Runscanner : freeware startup analyzer
If you want free network inventory don't forget to visit Lansweeper : Freeware asset and software inventory
Welcome Guest Search | Active Topics | Members | Log In | Register

some crazy ideas Options
LUSHER
Posted: Friday, March 02, 2007 10:26:30 PM
Rank: Member
Groups: Member

Joined: 3/2/2007
Posts: 53
Points: 159
Hello.

I recommend you take a look at http://wiki.castlecops.com/Lists_of_freeware_analysis_tools#Advanced to see some of your competitors.

http://wiki.castlecops.com/Lists_of_freeware_analysis_tools#Lists_of_autostart_locations
lists some links that might be interest to you, if you intend to be as comprehensive as possible.


Some crazy wishes

1) Is it possible to make it such that the user can choose to monitor/list any registry key or value or file/folder. This can be helpful for example, if say one became aware of a certain autostart up method involving a registry key that was missed out by the program. So instead of waiting for you to hard code it in, we could just add it, and it would display under "custom" or something.

2) Being able to temporarily "turn off" registry keys as in autoruns

3) For services and easy way to start stop them, and/or change them from auto to manual to disabled etc. Hopefully via context menu.

4) being able to load your own white list or point to another database (format should be standardised or known). There are way too many of these online resources around listing files/registry keys, but each of them uses a different standard, which is a pity, since there is no interoperationability.

5) Being able to specify some kind of antivirus of your choosing so you can right click and scan suspect files. Even better, one click and it loads up automatically to virustotal, jotti etc.

6) More powerful kill methods for process killer as well as option to delete at next reboot, terminate and delete, terminate and rename etc. See Procx for example.




GeertM
Posted: Monday, March 05, 2007 1:58:35 PM

Rank: Administration
Groups: Administration

Joined: 2/16/2007
Posts: 142
Points: 195
Location: Belgium
1) Would be hard/impossible, since almost all currently scanned items use different methods

2) Have to take a look how this exactly works.

3) The standard windows .mmc tools can already do all these things

4) I'm looking with merijn from hijackthis to make a format and one database that both programs can use (and others)

5) Maybe useful in a later version.

6) I'll take a look at the program, these are indeed useful features.


Lansweeper : free software and computer inventory
Pierre
Posted: Thursday, March 08, 2007 2:08:04 PM
Rank: Member
Groups: Member

Joined: 2/26/2007
Posts: 41
Points: 123
Location: Paris (France)
Hi,

The good thing would be that RunScanner act as a front end for DB like

Castlecops
http://hashes.castlecops.com/Hashes.html (31 743 604 file hash entries including parasites (this is what we are looking for))

File Advisor File Identification
http://www.bit9.com/index.php (2 054 736 194 file hash entries without parasites (!))

My dream of the day Whistle

@+

Pierre (aka Terdef)
Assiste.com - ASAP
GeertM
Posted: Friday, March 09, 2007 9:32:12 AM

Rank: Administration
Groups: Administration

Joined: 2/16/2007
Posts: 142
Points: 195
Location: Belgium
I will ask them, not sure if they'll agree.
I can store the items in my database (with some more explanation) and verify the hashes with castlecops.


Lansweeper : free software and computer inventory
GeertM
Posted: Monday, November 19, 2007 11:48:08 PM

Rank: Administration
Groups: Administration

Joined: 2/16/2007
Posts: 142
Points: 195
Location: Belgium
A late reply to this post, but in the next release the following will be integrated (and approved by the site owners)

Check MD5 at Bit9 fileadvisor
Check MD5 at Castlecops
Upload file for inspection to Virustotal


Lansweeper : free software and computer inventory
LUSHER
Posted: Tuesday, November 20, 2007 3:04:03 PM
Rank: Member
Groups: Member

Joined: 3/2/2007
Posts: 53
Points: 159
GeertM wrote:
A late reply to this post, but in the next release the following will be integrated (and approved by the site owners)

Check MD5 at Bit9 fileadvisor
Check MD5 at Castlecops
Upload file for inspection to Virustotal


Excellent!

I will start the PR machine going again...
GeertM
Posted: Tuesday, November 20, 2007 3:10:31 PM

Rank: Administration
Groups: Administration

Joined: 2/16/2007
Posts: 142
Points: 195
Location: Belgium
Better wait till it's finished and fully tested.

Without any further big problems, it should be finished in one or 2 weeks, but I still have 2 vista issues and a memory problem (only on windows 2000)


Lansweeper : free software and computer inventory
GeertM
Posted: Sunday, December 02, 2007 11:08:48 AM

Rank: Administration
Groups: Administration

Joined: 2/16/2007
Posts: 142
Points: 195
Location: Belgium
LUSHER
Posted: Sunday, December 02, 2007 4:34:34 PM
Rank: Member
Groups: Member

Joined: 3/2/2007
Posts: 53
Points: 159
Looks amazing.

The intergretation with virustotal and bit9 are winners IMHO.

Loaded modules looks interesting, but i use Gmer, rootkit unhooker etc for that.

The interface is imho generally a improvement, the old one was a bit hard to figure out where the scan button was.

In expert mode, I was a bit confused by the point of the extra "hijack items" tab, but i see it allows you to sort without taking into account categories (O11,012 etc). So i guess it shows a more HJT! like interface..


I love the new column showing the signer and CA! Much, Much clearer.

In the old 1.0.3 there was

"none-whitelisted"
"unsigned"
"non-microsoft"

Now there is only "signed" and "non-signed"...

What happend to "non-microsoft" ?

Also i was never clear what none-whitelisted meant in the past ....

Totally confused...

Signed is clear enough to me but does it mean

1)signed by anybody? (including self-signatures)
2)or does it mean it has to be verified by trusted CA (but anyone can buy a cert from versign!)
3) or does it simply mean signed by known publishers like MS, independent of whether it is countersigned by CA...

Same thing for the old "whitelisted". Does it mean files known to be safe, whether it is signed or not?




GeertM
Posted: Sunday, December 02, 2007 7:52:47 PM

Rank: Administration
Groups: Administration

Joined: 2/16/2007
Posts: 142
Points: 195
Location: Belgium
I try to answer all your questions:

The "hijack items" tab is similar to the "classic mode" which is similar to HJT : it only shows non-whitelist items.

Signed : signed by any publisher/issuer (you can see the signer in the grid)
Unsigned : no digital signature
Whitelist : signed by a publisher which is in my list of trusted publishers/issuers (56 in my current list, I'll post the list in another thread)
whitelist also contains non-file items like standard search pages (google.com), standard trusted zones, ...
This list will be extended and is based on statistics gathered by the online malware analysis.
I deleted non-microsoft because it was too confusing.
I deleted the green/blue certificate icons because they were also too confusing.

I added loaded modules + the filter to check if there are dll's running that aren't in the startup list (+ ofcource the integration with virustotal)


Lansweeper : free software and computer inventory
LUSHER
Posted: Monday, December 03, 2007 3:32:55 PM
Rank: Member
Groups: Member

Joined: 3/2/2007
Posts: 53
Points: 159
GeertM wrote:
I try to answer all your questions:

The "hijack items" tab is similar to the "classic mode" which is similar to HJT : it only shows non-whitelist items.

Signed : signed by any publisher/issuer (you can see the signer in the grid)
Unsigned : no digital signature
Whitelist : signed by a publisher which is in my list of trusted publishers/issuers (56 in my current list, I'll post the list in another thread)
whitelist also contains non-file items like standard search pages (google.com), standard trusted zones, ...
This list will be extended and is based on statistics gathered by the online malware analysis.
I deleted non-microsoft because it was too confusing.
I deleted the green/blue certificate icons because they were also too confusing.

I added loaded modules + the filter to check if there are dll's running that aren't in the startup list (+ ofcource the integration with virustotal)


Thanks, very clear.
Users browsing this topic
Guest


Forum Jump
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.

SoClean Theme Created by Jaben Cargman
Powered by YetAnotherforum.net
Copyright © 2003-2006 Yet Another Forum.net. All rights reserved.
This page was generated in 0.168 seconds.