Home / Other / Other / New Computer Hope tool
0 Members and 1 Guest are viewing this topic. « previous next »
Pages: 1 ... 7 8 [9] - (Bottom) Print
Author Topic: New Computer Hope tool  (Read 29616 times)
evilfantasy
Malware Removal Specialist
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #120 on: February 08, 2010, 05:00:35 PM »

Did you change anything just now? It's back to blocking my logs.
IP logged

Computer Hope Admin
Topic Starter
Administrator
Prodigy



Thanked: 210
Posts: 6,065

Certifications: List
Computer: Specs
Experience: Guru
OS: Windows Vista

Computer Hope 1 1 1
« Reply #121 on: February 08, 2010, 05:06:25 PM »

Did you change anything just now? It's back to blocking my logs.

Nope nothings been changed.
IP logged

Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein
evilfantasy
Malware Removal Specialist
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #122 on: February 08, 2010, 05:16:37 PM »

Strange.  ???
IP logged

Computer Hope Admin
Topic Starter
Administrator
Prodigy



Thanked: 210
Posts: 6,065

Certifications: List
Computer: Specs
Experience: Guru
OS: Windows Vista

Computer Hope 1 1 1
« Reply #123 on: February 08, 2010, 05:17:37 PM »

Strange.  ???

Have an example log you can send me a link to or what you're doing so I can see if I can duplicate it?
IP logged

Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein
evilfantasy
Malware Removal Specialist
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #124 on: February 08, 2010, 05:22:08 PM »

Okay. It took one log but blocks another. Could it be something in the logs (text, URL...) that it's hitting on?

2 logs. Blocked and not blocked.

[Saving space, attachment deleted by admin]
IP logged

Computer Hope Admin
Topic Starter
Administrator
Prodigy



Thanked: 210
Posts: 6,065

Certifications: List
Computer: Specs
Experience: Guru
OS: Windows Vista

Computer Hope 1 1 1
« Reply #125 on: February 08, 2010, 05:28:06 PM »

Hmm both of these worked for me with no issues. The blocked one worked but I did get a Kaspersky false warning, is it maybe something to do with that? What is happening when it's saying it's blocked?
IP logged

Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein
evilfantasy
Malware Removal Specialist
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #126 on: February 08, 2010, 05:30:28 PM »

Using Firefox.

IP logged

Computer Hope Admin
Topic Starter
Administrator
Prodigy



Thanked: 210
Posts: 6,065

Certifications: List
Computer: Specs
Experience: Guru
OS: Windows Vista

Computer Hope 1 1 1
« Reply #127 on: February 08, 2010, 06:06:02 PM »

Yeah that's something to do Kaspersky and not the process tool. It's the false infection warning and I believe can be ignored to load the page or if a rule for it has been set it may have to be adjusted through Kaspersky.

Update: v1.6a

* Corrected issues with false detections when looking at the directory of the file. e.g. java.exe being found in program files directory and the tool believing it's a potentially infected file.
IP logged

Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein
Computer Hope Admin
Topic Starter
Administrator
Prodigy



Thanked: 210
Posts: 6,065

Certifications: List
Computer: Specs
Experience: Guru
OS: Windows Vista

Computer Hope 1 1 1
« Reply #128 on: February 09, 2010, 08:08:31 AM »

Update: v1.6c

- Updated structure of how files with directory locations are listed in database
- If malware found in /temp/directory additional suggestion of running a Windows cleanup to clear out all temporary files is suggested.
- Corrected files not getting logged if they're in the Windows directory even if they are unknown
- Corrected issue with seriously corrupted hijackthis logs containing HTML to not be parsed as HTML.
- Added several hundred more files to database

IP logged

Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein
Computer Hope Admin
Topic Starter
Administrator
Prodigy



Thanked: 210
Posts: 6,065

Certifications: List
Computer: Specs
Experience: Guru
OS: Windows Vista

Computer Hope 1 1 1
« Reply #129 on: February 10, 2010, 09:32:54 AM »

Update v2.0

- Big update to how this tool queries the files being looked up. The method of going through the files should be a lot faster and a lot less resource intensive on the server.
- When hovering the mouse over the folder icons to display the path if that particular file is in multiple paths it'll now show all paths, separating each path with >>> as shown below.

Quote
o2 - bho: swag bucks toolbar - {a057a204-bacc-4d26-b2fc-48f8ccab3ed4} - c:\program files\prodeg~1\prodeg~1.dll >>> o3 - toolbar: swag bucks toolbar - {a057a204-bacc-4d26-b2fc-48f8ccab3ed4} - c:\program files\prodeg~1\prodeg~1.dll

- Better file detection and listing for files embedded within missing files / potential protocol hijacks.
- Corrected file errors within database
- Added several dozen more files
- Few grammatical errors and other minor updates

Although I did spend about an hour going through the a few of the older stored logs I didn't fully test this as of yet. Although it seems stable because of the amount of re-write I did on the code it's possible that issues could still exist since so much was changed. Just got too tired for any more testing. ;)


IP logged

Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein
dlx
Rookie



Thanked: 2
Posts: 47


« Reply #130 on: March 30, 2010, 10:24:53 PM »

fantastic tool! ;D
IP logged
pathe3
Greenhorn



Posts: 6

Experience: Beginner
OS: Unknown

« Reply #131 on: April 04, 2011, 03:51:16 AM »

Nice tool.  However, I'm not sure that everything.exe can be defined as malware.
IP logged
reddevilggg
Mentor



Thanked: 55
Posts: 1,812

Experience: Familiar
OS: Windows 7



« Reply #132 on: April 04, 2011, 04:27:33 AM »


Nice tool.  However, I'm not sure that everything.exe can be defined as malware.

Everything??
IP logged

11 cheers for binary !
Computer Hope Admin
Topic Starter
Administrator
Prodigy



Thanked: 210
Posts: 6,065

Certifications: List
Computer: Specs
Experience: Guru
OS: Windows Vista

Computer Hope 1 1 1
« Reply #133 on: July 29, 2011, 02:48:47 AM »

http://www.computerhope.com/cgi-bin/process.pl?p=everything.exe

Thanks for the suggestion, the reason this is reporting as malware is infections of everything.exe that are stored in the \windows / \windows\system32 directory. It should probably be mentioned that if this file is in another directory that it is not likely an infection. Will add to my endless todo list. :)
IP logged

Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein
Pages: 1 ... 7 8 [9] - (Top) Print 
Home / Other / Other / New Computer Hope tool « previous next »
 


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright © 2010 Computer Hope ® All rights reserved.
Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC
Page created in 0.097 seconds with 20 queries.