instances<p>Hi I am having trouble with forefront client cleaning bancos virus. It doesnt seem to clean it successfully across all machines.  given below info from MOM<br/><br/>Severity: Security Issue<br/>Maintenance Mode: False<br/>Domain: <br/>Computer: <br/>Time Last Modified: 8/2/2009 1:20:30 PM<br/>Resolution State: New<br/>Time in State: 8/2/2009 8:43:39 AM<br/>Problem State: 0<br/>Repeat Count: 3<br/>Name: Malware on Network - Failed Response (Alert Level 2)<br/>Source: Microsoft Forefront Client Security Threat ID = 2147627172<br/>Ticket Id: <br/>Owner: <br/>Description: Client Security failed to eliminate the following threat:<br/>            - Threat name: TrojanSpy:Win32/Bancos.OH<br/>            - Attempted action: Remove</p> <p>        The antimalware engine on the client computer returned the following:<br/>            - Error code: 0x80508024<br/>            - Error message: To finish removing spyware and other potentially unwanted software, you need to run a full scan. For information about scanning options, see Help and Support. <br/>            <br/>        To investigate and resolve this incident:<br/>            1. Learn about the threat and its mitigation. Consult the Microsoft Malicious Software Encyclopedia:<br/>                 <a href="http://go.microsoft.com/fwlink/?linkid=37020&amp;name=TrojanSpy:Win32/Bancos.OH">http://go.microsoft.com/fwlink/?linkid=37020&amp;name=TrojanSpy:Win32/Bancos.OH</a> <br/>            2. Identify computers infect with this malware. Consult the Malware Detail Report:<br/>                tab.<br/>Time of Last Event: 8/2/2009 1:20:29 PM<br/>Time Raised: 8/2/2009 12:43:37 PM<br/>Alert Id: bd634331-b0be-40c1-bea1-ab35d3ac6d83<br/>Rule Id: 2182f53c-a676-478d-a758-9280b908e181<br/>Rule Name: Malware on Network - Failed Response (Alert Level 2)<br/>CustomField1: Microsoft Forefront Client Security<br/>CustomField2: Threat<br/>CustomField3: 2147627172<br/>CustomField4: <br/>CustomField5: <br/>Time Added: 8/2/2009 12:43:39 PM<br/>Time of First Event: 8/2/2009 12:43:37 PM<br/>Time Resolved: <br/>Resolved By: <br/>Modified By: NT AUTHORITY\NETWORK SERVICE<br/>Computer Custom Data 1: <br/>Computer Custom Data 2: <br/>Maintenance Mode End: <br/>Maintenance Mode User: <br/>Maintenance Mode Reason:</p>Tue, 04 Aug 2009 07:06:08 Z2009-08-17T01:36:05Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/41f31394-6bc2-401c-956a-f541303180cehttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/41f31394-6bc2-401c-956a-f541303180ceRyan Seniohttp://social.technet.microsoft.com/Profile/en-US/?user=Ryan%20SenioNo other way?Here is my current policy setup with regards to the area i'm wondering about. <br/><br/>Client Options:<br/>users can view all client security agents and settings<br/>only administrators can change client security agent settings<br/><br/>Currently my domain account is a local admin on my machine. When I run a test scan and it detects I have an option of what I want to do with the alert (remove, ignore etc) which is great. Us admins should be able to choose what they want to do<br/><br/>On a regular users machine (where they are only power users) the same scan will only result in the tray icon turning orange (and appropriate event logged in the event viewer), and they cannot access the gui..nor does the program seem to do anything with the infected file. It's still in the directory I put it in. This is not good at all. Can there not be a default action put in place? As per the ballon tip on the client machine...&quot;A system administrator manages Microsoft Forefront Client Security for all users on this computer. The program will notify you to take actions only if malicious software is detected&quot;<br/><br/>And it certainly doesn't. HELP!<br/><br/><br/><br/>Mon, 20 Jul 2009 19:26:26 Z2009-10-27T23:51:07Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/1282d306-5d96-4e59-ae2e-26388df8fb8ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/1282d306-5d96-4e59-ae2e-26388df8fb8eComputerHamsterhttp://social.technet.microsoft.com/Profile/en-US/?user=ComputerHamsterMy HP Media Center PC with vista has odd behavior: destroys usb drive, crashes computer I have a serious problem: my computer is destroying itself!