Author Topic: Safe or a virus? wpwin8-exe  (Read 10803 times)

0 Members and 1 Guest are viewing this topic.

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Safe or a virus? wpwin8-exe
« on: February 20, 2015, 09:05:28 pm »
« Last Edit: February 20, 2015, 09:55:45 pm by Rick »

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: Safe or a virus? wpwin8-exe
« Reply #1 on: February 20, 2015, 10:43:18 pm »
http://www.removeonline.com/wpwin8-exe/

another idea to look at; download to try and does it chk online?
http://systemexplorer.net/installdone.php?v=6.3.2.5317&au=1&iu=0

file attached is where it was loaded

research ;

Windows Vista Security update for August 2008
http://www.uninformed.org/?v=5&a=2&t=sumry

SEH chain validation
Windows Server 2008 introduced a new SEH protection mechanism that detects exception
handler record overwrites by validating the SEH linked list. This protection mechanism
is enabled by default on Windows Server 2008. It is also available on Vista SP1, but is
not turned on by default. It can be enabled by setting the undocumented registry key
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\DisableExceptionChainValidation
to 0.

-------

On 64-bit versions of Windows, DEP is always turned on for 64-bit processes and cannot be
disabled. However, Internet Explorer on Vista x64 is still a 32-bit process and is subject to the
policies described above.

DLLs that are listed in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Image File Execution Options\DllNXOptions registry key. This key
contains a list of DLLs that are known to be incompatible with DEP.

DEP always on
Control Panel -> System -> Advanced System Settings ->
System Properties window -> Advanced tab -> Performance -> Settings ->
Performance Options window -> Data Execution Prevention tab -> Turn on DEP for all programs
IF you see: 'Your computer's processor supports hardware-based DEP'

editor's note: I run with DEP on all of my 32bit and 64bit Vista Home and Vista
Ultimate. I've only found one program, an obscure flash player, that won't work
with DEP enabled, and it only takes a minute to add it the the 'exceptions' list.
« Last Edit: February 20, 2015, 11:10:31 pm by Rick »

Offline Shane

  • Administrator
  • Hero Member
  • *****
  • Join Date: Sep 2011
  • Posts: 9281
  • Location: USA
  • Karma: 137
  • "Knowledge should be shared not hidden."
    • View Profile
Re: Safe or a virus? wpwin8-exe
« Reply #2 on: February 21, 2015, 12:01:15 am »
Did you upload it to virustotal.com to see what the AV's show?

Shane

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: Safe or a virus? wpwin8-exe
« Reply #3 on: February 21, 2015, 12:19:34 am »
Did you upload it to virustotal.com to see what the AV's show?

Shane

the reg key is still their with no functions, can chk the txt file i added, file not found on system
remnant of?

Offline Boggin

  • Global Moderator
  • Hero Member
  • *****
  • Join Date: Jul 2014
  • Posts: 10182
  • Location: UK
  • Karma: 122
    • View Profile
Re: Safe or a virus? wpwin8-exe
« Reply #4 on: February 21, 2015, 06:13:34 am »
Download Process Explorer https://technet.microsoft.com/en-gb/sysinternals/bb896653.aspx

When you have the program up and running, click on Options - ensure Verify Signatures is checked then hover over VirusTotal.com and check its box.

That will give you its column in blue where you should be able to see that file.

If it has a red high value/~50 and it isn't listed as a Corel file, then delete it.

Check for any other similar red valued files and Google to see what they are if their Signature isn't verified.

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: Safe or a virus? wpwin8-exe
« Reply #5 on: February 22, 2015, 12:11:12 am »
Did you upload it to virustotal.com to see what the AV's show?

Shane

shane, can you consolidate your idea with boggins, thanks in advance

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: Safe or a virus? wpwin8-exe
« Reply #6 on: February 22, 2015, 01:46:42 am »
Download Process Explorer https://technet.microsoft.com/en-gb/sysinternals/bb896653.aspx

When you have the program up and running, click on Options - ensure Verify Signatures is checked then hover over VirusTotal.com and check its box.

That will give you its column in blue where you should be able to see that file.

If it has a red high value/~50 and it isn't listed as a Corel file, then delete it.

Check for any other similar red valued files and Google to see what they are if their Signature isn't verified.

did you download my txt file?

Offline Boggin

  • Global Moderator
  • Hero Member
  • *****
  • Join Date: Jul 2014
  • Posts: 10182
  • Location: UK
  • Karma: 122
    • View Profile
Re: Safe or a virus? wpwin8-exe
« Reply #7 on: February 22, 2015, 02:09:29 am »
Which one ? - is this it http://www.tweaking.com/forums/index.php?action=dlattach;topic=2820.0;attach=4724

It may tell Shane something but it doesn't do anything for me.
« Last Edit: February 22, 2015, 02:26:55 am by Boggin »

Offline Shane

  • Administrator
  • Hero Member
  • *****
  • Join Date: Sep 2011
  • Posts: 9281
  • Location: USA
  • Karma: 137
  • "Knowledge should be shared not hidden."
    • View Profile
Re: Safe or a virus? wpwin8-exe
« Reply #8 on: February 23, 2015, 09:12:27 pm »
Only text file on the post was just the one with the image options in the registry which doesnt tell any information.

Thats why I wanted to see what virus total says on it, not only does it scan it but it also gives more detailed info about the exe itself, upload it to virus total then just copy and past the link of the results and I can take a look. :wink:

Shane

Offline Boggin

  • Global Moderator
  • Hero Member
  • *****
  • Join Date: Jul 2014
  • Posts: 10182
  • Location: UK
  • Karma: 122
    • View Profile
Re: Safe or a virus? wpwin8-exe
« Reply #9 on: February 24, 2015, 02:02:27 am »
When I Googled it, it came up as a Corel file but VirusTotal in Process Explorer, should confirm its Signature give a it security rating.

http://searchtasks.answersthatwork.com/tasklist.php?File=Wpwin8

http://www.pcpitstop.com/libraries/fileextension/application.asp?appname=wpwin8.exe.html