Find Jobs
Hire Freelancers

Python search for Windows Executables

$10-30 USD

已关闭
已发布大约 5 年前

$10-30 USD

货到付款
I NEED THIS IN 48 HOURS. Create a tool to scan and detect malicious executables in Windows persistence mechanisms. Some of these locations may not exist on certain systems.... the program should check if key exists before trying to read from it, and handle failures gracefully. Some of these paths are Registry "folders" and some are Keys for "Key/Value" pairs HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\*\ImagePath So each Key under HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\, if that key has a Key named key/value named ImagePath, then hash that target HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler (XP, NT, W2k only) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ------------------------------------------------------------------------------------------------- The goal is to scan and find the target .exe, .dll & .sys files and hash the files. Then, we want to compare the the hashes from a source of malicious file hashes and alert if any match. --- I think it makes sense on some of these, like "Shell" where it may be set to "[login to view URL]" with no path, to just check c:\windows\[login to view URL] and c:\windows\system32\[login to view URL] for the file, and otherwise report that file could not be found. For testing, make sure to actually put a hash in your hash dataset that matches something to make sure it actually catches things.
项目 ID: 19308428

关于此项目

3提案
远程项目
活跃5 年前

想赚点钱吗?

在Freelancer上竞价的好处

设定您的预算和时间范围
为您的工作获得报酬
简要概述您的提案
免费注册和竞标工作
3威客以平均价$155 USD来参与此工作竞价
用户头像
Hello Very interested in your project I can do it in 48 hours. Review my work on my profile Let's have a talk for more detail Thanks
$222 USD 在1天之内
4.8 (8条评论)
4.7
4.7
用户头像
hello Mr I can help you with this project. I have big experience with windows api and Python I also have experience search virus. let me help you with this project contact me by chat to get more information. best regards
$133 USD 在2天之内
5.0 (9条评论)
3.6
3.6
用户头像
Hey, I have prior experience in this type of program, can deliver in a day without any errors. I am just starting out here on freelancer but have more than 4 years of experience in coding using python.
$111 USD 在1天之内
0.0 (0条评论)
0.0
0.0

关于客户

UNITED STATES的国旗
huntsville, United States
5.0
2
付款方式已验证
会员自3月 3, 2019起

客户认证

谢谢!我们已通过电子邮件向您发送了索取免费积分的链接。
发送电子邮件时出现问题。请再试一次。
已注册用户 发布工作总数
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
加载预览
授予地理位置权限。
您的登录会话已过期而且您已经登出,请再次登录。