<br>    <br>It all started when I ran pinnacle studio 8 installation in compatability mode for windows xp service pack 2. After that, Windows Media Center Receiver Service Started Crashing. Then RunDLL32 windows host process. And then COM Surrogate. The last one it started crashing was Windows DVD maker. For A while I didn't Know why. Then I discovered it was Pinnacle and it was using AVI files (I'm not kidding, AVIs) to crash programs. I immediatelly probed my system for anytyhing with the name pinnacle or AVI and deleted it.<br><br>Here's where I was REALLY stupid. I found the LAST pinnacle files in my PC . As I ran the uninstaller, I noticed its name was UNWISE. I Ignored it.I got rid of all the pinnacle files, but it still crashed those programs!<br>    And JUST when I thought it couldn't get ANY worse, I put in a USB device. As SOON as I took it out , the screen changed To blue and it said<br><br>Start process: minidump<br><br>Dumping Physical Memory<br><br>IMMEDIATELY I cut the power to the PC, took out the USB port, And turned on the PC. Fine.<br>THEN IT SAID:(in a window)<br><br>Windows has recovered from an unexpected Shut Down.<br><br>I clicked &quot;More Details&quot;<br><br>The name of the program: BlueScreen.<br><br><br>AAAAH! The Blue Screen Of Death!<br><br>I Put in my USB device Again and took it out. Nothing happened. LITERALLY!<br><br>MY DRIVE WAS DESTROYED!<br><br>If anybody could help me out I'd really appreciate it<br><br>-ComputerHamster<br>Thu, 14 Aug 2008 15:20:44 Z2009-07-10T07:47:39Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/51193bdf-8e24-4f3e-8c5e-0c756e9c093dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/51193bdf-8e24-4f3e-8c5e-0c756e9c093djaxbeachhttp://social.technet.microsoft.com/Profile/en-US/?user=jaxbeachCan printing launch a virus?<p>I was sent an email stating it is possible to launch a virus by only printing something off the internet.  There are no details to pass on from this statement.  Am I wrong when I say it is <span style="text-decoration:underline">not</span> possible <span style="text-decoration:underline">without</span> opening an attachment?</p>Thu, 04 Jun 2009 23:53:26 Z2009-06-15T07:51:24Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/41ac6959-eb6e-44ab-ad1b-a0316db2a3e8http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/41ac6959-eb6e-44ab-ad1b-a0316db2a3e8Edsaodjhoiahttp://social.technet.microsoft.com/Profile/en-US/?user=EdsaodjhoiaQuestion for the Product Team :-)<p align=left><font face=Arial size=2></font> </p> <p>Hello guys and girls, </p> <p align=left>A quick question, we are working with a customer and quite close to displacing one of our competitors for their client AV solution however at a meeting yesterday the client raised and interesting question that I did´nt have an answer too.</p> <p align=left>Do you have an application capable of detecting Kernel Mode rootkits? or are you working on something to that effect?</p> <p align=left>As I understand it, the only way of doing this would be from outside the OS, either a bootable CD or pre installed app capable of booting up in a linux / winPE etc. environment. Other AV vendors have this kind of solution for example McAfee previousley had Cleanboot and now prescan and the command line scanner package that is included in Hirens boot cd etc... the good thing about prescan is that it allowed a simultaneous reboot and then scan of entire groups or even the whole network from the management console, <img alt=Smile src="http://forums.microsoft.com/MSDN/emoticons/emotion-1.gif"> usefull for an outbreak if you want to make sure all machines are clean before you bring your network back up.