Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

In computing, the mean time to failure keeps getting shorter.


computers / alt.comp.os.windows-10 / Re: msert

SubjectAuthor
* msertJason
`* Re: msertVanguardLH
 `* Re: msertJason
  +- Re: msertAndy Burns
  `- Re: msertVanguardLH

1
msert

<MPG.3c92f48cb8d8c8029897ab@reader443.eternal-september.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=60349&group=alt.comp.os.windows-10#60349

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: jason_wa...@ieee.DELETE.org (Jason)
Newsgroups: alt.comp.os.windows-10
Subject: msert
Date: Wed, 9 Mar 2022 17:30:23 -0500
Organization: A noiseless patient Spider
Lines: 5
Message-ID: <MPG.3c92f48cb8d8c8029897ab@reader443.eternal-september.org>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Injection-Info: reader02.eternal-september.org; posting-host="da309c9f31c1d4180a8331ade56008c6";
logging-data="14687"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/g9AC60aA4qSpMppHtdYIYziNxq/F/tFc="
User-Agent: MicroPlanet-Gravity/3.0.4
Cancel-Lock: sha1:QkTBA/HfwRJ1e52xRAhsLAkxOhU=
 by: Jason - Wed, 9 Mar 2022 22:30 UTC

I ran msert, the Microsoft Safter Scanner. In "quick" mode it
scanned about 75000 files and reported finding 4 infected files.
Yet, when I look at the logfile it creates, it says that nothing
susicious was found. Huh?

Re: msert

<14pcyv5uke1ia$.dlg@v.nguard.lh>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=60351&group=alt.comp.os.windows-10#60351

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: V...@nguard.LH (VanguardLH)
Newsgroups: alt.comp.os.windows-10
Subject: Re: msert
Date: Wed, 9 Mar 2022 17:49:00 -0600
Organization: Usenet Elder
Lines: 31
Message-ID: <14pcyv5uke1ia$.dlg@v.nguard.lh>
References: <MPG.3c92f48cb8d8c8029897ab@reader443.eternal-september.org>
Reply-To: invalid@invalid.invalid
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net Tl42rT0fRugqJ1TDFfgCyAgPvCykClHMBjQNZOvqVMuZeV3frP
Keywords: VanguardLH VLH811
Cancel-Lock: sha1:sSaKFXHZ9E+C5IyT/CTY+7938jQ=
User-Agent: 40tude_Dialog/2.0.15.41
 by: VanguardLH - Wed, 9 Mar 2022 23:49 UTC

Jason wrote:

> I ran msert, the Microsoft Safter Scanner. In "quick" mode it
> scanned about 75000 files and reported finding 4 infected files.
> Yet, when I look at the logfile it creates, it says that nothing
> susicious was found. Huh?

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download

has links to:

https://support.microsoft.com/en-us/topic/how-to-troubleshoot-an-error-when-you-run-the-microsoft-safety-scanner-6cd5faa1-f7b4-afd2-85c7-9bed02860f1c
https://www.thewindowsclub.com/troubleshoot-microsoft-safety-scanner-errors-in-windows-10

which mentions error codes start with 0x (zero hex which means the error
code is a hexadecimal value). There were none in the msert.log logfile?
If not, maybe the reported infections were PUPs (Probably Unwanted
Programs) that were found but are not themselves malicious, but could be
used by scripts to perform malicious behavior.

When msert reports errors or infections, it provides no details on what
it found, or where? When you looked in the msert.log file, on what did
you search? Did you search the msert.log file on "threat detected" as
shown below?

https://www.bleepstatic.com/images/news/security/microsoft/exchange/microsoft-safety-scanner/msert-webshell-detected.jpg

When you ran the scanner, and it claimed there was malware, you didn't
get a list, like that shown below?

https://i0.wp.com/howtofix.guide/wp-content/uploads/2021/10/msert-after-scan-report.jpg?resize=750%2C685&ssl=1

Re: msert

<MPG.3c94571d3c2590fd9897ac@reader443.eternal-september.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=60416&group=alt.comp.os.windows-10#60416

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: jason_wa...@ieee.DELETE.org (Jason)
Newsgroups: alt.comp.os.windows-10
Subject: Re: msert
Date: Thu, 10 Mar 2022 18:43:10 -0500
Organization: A noiseless patient Spider
Lines: 59
Message-ID: <MPG.3c94571d3c2590fd9897ac@reader443.eternal-september.org>
References: <MPG.3c92f48cb8d8c8029897ab@reader443.eternal-september.org> <14pcyv5uke1ia$.dlg@v.nguard.lh>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Injection-Info: reader02.eternal-september.org; posting-host="6f9d5aeaef31eeadf18b796345bc63e9";
logging-data="27639"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/bFWHc7tvAQRUym2G1ZYU4ega3cq/9hy0="
User-Agent: MicroPlanet-Gravity/3.0.4
Cancel-Lock: sha1:lh8h2XqnDotaQJppqk+88L/Fkic=
 by: Jason - Thu, 10 Mar 2022 23:43 UTC

In article <14pcyv5uke1ia$.dlg@v.nguard.lh>, V@nguard.LH says...
>
> Jason wrote:
>
> > I ran msert, the Microsoft Safter Scanner. In "quick" mode it
> > scanned about 75000 files and reported finding 4 infected files.
> > Yet, when I look at the logfile it creates, it says that nothing
> > susicious was found. Huh?
>
> https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download
>
> has links to:
>
> https://support.microsoft.com/en-us/topic/how-to-troubleshoot-an-error-when-you-run-the-microsoft-safety-scanner-6cd5faa1-f7b4-afd2-85c7-9bed02860f1c
> https://www.thewindowsclub.com/troubleshoot-microsoft-safety-scanner-errors-in-windows-10
>
> which mentions error codes start with 0x (zero hex which means the error
> code is a hexadecimal value). There were none in the msert.log logfile?
> If not, maybe the reported infections were PUPs (Probably Unwanted
> Programs) that were found but are not themselves malicious, but could be
> used by scripts to perform malicious behavior.
>
> When msert reports errors or infections, it provides no details on what
> it found, or where? When you looked in the msert.log file, on what did
> you search? Did you search the msert.log file on "threat detected" as
> shown below?
>
> https://www.bleepstatic.com/images/news/security/microsoft/exchange/microsoft-safety-scanner/msert-webshell-detected.jpg
>
> When you ran the scanner, and it claimed there was malware, you didn't
> get a list, like that shown below?
>
> https://i0.wp.com/howtofix.guide/wp-content/uploads/2021/10/msert-after-scan-report.jpg?resize=750%2C685&ssl=1

Here's the entire log file.....

------------------------------------------------------------------------
---------------
Microsoft Safety Scanner v1.359, (build 1.359.1703.0)
Started On Thu Mar 10 16:42:10 2022

Engine: 1.1.19000.8
Signatures: 1.359.1703.0
MpGear: 1.1.16330.1
Run Mode: Interactive Graphical Mode

Results Summary:
----------------
No infection found.
Successfully Submitted MAPS Report
Successfully Submitted Heartbeat Report
Microsoft Safety Scanner Finished On Thu Mar 10 16:58:35 2022

Return code: 0 (0x0)

I'm guessing you speculation about PUPS is correct. Other scanning
programs (i.e., mbam) have spotted those in the past also.

Re: msert

<j90dk5Fhu0eU1@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=60425&group=alt.comp.os.windows-10#60425

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!usenet.goja.nl.eu.org!3.eu.feeder.erje.net!feeder.erje.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: use...@andyburns.uk (Andy Burns)
Newsgroups: alt.comp.os.windows-10
Subject: Re: msert
Date: Fri, 11 Mar 2022 07:55:47 +0000
Lines: 11
Message-ID: <j90dk5Fhu0eU1@mid.individual.net>
References: <MPG.3c92f48cb8d8c8029897ab@reader443.eternal-september.org>
<14pcyv5uke1ia$.dlg@v.nguard.lh>
<MPG.3c94571d3c2590fd9897ac@reader443.eternal-september.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 7EjqgqvOiIM3EfOkNtuUpgi3vJ0ro4en3OLns9nXaer/6Pr7xY
Cancel-Lock: sha1:IHqzhTH9TJRUgx9jpzAvdnZKk5Y=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.7.0
Content-Language: en-GB
In-Reply-To: <MPG.3c94571d3c2590fd9897ac@reader443.eternal-september.org>
 by: Andy Burns - Fri, 11 Mar 2022 07:55 UTC

Jason wrote:

> I'm guessing you speculation about PUPS is correct. Other scanning
> programs (i.e., mbam) have spotted those in the past also.

I left my laptop doing a full scan yesterday (8 million files) during the scan
it claimed to have found 17 "infected" files, after it had done the report aid
there was 1 threat found, and it was a password-revealer tool that I had
deliberately installed, but MS don;t like the idea of, no doubt they would flag
magic jelly bean and psexec etc the same way.

Re: msert

<1ekfdnv46ethd$.dlg@v.nguard.lh>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=60426&group=alt.comp.os.windows-10#60426

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!lilly.ping.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: V...@nguard.LH (VanguardLH)
Newsgroups: alt.comp.os.windows-10
Subject: Re: msert
Date: Fri, 11 Mar 2022 02:07:08 -0600
Organization: Usenet Elder
Lines: 70
Message-ID: <1ekfdnv46ethd$.dlg@v.nguard.lh>
References: <MPG.3c92f48cb8d8c8029897ab@reader443.eternal-september.org> <14pcyv5uke1ia$.dlg@v.nguard.lh> <MPG.3c94571d3c2590fd9897ac@reader443.eternal-september.org>
Reply-To: invalid@invalid.invalid
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net Fgwk9natdD3CrQBFN9k/LATgHRNb1pcgwDK7yE7zcGrcGR2VfS
Keywords: VanguardLH VLH811
Cancel-Lock: sha1:J0itgK5sIQDr9Skv5mQZB6jyNHQ=
User-Agent: 40tude_Dialog/2.0.15.41
 by: VanguardLH - Fri, 11 Mar 2022 08:07 UTC

Jason wrote:

> In article <14pcyv5uke1ia$.dlg@v.nguard.lh>, V@nguard.LH says...
>>
>> Jason wrote:
>>
>>> I ran msert, the Microsoft Safter Scanner. In "quick" mode it
>>> scanned about 75000 files and reported finding 4 infected files.
>>> Yet, when I look at the logfile it creates, it says that nothing
>>> susicious was found. Huh?
>>
>> https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download
>>
>> has links to:
>>
>> https://support.microsoft.com/en-us/topic/how-to-troubleshoot-an-error-when-you-run-the-microsoft-safety-scanner-6cd5faa1-f7b4-afd2-85c7-9bed02860f1c
>> https://www.thewindowsclub.com/troubleshoot-microsoft-safety-scanner-errors-in-windows-10
>>
>> which mentions error codes start with 0x (zero hex which means the error
>> code is a hexadecimal value). There were none in the msert.log logfile?
>> If not, maybe the reported infections were PUPs (Probably Unwanted
>> Programs) that were found but are not themselves malicious, but could be
>> used by scripts to perform malicious behavior.
>>
>> When msert reports errors or infections, it provides no details on what
>> it found, or where? When you looked in the msert.log file, on what did
>> you search? Did you search the msert.log file on "threat detected" as
>> shown below?
>>
>> https://www.bleepstatic.com/images/news/security/microsoft/exchange/microsoft-safety-scanner/msert-webshell-detected.jpg
>>
>> When you ran the scanner, and it claimed there was malware, you didn't
>> get a list, like that shown below?
>>
>> https://i0.wp.com/howtofix.guide/wp-content/uploads/2021/10/msert-after-scan-report.jpg?resize=750%2C685&ssl=1
>
> Here's the entire log file.....
>
> ------------------------------------------------------------------------
> ---------------
> Microsoft Safety Scanner v1.359, (build 1.359.1703.0)
> Started On Thu Mar 10 16:42:10 2022
>
> Engine: 1.1.19000.8
> Signatures: 1.359.1703.0
> MpGear: 1.1.16330.1
> Run Mode: Interactive Graphical Mode
>
> Results Summary:
> ----------------
> No infection found.
> Successfully Submitted MAPS Report
> Successfully Submitted Heartbeat Report
> Microsoft Safety Scanner Finished On Thu Mar 10 16:58:35 2022
>
> Return code: 0 (0x0)
>
> I'm guessing you speculation about PUPS is correct. Other scanning
> programs (i.e., mbam) have spotted those in the past also.

That log is dated after (Mar 10) when you posted here (Mar 9) about a
log dated prior to when you posted here. If the infections got cleaned
up, another scan wouldn't find any problems. Anti-malware gets updated,
especially regarding false positives. The prior scan might've reported
infections, but false positives got addressed, so they wouldn't be
reported in later scans. PUPs should not be eradicated without your
permission. PUPs are /probably/ unwanted programs, but many so-called
PUPs are tools that you choose to install. At one time, all the Nirsoft
tools were flagged as PUPs. You didn't say you were prompted and
allowed any changes.

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor