Author Topic: Farbar (frst), OTL, HijackThis log analyzing  (Read 31462 times)

0 Members and 1 Guest are viewing this topic.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Farbar (frst), OTL, HijackThis log analyzing
« on: March 17, 2015, 12:44:47 PM »
I am working on a "multiple log file analyzer" at the moment.

I'm trying to make it work with:
- Farbar logs (FRST.txt and addition.txt)
- HijackThis logs (hijackthis.log)
- OTL logs
- Other log files ?

I have the analyzing part for FRST.txt (kinda?) working.
Ofcourse the database is still very small, but it will grow :-)

Things that I want/thinking of to add (in random order):
- Detection for things in addition.txt (Farbar)
- Completely rewritten HijackThis log analyzing part
- OTL log file analyzing
- Admin console
- Settings file to customize some things

A sneak(y) preview can be found at:
http://www.ache.nl/cgi-bin/download.pl?file=Ala

To use it:
place FRST.txt in the same folder as you installed the analyzer and run ALA.exe

If you run it and get to see "You are using a old version of Farbar.",
just change the end of the first line in FRST.txt to "11-03-2015"

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #1 on: March 17, 2015, 04:38:43 PM »
Have I done something wrong Eddy ?


Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #2 on: March 17, 2015, 05:16:35 PM »
Yes, the log file need be named FRST.txt

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #3 on: March 17, 2015, 06:42:33 PM »
:) fixt and now running

Where does it save the fixlist ?
« Last Edit: March 17, 2015, 06:44:15 PM by essexboy »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #4 on: March 17, 2015, 07:09:40 PM »
In the same folder as the tool is installed.
Or at least it should do so  ;D

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #5 on: March 17, 2015, 07:12:21 PM »
Hmm did not appear there, I will do a search :)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #6 on: March 18, 2015, 05:59:56 AM »
I am working on a "multiple log file analyzer" at the moment.
Interesting, thanks for sharing Eddy.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #7 on: March 18, 2015, 07:39:18 AM »
A sneak(y) preview can be found at:
http://www.ache.nl/cgi-bin/download.pl?file=Ala
Note: I got the following Avast warning. (See Screenshot)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #8 on: March 18, 2015, 12:28:00 PM »
It is a false positive that I have reported to avast about 3 weeks ago already.
They still haven't fixed it  :'(

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #9 on: March 19, 2015, 06:53:31 AM »
It is a false positive that I have reported to avast about 3 weeks ago already.
They still haven't fixed it  :'(
It might help to PM Milos.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #10 on: March 21, 2015, 04:08:02 PM »
Project update:

1]
Added analyzing for addition.txt

2]
Made a (small) start on the analyzing part for HijackThis log files.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #11 on: March 26, 2015, 06:32:19 PM »
- Added checking for things in addition.txt
- Added detection for Poweliks! in addition.txt
- Added detection for items in the Farbar logfile
- Fixed a bug where Addition.txt wasn't scanned.

http://www.ache.nl/cgi-bin/download.pl?file=Ala-B10

NOTE:
The tool is still under development and is released for testing purposes only.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #12 on: March 26, 2015, 06:40:27 PM »
Avast still doesn't like it Eddy .. Nor does windows smart filter :)

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #13 on: March 26, 2015, 07:08:04 PM »
Only avast detects it.
Reported it through the contact form.
Reported it multiple times by submitting through the UI.
Still not fixed by avast  :'(

https://www.virustotal.com/en/file/2f807a9aded209ed5c04061b0a582f813d5bedf2516634d02a292703eca604b9/analysis/1427392091/
http://www.virscan.org/scan/b3a9b0fb57560700c31202e71dba10fd

Little information about the current development status (Hijackthis part):
- Routine for checking which Hijackthis version is used is ready.
- Routine for checking what OS/SP is used is ready.

These are ready but not implemented yet.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #14 on: March 27, 2015, 05:36:53 AM »
Only avast detects it.
Reported it through the contact form.
Reported it multiple times by submitting through the UI.
Still not fixed by avast  :'(
As said, best you drop Milos a line.
-> http://sitecheck.sucuri.net/results/downloads.ache.nl/ala-b10-20150327.exe
-> http://zulu.zscaler.com/submission/show/b9a720aeeed53f58fa33d78c43fee7ff-1427430583

PS: Seems your Apache sever needs an update. ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0