<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>wssc.exe in Security</title>
<link>http://www.dslreports.com/forum/r17102166</link>
<description></description>
<language>en</language>
<pubDate>Sun, 06 Dec 2009 09:15:01 EDT</pubDate>
<lastBuildDate>Sun, 06 Dec 2009 09:15:01 EDT</lastBuildDate>

<item>
<title>Re: wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17120904</link>
<description><![CDATA[<A HREF="/useremail/u/773102"><b>richtig</b></A> : Icesword didn't find it.<br><br>I think WINSEC.EXE was being created by WSSC.EXE, at least I hope so. It hasn't raised its ugly head again.<br><br>I have just removed the blocking rule for WSSC.EXE from Blink, so I will now wait and see.<br><SMALL>--<br><B>We are the music makers,We are the dreamers of dreams.<I>Arthur William Edgar O'Shaugnessy</I></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17120904</guid>
<pubDate>Thu, 19 Oct 2006 23:27:50 EDT</pubDate>
</item>

<item>
<title>Re: wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17119013</link>
<description><![CDATA[<A HREF="/useremail/u/1162456"><b>fatdcuk</b></A> : Not quite,<br><br>WINSEC.EXE is still MIA,KAV must of updated FWIW to find what it has ;)<br><br>Richtig<br><br>Try IceSword(its good at grabbin UPX malwares amongst other things :D)<br><br>&raquo;<A HREF="http://majorgeeks.com/Icesword_d5199.html" >majorgeeks.com/Icesword_d5199.html</A><br><br>Open the software,left hand column file box and then follow the folder tree to the reported folder location.Scroll down to entry if found,copy & rename if you wish to submit to vendors(s)etc ,use delete option to expunge the file from your system. <br><br>HTH :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17119013</guid>
<pubDate>Thu, 19 Oct 2006 18:16:43 EDT</pubDate>
</item>

<item>
<title>Re: wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17118259</link>
<description><![CDATA[<A HREF="/useremail/u/1139743"><b>Rocky67</b></A> : Excellent. Glad KAV found and killed it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17118259</guid>
<pubDate>Thu, 19 Oct 2006 16:01:59 EDT</pubDate>
</item>

<item>
<title>Re: wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17117570</link>
<description><![CDATA[<A HREF="/useremail/u/773102"><b>richtig</b></A> : Curiously, after a recent reboot, KAV found several associated pieces of malware. See attached image.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/17117570?c=1077043&ret=L2ZvcnVtL3IxNzEwMjE2Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="20372 bytes" WIDTH=600 HEIGHT=477 SRC="/r0/download/1077043.thumb600~d3aa9031b68de0df65df7776dc8a2f43/KAV Kill.gif/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17117570</guid>
<pubDate>Thu, 19 Oct 2006 13:53:27 EDT</pubDate>
</item>

<item>
<title>Re: wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17117309</link>
<description><![CDATA[<A HREF="/useremail/u/1139743"><b>Rocky67</b></A> : Try checking your C:\WINDOWS\SYSTEM32 for wssc.exe and wsscserv.exe. They are associated with a trojan which PREVX claims to be able to remove.<br><SMALL>--<br>"The Internet? Is that still around?" - Homer</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17117309</guid>
<pubDate>Thu, 19 Oct 2006 13:06:07 EDT</pubDate>
</item>

<item>
<title>Re: wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17116277</link>
<description><![CDATA[<A HREF="/useremail/u/773102"><b>richtig</b></A> : Trojan Hunter found nothing.<br><br>I am running KIS 6.0 and it finds nothing.<br><br>Is there any reason to think that DrWeb will be any more useful?<br><br>The thing is that only Blink is purporting to find this offender. A registry search only finds Blink's firewall entries for these images.<br><br>If they are real, something is starting them up. ProcessExplorer only shows explorer.exe as the parent process.<br><br>If these processes are real, is there a way to find what is creating them?<br><br>For the moment, I simply have Blink denying them access.<br><SMALL>--<br><B>We are the music makers,We are the dreamers of dreams.<I>Arthur William Edgar O'Shaugnessy</I></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17116277</guid>
<pubDate>Thu, 19 Oct 2006 09:49:15 EDT</pubDate>
</item>

<item>
<title>Re: wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17115607</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : richtig, it is possible that the files are invisible "UPX-packed" files..<br><br>you could run a scan with "trojanhunter" and see if it flags the files as being UPX-packed files, or you could install a program called "supercleaner" and add the files' names ie "wssc.exe" to the list of "junk" files to scan for, and then see if it flags the files..<br><br>i have found invisible upx-packed files on my computer before, flagged by trojanhunter, but i had to use "supercleaner" to remove the files..<br><br>here are the links for "trojanhunter" and "supercleaner", both of which have free trial periods..<br><br>&raquo;<A HREF="http://www.misec.net/trojanhunter/" >www.misec.net/trojanhunter/</A><br><br>&raquo;<A HREF="http://www.southbaypc.com/SuperCleaner/" >www.southbaypc.com/SuperCleaner/</A><br><br>you could also try running "dr.web's cureit" and see if it flags the files.. but, again, make sure that any files that are flagged actually are malware before you delete them..<br><br>&raquo;<A HREF="http://www.freedrweb.com/cureit/?lng=en" >www.freedrweb.com/cureit/?lng=en</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17115607</guid>
<pubDate>Thu, 19 Oct 2006 05:09:33 EDT</pubDate>
</item>

<item>
<title>Re: wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17110196</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : Follow the steps as outlined here:  &raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13616">Mandatory Steps Before  Requesting Assistance</A><br><br>WINSEC.EXE indicates CWS -   &raquo;<A HREF="http://www.castlecops.com/s4326-winsec_exe.html" >www.castlecops.com/s4326-winsec_exe.html</A><br><br>:)<br><SMALL>--<br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17110196</guid>
<pubDate>Wed, 18 Oct 2006 10:32:57 EDT</pubDate>
</item>

<item>
<title>Re: wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17109824</link>
<description><![CDATA[<A HREF="/useremail/u/773102"><b>richtig</b></A> : Sorry, gave the wrong location for that file. It is reported by Blink as C:\WINDOWS\SYSTEM32\COM\WSSC.EXE, but there is no such file. It is also report a WINSEC.EXE from the same location - once again, non-existent.<br><SMALL>--<br><B>We are the music makers,We are the dreamers of dreams.<I>Arthur William Edgar O'Shaugnessy</I></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17109824</guid>
<pubDate>Wed, 18 Oct 2006 09:27:41 EDT</pubDate>
</item>

<item>
<title>Re: wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17102874</link>
<description><![CDATA[<A HREF="/useremail/u/1159554"><b>norwegian</b></A> : <div class="bquote"><SMALL>said by  richtig <A HREF="/useremail/u/773102"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>(2) How can I find out what is originating it?<br> </DIV>Not tried using the search function for DLL/HANDLE in Process Explorer ? It should return the user of that .exe<br><SMALL>--<br>The only thing necessary for the triumph of evil is for good men to do nothing - Edmund Burke</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17102874</guid>
<pubDate>Tue, 17 Oct 2006 09:21:20 EDT</pubDate>
</item>

<item>
<title>Re: wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17102215</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : if you are able to surf the internet without allowing the tcp-out connection, i would not allow it, for the time being.. then, you could upload the file for scanning at "virusscan.jotti" to see if any programs there flag it as "malware".. here is the link for "virusscan.jotti":<br><br>&raquo;<A HREF="http://virusscan.jotti.org/" >virusscan.jotti.org/</A><br><br>did you scan your computer with your antivirus progtram? you could also use kaspersky's online-virusscan to see if it flags anything, or "dr.web's cureit", but, imo, you should not delete any files before making sure that they are, infact, malware.. some programs use "heuristics" where they can flag files that are suspicious, but might not actually be "malware"..<br><br>&raquo;<A HREF="http://www.kaspersky.com/virusscanner" >www.kaspersky.com/virusscanner</A><br><br>&raquo;<A HREF="http://www.freedrweb.com/cureit/?lng=en" >www.freedrweb.com/cureit/?lng=en</A><br><br>you could also locate the file and check the file's "properties".. maybe that will give you a clue as to what the file is associated with, if it is a legitimate file..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17102215</guid>
<pubDate>Tue, 17 Oct 2006 04:23:08 EDT</pubDate>
</item>

<item>
<title>wssc.exe</title>
<link>http://www.dslreports.com/forum/remark,17102166</link>
<description><![CDATA[<A HREF="/useremail/u/773102"><b>richtig</b></A> : I am trialling Blink from eEye and it is detecting that a request for outbound (TCP) access for C:\WINDOWS32\COM\WSSC.EXE is happening.<br><br>(1) Can anyone tell me whether this is a threat?<br>(2) How can I find out what is originating it?<br><SMALL>--<br><B>We are the music makers,We are the dreamers of dreams.<I>Arthur William Edgar O'Shaugnessy</I></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17102166</guid>
<pubDate>Tue, 17 Oct 2006 03:49:13 EDT</pubDate>
</item>

</channel>
</rss>
