techPowerUp! Forums

Go Back   techPowerUp! Forums > Software > General Software

Reply
 
Thread Tools
Old May 23, 2012, 09:35 AM   #1
1nf3rn0x
1000 Posts
 
1nf3rn0x's Avatar
 
Join Date: Sep 2009
Location: Sydney, Australia
Posts: 1,707 (1.27/day)
Thanks: 509
Thanked 331 Times in 242 Posts

System Specs

What is WinDefend?

I'm pretty sure I haven't seem this before If it's normal what's its role?


__________________
1nf3rn0x is offline  
Reply With Quote
Old May 23, 2012, 09:37 AM   #2
brandonwh64
Addicted to Bacon and StarCrunches!!!
 
brandonwh64's Avatar
 
Join Date: Sep 2009
Location: Chatsworth, GA
Posts: 13,560 (10.03/day)
Thanks: 2,138
Thanked 5,338 Times in 3,695 Posts
Send a message via ICQ to brandonwh64 Send a message via AIM to brandonwh64 Send a message via MSN to brandonwh64 Send a message via Yahoo to brandonwh64

System Specs

Looks to be malware.

http://www.sevenforums.com/system-se...-defender.html

Adaware will remove it
__________________
Cruncher's:
All GPU's
GPU's:
7970 3GB *Unlocked* = 8 Threads
5770 1GB OCed = 2 Threads
brandonwh64 is offline  
Crunching for Team TPU
Reply With Quote
The Following User Says Thank You to brandonwh64 For This Useful Post:
Old May 23, 2012, 09:42 AM   #3
1nf3rn0x
1000 Posts
 
1nf3rn0x's Avatar
 
Join Date: Sep 2009
Location: Sydney, Australia
Posts: 1,707 (1.27/day)
Thanks: 509
Thanked 331 Times in 242 Posts

System Specs

Quote:
Originally Posted by brandonwh64 View Post
Looks to be malware.

http://www.sevenforums.com/system-se...-defender.html

Adaware will remove it
Hmm, where could I have picked it up from? I know I haven't viewed any pr0n or downloaded any torrents
__________________
1nf3rn0x is offline  
Reply With Quote
Old May 23, 2012, 09:49 AM   #4
Solaris17
Creator Solaris Utility DVD
 
Solaris17's Avatar
 
Join Date: Aug 2005
Location: Reinacting scenes from platoon with Charlie Sheen
Posts: 13,708 (4.84/day)
Thanks: 4,365
Thanked 3,295 Times in 2,311 Posts
Send a message via ICQ to Solaris17 Send a message via AIM to Solaris17 Send a message via MSN to Solaris17 Send a message via Yahoo to Solaris17 Send a message via Skype™ to Solaris17

System Specs

Malware iv had to remove this from customer pcs
__________________
I Made the Millionth post! | "Please come to WI now so I can beat you over the head with a bratwurst."-Kreij
PS3 mod 8500/8600GT Mod Guide Rebuild a Copperhead Heat Ware
NF4 Ultra SLI Mod Solaris Utility DVD 4.0 Broken CPU pin guide
Vista Mark
Solaris17 is offline  
Reply With Quote
The Following User Says Thank You to Solaris17 For This Useful Post:
Old May 23, 2012, 09:52 AM   #5
1nf3rn0x
1000 Posts
 
1nf3rn0x's Avatar
 
Join Date: Sep 2009
Location: Sydney, Australia
Posts: 1,707 (1.27/day)
Thanks: 509
Thanked 331 Times in 242 Posts

System Specs



I might post a screenie of everything running to see if there's any other crazy stuff on it. And what does this malware specifically do?

But I'm totally in shock, I haven't download a single torrent, nor looked at a single pr0n and haven't been on any websites that I know aren't safe. D:
__________________
1nf3rn0x is offline  
Reply With Quote
Old May 23, 2012, 10:03 AM   #6
Solaris17
Creator Solaris Utility DVD
 
Solaris17's Avatar
 
Join Date: Aug 2005
Location: Reinacting scenes from platoon with Charlie Sheen
Posts: 13,708 (4.84/day)
Thanks: 4,365
Thanked 3,295 Times in 2,311 Posts
Send a message via ICQ to Solaris17 Send a message via AIM to Solaris17 Send a message via MSN to Solaris17 Send a message via Yahoo to Solaris17 Send a message via Skype™ to Solaris17

System Specs

Quote:
Originally Posted by 1nf3rn0x View Post
http://img.techpowerup.org/120523/windefender136.jpg

I might post a screenie of everything running to see if there's any other crazy stuff on it. And what does this malware specifically do?

But I'm totally in shock, I haven't download a single torrent, nor looked at a single pr0n and haven't been on any websites that I know aren't safe. D:
its a downloader IIRC and dont be in such shock. Viruses appear in the wild. tighten the settings on your AV and scan more often.
__________________
I Made the Millionth post! | "Please come to WI now so I can beat you over the head with a bratwurst."-Kreij
PS3 mod 8500/8600GT Mod Guide Rebuild a Copperhead Heat Ware
NF4 Ultra SLI Mod Solaris Utility DVD 4.0 Broken CPU pin guide
Vista Mark
Solaris17 is offline  
Reply With Quote
Old May 23, 2012, 10:06 AM   #7
1nf3rn0x
1000 Posts
 
1nf3rn0x's Avatar
 
Join Date: Sep 2009
Location: Sydney, Australia
Posts: 1,707 (1.27/day)
Thanks: 509
Thanked 331 Times in 242 Posts

System Specs

Quote:
Originally Posted by Solaris17 View Post
its a downloader IIRC and dont be in such shock. Viruses appear in the wild. tighten the settings on your AV and scan more often.
I'm using Avast free and scan fortnightly, what else can I do

Any of this out of line? If I have one I probably have more D:










__________________

Last edited by 1nf3rn0x; May 23, 2012 at 10:18 AM.
1nf3rn0x is offline  
Reply With Quote
Old May 23, 2012, 10:17 AM   #8
Solaris17
Creator Solaris Utility DVD
 
Solaris17's Avatar
 
Join Date: Aug 2005
Location: Reinacting scenes from platoon with Charlie Sheen
Posts: 13,708 (4.84/day)
Thanks: 4,365
Thanked 3,295 Times in 2,311 Posts
Send a message via ICQ to Solaris17 Send a message via AIM to Solaris17 Send a message via MSN to Solaris17 Send a message via Yahoo to Solaris17 Send a message via Skype™ to Solaris17

System Specs

Quote:
Originally Posted by 1nf3rn0x View Post
I'm using Avast free and scan fortnightly, what else can I do
i mean i guess you could laugh but you did ask.

well for starters you can go into the avast CP and go to each individual shield control and tighten the security settings on it.

i modify

"Actions"
"packers"
"Sensitivity"

I suppose while we are being smart asses ill leave it at that. I mean if you cant figure it out thats part of the problem right?
__________________
I Made the Millionth post! | "Please come to WI now so I can beat you over the head with a bratwurst."-Kreij
PS3 mod 8500/8600GT Mod Guide Rebuild a Copperhead Heat Ware
NF4 Ultra SLI Mod Solaris Utility DVD 4.0 Broken CPU pin guide
Vista Mark
Solaris17 is offline  
Reply With Quote
Old May 23, 2012, 10:23 AM   #9
1nf3rn0x
1000 Posts
 
1nf3rn0x's Avatar
 
Join Date: Sep 2009
Location: Sydney, Australia
Posts: 1,707 (1.27/day)
Thanks: 509
Thanked 331 Times in 242 Posts

System Specs

Quote:
Originally Posted by Solaris17 View Post
i mean i guess you could laugh but you did ask.

well for starters you can go into the avast CP and go to each individual shield control and tighten the security settings on it.

i modify

"Actions"
"packers"
"Sensitivity"

I suppose while we are being smart asses ill leave it at that. I mean if you cant figure it out thats part of the problem right?
Can you check to see if the processes I have currently running are also not malware XD. I'm running a scan with Ad-aware so i'll be doing my maths homework while I wait
__________________
1nf3rn0x is offline  
Reply With Quote
Old May 23, 2012, 10:31 AM   #10
Solaris17
Creator Solaris Utility DVD
 
Solaris17's Avatar
 
Join Date: Aug 2005
Location: Reinacting scenes from platoon with Charlie Sheen
Posts: 13,708 (4.84/day)
Thanks: 4,365
Thanked 3,295 Times in 2,311 Posts
Send a message via ICQ to Solaris17 Send a message via AIM to Solaris17 Send a message via MSN to Solaris17 Send a message via Yahoo to Solaris17 Send a message via Skype™ to Solaris17

System Specs

all of the service check out.

make sure you have things like the windows firewall etc set to auto etc and havent made a bunch of custom rules.

go to gibson research

https://www.google.com/webhp?sourcei...w=1366&bih=653

mouse over the services tab click on shields up, press proceed and click on all service ports.

ideally thay should be all green
__________________
I Made the Millionth post! | "Please come to WI now so I can beat you over the head with a bratwurst."-Kreij
PS3 mod 8500/8600GT Mod Guide Rebuild a Copperhead Heat Ware
NF4 Ultra SLI Mod Solaris Utility DVD 4.0 Broken CPU pin guide
Vista Mark
Solaris17 is offline  
Reply With Quote
The Following User Says Thank You to Solaris17 For This Useful Post:
Old May 23, 2012, 10:33 AM   #11
1nf3rn0x
1000 Posts
 
1nf3rn0x's Avatar
 
Join Date: Sep 2009
Location: Sydney, Australia
Posts: 1,707 (1.27/day)
Thanks: 509
Thanked 331 Times in 242 Posts

System Specs

Quote:
Originally Posted by Solaris17 View Post
all of the service check out.

make sure you have things like the windows firewall etc set to auto etc and havent made a bunch of custom rules.

go to gibson research

https://www.google.com/webhp?sourcei...w=1366&bih=653

mouse over the services tab click on shields up, press proceed and click on all service ports.

ideally thay should be all green
Thanks!

Apparently windefend is not bad afterall? Open Windows Defender by clicking the Start button . In the search box, type Defender, and then, in the list of results, click Windows Defender. (from Micro$oft)

I have noticed that the program has now stopped as I am running ad-aware for a scan to remove it, when I try run the program (windows defender from start), windows says it has been stopped. I'm not sure but I;d rather be safe
__________________
1nf3rn0x is offline  
Reply With Quote
Old May 23, 2012, 10:40 AM   #12
Solaris17
Creator Solaris Utility DVD
 
Solaris17's Avatar
 
Join Date: Aug 2005
Location: Reinacting scenes from platoon with Charlie Sheen
Posts: 13,708 (4.84/day)
Thanks: 4,365
Thanked 3,295 Times in 2,311 Posts
Send a message via ICQ to Solaris17 Send a message via AIM to Solaris17 Send a message via MSN to Solaris17 Send a message via Yahoo to Solaris17 Send a message via Skype™ to Solaris17

System Specs

um no

windows defender is

MSASCui.exe


windefend is supposed to look like windows defender but it is not.
__________________
I Made the Millionth post! | "Please come to WI now so I can beat you over the head with a bratwurst."-Kreij
PS3 mod 8500/8600GT Mod Guide Rebuild a Copperhead Heat Ware
NF4 Ultra SLI Mod Solaris Utility DVD 4.0 Broken CPU pin guide
Vista Mark
Solaris17 is offline  
Reply With Quote
Old May 23, 2012, 10:43 AM   #13
1nf3rn0x
1000 Posts
 
1nf3rn0x's Avatar
 
Join Date: Sep 2009
Location: Sydney, Australia
Posts: 1,707 (1.27/day)
Thanks: 509
Thanked 331 Times in 242 Posts

System Specs

Quote:
Originally Posted by Solaris17 View Post
um no

windows defender is

MSASCui.exe


windefend is supposed to look like windows defender but it is not.
Oh. Thanks for clearing that up .
With me being 15 I haven't delved into this side of windows
__________________
1nf3rn0x is offline  
Reply With Quote
Old May 23, 2012, 10:45 AM   #14
Solaris17
Creator Solaris Utility DVD
 
Solaris17's Avatar
 
Join Date: Aug 2005
Location: Reinacting scenes from platoon with Charlie Sheen
Posts: 13,708 (4.84/day)
Thanks: 4,365
Thanked 3,295 Times in 2,311 Posts
Send a message via ICQ to Solaris17 Send a message via AIM to Solaris17 Send a message via MSN to Solaris17 Send a message via Yahoo to Solaris17 Send a message via Skype™ to Solaris17

System Specs

__________________
I Made the Millionth post! | "Please come to WI now so I can beat you over the head with a bratwurst."-Kreij
PS3 mod 8500/8600GT Mod Guide Rebuild a Copperhead Heat Ware
NF4 Ultra SLI Mod Solaris Utility DVD 4.0 Broken CPU pin guide
Vista Mark
Solaris17 is offline  
Reply With Quote
The Following User Says Thank You to Solaris17 For This Useful Post:
Old May 23, 2012, 11:09 AM   #15
1nf3rn0x
1000 Posts
 
1nf3rn0x's Avatar
 
Join Date: Sep 2009
Location: Sydney, Australia
Posts: 1,707 (1.27/day)
Thanks: 509
Thanked 331 Times in 242 Posts

System Specs

Ad-aware just said it had removed it. Rebooted pc. Now what?




Can I find the exe?

Item Name: Windows Defender
Author: Unknown
Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\WINDEFENDER.EXE
Type: Explorer Run

Item Name: {FF92BFB4-4DDA-FFC7-C394-6D8A0C9D5DEB}
Author: Unknown
Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\WINDEFENDER.EXE
Type: ActiveSetup

Item Name: WinDefender.exe
Author: Unknown
Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\WINDEFENDER.EXE
Type: Running Processes
__________________
1nf3rn0x is offline  
Reply With Quote
Old May 23, 2012, 11:14 AM   #16
Solaris17
Creator Solaris Utility DVD
 
Solaris17's Avatar
 
Join Date: Aug 2005
Location: Reinacting scenes from platoon with Charlie Sheen
Posts: 13,708 (4.84/day)
Thanks: 4,365
Thanked 3,295 Times in 2,311 Posts
Send a message via ICQ to Solaris17 Send a message via AIM to Solaris17 Send a message via MSN to Solaris17 Send a message via Yahoo to Solaris17 Send a message via Skype™ to Solaris17

System Specs

enable hidden files and folders if you havent already check for windefend.exe in these places.

C:\Documents and Settings\User\Application Data\WinDefend.exe

C:\Windows\System\WinDefend.exe

but first kill the process.

then press windows key+R and type

"msconfig"

go to the startup tab and show me everything in it.
__________________
I Made the Millionth post! | "Please come to WI now so I can beat you over the head with a bratwurst."-Kreij
PS3 mod 8500/8600GT Mod Guide Rebuild a Copperhead Heat Ware
NF4 Ultra SLI Mod Solaris Utility DVD 4.0 Broken CPU pin guide
Vista Mark
Solaris17 is offline  
Reply With Quote
Old May 23, 2012, 11:16 AM   #17
temp02
200 Posts
 
Join Date: Mar 2009
Posts: 490 (0.32/day)
Thanks: 0
Thanked 171 Times in 158 Posts

Quote:
Originally Posted by Solaris17 View Post
um no

windows defender is

MSASCui.exe


windefend is supposed to look like windows defender but it is not.
Sorry but we are talking about services, and believe it or not, the legit Windows Defender service (Microsoft anti malware that is shipped with Windows Vista, and later, on install) is called WinDefend. And if you don't believe me, try running it yourself:
Code:
sc start WinDefend
If you don't want it running (or you have another anti-virus solution running), launch a command prompt in admin mode and do this:
Code:
sc config WinDefend start="disabled"
sc stop WinDefend
Good luck.
temp02 is offline  
Reply With Quote
The Following User Says Thank You to temp02 For This Useful Post:
Old May 23, 2012, 11:24 AM   #18
1nf3rn0x
1000 Posts
 
1nf3rn0x's Avatar
 
Join Date: Sep 2009
Location: Sydney, Australia
Posts: 1,707 (1.27/day)
Thanks: 509
Thanked 331 Times in 242 Posts

System Specs

Quote:
Originally Posted by temp02 View Post
Sorry but we are talking about services, and believe it or not, the legit Windows Defender service (Microsoft anti malware that is shipped with Windows Vista, and later, on install) is called WinDefend. And if you don't believe me, try running it yourself:
Code:
sc start WinDefend
If you don't want it running (or you have another anti-virus solution running), launch a command prompt in admin mode and do this:
Code:
sc config WinDefend start="disabled"
sc stop WinDefend
Good luck.
That worked, thanks. I'll reboot and see if it stays. Should I be running it or not?
__________________
1nf3rn0x is offline  
Reply With Quote
Old May 23, 2012, 11:27 AM   #19
temp02
200 Posts
 
Join Date: Mar 2009
Posts: 490 (0.32/day)
Thanks: 0
Thanked 171 Times in 158 Posts

If you have another Anti-Virus suite installed (like Nod32) you can probably disable Windows Defender and still be protected against malware intrusions (truth be told, Defender without Security Essentials isn't gonna protect you against much anyway :P).
temp02 is offline  
Reply With Quote
Old May 23, 2012, 11:31 AM   #20
1nf3rn0x
1000 Posts
 
1nf3rn0x's Avatar
 
Join Date: Sep 2009
Location: Sydney, Australia
Posts: 1,707 (1.27/day)
Thanks: 509
Thanked 331 Times in 242 Posts

System Specs

Quote:
Originally Posted by temp02 View Post
If you have another Anti-Virus suite installed (like Nod32) you can probably disable Windows Defender and still be protected against malware intrusions (truth be told, Defender without Security Essentials isn't gonna protect you against much anyway :P).
If I go into my brothers computer I see no such thing in his processes so why is that? Even when I ran the denfender from start menu nothing appeared.
__________________
1nf3rn0x is offline  
Reply With Quote
Old May 23, 2012, 11:35 AM   #21
Solaris17
Creator Solaris Utility DVD
 
Solaris17's Avatar
 
Join Date: Aug 2005
Location: Reinacting scenes from platoon with Charlie Sheen
Posts: 13,708 (4.84/day)
Thanks: 4,365
Thanked 3,295 Times in 2,311 Posts
Send a message via ICQ to Solaris17 Send a message via AIM to Solaris17 Send a message via MSN to Solaris17 Send a message via Yahoo to Solaris17 Send a message via Skype™ to Solaris17

System Specs

Quote:
Originally Posted by 1nf3rn0x View Post
If I go into my brothers computer I see no such thing in his processes so why is that? Even when I ran the denfender from start menu nothing appeared.
I think he was trying to correct me. I dont think his post was aimed at you. besides im staring at your infection

Quote:
Originally Posted by 1nf3rn0x View Post

Item Name: Windows Defender
Author: Unknown
Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\WINDEFENDER.EXE
Type: Explorer Run

Item Name: {FF92BFB4-4DDA-FFC7-C394-6D8A0C9D5DEB}
Author: Unknown
Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\WINDEFENDER.EXE
Type: ActiveSetup

Item Name: WinDefender.exe
Author: Unknown
Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\WINDEFENDER.EXE
Type: Running Processes
__________________
I Made the Millionth post! | "Please come to WI now so I can beat you over the head with a bratwurst."-Kreij
PS3 mod 8500/8600GT Mod Guide Rebuild a Copperhead Heat Ware
NF4 Ultra SLI Mod Solaris Utility DVD 4.0 Broken CPU pin guide
Vista Mark
Solaris17 is offline  
Reply With Quote
Old May 23, 2012, 11:36 AM   #22
temp02
200 Posts
 
Join Date: Mar 2009
Posts: 490 (0.32/day)
Thanks: 0
Thanked 171 Times in 158 Posts

Windows Defender can't be started from the "Run" thingy like any other program, it's a service, if you want to start it on your brothers computer you need to run
Code:
sc start WinDefend
on an admin command prompt.
temp02 is offline  
Reply With Quote
Old May 23, 2012, 11:38 AM   #23
1nf3rn0x
1000 Posts
 
1nf3rn0x's Avatar
 
Join Date: Sep 2009
Location: Sydney, Australia
Posts: 1,707 (1.27/day)
Thanks: 509
Thanked 331 Times in 242 Posts

System Specs

Quote:
Originally Posted by Solaris17 View Post
I think he was trying to correct me. I dont think his post was aimed at you. besides im staring at your infection

So it's a virus?

The data posted is not mine, from a website about WinDefend.

Solaris do you have skype or teamviewer? I think more can be done there!
__________________

Last edited by 1nf3rn0x; May 23, 2012 at 11:44 AM.
1nf3rn0x is offline  
Reply With Quote
Old May 23, 2012, 11:45 AM   #24
Solaris17
Creator Solaris Utility DVD
 
Solaris17's Avatar
 
Join Date: Aug 2005
Location: Reinacting scenes from platoon with Charlie Sheen
Posts: 13,708 (4.84/day)
Thanks: 4,365
Thanked 3,295 Times in 2,311 Posts
Send a message via ICQ to Solaris17 Send a message via AIM to Solaris17 Send a message via MSN to Solaris17 Send a message via Yahoo to Solaris17 Send a message via Skype™ to Solaris17

System Specs

Quote:
Originally Posted by 1nf3rn0x View Post
So it's a virus?

The data posted is not mine, from a website about WinDefend.
well you said adaware found it. and i gave you the paths. i suppose you could always go look.
__________________
I Made the Millionth post! | "Please come to WI now so I can beat you over the head with a bratwurst."-Kreij
PS3 mod 8500/8600GT Mod Guide Rebuild a Copperhead Heat Ware
NF4 Ultra SLI Mod Solaris Utility DVD 4.0 Broken CPU pin guide
Vista Mark
Solaris17 is offline  
Reply With Quote
Old May 23, 2012, 11:47 AM   #25
qubit
Overclocked quantum bit
 
qubit's Avatar
 
Join Date: Dec 2007
Location: Quantumville UK
Posts: 8,643 (4.34/day)
Thanks: 4,171
Thanked 3,301 Times in 1,941 Posts

System Specs

@1nf3rn0x

As you have malware on your system, the only guaranteed way of removing it, plus ensuring that Windows works reliably and properly, is to format your system disc and reinstall from scratch - or just put an image over it instead if you have one, which accomplishes the same thing. Make sure to back up any data first...

And how did it get on your system? The reason is in what you said: manual virus scan every two weeks with a free a/v. You might as well not bother. It's critical to have realtime scans done from a reputable a/v company. Personally, I've used the excellent Kaspersky Internet Security for years and its stopped a few nasties in its time.
__________________
Siggie in the post.
qubit is offline  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
HTPC - can I use what I have? What should I buy? Suggestions? Black Panther System Builder's Advice 6 Jan 12, 2011 10:50 AM
What do these voltages do & what is the best setting for each? Wingo101 Overclocking & Cooling 3 Jan 1, 2009 06:00 PM
What do you pick - E21xx OR E7200 OR Others, and what RAM? Wai_Wai General Hardware 11 Sep 10, 2008 06:44 PM
What is a MOSFET, what does it look like, and where are they on my motherboard? W1zzard Articles 0 May 24, 2004 08:11 AM


All times are GMT. The time now is 08:29 PM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts