Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

"Send lawyers, guns and money..." -- Lyrics from a Warren Zevon song


computers / alt.windows7.general / Virus or what ?

SubjectAuthor
* Virus or what ?Roberta
+- Re: Virus or what ?David E. Ross
+- Re: Virus or what ?Stan Brown
+- Re: Virus or what ?Mayayana
+* Re: Virus or what ?Paul
|`* Re: Virus or what ?Paul
| `* Re: Virus or what ?Roberta
|  +- Re: Virus or what ?Java Jive
|  `- Re: Virus or what ?Paul
`- Re: Virus or what ?KenW

1
Virus or what ?

<thpsff$dfc$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=4992&group=alt.windows7.general#4992

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!8ER4TMW3TSRnvS06aECo6g.user.46.165.242.91.POSTED!not-for-mail
From: Roberta@Roberta.com (Roberta)
Newsgroups: alt.windows7.general
Subject: Virus or what ?
Date: Fri, 7 Oct 2022 11:51:23 -0700
Organization: Aioe.org NNTP Server
Message-ID: <thpsff$dfc$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="13804"; posting-host="8ER4TMW3TSRnvS06aECo6g.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:52.0) Gecko/20100101 Firefox/52.0
SeaMonkey/2.49.5
X-Mozilla-News-Host: news://news.aioe.org:119
X-Notice: Filtered by postfilter v. 0.9.2
 by: Roberta - Fri, 7 Oct 2022 18:51 UTC

Home network.
3 Win XP Pro laptops.
2 Win 7 Pro laptops.
2 Win 7 Pro Desktops.

All on the LAN and Internet.

The problems seems to be only with the Win XP Pro PCs.

Started with one Win XP Pro PC (on Cat5)
Then weeks later the next XP PC started the same problems (on Cat5).
Finally the third one on WiFi started problems.

Boot up any and all seems fine.
After leaving each on for days eventually this starts happening.
Power off boot gets it back to operating OK (so it seems) for a while,
then problems.

Problems.
Cannot start some apps. Others start.
Cannot update apps like Malwarebytes database etc at any time even after
boot.
Cannot runs apps once started.
Cannot copy / paste.
Cannot use Explorer.

Suggestion please for cleaning or ...

It will be a real pain to try to re-image these.
I did re-image the original problem one and so far it seems OK.
Way too much work to bring it back now all the way.

Are others having this problem ?

Re: Virus or what ?

<thpv9u$1r7q$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=4995&group=alt.windows7.general#4995

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!3Mhv7/5wGMalT5I1PrEuIA.user.46.165.242.75.POSTED!not-for-mail
From: nobody@notme.invalid (David E. Ross)
Newsgroups: alt.windows7.general
Subject: Re: Virus or what ?
Date: Fri, 7 Oct 2022 12:39:40 -0700
Organization: I am @ David at rossde dot com.
Message-ID: <thpv9u$1r7q$1@gioia.aioe.org>
References: <thpsff$dfc$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="60666"; posting-host="3Mhv7/5wGMalT5I1PrEuIA.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101
Thunderbird/52.9.1
Content-Language: en-US
X-Notice: Filtered by postfilter v. 0.9.2
 by: David E. Ross - Fri, 7 Oct 2022 19:39 UTC

On 10/7/2022 11:51 AM, Roberta wrote:
>
> Home network.
> 3 Win XP Pro laptops.
> 2 Win 7 Pro laptops.
> 2 Win 7 Pro Desktops.
>
> All on the LAN and Internet.
>
> The problems seems to be only with the Win XP Pro PCs.
>
> Started with one Win XP Pro PC (on Cat5)
> Then weeks later the next XP PC started the same problems (on Cat5).
> Finally the third one on WiFi started problems.
>
> Boot up any and all seems fine.
> After leaving each on for days eventually this starts happening.
> Power off boot gets it back to operating OK (so it seems) for a while,
> then problems.
>
> Problems.
> Cannot start some apps. Others start.
> Cannot update apps like Malwarebytes database etc at any time even after
> boot.
> Cannot runs apps once started.
> Cannot copy / paste.
> Cannot use Explorer.
>
> Suggestion please for cleaning or ...
>
> It will be a real pain to try to re-image these.
> I did re-image the original problem one and so far it seems OK.
> Way too much work to bring it back now all the way.
>
> Are others having this problem ?
>

Can you do a virus scan with a current virus database from one of the
Windows 7 desktops? In my LAN, I can scan my wife's Windows XP PC from
my Windows 7 PC.

--
David E. Ross
<http://www.rossde.com/>

Donald Trump demands that he be declared the winner of
the 2020 presidential election. Otherwise, he demands
that the election be rerun immediately.

What has he been smoking?

Re: Virus or what ?

<MPG.3daa6667fc0a5a4298ffd0@news.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=4997&group=alt.windows7.general#4997

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!news.neodome.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: the_stan_brown@fastmail.fm (Stan Brown)
Newsgroups: alt.windows7.general
Subject: Re: Virus or what ?
Date: Fri, 7 Oct 2022 17:38:36 -0700
Organization: Oak Road Systems
Lines: 34
Message-ID: <MPG.3daa6667fc0a5a4298ffd0@news.individual.net>
References: <thpsff$dfc$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net Q/VEAI9KmD8ISQ4ueX4uhwkJllZt64SVzITwzaYr4nDyo51WYT
Cancel-Lock: sha1:PrO+q98+x0zL4NcbLDh+jdw4s4Y=
User-Agent: MicroPlanet-Gravity/3.0.11 (GRC)
 by: Stan Brown - Sat, 8 Oct 2022 00:38 UTC

On Fri, 7 Oct 2022 11:51:23 -0700, Roberta wrote:
>
> Home network.
> 3 Win XP Pro laptops.
> 2 Win 7 Pro laptops.
> 2 Win 7 Pro Desktops.
>
> All on the LAN and Internet.
>
> The problems seems to be only with the Win XP Pro PCs.
>
> Started with one Win XP Pro PC (on Cat5)
> Then weeks later the next XP PC started the same problems (on Cat5).
> Finally the third one on WiFi started problems.
>
> Boot up any and all seems fine.
> After leaving each on for days eventually this starts happening.
> Power off boot gets it back to operating OK (so it seems) for a while,
> then problems.
>
> Problems.
> Cannot start some apps. Others start.
> Cannot update apps like Malwarebytes database etc at any time even after
> boot.

Sounds to me like a virus, though I could be wrong. Can you put
Malwarebytes latest version on a USB stick or CD-ROM with a known
good computer, then take all the bad ones off network and clean them
with Malwarebytes?

--
Stan Brown, Tehachapi, California, USA https://BrownMath.com/
Shikata ga nai...

Re: Virus or what ?

<thrph7$6cc9$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=4999&group=alt.windows7.general#4999

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: mayayana@invalid.nospam (Mayayana)
Newsgroups: alt.windows7.general
Subject: Re: Virus or what ?
Date: Sat, 8 Oct 2022 08:12:21 -0400
Organization: A noiseless patient Spider
Lines: 27
Message-ID: <thrph7$6cc9$1@dont-email.me>
References: <thpsff$dfc$1@gioia.aioe.org>
Injection-Date: Sat, 8 Oct 2022 12:13:27 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="e9898d077305841ea8b5e7ba78ef48ff";
logging-data="209289"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18t5TsvKLqhk7Djo3se00HtKDQ7OReU9FA="
Cancel-Lock: sha1:N56VOkPscEgi39kAehCAaqcFw1k=
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-MSMail-Priority: Normal
X-Priority: 3
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
 by: Mayayana - Sat, 8 Oct 2022 12:12 UTC

"Roberta" <Roberta@Roberta.com> wrote

| Problems.
| Cannot start some apps. Others start.
| Cannot update apps like Malwarebytes database etc at any time even after
| boot.
| Cannot runs apps once started.
| Cannot copy / paste.
| Cannot use Explorer.
|

Sounds to me like it might just be funky with age.
One or more things acting up. I'd start by using ProcExplorer
to see what's running. Then check autoruns and the services
list to see what else runs. Make sure there are no extra
complications, like a printer hooked up. Then check specifics.
If a program doesn't start... Can you start the EXE directly?
Where is the shortcut pointing?

