Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

file "Microsoft.WSMan.Management.resources.dll"


  • Please log in to reply
17 replies to this topic

#1 Clade

Clade

  • Members
  • 187 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:46 PM

Posted 13 July 2015 - 10:36 AM

Hi everyone!
 
Searching the web about the file "Microsoft.WSMan.Management.resources.dll" of Microsoft.WSMan.Management.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_MSIL (8), Culture = [l: 10 {5}] "en-us ", VersionScope = 1 nonSxS, PublicKeyToken = {l: 8b: 31bf3856ad364e35}, Type neutral, neutral TypeName, PublicKey neutral in the store, hash mismatch, nothing found, unless attempts to suggest the use of clean out of records and the like.
 
Someone could say what is the real utility of this file and what its no presence in the OS might cause?
 
Grateful for the attention!


BC AdBot (Login to Remove)

 


#2 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:46 PM

Posted 13 July 2015 - 10:40 AM

Hi Clade :)

If needed, I can assist you with this issue I just have to ask for permission first to one of my teacher on Sysnative.

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#3 Clade

Clade
  • Topic Starter

  • Members
  • 187 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:46 PM

Posted 13 July 2015 - 10:50 AM

Hi Aura!
 
We can see yes. . . What to I can say that the software Sysnative staff made corrections in equpamento and only this file "left" and, according to the analyst who helped me, would not influence the OS. He still "left over" when the SFC use.
 
The information requested relates solely curiosity. Clean and fast system.


#4 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:46 PM

Posted 13 July 2015 - 11:28 AM

May I ask who assisted you and on which forum? And if possible, can you post the link to that thread?

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#5 Clade

Clade
  • Topic Starter

  • Members
  • 187 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:46 PM

Posted 13 July 2015 - 12:23 PM

For me I do not see difficulty, but do not know if Sysnative the site allows. . .



#6 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:46 PM

Posted 13 July 2015 - 01:31 PM

Alright Clade, follow the instructions below please :)

EndqYRa.pngSystem File Checker (SFC)
Follow the instructions below to run a SFC scan on your system and to provide the CBS log in your next reply;
  • On Windows Vista & 7, click on the Windows Start Menu, then enter cmd in the search box, right-click on the cmd icon and select Spcusrh.pngRun as Administrator
  • On Windows 8, drag your cursor in the bottom-left corner, and right-click on the metro menu preview, then select Command Prompt (Admin);
  • On Windows 8.1, right click on the Windows logo in the bottom-left corner and select Command Prompt (Admin);
  • Enter the command below and press on Enter;
    sfc /scannow
    Note: There's a space between "sfc" and "/scannow";
  • Once the scan is complete, enter the command below and press on Enter
    copy %windir%\logs\cbs\cbs.log "%userprofile%\Desktop\cbs.txt"
  • A file called cbs.txt will have appeared on your Desktop. Upload the file on Dropbox, Google Drive or OneDrive and post the download URL for it here;

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#7 Clade

Clade
  • Topic Starter

  • Members
  • 187 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:46 PM

Posted 13 July 2015 - 01:45 PM

Follows the requested file:

 

https://drive.google.com/drive/my-drive



#8 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:46 PM

Posted 13 July 2015 - 02:07 PM

This is a general URL to access GoogleDrive, not the download URL of the file :)

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#9 Clade

Clade
  • Topic Starter

  • Members
  • 187 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:46 PM

Posted 13 July 2015 - 03:15 PM

Sorry Aura!

 

https://drive.google.com/file/d/0BxGHltBcLVYDQ0swTE5aZ3pYMjA/view?usp=sharing



#10 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:46 PM

Posted 13 July 2015 - 04:28 PM

It seems that you truncated the log using the sfcdetails.txt technique. Please follow the instructions I posted only and give me a full CBS.log for analysis.

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#11 Clade

Clade
  • Topic Starter

  • Members
  • 187 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:46 PM

Posted 13 July 2015 - 04:51 PM

Follow link (CBS.log): . 

 

https://drive.google.com/file/d/0BxGHltBcLVYDeVdUaDAtOWxWOTQ/view?usp=sharing



#12 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:46 PM

Posted 14 July 2015 - 04:36 PM

Sorry for the delay Clade. Here follow the instructions below please.

myjIXnC.pngSFCFix - Fix Time
Follow the instructions below to download and execute a SFCFix fix, and provide the log.
  • Download SFCFix and move the executable on your Desktop;
  • Download the attached SFCFix.zip and move the archive to your Desktop;
    Note: Make sure that the file is named SFCFix.zip, do not rename it.
  • Save any work you have open, and close every programs;
  • Drag the SFCFix.zip archive file over the SFCFix.exe executable and release it;
  • SFCFix will launch, let it complete;
  • Once done, a file will appear on your Desktop, called SFCFix.txt;
  • Open the file, then copy and paste its content in your next reply;
SFCFix.zip

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#13 Clade

Clade
  • Topic Starter

  • Members
  • 187 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:46 PM

Posted 14 July 2015 - 05:32 PM

Aura No problems. . . I imagine how it should be run your everyday life. . .
 
The following results of the fix:
 
SFCFix version 2.4.5.0 by niemiro.
Start time: 2015-07-14 19:26:25.394
Microsoft Windows 7 Service Pack 1 - amd64
Using .zip script file at C:\Users\Clade\Desktop\SFCFix.zip [0]
 
PowerCopy::
Successfully took permissions for file or folder C:\Windows\winsxs\msil_microsoft.wsman.management.resources_31bf3856ad364e35_6.1.7600.16385_pt-br_2c2b562e7007a85c\microsoft.wsman.management.resources.dll
 
Successfully copied file C:\Users\Clade\AppData\Local\niemiro\Archive\winsxs\msil_microsoft.wsman.management.resources_31bf3856ad364e35_6.1.7600.16385_pt-br_2c2b562e7007a85c\microsoft.wsman.management.resources.dll to C:\Windows\winsxs\msil_microsoft.wsman.management.resources_31bf3856ad364e35_6.1.7600.16385_pt-br_2c2b562e7007a85c\microsoft.wsman.management.resources.dll.
 
Successfully restored ownership for C:\Windows\winsxs\msil_microsoft.wsman.management.resources_31bf3856ad364e35_6.1.7600.16385_pt-br_2c2b562e7007a85c\microsoft.wsman.management.resources.dll
Successfully restored permissions on C:\Windows\winsxs\msil_microsoft.wsman.management.resources_31bf3856ad364e35_6.1.7600.16385_pt-br_2c2b562e7007a85c\microsoft.wsman.management.resources.dll
PowerCopy:: directive completed successfully.
 
Successfully processed all directives.
SFCFix version 2.4.5.0 by niemiro has completed.
Currently storing 21 datablocks.
Finish time: 2015-07-14 19:26:40.481
Script hash: 2jfh7mbqyN1SPBmWGdD3nTeQi8ojCUMa5nT3zcT7VOc=
----------------------EOF-----------------------
 
 
New SFC / scannow?


#14 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:46 PM

Posted 14 July 2015 - 05:34 PM

Yes. Run a new SFC scan and upload the new CBS.log for me please.

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#15 Clade

Clade
  • Topic Starter

  • Members
  • 187 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:46 PM

Posted 14 July 2015 - 06:16 PM

"No violation of integrity "
 
Please, state the Function that file in the OS. . . 
 
Follow. . . 

 

https://drive.google.com/file/d/0BxGHltBcLVYDMUY4eWdwSm15T1E/view?usp=sharing






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users