</p> <p align=left>It could also be usefull to have this for peace of mind, as I asume this would give it greater accuracy and less problems as no services / processes could be loaded.. </p> <p align=left>thanks for your time <img height=19 alt=Smile src="http://forums.microsoft.com/MSDN/emoticons/emotion-1.gif" width=19></p> <p align=left>Ed</p> <p align=left> </p>Wed, 07 May 2008 14:33:49 Z2009-06-02T21:41:13Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/0e674685-61e0-4599-8641-2d3ac938a505http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/0e674685-61e0-4599-8641-2d3ac938a505whatisthispleezehttp://social.technet.microsoft.com/Profile/en-US/?user=whatisthispleezeUninvited Virus Removal 2009 program has been detected, trying to remove all traces I've heard about this Confiker malware and just had McAfee alert re: Virus Removal 2009 program has been detected as malware, I instructed McAfee to remove. Fearing possibly damage has been done, still trying to remove all traces.   When I went to control panel it wouldn't uninstall, only removal.  Adaware &amp; McAfee scanned and found nothing. Performed search, found vrm2009.exe-02B553A6.pf  Is this file worm/malware corruption? Pls identify if it's necessary to delete this file? At this moment am performg full scan at safety.live.com.  <br/>Any suggestions in basic laymen's terms please is appreciated.Wed, 01 Apr 2009 06:39:05 Z2009-05-23T14:06:02Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/0021ca51-8b51-4502-9d63-dc12d339340chttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/0021ca51-8b51-4502-9d63-dc12d339340chowardmphttp://social.technet.microsoft.com/Profile/en-US/?user=howardmpForefront Client Security and Malicious software Removal Tool<p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:small;font-family:Times New Roman">Hello all,</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:small;font-family:Times New Roman">I understand the purpose of MSRT is to remove infections from computers as opposed to Forefront pre-empting the infection. What I’d like to understand is, if Forefront is unable to remove a malware, is there any point in running MSRT in an attempt to remove the malware?. Does MSRT do any additional tasks or have a different definitions list?</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:small;font-family:Times New Roman">Many thanks</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:small;font-family:Times New Roman">Howard</span></p>Thu, 09 Apr 2009 11:58:54 Z2009-05-17T20:45:50Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/0979f328-9da7-4cd6-8fa2-e72fe54a5ff1http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/0979f328-9da7-4cd6-8fa2-e72fe54a5ff1Dharm Dhwaj Singhhttp://social.technet.microsoft.com/Profile/en-US/?user=Dharm%20Dhwaj%20SinghHow to Exclude network Drive Scanning in FCSThe FCS starts to scan network drives once the scan in initiated through the FCS policy. There is no option to select/deselect the network drives scan in FCs policy ?Wed, 13 May 2009 10:54:41 Z2009-05-19T06:07:55Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/47b81ab3-389d-4eb3-9f26-cc572e747c61http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/47b81ab3-389d-4eb3-9f26-cc572e747c61dcfayhttp://social.technet.microsoft.com/Profile/en-US/?user=dcfayI have a Worm_strat/gen3 and cant figure out how to get rid of itI have tried various tools, malware  when I use this i get the blue screen of death, I have used windows live one care and it doesn;t get rid of it. I also tried to use spybot and again it gives me the blue screeen. Does anyone know how I can get rid of this??<br/>The error message i get is Potential Threat detected Worm_Strat.Gen3  C/system Volume Information restore and lots of #s . I tried to do a system restore to a point previous to getting the error message and i can;t complete one. HELP<br/><br/>ThanksTue, 05 May 2009 20:44:41 Z2009-10-31T20:08:33Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/5e8164b0-43e9-43ac-a5e8-a02cbd9debb6http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/5e8164b0-43e9-43ac-a5e8-a02cbd9debb6Hiram Dantehttp://social.technet.microsoft.com/Profile/en-US/?user=Hiram%20DanteMicrosoft DONT KNOW HOW TO RESPONSE MALWARE THREATS Hi we deploy Forefront Client Security on aproximatly 6500 computers.