Paul's "X" files

Discussion in 'Windows 10' started by PaulDesmond, Oct 1, 2014.

Thread Status:
Not open for further replies.
  1. Nucleus

    Nucleus MDL Guru

    Aug 4, 2009
    2,868
    2,950
    90
    #121 Nucleus, Dec 2, 2014
    Last edited by a moderator: Apr 20, 2017
    Just grabbed this off PD's box ( Thank you PD ;) ) and SHA1 hash matches the published 4F16...

    Code:
    JM1_CCSA_X64FRE_EN-US_DV5.iso
    SHA1: 4F1609E39F1A067AE00D39C3EED7B099EDE83C07
    hash.png
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. PaulDesmond

    PaulDesmond MDL Magnet

    Aug 6, 2009
    6,979
    7,149
    240
    lol .. it was the last significant bit which I saved for last :druff:
     
  3. Mr.X

    Mr.X MDL Guru

    Jul 14, 2013
    8,575
    15,646
    270
    Then sorry for the double upload Paul :laie:
     
  4. Mr.X

    Mr.X MDL Guru

    Jul 14, 2013
    8,575
    15,646
    270
    Nope. I hashed it and it was good... From the very first time :D
     
  5. MrG

    MrG MDL Expert

    May 31, 2010
    1,403
    1,626
    60
    I just installed the 1 I downloaded, it installed (clean) fine in 19 minutes in VMware 9.
    Its is the x64 Professional edition.
     
  6. Skaendo

    Skaendo MDL Addicted

    Sep 23, 2014
    888
    534
    30
    #126 Skaendo, Dec 2, 2014
    Last edited: Dec 2, 2014
    I've downloaded both and there is something different between the 2.
    first one I downloaded 4f160........
    then I downloaded the other one and qbittorrent proceeded to check the first one against the second and found an anomaly.
    So I installed the second one and ran malwarebytes. 2 objects detected.

    Anyone who has downloaded either of these please scan for virus' and spy/malware!

    sha1: 4f1609e39f1a067ae00d39c3eed7b099ede83c07
    sha1: d31e75e0bc2fdeee517b2514b37eb7cfa6a88505

    Security.Hijack HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\svchost.exe

    Security.Hijack HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\svchost.exe

    UPDATE:

    I have scanned 4f1609......... and found the same bugs.
    Someone needs to look into this!

     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  7. davidtuning

    davidtuning MDL Novice

    Aug 10, 2012
    36
    8
    0
    So, what version is free of virus?
     
  8. Underclocked

    Underclocked MDL Member

    Sep 3, 2013
    247
    42
    10
    Downloaded one per the magnet link in this thread. Bitdefender found virus in one of the system files (sorry, can't be more specific as to which file as my CRS is flaring up). I had upgraded 9879 to 9888 before the virus was located. Might be a false positive, don't know as I didn't follow up on it. Back to 8.1 and 9888 is going bye-bye now.
     
  9. murphy78

    murphy78 MDL DISM Enthusiast

    Nov 18, 2012
    7,389
    11,614
    240
    It wouldn't surprise me if svchost was returning false positives for hijack.
    That's kind-of it's entire function.
     
  10. Mr.X

    Mr.X MDL Guru

    Jul 14, 2013
    8,575
    15,646
    270
    Then how can this happen murphy? I mean an A/V detecting a legitimate function?
     
  11. EFA11

    EFA11 Avatar Guru

    Oct 7, 2010
    8,719
    6,741
    270
    #131 EFA11, Dec 3, 2014
    Last edited by a moderator: Apr 20, 2017
  12. Underclocked

    Underclocked MDL Member

    Sep 3, 2013
    247
    42
    10
    Okay, scanned my Win10 drive with Avast from 8.1 and came up clean. The quarantined file was Windows\syswow64\wpc.dll
     
  13. Skaendo

    Skaendo MDL Addicted

    Sep 23, 2014
    888
    534
    30
    I wouldn't be a bit suprised if it was a false positive either, since I got the same report from both versions that I downloaded and tested.
    I'm still wondering about why sha1: 4f1609e39f1a067ae00d39c3eed7b099ede83c07 and sha1: d31e75e0bc2fdeee517b2514b37eb7cfa6a88505 have 1 bit difference.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  14. murphy78

    murphy78 MDL DISM Enthusiast

    Nov 18, 2012
    7,389
    11,614
    240
    My guess? They search for known exploits such as exe system files not in correct location.
    Also could be searching for certain code that allows control over the ACL stuff.
     
  15. Shayne

    Shayne MDL Addicted

    Jul 31, 2009
    752
    181
    30
    Straight from M$

    Computer viruses are small software programs that are designed to spread from one computer to another and to interfere with computer operation.

    Keygens and numerous other exec files do not do this but are still tagged as virus to scare the masses into not using them and deleting them.

    The worst virus I can remember was the Michelangelo (computer virus) of 1991 written to spread to a floppy disk every time inserted since there was no email or internet. It spread from office to office on a floppy disk since no one had virus scanners then. It was to have a time bomb but I never lost any of our whooping 20 meg hard drives.

    So Norton the producer of the first virus scanner and ruler of the y2k scare was born and the black box virus scare continues today and is blamed every time people screw up their OS or something does not work the way they want it.

    I would have a tendency of trusting the boyz here, they seem to know what they are doing.

    Regards
     
  16. PaulDesmond

    PaulDesmond MDL Magnet

    Aug 6, 2009
    6,979
    7,149
    240
    Today I like to announce a new entry in X-files section: Microsoft Desktop Optimization Pack R2 multi-language :D

    enjoy


    credits to fellow member BAV0
     
  17. bchat

    bchat MDL Smart Azz

    Nov 7, 2008
    1,722
    453
    60
    At this very moment I am conferring with the other angels up here about anointing you Saint Paul. I base this on your endless contribution to MDL, jazz music, and grape growers everywhere. I'll let you know the results of this conference at a future date.

    FYI - None of us angels are thrilled with the new "cloud" storage plans. We don't mess with your backyards, we don't want you messing with ours.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  18. apologized

    apologized MDL Addicted

    Nov 29, 2012
    874
    507
    30
    Thanks Paul for the update
    day after day ... Suprise us with gifts
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  19. PaulDesmond

    PaulDesmond MDL Magnet

    Aug 6, 2009
    6,979
    7,149
    240
    placed latest leak of Chinese iso into the X-file section for easy deployment

    credits Bobby M
     
  20. prijatelj.v

    prijatelj.v MDL Novice

    May 9, 2013
    35
    1
    0
    #140 prijatelj.v, Dec 13, 2014
    Last edited by a moderator: Dec 13, 2014
    hey "PaulDesmond"...my friend,brother,cousin,etc.

    I need to win 10 9888 32bit. (ISO) "checked installation"
    for a person dear to me...
    but looking.....give a link to brother (each gave you my friend)...

    I urgently this...