Jump to content

Malwarebytes

FileASSASSIN 2.00 BETA


20 replies to this topic

#1
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,092 posts
  • Gender:Male
This is a complete rewrite in C++. It will allow for increased portability and faster processing. A lot of bugs have been fixed. The following restrictions apply:

1. Command line parameters are still not ready.
2. No application icon.
3. No banner at the top.

http://www.malwareby...org/fa_beta.zip

Please do not distribute this link. It is a forum members only beta. Anybody interested in creating an icon or banner, feel free to (hint, hint). This is beta software. Use at your own risk.
Marcin Kleczynski
Chief Executive Officer

Posted Image

Follow me on Twitter or check out my Blog!

#2
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,092 posts
  • Gender:Male
Any comments on this. Or graphics suggestions?
Marcin Kleczynski
Chief Executive Officer

Posted Image

Follow me on Twitter or check out my Blog!

#3
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 26,914 posts
  • Gender:Male
  • Location:US

View PostRubbeR DuckY, on Feb 12 2008, 06:39 PM, said:

Any comments on this. Or graphics suggestions?

Did not extensively test but basic testing it worked fine. Will try to test it more tonight if I get time.
Will maybe look at some graphics for it too - maybe something with like a sniper?
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

#4
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,092 posts
  • Gender:Male

Quote

Maybe something with like a sniper?

Why does everybody keep suggesting that :).
Marcin Kleczynski
Chief Executive Officer

Posted Image

Follow me on Twitter or check out my Blog!

#5
screen317

    MBAM Sentinel

  • Moderators
  • PipPipPipPipPipPip
  • 19,465 posts
  • Gender:Male
  • Location:New Haven, CT
Icon ideas (made by yours truly in MS Paint :) ):

Posted Image

Posted Image



Too cheesy? :)
Chris Fistonich
Research Team

Posted Image

Follow us: Twitter, Become a fan: Facebook

#6
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 26,914 posts
  • Gender:Male
  • Location:US
Sorry, did not get time to test FA or create any graphics. Work is having some issues that are taking up a lot of my time right now.

Will look into it soon though.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 26,914 posts
  • Gender:Male
  • Location:US
Just ran the latest version and it was unable to unlock a zero-byte temp file in the C:\WINDOWS folder.

See post here: S0224A913.TMP what is it

I used Unlocker and it was able to delete it, though it was recreated pretty quickly. Not sure what methods Unlocker uses but it was able to unlock and delete.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

#8
exile360

    exile

  • Administrators
  • PipPipPipPipPipPip
  • 15,087 posts
  • Gender:Male
I'm not an artist so I can't create one, but how about a ninja or something like that?
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,092 posts
  • Gender:Male
Ron, what was the hook that Unlocker noticed?
Marcin Kleczynski
Chief Executive Officer

Posted Image

Follow me on Twitter or check out my Blog!

#10
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 26,914 posts
  • Gender:Male
  • Location:US

View PostRubbeR DuckY, on Feb 14 2008, 07:36 PM, said:

Ron, what was the hook that Unlocker noticed?

I used Microsoft / Sysinternals ProcessExplorer to locate what was locking the file and it was the very top SYSTEM (which is a bit ambiguous since many items launch under that) not sure how to fully trace it down to a specific DLL hook at this time. Will need to research more.

You may find it on your own system or one there in your area, it's even here on my home system XP Pro w/SP2. In all my systems it starts as SF??????.TMP

C:
CD \WINDOWS
ATTRIB *.TMP (then should see it)
ATTRIB -R -A -S -H *.TMP
DIR *.TMP


If you have or know of a method to track down to the specific DLL that would be great as ProcessExplorer doesn't seem to be able to do that in this case.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

#11
fredvries

    Elite Member

  • Experts
  • PipPipPipPipPip
  • 721 posts
  • Gender:Male
  • Location:Harlingen - The Netherlands
  • Interests:
Worked nicely.

As the removed file name is left in the box, I would like to see a 'Clear' button to remove that file name.
    [•]www.pdd-nos.nl
    [•]www.pdd-nos.be
    [•]www.pdd-nos.com

#12
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,092 posts
  • Gender:Male
Updated. Now compiled using Dev-C++ and compressed with UPX. Still trying to work some main bugs out and get some very stable code.

http://www.malwareby...org/fa_beta.zip

Will not be incorporating new features until I have released 2.00 and know it is stable enough for them.
Marcin Kleczynski
Chief Executive Officer

Posted Image

Follow me on Twitter or check out my Blog!

#13
Gimpguy2000

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 132 posts
  • Gender:Male
  • Location:Michigan
I'll throw one at ya. Anyone get some ideas from these, feel free...

Attached Images

  • Attached Image: assanbutton.png
  • Attached Image: assanbutton2.png


#14
screen317

    MBAM Sentinel

  • Moderators
  • PipPipPipPipPipPip
  • 19,465 posts
  • Gender:Male
  • Location:New Haven, CT
What.... are you telling me no one liked mine? :)
Chris Fistonich
Research Team

Posted Image

Follow us: Twitter, Become a fan: Facebook

#15
Gimpguy2000

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 132 posts
  • Gender:Male
  • Location:Michigan

View Postscreen317, on Mar 2 2008, 03:29 AM, said:

What.... are you telling me no one liked mine? :)

LOL, no, not at all. AAMOF, they look great. Just some ideas for masses is all..... :)

#16
fredvries

    Elite Member

  • Experts
  • PipPipPipPipPip
  • 721 posts
  • Gender:Male
  • Location:Harlingen - The Netherlands
  • Interests:
FileASSASSIN 2.0 beta can't delete a 0-bytes file in a folder called autorun.inf

Folder:
Size: 0 bytes
Files: lpt3. This folder was created by Flash_Disinfector
    [•]www.pdd-nos.nl
    [•]www.pdd-nos.be
    [•]www.pdd-nos.com

#17
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,092 posts
  • Gender:Male
Can I have the full path/filename.
Marcin Kleczynski
Chief Executive Officer

Posted Image

Follow me on Twitter or check out my Blog!

#18
fredvries

    Elite Member

  • Experts
  • PipPipPipPipPip
  • 721 posts
  • Gender:Male
  • Location:Harlingen - The Netherlands
  • Interests:
C:\autorun.inf (lpt3.This folder was created by Flash_Disinfector)
    [•]www.pdd-nos.nl
    [•]www.pdd-nos.be
    [•]www.pdd-nos.com

#19
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,092 posts
  • Gender:Male
Updated. Fred, can you tell me if the problem still persists.

http://www.malwareby...org/fa_beta.zip

Fixed a few other problems and improved other things.
Marcin Kleczynski
Chief Executive Officer

Posted Image

Follow me on Twitter or check out my Blog!

#20
fredvries

    Elite Member

  • Experts
  • PipPipPipPipPip
  • 721 posts
  • Gender:Male
  • Location:Harlingen - The Netherlands
  • Interests:
Sorry to say: yes, it does.
    [•]www.pdd-nos.nl
    [•]www.pdd-nos.be
    [•]www.pdd-nos.com





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us