<br><br>All de process is easy winth scripts or WSUS or both. At this moment we have a treath<br>with the <span style="font-size:11pt;line-height:115%;font-family:'Calibri','sans-serif'"><strong>Virus:Win32/Sality.AM</strong> and <strong>Worm</strong><span style="font-size:11pt;line-height:115%;font-family:'Calibri','sans-serif'"><strong>:Win32/Sality.AM</strong> and a lot of other malware.<br></span>The malware causes files infection, reg keys deletion, FCS corruption.<br><br>We call to MS Support with the case SRX080826600424 anh they said us &quot;FCS <font face=Calibri>reports <br>was determined that the FCS client anti-malware files were older than the most current versions <br>available&quot; They built a hotfix <font face=Calibri>(KB956280 – 1.5.1958.0) and after <span><font face=Calibri>subsequent scans detected and <br>removed the malware.<br></font></span></font></font><br>Now all the computer pre-cleaned has the virus again. (Reinfected) <br><br>We call partners or another companies and they have removed FCS<br><br><font style="font-size:16px" color="#990000">In summary <strong><u>Microsoft</u> DONT KNOW HOW TO RESPONSE MALWARE THREATS </strong> and they just say &quot;If FCS<br>does not detect the malware please submit it (</font><a href="https://www.microsoft.com/security/portal/submit.aspx"><font style="font-size:16px" color="#990000">https://www.microsoft.com/security/portal/submit.aspx</font></a><font style="font-size:16px"><font style="font-size:16px" color="#990000">)&quot;<br>and the Management Consoles (MOM or FCS MC) dont help on this cases.<br><br></font><br></font>FCS could be integred on Enterprise Agreement but is not the better solution. Maybe on a few years with <span style="font-size:11pt;color:#1f497d;font-family:'Calibri','sans-serif'"><font color="#000000">Forefront codename &quot;Stirling&quot;</font></span><br><br><br>I Speak Spanish.. so my english is not perfect.</span><hr size="1" align="left" width="25%">H1R@MThu, 28 Aug 2008 17:33:52 Z2009-04-22T20:13:13Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/374e1efa-7412-4210-b1d7-0660f5e94267http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/374e1efa-7412-4210-b1d7-0660f5e94267Yed Iedhttp://social.technet.microsoft.com/Profile/en-US/?user=Yed%20Iedbugs.tmpDoing &quot;cleanup disk&quot; with Acronis, and found two bugs Acronis can't fix &quot;~DF5063.tmp&quot; and &quot;~DF94F1.tmp&quot;.  I can run &quot;CHKDSK&quot; but am unable to use /f or /r, &quot;hpcommgr&quot; butts in and I can't close session without cancelling /f and /r.  In Securties&gt;Internet Properties&gt;Advanced tab&gt;Phishing (has yellow exclamation mark) in expanded the &quot;turn on auto website checking&quot; is checked.  My system is XP Pro-HP 1125a-one Gig-3.20GHz. I have PC TOOLS-MAX SECURE REG CLEANER-SPYWARE DETECTOR.  Everything seems to work well, but it takes a long (longer than usual) time to boot up, and turn off.  If I could get some help with this it would make me smile, cause I know someone is looking over my shoulder.Sat, 04 Apr 2009 10:52:18 Z2009-04-04T10:52:20Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/8464309d-56f6-4758-ac65-20584ef00074http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/8464309d-56f6-4758-ac65-20584ef00074Andrewm1972http://social.technet.microsoft.com/Profile/en-US/?user=Andrewm1972Virus Detection with out-of-date signatures\definition updates.What happens when a virus is detected and Forefront Client Security doesn't have the updated signature for that infection?<br/>Does it go into Quarantine?<br/>(Specifically for AntiMalware)Sun, 29 Mar 2009 05:10:26 Z2009-04-02T21:08:25Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/208f6748-791b-4306-8a3b-5e8a5ad9b058http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/208f6748-791b-4306-8a3b-5e8a5ad9b058Microsoftinatorhttp://social.technet.microsoft.com/Profile/en-US/?user=Microsoftinatorworm:win32/hamweq!infHi, I have a problem with the above mentioned virus. Forefront detects it and also &quot;cleans&quot; it, but not properly. I clean my flashdisk\thumbdrive but once I stick it back into my PC it gets reinfected. I have updated to today's definition file but it is no good. This particular virus cannot infect Vista machines, but it seriously attacks XP. I do not know what to do. Forefront