Maybe also check RAM and hard disks. But if a disk image
restore works then those are probably not a problem --
unless the new installs start acting up. This is also the time
to back up personal files in case you restore a disk image.
There's no sense having disk image backup if restoring the
backup is too much trouble to do.

Re: Virus or what ?

<thsbjv$7qes$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=5004&group=alt.windows7.general#5004

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: alt.windows7.general
Subject: Re: Virus or what ?
Date: Sat, 8 Oct 2022 13:22:08 -0400
Organization: A noiseless patient Spider
Lines: 117
Message-ID: <thsbjv$7qes$1@dont-email.me>
References: <thpsff$dfc$1@gioia.aioe.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Sat, 8 Oct 2022 17:22:08 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="2033a954421ad3266d49f3daee4ea902";
logging-data="256476"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/S28R1e6fZvtMg0eLcvlSZFEs8GoTZa0I="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:lU6l4MEIOyLvbJLQ4yR63ccLfTc=
Content-Language: en-US
In-Reply-To: <thpsff$dfc$1@gioia.aioe.org>
 by: Paul - Sat, 8 Oct 2022 17:22 UTC

On 10/7/2022 2:51 PM, Roberta wrote:
>
> Home network.
> 3 Win XP Pro laptops.
> 2 Win 7 Pro laptops.
> 2 Win 7 Pro Desktops.
>
> All on the LAN and Internet.
>
> The problems seems to be only with the Win XP Pro PCs.
>
> Started with one Win XP Pro PC  (on Cat5)
> Then weeks later the next XP PC started the same problems (on Cat5).
> Finally the third one on WiFi started problems.
>
> Boot up any and all seems fine.
> After leaving each on for days eventually this starts happening.
> Power off boot gets it back to operating OK (so it seems) for a while, then problems.
>
> Problems.
> Cannot start some apps.  Others start.
> Cannot update apps like Malwarebytes database etc at any time even after boot.
> Cannot runs apps once started.
> Cannot copy / paste.
> Cannot use Explorer.
>
> Suggestion please for cleaning or ...
>
> It will be a real pain to try to re-image these.
> I did re-image the original problem one and so far it seems OK.
> Way too much work to bring it back now all the way.
>
> Are others having this problem ?

I tried to find an offline scanner.

Some options:

1) Kaspersky Rescue CD. This has a good record of being able to do scans.
However, it has politically inspired reputation problems now.
Which is a shame, when you consider that technically
competent people built this scanning CD. The same
cannot be said for the others.

2) Bitdefender (rescue CD). The scanner actually works, but the display
to the screen does not work. (linux modesetting failure)
Can be made to work, using an Xorg on a second computer.
Considered "not to work, out of the box".

3) Microsoft Safety Scanner. May have worked at one time, seems to have a problem
today with MPAM-FE or with acquiring yet another MPAM-FE
from the Internet. I would consider this broken.

For those who like to tinker, there is some background info available.
This at least explains how it launches.

https://www.verboon.info/2012/01/how-the-windows-defender-offline-beta-tool-works/
https://www.verboon.info/2012/03/how-to-add-drivers-to-the-windows-defender-offline-tool/

4) This is todays find - The ESET rescue disc. A large CD-sized download with
Ubuntu LXTerminal (could be LXDE).

https://www.eset.com/ca/download/tools-and-utilities/sysrescue/

The only problem with this one, is the interface on the scanner
does not follow any useful convention. For example, if you see
square boxes with tick marks, those are tabs with the scan results
in them, and are not "scanning kickoff" buttons.

