BleepingComputer.com: Win XP Security Center products listed

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Win XP Security Center products listed Is an AV or Firewall really installed if listed in Security Center?

#1 User is offline   abidlen 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 4
  • Joined: 16-February 11

Posted 16 February 2011 - 09:09 AM

I have a computer that for sure was infected with Smart Internet Protection 2011.
I went through the common documented steps to remove the infection.
Nothing that I scan with shows any more traces of the infection. Yet, it's still listed in Security Center as an active Firewall and AntiVirus product.

Can anyone shed some light on how a product gets listed in the Security Center? If it's shown, does that mean that the computer is still infected or is there just some entry somewhere telling the Security Center that it's installed?

This post has been edited by abidlen: 16 February 2011 - 09:10 AM


#2 User is offline   Didier Stevens 

  • Senior Member
  • PipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 594
  • Joined: 12-October 10
  • Gender:Male

Posted 16 February 2011 - 09:55 AM

The Security Center gets its data from WMI. I assume you've not installed another AV or firewall?

I've written a VB script to display the Security Center data WMI has for AV and Firewall.
That's the same data the Windows Security Center is accessing to display its information.
You can download it from here:
http://DidierStevens.com/files/software/wmi-sc.zip

Unzip it and execute it (double-click).

You'll have at least 2 message boxes, and 4 at most.
First one displays "Start"
Second one displays the AV info, if there is no info, this message box is not displayed.
Third one displays the FW info, if there is no info, this message box is not displayed.
Fourth one displays "Done"

Please report back which messages were displayed.
Didier Stevens
http://blog.DidierStevens.com
Microsoft MVP 2011-2012 Consumer Security
Posted Image

#3 User is offline   abidlen 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 4
  • Joined: 16-February 11

Posted 16 February 2011 - 10:18 AM

I installed MS Security Essentials also, which you'll see below.
If I disable the realtime scanning in MSSE, then I see SIP2011 listed specifically in Security Center, otherwise I see the message about having multiple AV's installed...

1. Start
2. AVP Inc
Smart Internet Protection 2011
True
True
3. Microsoft Corporation
Microsoft Security Essentials
True
True
3.0.8107.0
4. AVP Inc
Smart Internet Protection 2011
True
5. WMI Class SecurityCenter2 not found
6. Done

#4 User is offline   Didier Stevens 

  • Senior Member
  • PipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 594
  • Joined: 12-October 10
  • Gender:Male

Posted 16 February 2011 - 03:09 PM

OK, the fact that you've two entries for AV products in WMI explains why the security center still reports Smart Internet Protection 2011.

I assume that you want that we try to remove this entry?

This post has been edited by Didier Stevens: 16 February 2011 - 03:09 PM

Didier Stevens
http://blog.DidierStevens.com
Microsoft MVP 2011-2012 Consumer Security
Posted Image

#5 User is offline   abidlen 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 4
  • Joined: 16-February 11

Posted 16 February 2011 - 03:23 PM

Yes, I would like to.
It sounds like I'm right in assuming that just because it's listed does not mean that it's still infected - agree?

#6 User is offline   Didier Stevens 

  • Senior Member
  • PipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 594
  • Joined: 12-October 10
  • Gender:Male

Posted 16 February 2011 - 03:41 PM

View Postabidlen, on 16 February 2011 - 03:23 PM, said:

It sounds like I'm right in assuming that just because it's listed does not mean that it's still infected - agree?


Not necessarily. It could be that the entry is created because there is still a software component active. But we'll establish that.

Do the following from a Windows XP administrator account:

Start the security center.
Start Run... and launch wbemtest.
Click Connect...
Replace default with SecurityCenter in the first input box
Click connect
Click Enum Classes
Click OK
Double-click AntiVirusProduct
Click Instances
You will see 1 or 2 objects (AntiVirusProduct.instanceGUID...)

If there is only one:
select it and Delete it.

If there are two:
Double click the first entry
Scroll down until you see displayName, if it is something like Smart Internet Protection 2011, then you've to delete this entry, otherwise it is the second entry you need to delete.
Click close
Select the correct entry
Click Delete

The moment you delete the entry, Security Center will update its status (that's why I asked you to start the Security Center).

Click Close, Close and Exit.



Now you have deleted the WMI entry for SIP that the Security Center uses to display its status.
Reboot your machine.
If the entry reappears, then there is still a component of SIP installed that recreates the entry.
You'll need to find that component and remove it.

This post has been edited by Didier Stevens: 16 February 2011 - 03:42 PM

Didier Stevens
http://blog.DidierStevens.com
Microsoft MVP 2011-2012 Consumer Security
Posted Image

#7 User is offline   abidlen 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 4
  • Joined: 16-February 11

Posted 16 February 2011 - 04:21 PM

After reboot it only showed MS Security Essentials - which I interpret to be GOOD NEWS!

Thanks so much for your time and sharing your knowledge!

#8 User is offline   Didier Stevens 

  • Senior Member
  • PipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 594
  • Joined: 12-October 10
  • Gender:Male

Posted 16 February 2011 - 04:24 PM

View Postabidlen, on 16 February 2011 - 04:21 PM, said:

After reboot it only showed MS Security Essentials - which I interpret to be GOOD NEWS!


Yep, that is good news, there is no active SIP component left to create the WMI entries.
Didier Stevens
http://blog.DidierStevens.com
Microsoft MVP 2011-2012 Consumer Security
Posted Image

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users