picks it up over and over again and says it cleaned it succesfully but the virus just stays. I have disabled System Restore to no avail. Stinger from Mcafee also does'nt even detect it, but then again I have never seen it pick up anything before in my life. Please help as I was the one that pushed the client to get Forefront as I had faith in the product.Tue, 03 Mar 2009 17:24:27 Z2009-10-31T20:08:33Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/530fb325-c738-4f4e-af14-22d0e8724865http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/530fb325-c738-4f4e-af14-22d0e8724865Thabiethttp://social.technet.microsoft.com/Profile/en-US/?user=Thabietskp66.exehi guys do you have some advise in removing skp66.exe<br><br>thanks<br> Sat, 18 Oct 2008 03:17:04 Z2009-03-19T22:34:21Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/2271732d-17fa-4163-af4e-01c425f4cd50http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/2271732d-17fa-4163-af4e-01c425f4cd50Mark Blomhttp://social.technet.microsoft.com/Profile/en-US/?user=Mark%20BlomForefront Client vs Antivirus XP 2008 Hi,<br><br>In my company we use Forefront Client as the main anti-virus/anti-malware tool for our windows xp clients.<br><br>Unfortunately, some of these clients got infected by the Antivirus XP 2008 spy/malware even though they had the Forefront client installed and updated.<br><br>Does anyone else have this problem that Forefront does not protect the client from being infected by this specific virus or are we doing something wrong in our security policy?<br><br>Regards,<br><br>MarkWed, 08 Oct 2008 06:24:27 Z2009-03-19T21:30:59Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/2271a815-8ded-4808-ac3b-5cbc32c4afc8http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/2271a815-8ded-4808-ac3b-5cbc32c4afc8Pedro Gonçalveshttp://social.technet.microsoft.com/Profile/en-US/?user=Pedro%20Gon%u00e7alvesFCS don't remove Backdoor:Win32\Agent.CR from Win32l.dll Hi,<br><br>I'm having problems removing Win32\Agent.CR from Windows\System32\Win32l.dll (Windows 2003 Server) with Forefront Client Security.<br><br>It is classified as a backdoor and risk as <strong>Severe</strong>.<br><br>If a choose SmartClean button it saids that it needs to restart the server because to remove it. But after restart, if I scan, it is there again.<br><br>I used tasklist to identify the program that is using it. It is msiexc.exe.<br>I killed the process at task manager and try it again. It seams to remove it. But if I restart the server and scan again. Yes, it is there again!<br><br>How can I remove it? Could it be a false positive?<br><br>Thanks,<br>Pedro Gonçalves<br>Sun, 15 Feb 2009 23:39:24 Z2009-10-31T20:08:34Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/3610b930-c366-435c-b539-0134e2a72db3http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/3610b930-c366-435c-b539-0134e2a72db3chogyehttp://social.technet.microsoft.com/Profile/en-US/?user=chogyeRemoved VUNDO worm. Now Automatics Updates service will not startAutomatic Updates service and BITS service will not start.  Get a message from both:<br>Could not start (either above) server on local computer.  Error 2: The system cannot find the file specified.<br><br>These began after cleaning out the VUNDO worm.  These services are not running.  How do I repair them to run?<br>Wed, 04 Mar 2009 17:51:16 Z2009-03-06T17:11:58Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/bf035b92-2c3c-44c7-9d02-3dc147fbe3e2http://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/bf035b92-2c3c-44c7-9d02-3dc147fbe3e2Dan Spechthttp://social.technet.microsoft.com/Profile/en-US/?user=Dan%20SpechtForefront Client Security hits positive on Mailfrontier-SonicWall email security tmp file    <p style="font-size:11pt;margin:0in;font-family:Calibri">Hello,</p> <p style="font-size:11pt;margin:0in;font-family:Calibri"> </p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Forefront Client Security is finding a virus in a temp folder on my Windows Server 2003 - Standard, running Mailfrontier sonic wall email security here:</p> <p style="font-size:11pt;margin:0in;font-family:Calibri"> </p> <p