Folder AVG Forums » Archive » Archive » AVG Free » AVG 2011 Free Edition » [SOLVED] AVG & XP Security Center Reports Win FW Off, But Why
Page 3 of 4 ‹‹1234››
February 24, 2011 03:58 Re: AVG & XP Security Center Reports Win FW Off, But Why #150352
Reply with Quote | Quick Reply | Top
elfelfbaby

Avatar

Novice
Join Date: 21.2.2011
Posts: 22
It is WSCNTIFY..

I just observed WSCNTIFY.exe start at 10:47 in Image Names, last for about 10 seconds, and then stop. So that is definitely what is doing this. During that time the Windows Firewall was reported as off. I took jpg images of Task Manager showing this.
I was doing, as it happens, of a full thorough all-files AVG whole computer scan. C & D are complete, and what remains is my USB hard drive where backups are stored etc. Nothing has been reported by the scan of interest - just tracking cookies and one adware. The cookies are all in Firefox Application Data.

Before scanning I turned off the System Restore per the (Symantec) Instructions, and will turn it back on after this is completed. Btw, this scan is taking 3-4 times as long a scan using the default settings.

Please advise what do do; the Symantec documentation on wscntify is pretty scary. I have not yet run the 'fix problems' on the CCleaner Registry Cleaner. Thank you. Btw, if nothing further shows up on the scan, I will not add to this thread about that.
Thank you.

EDIT.. I ran CCleaner's registry cleaner

Hello.
I decided to go ahead and run CCleaner's Registry Fix Selected (all found) problems.
I will report back here in the morning, when I see whether the wscntify starts up again.
Thank you.
February 24, 2011 04:49 Re: AVG & XP Security Center Reports Win FW Off, But Why #150358
Reply with Quote | Quick Reply | Top
elfelfbaby

Avatar

Novice
Join Date: 21.2.2011
Posts: 22
wscntfy lives..

Hi. I got the correct spelling this time.
Anyway, at 11:47, the wscntfy.exe started up and the firewall reported as off, for about 10 seconds. Apparently the registry cleaning did not fix the problem.

Comments welcomed... Thank you.
February 24, 2011 08:00 Re: AVG & XP Security Center Reports Win FW Off, But Why #150368
Reply with Quote | Quick Reply | Top
Pokornyz

Avatar

Administrator
Join Date: 29.11.2010
Posts: 8222
Hello elfelfbaby,

If you are not sure about this file please follow: How To Handle Infection Suspicion?

But on Windows XP "wscntfy.exe" is the Windows Security Center Notify Application.
Is this situation started after AVG installation?
Also install all windows updates.

Thank you
___________________AVG TeamHow-To articles | FAQ
February 24, 2011 13:59 Re: AVG & XP Security Center Reports Win FW Off, But Why #150387
Reply with Quote | Quick Reply | Top
elfelfbaby

Avatar

Novice
Join Date: 21.2.2011
Posts: 22
WSCNTFY..

Hello. I have always kept my computer up-to-date with Windows updates. And yes, this issue only started, or rather, became visible, when I changed over from Corporate Symantec to AVG, and from ZA Pro to Windows Firewall last week . I have changed 4 laptops also, over the last 6 months, but none do this.
I went thru the normal procedures for cleaning an infection, and also did the Registry Clean. I just did a regedit search too, and found under hKEY_CURRENT_USER/Software/NVidia/Global/nView/
Windowmanagement/wscntfy.exe there is a REG_SZ and REG_DWORD with nothing set or zeroes. The same is in KEY_LOCAL_MACHINE.

(I also did an ordinary search for wscntfy.exe as a file name with nothing found, on my hard drive.)
And for kicks, I also searched the registry on my primary laptop for wscntfy and there was nothing at all.

8:47 and it did it again.
Should I delete those Registry entries? Thank you.
February 24, 2011 14:49 Re: AVG & XP Security Center Reports Win FW Off, But Why #150391
Reply with Quote | Quick Reply | Top
elfelfbaby

Avatar

Novice
Join Date: 21.2.2011
Posts: 22
additional info..

Hello.
I checked my husband's desktop, which also has an NVidia card. He still uses ZAPro and Corporate Symantec.

His registry has the wscntfy entries.