So the main barrier on this tool, is not being able to tell if
you actually ran a scan. And not being able to tell even, whether
C: got scanned or not.

It was all as much fun as I expected it to be.

*******

For online tools (you run these while the sick OS is booted), we have:

https://support.norton.com/sp/static/external/tools/npe.html

Norton Power Eraser

# The WinXP/Vista one.

https://buy-download.norton.com/downloads/premium_services/NPE/5.3/en/NPE.exe

Name: NPE.exe
Size: 9,639,912 bytes (9413 KiB)
SHA256: E9AA615D100B14D6A85D3DAD8BCE832B9DBE84568EB5BF975365C3467E3E652B

I did not test this.

MBAR (MalwareBytes Rootkit scanner) is one tool for rootkits.
(The MBAM is the AV scanner.)

TDSSKiller is another. TDSS is a rootkit that infects atapi.sys amongst others.

https://www.bleepingcomputer.com/download/tdsskiller/

# Or, from the site that made it.

https://support.kaspersky.com/5350

The nice thing about a rootkit, is there is nothing to see in Task Manager.
That's the power of the thing. A rootkit can cloak just about anything
it is doing, with the exception of the "weird symptoms" and "I can't
run this or that, mainly AV products" symptoms.

If malware attempts to protect itself against removal, that's
when you start seeing the weird side effects of that.

I guarantee there will be hair loss, before you get the tools
to do what they're supposed to do. I wasn't shocked by what I found,
as it's been like this for some number of years.

Paul

Re: Virus or what ?

<ahd3kh5cbojip6ceh4kompttsddah0eoal@4ax.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=5007&group=alt.windows7.general#5007

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx12.iad.POSTED!not-for-mail
From: ken1943@invalid.net (KenW)
Newsgroups: alt.windows7.general
Subject: Re: Virus or what ?
Organization: Home
Message-ID: <ahd3kh5cbojip6ceh4kompttsddah0eoal@4ax.com>
References: <thpsff$dfc$1@gioia.aioe.org>
User-Agent: ForteAgent/8.00.32.1272
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Lines: 42
X-Complaints-To: abuse(at)newshosting.com
NNTP-Posting-Date: Sat, 08 Oct 2022 17:43:05 UTC
Date: Sat, 08 Oct 2022 11:43:06 -0600
X-Received-Bytes: 1810
 by: KenW - Sat, 8 Oct 2022 17:43 UTC

On Fri, 7 Oct 2022 11:51:23 -0700, Roberta <Roberta@Roberta.com>
wrote:

>
>Home network.
>3 Win XP Pro laptops.
>2 Win 7 Pro laptops.
>2 Win 7 Pro Desktops.
>
>All on the LAN and Internet.
>
>The problems seems to be only with the Win XP Pro PCs.
>
>Started with one Win XP Pro PC (on Cat5)
>Then weeks later the next XP PC started the same problems (on Cat5).
>Finally the third one on WiFi started problems.
>
>Boot up any and all seems fine.
>After leaving each on for days eventually this starts happening.
>Power off boot gets it back to operating OK (so it seems) for a while,
>then problems.
>
>Problems.
>Cannot start some apps. Others start.
>Cannot update apps like Malwarebytes database etc at any time even after
>boot.
>Cannot runs apps once started.
>Cannot copy / paste.
>Cannot use Explorer.
>
>Suggestion please for cleaning or ...
>
>It will be a real pain to try to re-image these.
>I did re-image the original problem one and so far it seems OK.
>Way too much work to bring it back now all the way.
>
>Are others having this problem ?
I have used Sophos free scanner for about 3 years. It found things
others have not. They have a new version out.

KenW

Re: Virus or what ?

<ti1752$qq07$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=5019&group=alt.windows7.general#5019

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: alt.windows7.general
Subject: Re: Virus or what ?
Date: Mon, 10 Oct 2022 09:36:36 -0400
Organization: A noiseless patient Spider
Lines: 62
Message-ID: <ti1752$qq07$1@dont-email.me>
References: <thpsff$dfc$1@gioia.aioe.org> <thsbjv$7qes$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Mon, 10 Oct 2022 13:36:35 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="0cb50f0f592659a3c18c40c7d452b37e";
logging-data="878599"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18UEUX3R5CH0h/Sp7BqKPyfrYDOppFJx2c="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:As94ohPzIK2SjauO9Hfh5nefV+U=
Content-Language: en-US
In-Reply-To: <thsbjv$7qes$1@dont-email.me>
 by: Paul - Mon, 10 Oct 2022 13:36 UTC

On 10/8/2022 1:22 PM, Paul wrote:

>
> 3) Microsoft Safety Scanner. May have worked at one time, seems to have a problem
>                              today with MPAM-FE or with acquiring yet another MPAM-FE
>                              from the Internet. I would consider this broken.
>
>    For those who like to tinker, there is some background info available.
>    This at least explains how it launches.
>
>    https://www.verboon.info/2012/01/how-the-windows-defender-offline-beta-tool-works/
>    https://www.verboon.info/2012/03/how-to-add-drivers-to-the-windows-defender-offline-tool/

I got this working.

The verboon.info articles really helped a lot.
Couldn't have done it, without them.

I made a USB stick first, using the mssstool stub.

Then, I replaced the crusty old boot.wim on the USB stick,
with a boot.wim from another WinPE CD.

Admin Terminal on Windows 11 (what was in front of me).
I simply assumed there was only one index on the boot.wim,
as there was no XML file for me to check.

dism.exe /mount-wim /wimfile:d:\tempwdo\boot.wim /index:1 /MountDir:d:\tempwdo\mount

Deployment Image Servicing and Management tool
Version: 10.0.22621.1

Mounting image
[==========================100.0%==========================]
The operation completed successfully.

Using 7ZIP, I opened the USB stick boot.wim and copied out
the safety scanner Program Files entry and moved it into the d:\tempwdo\mount tree.
The winpeshl.ini file needs to be moved into d:\tempwdo\mount\windows\system32
in place of whatever winpeshl.ini was already there. I also moved over an
Internet Explorer chunk that was next to the safety scanner folder in
Program Files. ( Since my WinPE was a 32-bit one, there is only a Program
Files and no Program Files (x86) thing. )

This command, then generates an updated boot.wim using the
contents of d:\tempwdo\mount .

dism.exe /Unmount-Wim /Mountdir:d:\tempwdo\mount /commit

Then, I copied the new boot.wim, into the "source" directory
on the USB stick.

The USB stick booted up fine, it read the mpam-fe.exe I put on
the top level of the USB stick, using the download from here.
This is the 32 bit mpam-fe.exe .

http://go.microsoft.com/fwlink/?LinkID=209593&clcid=0x409

While I've been writing this, the scanner has scanned 337,000
files. And isn't quite finished yet.

Paul

Re: Virus or what ?

<ti1ma9$15e7$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=5022&group=alt.windows7.general#5022

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!8ER4TMW3TSRnvS06aECo6g.user.46.165.242.91.POSTED!not-for-mail
From: Roberta@Roberta.com (Roberta)
Newsgroups: alt.windows7.general
Subject: Re: Virus or what ?
Date: Mon, 10 Oct 2022 10:55:13 -0700
Organization: Aioe.org NNTP Server
Message-ID: <ti1ma9$15e7$1@gioia.aioe.org>
References: <thpsff$dfc$1@gioia.aioe.org> <thsbjv$7qes$1@dont-email.me>
<ti1752$qq07$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Info: gioia.aioe.org; logging-data="38343"; posting-host="8ER4TMW3TSRnvS06aECo6g.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:52.0) Gecko/20100101 Firefox/52.0
SeaMonkey/2.49.5
X-Notice: Filtered by postfilter v. 0.9.2
 by: Roberta - Mon, 10 Oct 2022 17:55 UTC

My issue is on the Win XP Pro 32 bit laptops.

mpam-fe.exe is a 64bit program. I downloaded and started and it failed.
---------------------------
D:\ThisPC\Scanner\mpam-fe.exe
---------------------------
D:\ThisPC\Scanner\mpam-fe.exe is not a valid Win32 application.

Just ignorant here.

Paul wrote:
> On 10/8/2022 1:22 PM, Paul wrote:
>
>>
>> 3) Microsoft Safety Scanner. May have worked at one time, seems to
>> have a problem
>>                               today with MPAM-FE or with acquiring yet
>> another MPAM-FE
>>                               from the Internet. I would consider this
>> broken.
>>
>>     For those who like to tinker, there is some background info
>> available.
>>     This at least explains how it launches.
>>
>>
>> https://www.verboon.info/2012/01/how-the-windows-defender-offline-beta-tool-works/
>>
>>
>> https://www.verboon.info/2012/03/how-to-add-drivers-to-the-windows-defender-offline-tool/
>>
>
> I got this working.
>
> The verboon.info articles really helped a lot.
> Couldn't have done it, without them.
>
> I made a USB stick first, using the mssstool stub.
>
> Then, I replaced the crusty old boot.wim on the USB stick,
> with a boot.wim from another WinPE CD.
>
> Admin Terminal on Windows 11 (what was in front of me).
> I simply assumed there was only one index on the boot.wim,
> as there was no XML file for me to check.
>
>    dism.exe /mount-wim /wimfile:d:\tempwdo\boot.wim /index:1
> /MountDir:d:\tempwdo\mount
>
> Deployment Image Servicing and Management tool
> Version: 10.0.22621.1
>
> Mounting image
> [==========================100.0%==========================]
> The operation completed successfully.
>
> Using 7ZIP, I opened the USB stick boot.wim and copied out
> the safety scanner Program Files entry and moved it into the
> d:\tempwdo\mount tree.
> The winpeshl.ini file needs to be moved into
> d:\tempwdo\mount\windows\system32
> in place of whatever winpeshl.ini was already there. I also moved over an
> Internet Explorer chunk that was next to the safety scanner folder in
> Program Files. ( Since my WinPE was a 32-bit one, there is only a Program
> Files and no Program Files (x86) thing. )
>
> This command, then generates an updated boot.wim using the
> contents of d:\tempwdo\mount .
>
>    dism.exe /Unmount-Wim /Mountdir:d:\tempwdo\mount /commit
>
> Then, I copied the new boot.wim, into the "source" directory
> on the USB stick.
>
> The USB stick booted up fine, it read the mpam-fe.exe I put on
> the top level of the USB stick, using the download from here.
> This is the 32 bit mpam-fe.exe .
>
>    http://go.microsoft.com/fwlink/?LinkID=209593&clcid=0x409
>
> While I've been writing this, the scanner has scanned 337,000
> files. And isn't quite finished yet.
>
>    Paul

Re: Virus or what ?

<ti1ovl$sb2i$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=5024&group=alt.windows7.general#5024

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!paganini.bofh.team!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: java@evij.com.invalid (Java Jive)
Newsgroups: alt.windows7.general
Subject: Re: Virus or what ?
Date: Mon, 10 Oct 2022 19:40:49 +0100
Organization: A noiseless patient Spider
Lines: 90
Message-ID: <ti1ovl$sb2i$1@dont-email.me>
References: <thpsff$dfc$1@gioia.aioe.org> <thsbjv$7qes$1@dont-email.me>
<ti1752$qq07$1@dont-email.me> <ti1ma9$15e7$1@gioia.aioe.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Mon, 10 Oct 2022 18:40:54 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="b91866d209d56157de230038e3d4fb18";
logging-data="928850"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19ddbY7pCCTN/cS+V5vd50BWZQJoLhDz0E="
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:68.0) Gecko/20100101
Thunderbird/68.4.2
Cancel-Lock: sha1:yKOARo0ocVXv5z6sPbFPBY7Yg/4=
Content-Language: en-GB
In-Reply-To: <ti1ma9$15e7$1@gioia.aioe.org>
 by: Java Jive - Mon, 10 Oct 2022 18:40 UTC

On 10/10/2022 18:55, Roberta wrote:
>
> My issue is on the Win XP Pro 32 bit laptops.
>
> mpam-fe.exe is a 64bit program.  I downloaded and started and it failed.
> ---------------------------
> D:\ThisPC\Scanner\mpam-fe.exe
> ---------------------------
> D:\ThisPC\Scanner\mpam-fe.exe is not a valid Win32 application.

Sounds like you downloaded the wrong version for your OS - you
downloaded a 64-bit version of the file whereas you need a 32-bit version.

> Paul wrote:
>
>> On 10/8/2022 1:22 PM, Paul wrote:
>>
>>> 3) Microsoft Safety Scanner. May have worked at one time, seems to
>>> have a problem
>>>                               today with MPAM-FE or with acquiring
>>> yet another MPAM-FE
>>>                               from the Internet. I would consider
>>> this broken.
>>>
>>>     For those who like to tinker, there is some background info
>>> available.
>>>     This at least explains how it launches.
>>>
>>> https://www.verboon.info/2012/01/how-the-windows-defender-offline-beta-tool-works/
>>>
>>> https://www.verboon.info/2012/03/how-to-add-drivers-to-the-windows-defender-offline-tool/
>>
>> I got this working.
>>
>> The verboon.info articles really helped a lot.
>> Couldn't have done it, without them.
>>
>> I made a USB stick first, using the mssstool stub.
>>
>> Then, I replaced the crusty old boot.wim on the USB stick,
>> with a boot.wim from another WinPE CD.
>>
>> Admin Terminal on Windows 11 (what was in front of me).
>> I simply assumed there was only one index on the boot.wim,
>> as there was no XML file for me to check.
>>
>>     dism.exe /mount-wim /wimfile:d:\tempwdo\boot.wim /index:1
>> /MountDir:d:\tempwdo\mount
>>
>> Deployment Image Servicing and Management tool
>> Version: 10.0.22621.1
>>
>> Mounting image
>> [==========================100.0%==========================]
>> The operation completed successfully.
>>
>> Using 7ZIP, I opened the USB stick boot.wim and copied out
>> the safety scanner Program Files entry and moved it into the
>> d:\tempwdo\mount tree.
>> The winpeshl.ini file needs to be moved into
>> d:\tempwdo\mount\windows\system32
>> in place of whatever winpeshl.ini was already there. I also moved over an
>> Internet Explorer chunk that was next to the safety scanner folder in
>> Program Files. ( Since my WinPE was a 32-bit one, there is only a Program
>> Files and no Program Files (x86) thing. )
>>
>> This command, then generates an updated boot.wim using the
>> contents of d:\tempwdo\mount .
>>
>>     dism.exe /Unmount-Wim /Mountdir:d:\tempwdo\mount /commit
>>
>> Then, I copied the new boot.wim, into the "source" directory
>> on the USB stick.
>>
>> The USB stick booted up fine, it read the mpam-fe.exe I put on
>> the top level of the USB stick, using the download from here.
>> This is the 32 bit mpam-fe.exe .
>>
>>     http://go.microsoft.com/fwlink/?LinkID=209593&clcid=0x409
>>
>> While I've been writing this, the scanner has scanned 337,000
>> files. And isn't quite finished yet.