style="font-size:11pt;margin:0in;font-family:Calibri">&quot;Path Found: <a>file:C:\WINDOWS\Temp\kp19A3.tmp</a>&quot;</p> <p style="font-size:11pt;margin:0in;font-family:Calibri"> </p> <p style="font-size:11pt;margin:0in;font-family:Calibri">and identifying a process as running it, that is located here:</p> <p style="font-size:11pt;margin:0in;font-family:Calibri"> </p> <p style="font-size:11pt;margin:0in;font-family:Calibri">&quot;Process Name: C:\Program Files\MailFrontierEG\PluginDefault\policy\verity\bin\kvoop.exe&quot;<br></p> <p style="font-size:11pt;margin:0in;font-family:Calibri"><br>SonicWall ask that  &quot;C:\Program Files\MailFrontierEG\&quot; be excluded from virus scans. Recently Forefront has been finding this virus in the temp folder, and it never has done that before.<br></p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Is this proper practice for SonicWall Email security to temporarily store a virus in the temp folder while it deletes it? Or is this a possible vulnerability? Has anyone else seen anything like this on thier email virus scanning servers?</p> <p style="font-size:11pt;margin:0in;font-family:Calibri"> </p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Thanks,</p> <p style="font-size:11pt;margin:0in;font-family:Calibri"> </p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Dan</p> <p style="font-size:11pt;margin:0in;font-family:Calibri"> </p> <p style="font-size:11pt;margin:0in;font-family:Calibri">== Actual alert - I have received 5 of these in the last 24hrs ==</p> <p style="font-size:11pt;margin:0in;font-family:Calibri"> </p> <p style="font-size:11pt;margin:0in;font-family:Calibri"> </p> <p style="font-size:11pt;margin:0in;font-family:Calibri">10/21/2008 1:11:17 PM•3004• •Microsoft Forefront Client Security Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Microsoft Forefront Client Security can't undo changes that you allow.</p> <p style="font-size:11pt;margin:0in;font-family:Calibri">For more information please see the following:</p> <p style="font-size:11pt;margin:0in;font-family:Calibri"><a href="http://go.microsoft.com/fwlink/?linkid=37020&amp;name=Trojan:Win32/Wantvi.I&amp;threatid=2147607438">http://go.microsoft.com/fwlink/?linkid=37020&amp;name=Trojan:Win32/Wantvi.I&amp;threatid=2147607438</a></p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Scan ID: {F51F682C-85C4-40F4-BD46-7C761EF29F8E}</p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Agent: On Access</p> <p style="font-size:11pt;margin:0in;font-family:Calibri">User: NT AUTHORITY\SYSTEM</p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Name: Trojan:Win32/Wantvi.I</p> <p style="font-size:11pt;margin:0in;font-family:Calibri">ID: 2147607438</p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Severity: Severe</p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Category: Trojan</p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Path Found: <a>file:C:\WINDOWS\Temp\kp19A3.tmp</a></p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Alert Type: </p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Process Name: C:\Program Files\MailFrontierEG\PluginDefault\policy\verity\bin\kvoop.exe</p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Detection Type: Concrete</p> <p style="font-size:11pt;margin:0in;font-family:Calibri">Status: Suspend ••</p>Wed, 22 Oct 2008 00:06:13 Z2009-03-05T19:57:20Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/44b17c41-0ac9-40ad-a8a8-61c36fbdf0fehttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientMTR/thread/44b17c41-0ac9-40ad-a8a8-61c36fbdf0feJBarkhttp://social.technet.microsoft.com/Profile/en-US/?user=JBarkFalse Positive?Hi,<br> <p style="margin:0in 0in 0pt"><span style="font-size:9pt;font-family:'Verdana','sans-serif'"> I'm the SMS admin as well as one of the FCS admins. I'm setting up a push for a Ascent upgrade to a couple hundred workstations when FCS reported Trojan:Win32/Delfsnif.C in a file called MSIcleanup.exe that was temporarily extracted from the MSI that I'm installing from.<br><br>Any thoughts? I'll also be contacting the vendor today as well.</span></p>Fri, 06 Feb 2009 14:11:53 Z2009-02-07T21:07:32Z