PE Capture Service

Discussion in 'other anti-malware software' started by guest, May 21, 2017.

  1. guest

    guest Guest

    PE Capture Service is able to capture PE files loaded in the system:
    http://www.novirusthanks.org/products/pe-capture-service/
    Code:
    [21-May-2017] v1.1.0.0
    
    + Added option to delete log files older than N days
    + Added option to delete intercepted PE files older than N days
    + By default, delete logs older than 30 days
    + By default, delete intercepted PE files older than 30 days
    + Intercepted PE files are saved as %md5filehash%.file
    
    [13-Feb-2016] v1.0.0.0
    
    + Initial release
     
    Last edited by a moderator: May 25, 2017
  2. guest

    guest Guest

    After starting of a simple application (Notepad3) i can see this in the logfile:
    Code:
    25.05.2017 13:49:27
    C:\Program Files\Notepad3\Notepad3.exe
    9F6D6782268E16AD036B43ACD8DD70F2
    
    25.05.2017 13:49:28
    C:\Windows\System32\hmpalert.dll
    01BAAD5475E0C6DE3F4C62ABB1B55304
    
    25.05.2017 13:49:29
    C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.17359_none_4188b989718cf1c6\comctl32.dll
    9CCDE92BDACC2D39EA86C91BA2A0042A
    
    And these files were captured ("Intercepted PE files are saved as %md5filehash%.file")
    PeCaptureSvc_files.png
    The capturing of files can be turned off (EnableCapture = n), now it is only logging.

    I noticed that subsequent executions of applications are not logged.
    I executed VeraCrypt 5x times, but i can only see the first one:
    Code:
    25.05.2017 15:07:05
    C:\Program Files\VeraCrypt\VeraCrypt.exe
    61212B2F271DC1818BFB7412A5ED20AA
    
    After a restart of the service and executing VeraCrypt i can see it again in the logfile.
    It seems the information about executions is cached and is therefore only shown one time.
     
  3. guest

    guest Guest

    PE Capture Service v1.2 Released (September 26, 2018)
    Website
     
  4. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Now that it's officially signed I can try it.

    Thanks for bringing it up.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.