--

Fake news kills!

I may be contacted via the contact address given on my website:
www.macfh.co.uk

Re: Virus or what ?

<ti1tg7$snf2$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=5026&group=alt.windows7.general#5026

  copy link   Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: alt.windows7.general
Subject: Re: Virus or what ?
Date: Mon, 10 Oct 2022 15:57:57 -0400
Organization: A noiseless patient Spider
Lines: 68
Message-ID: <ti1tg7$snf2$1@dont-email.me>
References: <thpsff$dfc$1@gioia.aioe.org> <thsbjv$7qes$1@dont-email.me>
<ti1752$qq07$1@dont-email.me> <ti1ma9$15e7$1@gioia.aioe.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Mon, 10 Oct 2022 19:57:59 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="0cb50f0f592659a3c18c40c7d452b37e";
logging-data="941538"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18EEaR62cEoLV7PsZiYSrjv3WTK0JVScSs="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:YP8hh8jXWJC3inbaINqc4sA1jbA=
Content-Language: en-US
In-Reply-To: <ti1ma9$15e7$1@gioia.aioe.org>
 by: Paul - Mon, 10 Oct 2022 19:57 UTC

On 10/10/2022 1:55 PM, Roberta wrote:
>
> My issue is on the Win XP Pro 32 bit laptops.
>
> mpam-fe.exe is a 64bit program.  I downloaded and started and it failed.
> ---------------------------
> D:\ThisPC\Scanner\mpam-fe.exe
> ---------------------------
> D:\ThisPC\Scanner\mpam-fe.exe is not a valid Win32 application.
>
> Just ignorant here.

When you do online scans (like Windows 7, Windows 7 running some
version of Windows Defender), the OS has a bitness in that case.
You could receive a PC with a 32bit OS (x86) or a 64bit OS (x64).

In such a case, mpam-fe.exe would be for the 32bit OS.
Whereas mpam-fex64.exe would be for the 64bit OS.

On the offline scanner I was trying to get running, the scanning
CD or USB stick has its own OS. The version of mpam-fe would then
need to match the OS on the scanning CD.

The mpam-fe.exe is a signature definition delivery vehicle. The
executable in that case, does not open a graphical window. The offline
scanner has another file that is being executed, to do the actual scanning.

With online scanning, if for some reason the Microsoft software
was not able to pull in its own mpam-fe.exe , that is when you would
download one and use it.

When making offline scanners, if there's a choice, I would probably
stick with a 32-bit version of mssstool (that prepares the scanning
CD or USB stick) plus the 32-bit version of mpam-fe.exe to put at the
top level of the CD or USB stick.

I used a Macrium 32-bit boot CD, to gain a source of a boot.wim
prepared with winpe10. And used that, to build a repaired scanning
boot material for scanning my WinXP C: drive sample (I have one
sitting in the junk room for this). The theory being, the Macrium
boot.wim in that case, supports SHA2 signing and can compute the
signature of mpam-fe.exe and prove the file is legit. It's
the protection on that file which is failing (the offline scanner
then has no signatures it can use to do the scanning), and preventing
the offline scanner from working.

[Picture]

https://i.postimg.cc/bY6HtQ9j/mssstool-scan-finished.gif

But I can't prove that directly, because I have no Command Prompt
while that scan is running, so there's no opportunity to run other
tools.

The offline scan, offers options like quarantine, but I did not
see any of the detections from my sample disk offering "repair"
as an option. The disk drive in that case, probably did not have
a live infection present. I had one sample malware onboard, to verify
the scanner actually worked (signature detection). and a copy of ProduKey,
which sets off the "we don't like this" Microsoft response :-)
it's not a PUP, it's considered "hackerware" or some such.

For the average person though, rejigging a boot.wim like this,
is too much aggravation when you want a scanner that "just works".
Who knows, maybe KenW suggestion of Sophos is better. I haven't
got there yet, for a look.

Paul

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor