October 2011
4 posts
FreeFixer now supports Windows 8: http://www.freefixer.com/
Windows 8, VMWare, HAL_INITIALIZATION_FAILED, VirtualBox and broken network bridging. http://goo.gl/T2s5Z
My code that verifies a file’s signature using catalog files and WinVerifyTrust don’t work on Windows 8. Investigating…
Starting to port FreeFixer to Windows 8.
August 2011
1 post
Adolist v0.12 up and running. You can now edit your todos. http://www.adolist.com/
June 2011
3 posts
Running FreeFixer v0.59 on some real world malware. So far so good.
Adding “$err, hr” in Visual Studio’s watch window will show the value of GetLastError() and the associated error message.
Sveriges statsskuld 2011-06-10: 1053665000000 SEK
May 2011
2 posts
I’ve just uploaded a minor update at adolist.com. Anyone had the chance to try it? http://www.adolist.com/
What do you think about my latest project? http://www.adolist.com
January 2011
4 posts
www.qooqlle.com.. Anyone know how this start page gets its way into the machines out there?
Anyone using Flattr? How do you like it?
Getting a “Unexpected token in attribute selector: ‘!’” in Firefox just by including jQuery 1.4.4.
Ran into some new malware. LO0Pvkl.exe and LO0Pvkl20.dll. Detection rate around 33%: http://www.freefixer.com/library/file/66325/
October 2010
1 post
Parsing raw NTFS
September 2010
2 posts
andy128.exe is a new Koobface variant: http://www.freefixer.com/library/file/62397/
FreeFixer.com is now sending files to VirusTotal again for malware scanning. Thanks to great people over at VirusTotal for the new API.
August 2010
2 posts
Getting a 502 Bad Gateway while uploading files with VirusTotal’s new API :(
Writing new code to upload files to VirusTotal using the VirusTotal API.
July 2010
9 posts
Oh, meant MAX_PATH, not PATH_MAX.
PathCanonicalize is great, but what if my path is longer than PATH_MAX characters? Any suggestions? #win32
GetFileVersionInfoSize(“c:Program FilesAux”) blocks forever on Windows XP. Is that an OS bug?
srvklw32.exe - new Bredolab worm variant. Discovered a few days ago. 15% detection rate: http://www.freefixer.com/library/file/59990/
bill114.exe - another update of the Koobface download. http://www.freefixer.com/library/file/59929/
npi.dll nad npi.sys comes with the Koobface worm. Only Mcafee detects it at the moment: http://www.freefixer.com/library/file/59802/
Added rel=”canonical” to some of the file info pages on the FreeFixer.com web site.
sisytj32.exe is a Bredolab variant. A typical sign of infection is svchost.exe using 100% CPU. http://www.freefixer.com/library/file/59777/
Playing around with the C++ tr1 binders.
June 2010
13 posts
bill113.exe, yet another Koobface variant: http://www.freefixer.com/library/file/59577/
uClassify back-end server now available for download: http://blog.uclassify.com/download-evaluation-server/
Uploads to VirusTotal up and running again. Disabled cURLs “Expect: 100-continue” HTTP header and that solved the problem.
“Ping.fm have temporarily suspended the use of twitterfeed with their service” That’s why my feeds are not posted anymore :(
xiaosos.exe, xiaodll0.dll, xiaodll1.dll and xiaodll2.dll comes with a password stealer: http://www.freefixer.com/library/file/58980/
bill112.exe removal instructions: http://www.freefixer.com/library/file/58829/
TR/Buzus.dhxv blocks access to freefixer.com: http://www.avira.com/en/threats/section/fulldetails/id_vir/5193/tr_buzus.dhxv.html
netbhl32.exe comes with the Bredolab worm. I’ve posted removal instructions here: http://www.freefixer.com/library/file/58794/
ping.fm + twitterfeed does not work for me anymore. Anyone else also having the same problem?
Virustotal.com up and running again :) The 28 files in the queue at FreeFixer.com should be scanned shortly.
FreeFixer.com now running on 64-bit Linux. Please let me know if you see any problems.
bill111.exe, new Koobface downloader: http://www.freefixer.com/library/file/58672/
siszpe32.exe looks like a new Bredolab variant: http://www.freefixer.com/library/file/58569/
May 2010
11 posts
Just finished some performance improvements for the uClassify back-end server.
Back from a job interview ;)
dimax.dll and hlemunt.sys are two new Koobface files. http://www.freefixer.com/library/file/58122/
monmzb32.exe, new Bredolab variant: http://www.freefixer.com/library/file/57967/
Enumerating files by parsing the NTFS Master File Table.
FreeFixer v0.58 up and running: http://www.freefixer.com/about/release-notes.html#0.58
Ran into a new Koobface variant. bill110.exe, devconus.dll and multikey.sys: http://www.freefixer.com/library/file/57446/
CryptCATAdminCalcHashFromFileHandle fails with ERROR_INVALID_PARAMETER when hashing a .hxs file. Anyone know why?
wwwzuc32.exe, probably a new Bredolab variant: http://www.freefixer.com/library/file/57375/