We both use Spybot S&D, and neither of us uses Teatimer. (I do on the laptop). I just updated and ran it on mine, and there were no 'immediate threats.'

I understand that the Registry entries for wscntfy may be infected on my machine and that the instructions in your last post mentioned quarantining them. But can a registry entry cause an Image Name (ie, a process of some sort, right?) to appear or wake up every hour or so? I wish I could tell what was different (or not running) on my machine to cause the thing to change from :44 to :24 to :47.

My update times of day on AVG are 8am and 5pm. However, it's 9:36am and AVG was just updating. It even shows that the last update was 9:36am.
9:47 and wscntfy.exe did its thing. I'll post this.

Thank you.
February 24, 2011 14:57 Re: AVG & XP Security Center Reports Win FW Off, But Why #150393
Reply with Quote | Quick Reply | Top
Pokornyz

Avatar

Administrator
Join Date: 29.11.2010
Posts: 8222
Hello elfelfbaby,

File wscntfy.exe should be in the folder C:\Windows\System32.
You can use GMER File Manager to locate it.

This file should be only on computer with Windows XP

Thank you
___________________AVG TeamHow-To articles | FAQ
February 24, 2011 15:33 Re: AVG & XP Security Center Reports Win FW Off, But Why #150407
Reply with Quote | Quick Reply | Top
elfelfbaby

Avatar

Novice
Join Date: 21.2.2011
Posts: 22
GMER..

Hi.
These computers are all XP (MCE and laptops are Pro).

I installed GMER and checked every entry in Windows/System32 and all its sub-directories. I did this manually because I couldn't find a find function in GMER. I checked first for Hidden files only, and then under all files.

It was not present. I wouldn't bet my life on this, but I am very sure.

Thank you.

EDIT.. RIGHT THERE IN THE TOP LEVEL..

SORRY!!
WSCNTFY.EXE is right there in the TOP LEVEL of system32.

I determined, too, thru GMER's Processes tab, that that is where it is running from when it started up at 10:47 just now.
February 24, 2011 17:06 Re: AVG & XP Security Center Reports Win FW Off, But Why #150411
Reply with Quote | Quick Reply | Top
elfelfbaby

Avatar

Novice
Join Date: 21.2.2011
Posts: 22
scanned wscntfy.exe..

Scan "Shell extension scan" completed.
No infection was found during this scan
Folders selected for scanning:;"C:\WINDOWS\system32\wscntfy.exe;"
Scan started:;"Thursday, February 24, 2011, 12:03:02 PM"
Scan finished:;"Thursday, February 24, 2011, 12:03:02 PM (less than one second)"
Total object scanned:;"1"
User who launched the scan:;"me"

Hello - I checked my laptop's WSCNTFY against this problem desktop, and they appeared to be the same. I scanned this one with AVG and the results are above. So what is going on? If it's not infected, how is it seemingly giving the symptoms shown in the Symantec article on it?
Thank you.
February 24, 2011 18:23 Re: AVG & XP Security Center Reports Win FW Off, But Why #150415
Reply with Quote | Quick Reply | Top
elfelfbaby

Avatar

Novice
Join Date: 21.2.2011
Posts: 22
question..

Hello.
Is it possible that something else is turning off the Windows Firewall, and wscntfy.exe is simply reporting it, properly?

I wonder about that.

Except, that the Symantec article indicates that wscntfy might be a worm.
Thank you.
February 24, 2011 23:00 Re: AVG & XP Security Center Reports Win FW Off, But Why #150445
Reply with Quote | Quick Reply | Top
elfelfbaby

Avatar

Novice
Join Date: 21.2.2011
Posts: 22
aol..

The documentation I have seen on w32.spybot.AFEW which may mask itself as wscntfy.exe says it spreads thru AOL IM. I do not use that. I do not even have it installed on my computer.

Some of the documentation spells it wscntIfy and some spell it wscntFY (no 'i') but it is unclear whether the worm mis-spells it or the people writing the articles did.

Is it possible that AVG itself is checking for updates or similar every hour and is turning off the Firewall? If so, why wouldn't it do this on my other machines, in fact, with everyone else's?
Please respond. Thank you.
Page 3 of 4 ‹‹1234››