Process Logger Service

Discussion in 'other anti-malware software' started by Mister X, Mar 17, 2017.

  1. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,368
    I just installed this, but not sure if it is working or not.

    WinVersion_NVT_ProcessLogger_install_01.JPG
     
  2. askmark

    askmark Registered Member

    Joined:
    Jul 7, 2016
    Posts:
    251
    Location:
    united kingdom
    Did you click "Allow"?
     
  3. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,368
    Not sure what you mean, but I double clicked on the service in the folder and VS popped it's warning, and I allowed, but then I got a another warning message:

    WinVersion_NVT_ProcessLogger_install_02.JPG

    WinVersion_NVT_ProcessLogger_install_03.JPG
     
  4. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,368
    I am getting there. This time right-clicked on the service, and then Run as administrator, and this time WAR, popped it's warning, and I clicked on "allow next time". So, I will launch it again, and this time it should work.

    WinVersion_NVT_ProcessLogger_install_04.JPG
     
  5. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,368
    Well, I launched the service again, and no more warnings/popups...But, the service is still not able to run, for some reason.

    WinVersion_NVT_ProcessLogger_install_05.JPG
     
  6. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    2,190
    Location:
    The etherlands
    Did you right-click the install.bat in C:\ProcLoggerSvc and run that as Admin, as per the instructions?
     
  7. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,368
  8. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,368
    Now, I am trying Process Hacker to create the service...Nothing works, for me.

    WinVersion_NVT_ProcessLogger_install_06.JPG
     
  9. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    2,190
    Location:
    The etherlands
    OK, some people do seem to have issues running it on Win 10, although I haven't experienced this.
     
  10. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,488
    First thing I did was exit VS, turn off WAR and set Appguard to allow installs. Next I go to the service folder , 64 bit folder and copy the procloggersvc folder to my c: root drive. Then I navigate to that folder on my c: root , right click on install.bat as admin. Now you should see logging happening.
    I never clicked on the proscessloggersvc.EXE
     
  11. askmark

    askmark Registered Member

    Joined:
    Jul 7, 2016
    Posts:
    251
    Location:
    united kingdom
    sorry for not being specific. I wasn't sure if you clicked allow at the VS prompt as it was in your screenshot.
     
  12. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    2,190
    Location:
    The etherlands
    +1
     
  13. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,368
    Well, WAR has it as accepted/allowed, now.

    WinVersion_NVT_ProcessLogger_install_07.JPG
     
  14. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,368
    I understand, now what you meant...I was a little slow, comprehending. ;)
     
  15. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,488
    Tarnak

    From your above process hacker screen shot you were trying to do something to the EXE. Leave that file alone. It does appear you have copied the folder correctly.
    Just use the install.bat and you might have to do a reboot. Then checks the logs folder in that same folder not the one you copied it from.
     
  16. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,368
    I did use the install bat, but I didn't see any CMD window....I have checked the logs folder, and nothing is there.

    I am shutting down shortly, and going to bed.
     
  17. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,368
    I couldn't sleep, so I decided to get stuck into the problem. I reran the batch file, and this time SAP put in an appearance. Just about all layers of my security, have been involved up to this point. ;) ...anyway, I have got the process working, now, finally. :)

    WinVersion_NVT_ProcessLogger_install_08.JPG

    WinVersion_NVT_ProcessLogger_install_09.JPG

    WinVersion_NVT_ProcessLogger_install_10.JPG
     
  18. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,488
  19. askmark

    askmark Registered Member

    Joined:
    Jul 7, 2016
    Posts:
    251
    Location:
    united kingdom
    No problem. Glad to hear you finally have it working.
     
  20. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    742
    Location:
    Italy
    We've officially released the new version v1.3:
    http://www.novirusthanks.org/products/process-logger-service/

    Changelog:

     
  21. Mister X

    Mister X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    2,708
    Location:
    Mexico
    Thank you.
     
  22. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,368
    It was a relief to get it working.
     
  23. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    2,190
    Location:
    The etherlands
  24. mood

    mood Registered Member

    Joined:
    Oct 27, 2012
    Posts:
    2,571
    I extraced both .zip-files (Release version 1.3 + test version 1.3) and compared both folders. The only change was in the file Changelog.txt
    Process_Logger_Service_-_Folder-Comparison.png
     
  25. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    2,190
    Location:
    The etherlands
    Thanks @mood
     
Loading...