SecTeer VulnDetect & PatchPro Support Forum VulnDetect
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Download VulnDetect Installer
    • Login

    Detected Applications - There is no data to display.

    Scheduled Pinned Locked Moved Bugs and issues
    21 Posts 2 Posters 10.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      KI108 @Tom
      last edited by

      @Tom
      As mentioned in chat
      Running immediate
      with "C:" gave

      [2018-12-21 18:05:10.392-0360] Enumerating 'c:'
      [2018-12-21 18:05:10.419-0360] Recycle Bin: c:$Recycle.Bin
      [2018-12-21 18:05:10.421-0360] Skipping 'c:$Recycle.Bin', since it is a Recycle Bin
      [2018-12-21 18:05:10.442-0360] Error (a) enumerating directory 'c:\Documents and Settings' : 0x00000005 => Access is denied.
      [2018-12-21 18:05:21.171-0360] Error (a) enumerating directory 'c:\ProgramData\Application Data' : 0x00000005 => Access is denied.
      [2018-12-21 18:05:21.173-0360] Error (a) enumerating directory 'c:\ProgramData\Desktop' : 0x00000005 => Access is denied.
      [2018-12-21 18:05:21.174-0360] Error (a) enumerating directory 'c:\ProgramData\Documents' : 0x00000005 => Access is denied.
      [2018-12-21 18:05:21.768-0360] Error (a) enumerating directory 'c:\ProgramData\Microsoft\Diagnosis\FeedbackHub' : 0x00000005 => Access is denied.
      Error (a) enumerating directory 'c:\ProgramData\Microsoft\Diagnosis\TenantStorage\P-ARIA' : 0x00000005 => Access is denied.
      [2018-12-21 18:05:21.769-0360] Error (a) enumerating directory 'c:\ProgramData\Microsoft\Diagnosis\TimeTravelDebuggingStorage' : 0x00000005 => Access is denied.
      [2018-12-21 18:05:21.968-0360] Error (a) enumerating directory 'c:\ProgramData\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files\Documents and Settings' : 0x00000005 => Access is denied.
      [2018-12-21 18:05:22.381-0360] Error (a) enumerating directory 'c:\ProgramData\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files\ProgramData\Application Data' : 0x00000005 => Access is denied.
      [2018-12-21 18:05:22.381-0360]

      K 1 Reply Last reply Reply Quote 0
      • K Offline
        KI108 @KI108
        last edited by

        Basically it starts of with 34% memory and slowly increased around 80%, before it quit with bad allocation. The Secteer itself starts of around 2 MB or so and slowly went past 2000 MB or so.

        Mostly it was c:\ProgramData\Microsoft\Windows... or \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\ which was doing recursively inside up to 23 times in one path like below

        [2018-12-21 18:10:58.180-0360] Error (a) enumerating directory 'c:\Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files

        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files

        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\All Users\Microsoft\Windows\Containers\BaseImages\e5ee5788-c3b5-420c-9baa-16c0eee19a9e\Files
        \Users\WDAGUtilityAccount\AppData\Local\Application Data' : 0x00000005 => Access is denied.

        K 1 Reply Last reply Reply Quote 0
        • K Offline
          KI108 @KI108
          last edited by

          C:\ProgramData\Microsoft\Windows\Containers

          Directory of C:\ProgramData\Microsoft\Windows\Containers

          10/02/2018 11:00 PM <DIR> .
          10/02/2018 11:00 PM <DIR> ..
          12/21/2018 06:47 PM <DIR> BaseImages
          12/22/2018 11:54 AM <DIR> Dumps
          12/21/2018 08:20 PM <DIR> Sandboxes
          12/21/2018 08:20 PM <DIR> Zygotes
          0 File(s) 0 bytes
          6 Dir(s) 230,609,969,152 bytes free

          Directory of C:\ProgramData\Microsoft\Windows\Containers\BaseImages

          12/21/2018 06:47 PM <DIR> .
          12/21/2018 06:47 PM <DIR> ..
          12/21/2018 06:47 PM <DIR> 81d3cadc-05e5-4680-9e82-e479c73896b6
          0 File(s) 0 bytes

          Directory of C:\ProgramData\Microsoft\Windows\Containers\BaseImages\81d3cadc-05e5-4680-9e82-e479c73896b6

          12/21/2018 06:47 PM <DIR> .
          12/21/2018 06:47 PM <DIR> ..
          12/21/2018 06:46 PM <DIR> Files
          12/21/2018 06:47 PM <DIR> Snapshot
          12/21/2018 06:46 PM 4,194,304 SystemTemplate.vhdx
          12/21/2018 06:46 PM 75,497,472 SystemTemplateBase.vhdx
          2 File(s) 79,691,776 bytes
          4 Dir(s) 230,609,874,944 bytes free

          File folder

          C:\ProgramData\Microsoft\Windows

          3.23 GB (3,469,314,133 bytes)

          10,497 Files, 1,134 Folders

          Read-only (Only applies to files in folder)

          These were Containers Properties under C:\ProgramData\Microsoft\Windows

          K 1 Reply Last reply Reply Quote 0
          • K Offline
            KI108 @KI108
            last edited by

            For the time being I ran Secteer immediate for path C:\Program files and again with C:\Program Files (x86) to see if any software was not latest and I found two.
            After Secunia PSI went away, I have been using PatchMyPC, SUMO, Heimdal Pro to see what needs updating. Unlike Secunia which used to show almost everything, these 3 give bits and pieces and that is why I was looking for a better option.
            Thanks for looking into this.
            Like Secteer excludes scanning Recycle Bin, similarly this directory structure of Containers needs to be excluded also.
            C:\ProgramData\Microsoft\Windows
            and
            C:\Users\All Users\Microsoft\Windows
            That's my thought.
            @Tom Once again appreciate your time and patience in resolving these issues.

            1 Reply Last reply Reply Quote 0
            • T Offline
              Tom VulnDetect Team Member
              last edited by

              For some reason there is an issue in that folder, that cause the structure to recurse / loop endlessly.

              We are looking at approaches to avoid following such loops (in a generic way, rather than excluding that specific folder). Due to the holidays a solution is not right around the corner, but it is on the high priority list and we will address it soon.

              /Tom
              Download the latest SecTeer VulnDetect agent here:
              https://vulndetect.com/dl/secteerSetup.exe

              K 1 Reply Last reply Reply Quote 0
              • K Offline
                KI108 @Tom
                last edited by KI108

                @Tom
                Another question. Does one need to be logged in through browser for inspections to work? The reason I ask is, I did not login to vulndetect.com for few days and when i logged in today, I see last inspection 6 days ago.

                Last CheckIn a minute ago

                Last Inspection 6 days ago

                Next CheckIn in 11 minutes

                T 1 Reply Last reply Reply Quote 0
                • T Offline
                  Tom VulnDetect Team Member @KI108
                  last edited by

                  @KI108 No, the agent will run if the PC is turned on. So no need for logging in via browser.

                  But I suppose this could be because even the automatic inspection is failing for you.

                  Could you send me your log again via email?

                  /Tom
                  Download the latest SecTeer VulnDetect agent here:
                  https://vulndetect.com/dl/secteerSetup.exe

                  K 1 Reply Last reply Reply Quote 0
                  • K Offline
                    KI108 @Tom
                    last edited by

                    @Tom
                    I have emailed the log to you. Thanks for looking into it.

                    K 1 Reply Last reply Reply Quote 0
                    • K Offline
                      KI108 @KI108
                      last edited by

                      @Tom
                      It was set to 08:20 CST and I had changed to 09:20 CST to force it yesterday but it still didn't do anything.

                      Last CheckIn 14 minutes ago

                      Last Inspection 7 days ago

                      Next CheckIn in 9 minutes

                      Next Inspection in 9 minutes

                      Will see what happens in the next 10 minutes

                      K 1 Reply Last reply Reply Quote 0
                      • K Offline
                        KI108 @KI108
                        last edited by

                        @Tom
                        It worked this time.

                        Last CheckIn a minute ago

                        Last Inspection a minute ago

                        Next CheckIn in an hour

                        Next Inspection in a day

                        Though it did the c:\ and came back with the bad allocation after all the 0x00000005 => Access is denied.

                        Also the version still shows version:: 0.10.11.0 in the log. With the back -end changes you mentioned in other post of Nothing to see was this supposed to change?

                        T 2 Replies Last reply Reply Quote 0
                        • T Offline
                          Tom VulnDetect Team Member @KI108
                          last edited by

                          @KI108 Yes, this was expected 😞
                          We did not have time to work on changes to the agent yet, and this is something that we need to investigate and test properly, before we deploy it.
                          And I'm afraid that we need to clear an issue or two more before we can fix this one, sorry.
                          I'll keep you posted when there is news.

                          /Tom
                          Download the latest SecTeer VulnDetect agent here:
                          https://vulndetect.com/dl/secteerSetup.exe

                          1 Reply Last reply Reply Quote 0
                          • T Offline
                            Tom VulnDetect Team Member @KI108
                            last edited by

                            @KI108 Sorry for the long wait, we are planning to make improvements to the agent during next week. I hope you have time to test later in the week.

                            /Tom
                            Download the latest SecTeer VulnDetect agent here:
                            https://vulndetect.com/dl/secteerSetup.exe

                            K 1 Reply Last reply Reply Quote 0
                            • K Offline
                              KI108 @Tom
                              last edited by

                              @Tom Sure, I will once you update the agent. Thanks for looking into it.

                              T 1 Reply Last reply Reply Quote 0
                              • T Offline
                                Tom VulnDetect Team Member @KI108
                                last edited by

                                @KI108 We now have a new version of the agent, can you please test it and report back to us?
                                https://test.vulndetect.com/dl/secteerSetup.exe

                                The new version is NOT available from the normal download location yet.

                                /Tom
                                Download the latest SecTeer VulnDetect agent here:
                                https://vulndetect.com/dl/secteerSetup.exe

                                K 1 Reply Last reply Reply Quote 0
                                • K Offline
                                  KI108 @Tom
                                  last edited by

                                  @Tom Thanks. It worked now.
                                  Though it scanned some of the Containers sub directories like below, but it did complete - Enumerated filesystem in 15.439ms

                                  Adobe Flash Player	32.0.0.114	Ok	
                                  

                                  By: Adobe Systems Incorporated
                                  Based on: C:\ProgramData\Microsoft\Windows\Containers\BaseImages\2bf54f2a-aaae-44b6-af12-df9f443cfa5b\Files\Users\All Users\Microsoft\Windows\Containers\BaseImages\2bf54f2a-aaae-44b6-af12-df9f443cfa5b\Files\Windows\System32\Macromed\Flash\Flash.ocx
                                  Open product homepage

                                  curl	7.55.1	Insecure	  
                                  

                                  Recommended version: 7.63 Ok
                                  By: haxx.se
                                  Based on: C:\ProgramData\Microsoft\Windows\Containers\BaseImages\2bf54f2a-aaae-44b6-af12-df9f443cfa5b\Files\Users\All Users\Microsoft\Windows\Containers\BaseImages\2bf54f2a-aaae-44b6-af12-df9f443cfa5b\Files\Windows\System32\curl.exe
                                  Open product homepage

                                  Some are marked as Unknown / Untracked

                                  Microsoft Office 2016	16.0.11126.20200	                   Unknown	
                                  Microsoft Outlook 2016	16.0.11126.20266	           Unknown	
                                  Microsoft PowerPoint 2016	16.0.11126.20266	   Unknown	
                                  Microsoft Word 2016	16.0.11126.20266	                   Unknown	
                                  Opera Internet Browser	58.0.3135.53	Untracked Unknown	
                                  Amazon Kindle for PC	1.25.1.52064	        Untracked  Ok
                                  
                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Download SecTeer Personal VulnDetect - an alternative to the long lost Secunia PSI

                                  Please see our Privacy and Data Processing Policy
                                  Sponsored and operated by SecTeer | VulnDetect is a replacement for the EoL Secunia PSI
                                  Forum software by NodeBB