| OLD | NEW |
| 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "chrome/browser/win/enumerate_modules_model.h" | 5 #include "chrome/browser/win/enumerate_modules_model.h" |
| 6 | 6 |
| 7 #include <Tlhelp32.h> | 7 #include <softpub.h> |
| 8 #include <stddef.h> | 8 #include <stddef.h> |
| 9 #include <stdint.h> | 9 #include <stdint.h> |
| 10 #include <tlhelp32.h> |
| 11 #include <wincrypt.h> |
| 10 #include <wintrust.h> | 12 #include <wintrust.h> |
| 13 #include <mscat.h> // NOLINT: This must be after wincrypt and wintrust. |
| 11 | 14 |
| 12 #include <algorithm> | 15 #include <algorithm> |
| 13 #include <memory> | |
| 14 | 16 |
| 15 #include "base/bind.h" | 17 #include "base/bind.h" |
| 16 #include "base/command_line.h" | 18 #include "base/command_line.h" |
| 19 #include "base/debug/leak_annotations.h" |
| 17 #include "base/environment.h" | 20 #include "base/environment.h" |
| 18 #include "base/file_version_info.h" | 21 #include "base/file_version_info.h" |
| 19 #include "base/files/file_path.h" | 22 #include "base/files/file_path.h" |
| 20 #include "base/i18n/case_conversion.h" | 23 #include "base/i18n/case_conversion.h" |
| 21 #include "base/macros.h" | 24 #include "base/macros.h" |
| 22 #include "base/metrics/histogram.h" | 25 #include "base/metrics/histogram.h" |
| 26 #include "base/scoped_generic.h" |
| 23 #include "base/strings/string_number_conversions.h" | 27 #include "base/strings/string_number_conversions.h" |
| 24 #include "base/strings/string_util.h" | 28 #include "base/strings/string_util.h" |
| 25 #include "base/strings/utf_string_conversions.h" | 29 #include "base/strings/utf_string_conversions.h" |
| 26 #include "base/time/time.h" | 30 #include "base/time/time.h" |
| 27 #include "base/values.h" | 31 #include "base/values.h" |
| 28 #include "base/version.h" | 32 #include "base/version.h" |
| 29 #include "base/win/registry.h" | 33 #include "base/win/registry.h" |
| 30 #include "base/win/scoped_handle.h" | 34 #include "base/win/scoped_handle.h" |
| 31 #include "base/win/windows_version.h" | 35 #include "base/win/windows_version.h" |
| 32 #include "chrome/browser/chrome_notification_types.h" | |
| 33 #include "chrome/browser/net/service_providers_win.h" | 36 #include "chrome/browser/net/service_providers_win.h" |
| 34 #include "chrome/common/chrome_constants.h" | 37 #include "chrome/common/chrome_constants.h" |
| 35 #include "chrome/grit/generated_resources.h" | 38 #include "chrome/grit/generated_resources.h" |
| 36 #include "content/public/browser/notification_service.h" | |
| 37 #include "crypto/sha2.h" | 39 #include "crypto/sha2.h" |
| 38 #include "ui/base/l10n/l10n_util.h" | 40 #include "ui/base/l10n/l10n_util.h" |
| 39 | 41 |
| 40 using content::BrowserThread; | 42 using content::BrowserThread; |
| 41 | 43 |
| 42 // The period of time (in milliseconds) to wait until checking to see if any | |
| 43 // incompatible modules exist. | |
| 44 static const int kModuleCheckDelayMs = 45 * 1000; | |
| 45 | |
| 46 // The path to the Shell Extension key in the Windows registry. | 44 // The path to the Shell Extension key in the Windows registry. |
| 47 static const wchar_t kRegPath[] = | 45 static const wchar_t kRegPath[] = |
| 48 L"Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved"; | 46 L"Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved"; |
| 49 | 47 |
| 50 // Short-hand for things on the blacklist you should simply get rid of. | |
| 51 static const ModuleEnumerator::RecommendedAction kUninstallLink = | |
| 52 static_cast<ModuleEnumerator::RecommendedAction>( | |
| 53 ModuleEnumerator::UNINSTALL | ModuleEnumerator::SEE_LINK); | |
| 54 | |
| 55 // Short-hand for things on the blacklist we are investigating and have info. | |
| 56 static const ModuleEnumerator::RecommendedAction kInvestigatingLink = | |
| 57 static_cast<ModuleEnumerator::RecommendedAction>( | |
| 58 ModuleEnumerator::INVESTIGATING | ModuleEnumerator::SEE_LINK); | |
| 59 | |
| 60 // A sort method that sorts by bad modules first, then by full name (including | 48 // A sort method that sorts by bad modules first, then by full name (including |
| 61 // path). | 49 // path). |
| 62 static bool ModuleSort(const ModuleEnumerator::Module& a, | 50 static bool ModuleSort(const ModuleEnumerator::Module& a, |
| 63 const ModuleEnumerator::Module& b) { | 51 const ModuleEnumerator::Module& b) { |
| 64 if (a.status != b.status) | 52 if (a.status != b.status) |
| 65 return a.status > b.status; | 53 return a.status > b.status; |
| 66 | 54 |
| 67 if (a.location == b.location) | 55 if (a.location == b.location) |
| 68 return a.name < b.name; | 56 return a.name < b.name; |
| 69 | 57 |
| 70 return a.location < b.location; | 58 return a.location < b.location; |
| 71 } | 59 } |
| 72 | 60 |
| 73 namespace { | 61 namespace { |
| 74 | 62 |
| 75 // Used to protect the LoadedModuleVector which is accessed | |
| 76 // from both the UI thread and the FILE thread. | |
| 77 base::Lock* lock = NULL; | |
| 78 | |
| 79 // A struct to help de-duping modules before adding them to the enumerated | 63 // A struct to help de-duping modules before adding them to the enumerated |
| 80 // modules vector. | 64 // modules vector. |
| 81 struct FindModule { | 65 struct FindModule { |
| 82 public: | 66 public: |
| 83 explicit FindModule(const ModuleEnumerator::Module& x) | 67 explicit FindModule(const ModuleEnumerator::Module& x) |
| 84 : module(x) {} | 68 : module(x) {} |
| 85 bool operator()(const ModuleEnumerator::Module& module_in) const { | 69 bool operator()(const ModuleEnumerator::Module& module_in) const { |
| 86 return (module.location == module_in.location) && | 70 return (module.location == module_in.location) && |
| 87 (module.name == module_in.name); | 71 (module.name == module_in.name); |
| 88 } | 72 } |
| (...skipping 10 matching lines...) Expand all Loading... |
| 99 DWORD return_value = GetLongPathName(short_path.c_str(), long_path_buf, | 83 DWORD return_value = GetLongPathName(short_path.c_str(), long_path_buf, |
| 100 MAX_PATH); | 84 MAX_PATH); |
| 101 if (return_value != 0 && return_value < MAX_PATH) { | 85 if (return_value != 0 && return_value < MAX_PATH) { |
| 102 *long_path = long_path_buf; | 86 *long_path = long_path_buf; |
| 103 return true; | 87 return true; |
| 104 } | 88 } |
| 105 | 89 |
| 106 return false; | 90 return false; |
| 107 } | 91 } |
| 108 | 92 |
| 93 // Helper for scoped tracking an HCERTSTORE. |
| 94 struct ScopedHCERTSTORETraits { |
| 95 static HCERTSTORE InvalidValue() { return nullptr; } |
| 96 static void Free(HCERTSTORE store) { |
| 97 ::CertCloseStore(store, 0); |
| 98 } |
| 99 }; |
| 100 using ScopedHCERTSTORE = |
| 101 base::ScopedGeneric<HCERTSTORE, ScopedHCERTSTORETraits>; |
| 102 |
| 103 // Helper for scoped tracking an HCRYPTMSG. |
| 104 struct ScopedHCRYPTMSGTraits { |
| 105 static HCRYPTMSG InvalidValue() { return nullptr; } |
| 106 static void Free(HCRYPTMSG message) { |
| 107 ::CryptMsgClose(message); |
| 108 } |
| 109 }; |
| 110 using ScopedHCRYPTMSG = |
| 111 base::ScopedGeneric<HCRYPTMSG, ScopedHCRYPTMSGTraits>; |
| 112 |
| 113 // Returns the "Subject" field from the digital signature in the provided |
| 114 // binary, if any is present. Returns an empty string on failure. |
| 115 base::string16 GetSubjectNameInFile(const base::FilePath& filename) { |
| 116 ScopedHCERTSTORE store; |
| 117 ScopedHCRYPTMSG message; |
| 118 |
| 119 // Find the crypto message for this filename. |
| 120 { |
| 121 HCERTSTORE temp_store = nullptr; |
| 122 HCRYPTMSG temp_message = nullptr; |
| 123 bool result = !!CryptQueryObject(CERT_QUERY_OBJECT_FILE, |
| 124 filename.value().c_str(), |
| 125 CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED_EMBED, |
| 126 CERT_QUERY_FORMAT_FLAG_BINARY, |
| 127 0, |
| 128 nullptr, |
| 129 nullptr, |
| 130 nullptr, |
| 131 &temp_store, |
| 132 &temp_message, |
| 133 nullptr); |
| 134 store.reset(temp_store); |
| 135 message.reset(temp_message); |
| 136 if (!result) |
| 137 return base::string16(); |
| 138 } |
| 139 |
| 140 // Determine the size of the signer info data. |
| 141 DWORD signer_info_size = 0; |
| 142 bool result = !!CryptMsgGetParam(message.get(), |
| 143 CMSG_SIGNER_INFO_PARAM, |
| 144 0, |
| 145 nullptr, |
| 146 &signer_info_size); |
| 147 if (!result) |
| 148 return base::string16(); |
| 149 |
| 150 // Allocate enough space to hold the signer info. |
| 151 std::unique_ptr<BYTE[]> signer_info_buffer(new BYTE[signer_info_size]); |
| 152 CMSG_SIGNER_INFO* signer_info = |
| 153 reinterpret_cast<CMSG_SIGNER_INFO*>(signer_info_buffer.get()); |
| 154 |
| 155 // Obtain the signer info. |
| 156 result = !!CryptMsgGetParam(message.get(), |
| 157 CMSG_SIGNER_INFO_PARAM, |
| 158 0, |
| 159 signer_info, |
| 160 &signer_info_size); |
| 161 if (!result) |
| 162 return base::string16(); |
| 163 |
| 164 // Search for the signer certificate. |
| 165 CERT_INFO CertInfo = {0}; |
| 166 PCCERT_CONTEXT cert_context = nullptr; |
| 167 CertInfo.Issuer = signer_info->Issuer; |
| 168 CertInfo.SerialNumber = signer_info->SerialNumber; |
| 169 |
| 170 cert_context = CertFindCertificateInStore( |
| 171 store.get(), |
| 172 X509_ASN_ENCODING | PKCS_7_ASN_ENCODING, |
| 173 0, |
| 174 CERT_FIND_SUBJECT_CERT, |
| 175 &CertInfo, |
| 176 nullptr); |
| 177 if (!cert_context) |
| 178 return base::string16(); |
| 179 |
| 180 // Determine the size of the Subject name. |
| 181 DWORD subject_name_size = CertGetNameString( |
| 182 cert_context, CERT_NAME_SIMPLE_DISPLAY_TYPE, 0, nullptr, nullptr, 0); |
| 183 if (!subject_name_size) |
| 184 return base::string16(); |
| 185 |
| 186 base::string16 subject_name; |
| 187 subject_name.resize(subject_name_size); |
| 188 |
| 189 // Get subject name. |
| 190 if (!(CertGetNameString(cert_context, |
| 191 CERT_NAME_SIMPLE_DISPLAY_TYPE, |
| 192 0, |
| 193 nullptr, |
| 194 const_cast<LPWSTR>(subject_name.c_str()), |
| 195 subject_name_size))) { |
| 196 return base::string16(); |
| 197 } |
| 198 |
| 199 return subject_name; |
| 200 } |
| 201 |
| 202 // Helper for scoped tracking a catalog admin context. |
| 203 struct CryptCATContextScopedTraits { |
| 204 static PVOID InvalidValue() { return nullptr; } |
| 205 static void Free(PVOID context) { |
| 206 CryptCATAdminReleaseContext(context, 0); |
| 207 } |
| 208 }; |
| 209 using ScopedCryptCATContext = |
| 210 base::ScopedGeneric<PVOID, CryptCATContextScopedTraits>; |
| 211 |
| 212 // Helper for scoped tracking of a catalog context. A catalog context is only |
| 213 // valid with an associated admin context, so this is effectively a std::pair. |
| 214 // A custom operator!= is required in order for a null |catalog_context| but |
| 215 // non-null |context| to compare equal to the InvalidValue exposed by the |
| 216 // traits class. |
| 217 class CryptCATCatalogContext { |
| 218 public: |
| 219 CryptCATCatalogContext(PVOID context, PVOID catalog_context) |
| 220 : context_(context), catalog_context_(catalog_context) {} |
| 221 |
| 222 bool operator!=(const CryptCATCatalogContext& rhs) const { |
| 223 return catalog_context_ != rhs.catalog_context_; |
| 224 } |
| 225 |
| 226 PVOID context() const { return context_; } |
| 227 PVOID catalog_context() const { return catalog_context_; } |
| 228 |
| 229 private: |
| 230 PVOID context_; |
| 231 PVOID catalog_context_; |
| 232 }; |
| 233 |
| 234 struct CryptCATCatalogContextScopedTraits { |
| 235 static CryptCATCatalogContext InvalidValue() { |
| 236 return CryptCATCatalogContext(nullptr, nullptr); |
| 237 } |
| 238 static void Free(const CryptCATCatalogContext& c) { |
| 239 CryptCATAdminReleaseCatalogContext( |
| 240 c.context(), c.catalog_context(), 0); |
| 241 } |
| 242 }; |
| 243 using ScopedCryptCATCatalogContext = base::ScopedGeneric< |
| 244 CryptCATCatalogContext, CryptCATCatalogContextScopedTraits>; |
| 245 |
| 246 // Returns the "Subject" field associated with the certificate that signs |
| 247 // the catalog in which the given file is found, if any. Returns an empty string |
| 248 // on failure. |
| 249 base::string16 GetSubjectNameInCatalog(const base::FilePath& filename) { |
| 250 // Get a crypt context for signature verification. |
| 251 ScopedCryptCATContext context; |
| 252 { |
| 253 PVOID raw_context = nullptr; |
| 254 if (!CryptCATAdminAcquireContext(&raw_context, nullptr, 0)) |
| 255 return base::string16(); |
| 256 context.reset(raw_context); |
| 257 } |
| 258 |
| 259 // Open the file of interest. |
| 260 base::win::ScopedHandle file_handle(CreateFileW( |
| 261 filename.value().c_str(), GENERIC_READ, |
| 262 FILE_SHARE_READ | FILE_SHARE_WRITE | FILE_SHARE_DELETE, |
| 263 nullptr, OPEN_EXISTING, 0, nullptr)); |
| 264 if (!file_handle.IsValid()) |
| 265 return base::string16(); |
| 266 |
| 267 // Get the size we need for our hash. |
| 268 DWORD hash_size = 0; |
| 269 CryptCATAdminCalcHashFromFileHandle( |
| 270 file_handle.Get(), &hash_size, nullptr, 0); |
| 271 if (hash_size == 0) |
| 272 return base::string16(); |
| 273 |
| 274 // Calculate the hash. If this fails then bail. |
| 275 std::vector<BYTE> buffer(hash_size); |
| 276 if (!CryptCATAdminCalcHashFromFileHandle(file_handle.Get(), &hash_size, |
| 277 buffer.data(), 0)) { |
| 278 return base::string16(); |
| 279 } |
| 280 |
| 281 // Get catalog for our context. |
| 282 ScopedCryptCATCatalogContext catalog_context(CryptCATCatalogContext( |
| 283 context.get(), |
| 284 CryptCATAdminEnumCatalogFromHash(context.get(), buffer.data(), hash_size, |
| 285 0, nullptr))); |
| 286 if (!catalog_context.is_valid()) |
| 287 return base::string16(); |
| 288 |
| 289 // Get the catalog info. This includes the path to the catalog itself, which |
| 290 // contains the signature of interest. |
| 291 CATALOG_INFO catalog_info = {}; |
| 292 catalog_info.cbStruct = sizeof(catalog_info); |
| 293 if (!CryptCATCatalogInfoFromContext( |
| 294 catalog_context.get().catalog_context(), &catalog_info, 0)) { |
| 295 return base::string16(); |
| 296 } |
| 297 |
| 298 // Attempt to get the "Subject" field from the signature of the catalog file |
| 299 // itself. |
| 300 base::FilePath catalog_path(catalog_info.wszCatalogFile); |
| 301 return GetSubjectNameInFile(catalog_path); |
| 302 } |
| 303 |
| 109 } // namespace | 304 } // namespace |
| 110 | 305 |
| 111 ModuleEnumerator::Module::Module() { | 306 ModuleEnumerator::Module::Module() { |
| 112 } | 307 } |
| 113 | 308 |
| 114 ModuleEnumerator::Module::Module(const Module& rhs) = default; | 309 ModuleEnumerator::Module::Module(const Module& rhs) = default; |
| 115 | 310 |
| 116 ModuleEnumerator::Module::Module(ModuleType type, | 311 ModuleEnumerator::Module::Module(ModuleType type, |
| 117 ModuleStatus status, | 312 ModuleStatus status, |
| 118 const base::string16& location, | 313 const base::string16& location, |
| (...skipping 12 matching lines...) Expand all Loading... |
| 131 version(version), | 326 version(version), |
| 132 digital_signer(digital_signer), | 327 digital_signer(digital_signer), |
| 133 recommended_action(recommended_action), | 328 recommended_action(recommended_action), |
| 134 duplicate_count(0), | 329 duplicate_count(0), |
| 135 normalized(false) { | 330 normalized(false) { |
| 136 } | 331 } |
| 137 | 332 |
| 138 ModuleEnumerator::Module::~Module() { | 333 ModuleEnumerator::Module::~Module() { |
| 139 } | 334 } |
| 140 | 335 |
| 141 // The browser process module blacklist. This lists modules that are known | |
| 142 // to cause compatibility issues within the browser process. When adding to this | |
| 143 // list, make sure that all paths are lower-case, in long pathname form, end | |
| 144 // with a slash and use environments variables (or just look at one of the | |
| 145 // comments below and keep it consistent with that). When adding an entry with | |
| 146 // an environment variable not currently used in the list below, make sure to | |
| 147 // update the list in PreparePathMappings. Filename, Description/Signer, and | |
| 148 // Location must be entered as hashes (see GenerateHash). Filename is mandatory. | |
| 149 // Entries without any Description, Signer info, or Location will never be | |
| 150 // marked as confirmed bad (only as suspicious). | |
| 151 const ModuleEnumerator::BlacklistEntry ModuleEnumerator::kModuleBlacklist[] = { | |
| 152 // NOTE: Please keep this list sorted by dll name, then location. | |
| 153 | |
| 154 // Version 3.2.1.6 seems to be implicated in most cases (and 3.2.2.2 in some). | |
| 155 // There is a more recent version available for download. | |
| 156 // accelerator.dll, "%programfiles%\\speedbit video accelerator\\". | |
| 157 { "7ba9402f", "c9132d48", "", "", "", ALL, kInvestigatingLink }, | |
| 158 | |
| 159 // apiqq0.dll, "%temp%\\". | |
| 160 { "26134911", "59145acf", "", "", "", ALL, kUninstallLink }, | |
| 161 | |
| 162 // arking0.dll, "%systemroot%\\system32\\". | |
| 163 { "f5d8f549", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 164 | |
| 165 // arking1.dll, "%systemroot%\\system32\\". | |
| 166 { "c60ca062", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 167 | |
| 168 // aswjsflt.dll, "%ProgramFiles%\\avast software\\avast\\", "AVAST Software". | |
| 169 // NOTE: The digital signature of the DLL is double null terminated. | |
| 170 // Avast Antivirus prior to version 8.0 would kill the Chrome child process | |
| 171 // when blocked from running. | |
| 172 { "2ea5422a", "6b3a1b00", "a7db0e0c", "", "8.0", XP, | |
| 173 static_cast<RecommendedAction>(UPDATE | SEE_LINK | NOTIFY_USER) }, | |
| 174 | |
| 175 // aswjsflt.dll, "%ProgramFiles%\\alwil software\\avast5\\", "AVAST Software". | |
| 176 // NOTE: The digital signature of the DLL is double null terminated. | |
| 177 // Avast Antivirus prior to version 8.0 would kill the Chrome child process | |
| 178 // when blocked from running. | |
| 179 { "2ea5422a", "d8686924", "a7db0e0c", "", "8.0", XP, | |
| 180 static_cast<RecommendedAction>(UPDATE | SEE_LINK | NOTIFY_USER) }, | |
| 181 | |
| 182 // Said to belong to Killer NIC from BigFoot Networks (not verified). Versions | |
| 183 // 6.0.0.7 and 6.0.0.10 implicated. | |
| 184 // bfllr.dll, "%systemroot%\\system32\\". | |
| 185 { "6bb57633", "23d01d5b", "", "", "", ALL, kInvestigatingLink }, | |
| 186 | |
| 187 // clickpotatolitesahook.dll, "". Different version each report. | |
| 188 { "0396e037.dll", "", "", "", "", ALL, kUninstallLink }, | |
| 189 | |
| 190 // cvasds0.dll, "%temp%\\". | |
| 191 { "5ce0037c", "59145acf", "", "", "", ALL, kUninstallLink }, | |
| 192 | |
| 193 // cwalsp.dll, "%systemroot%\\system32\\". | |
| 194 { "e579a039", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 195 | |
| 196 // datamngr.dll (1), "%programfiles%\\searchqu toolbar\\datamngr\\". | |
| 197 { "7add320b", "470a3da3", "", "", "", ALL, kUninstallLink }, | |
| 198 | |
| 199 // datamngr.dll (2), "%programfiles%\\windows searchqu toolbar\\". | |
| 200 { "7add320b", "7a3c8be3", "", "", "", ALL, kUninstallLink }, | |
| 201 | |
| 202 // dsoqq0.dll, "%temp%\\". | |
| 203 { "1c4df325", "59145acf", "", "", "", ALL, kUninstallLink }, | |
| 204 | |
| 205 // flt.dll, "%programfiles%\\tueagles\\". | |
| 206 { "6d01f4a1", "7935e9c2", "", "", "", ALL, kUninstallLink }, | |
| 207 | |
| 208 // This looks like a malware edition of a Brazilian Bank plugin, sometimes | |
| 209 // referred to as Malware.Banc.A. | |
| 210 // gbieh.dll, "%programfiles%\\gbplugin\\". | |
| 211 { "4cb4f2e3", "88e4a3b1", "", "", "", ALL, kUninstallLink }, | |
| 212 | |
| 213 // hblitesahook.dll. Each report has different version number in location. | |
| 214 { "5d10b363", "", "", "", "", ALL, kUninstallLink }, | |
| 215 | |
| 216 // icf.dll, "%systemroot%\\system32\\". | |
| 217 { "303825ed", "23d01d5b", "", "", "", ALL, INVESTIGATING }, | |
| 218 | |
| 219 // idmmbc.dll (IDM), "%systemroot%\\system32\\". See: http://crbug.com/26892/. | |
| 220 { "b8dce5c3", "23d01d5b", "", "", "6.03", ALL, | |
| 221 static_cast<RecommendedAction>(UPDATE | DISABLE) }, | |
| 222 | |
| 223 // imon.dll (NOD32), "%systemroot%\\system32\\". See: http://crbug.com/21715. | |
| 224 { "8f42f22e", "23d01d5b", "", "", "4.0", ALL, | |
| 225 static_cast<RecommendedAction>(UPDATE | DISABLE) }, | |
| 226 | |
| 227 // is3lsp.dll, "%commonprogramfiles%\\is3\\anti-spyware\\". | |
| 228 { "7ffbdce9", "bc5673f2", "", "", "", ALL, | |
| 229 static_cast<RecommendedAction>(UPDATE | DISABLE | SEE_LINK) }, | |
| 230 | |
| 231 // jsi.dll, "%programfiles%\\profilecraze\\". | |
| 232 { "f9555eea", "e3548061", "", "", "", ALL, kUninstallLink }, | |
| 233 | |
| 234 // kernel.dll, "%programfiles%\\contentwatch\\internet protection\\modules\\". | |
| 235 { "ead2768e", "4e61ce60", "", "", "", ALL, INVESTIGATING }, | |
| 236 | |
| 237 // mgking0.dll, "%systemroot%\\system32\\". | |
| 238 { "d0893e38", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 239 | |
| 240 // mgking0.dll, "%temp%\\". | |
| 241 { "d0893e38", "59145acf", "", "", "", ALL, kUninstallLink }, | |
| 242 | |
| 243 // mgking1.dll, "%systemroot%\\system32\\". | |
| 244 { "3e837222", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 245 | |
| 246 // mgking1.dll, "%temp%\\". | |
| 247 { "3e837222", "59145acf", "", "", "", ALL, kUninstallLink }, | |
| 248 | |
| 249 // mstcipha.ime, "%systemroot%\\system32\\". | |
| 250 { "5523579e", "23d01d5b", "", "", "", ALL, INVESTIGATING }, | |
| 251 | |
| 252 // mwtsp.dll, "%systemroot%\\system32\\". | |
| 253 { "9830bff6", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 254 | |
| 255 // nodqq0.dll, "%temp%\\". | |
| 256 { "b86ce04d", "59145acf", "", "", "", ALL, kUninstallLink }, | |
| 257 | |
| 258 // nProtect GameGuard Anti-cheat system. Every report has a different | |
| 259 // location, since it is installed into and run from a game folder. Various | |
| 260 // versions implicated. | |
| 261 // npggnt.des, no fixed location. | |
| 262 { "f2c8790d", "", "", "", "", ALL, kInvestigatingLink }, | |
| 263 | |
| 264 // nvlsp.dll, | |
| 265 // "%programfiles%\\nvidia corporation\\networkaccessmanager\\bin32\\". | |
| 266 { "37f907e2", "3ad0ff23", "", "", "", ALL, INVESTIGATING }, | |
| 267 | |
| 268 // post0.dll, "%systemroot%\\system32\\". | |
| 269 { "7405c0c8", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 270 | |
| 271 // questbrwsearch.dll, "%programfiles%\\questbrwsearch\\". | |
| 272 { "0953ed09", "f0d5eeda", "", "", "", ALL, kUninstallLink }, | |
| 273 | |
| 274 // questscan.dll, "%programfiles%\\questscan\\". | |
| 275 { "f4f3391e", "119d20f7", "", "", "", ALL, kUninstallLink }, | |
| 276 | |
| 277 // radhslib.dll (Naomi web filter), "%programfiles%\\rnamfler\\". | |
| 278 // See http://crbug.com/12517. | |
| 279 { "7edcd250", "0733dc3e", "", "", "", ALL, INVESTIGATING }, | |
| 280 | |
| 281 // rlls.dll, "%programfiles%\\relevantknowledge\\". | |
| 282 { "a1ed94a7", "ea9d6b36", "", "", "", ALL, kUninstallLink }, | |
| 283 | |
| 284 // rooksdol.dll, "%programfiles%\\trusteer\\rapport\\bin\\". | |
| 285 { "802aefef", "06120e13", "", "", "3.5.1008.40", ALL, UPDATE }, | |
| 286 | |
| 287 // scanquery.dll, "%programfiles%\\scanquery\\". | |
| 288 { "0b52d2ae", "a4cc88b1", "", "", "", ALL, kUninstallLink }, | |
| 289 | |
| 290 // sdata.dll, "%programdata%\\srtserv\\". | |
| 291 { "1936d5cc", "223c44be", "", "", "", ALL, kUninstallLink }, | |
| 292 | |
| 293 // searchtree.dll, | |
| 294 // "%programfiles%\\contentwatch\\internet protection\\modules\\". | |
| 295 { "f6915a31", "4e61ce60", "", "", "", ALL, INVESTIGATING }, | |
| 296 | |
| 297 // sgprxy.dll, "%commonprogramfiles%\\is3\\anti-spyware\\". | |
| 298 { "005965ea", "bc5673f2", "", "", "", ALL, INVESTIGATING }, | |
| 299 | |
| 300 // snxhk.dll, "%ProgramFiles%\\avast software\\avast\\", "AVAST Software". | |
| 301 // NOTE: The digital signature of the DLL is double null terminated. | |
| 302 // Avast Antivirus prior to version 8.0 would kill the Chrome child process | |
| 303 // when blocked from running. | |
| 304 { "46c16aa8", "6b3a1b00", "a7db0e0c", "", "8.0", XP, | |
| 305 static_cast<RecommendedAction>(UPDATE | SEE_LINK | NOTIFY_USER) }, | |
| 306 | |
| 307 // snxhk.dll, "%ProgramFiles%\\alwil software\\avast5\\", "AVAST Software". | |
| 308 // NOTE: The digital signature of the DLL is double null terminated. | |
| 309 // Avast Antivirus prior to version 8.0 would kill the Chrome child process | |
| 310 // when blocked from running. | |
| 311 { "46c16aa8", "d8686924", "a7db0e0c", "", "8.0", XP, | |
| 312 static_cast<RecommendedAction>(UPDATE | SEE_LINK | NOTIFY_USER) }, | |
| 313 | |
| 314 // sprotector.dll, "". Different location each report. | |
| 315 { "24555d74", "", "", "", "", ALL, kUninstallLink }, | |
| 316 | |
| 317 // swi_filter_0001.dll (Sophos Web Intelligence), | |
| 318 // "%programfiles%\\sophos\\sophos anti-virus\\web intelligence\\". | |
| 319 // A small random sample all showed version 1.0.5.0. | |
| 320 { "61112d7b", "25fb120f", "", "", "", ALL, kInvestigatingLink }, | |
| 321 | |
| 322 // twking0.dll, "%systemroot%\\system32\\". | |
| 323 { "0355549b", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 324 | |
| 325 // twking1.dll, "%systemroot%\\system32\\". | |
| 326 { "02e44508", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 327 | |
| 328 // vksaver.dll, "%systemroot%\\system32\\". | |
| 329 { "c4a784d5", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 330 | |
| 331 // vlsp.dll (Venturi Firewall?), "%systemroot%\\system32\\". | |
| 332 { "2e4eb93d", "23d01d5b", "", "", "", ALL, INVESTIGATING }, | |
| 333 | |
| 334 // vmn3_1dn.dll, "%appdata%\\roaming\\vmndtxtb\\". | |
| 335 { "bba2037d", "9ab68585", "", "", "", ALL, kUninstallLink }, | |
| 336 | |
| 337 // webanalyzer.dll, | |
| 338 // "%programfiles%\\contentwatch\\internet protection\\modules\\". | |
| 339 { "c70b697d", "4e61ce60", "", "", "", ALL, INVESTIGATING }, | |
| 340 | |
| 341 // wowst0.dll, "%systemroot%\\system32\\". | |
| 342 { "38ad9963", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 343 | |
| 344 // wxbase28u_vc_cw.dll, "%systemroot%\\system32\\". | |
| 345 { "e967210d", "23d01d5b", "", "", "", ALL, kUninstallLink }, | |
| 346 }; | |
| 347 | |
| 348 // Generates an 8 digit hash from the input given. | |
| 349 static void GenerateHash(const std::string& input, std::string* output) { | |
| 350 if (input.empty()) { | |
| 351 *output = ""; | |
| 352 return; | |
| 353 } | |
| 354 | |
| 355 uint8_t hash[4]; | |
| 356 crypto::SHA256HashString(input, hash, sizeof(hash)); | |
| 357 *output = base::ToLowerASCII(base::HexEncode(hash, sizeof(hash))); | |
| 358 } | |
| 359 | |
| 360 // ----------------------------------------------------------------------------- | 336 // ----------------------------------------------------------------------------- |
| 361 | 337 |
| 362 // static | 338 // static |
| 363 void ModuleEnumerator::NormalizeModule(Module* module) { | 339 void ModuleEnumerator::NormalizeModule(Module* module) { |
| 364 base::string16 path = module->location; | 340 base::string16 path = module->location; |
| 365 if (!ConvertToLongPath(path, &module->location)) | 341 if (!ConvertToLongPath(path, &module->location)) |
| 366 module->location = path; | 342 module->location = path; |
| 367 | 343 |
| 368 module->location = base::i18n::ToLower(module->location); | 344 module->location = base::i18n::ToLower(module->location); |
| 369 | 345 |
| (...skipping 10 matching lines...) Expand all Loading... |
| 380 | 356 |
| 381 // Some version strings have things like (win7_rtm.090713-1255) appended | 357 // Some version strings have things like (win7_rtm.090713-1255) appended |
| 382 // to them. Remove that. | 358 // to them. Remove that. |
| 383 size_t first_space = module->version.find_first_of(L" "); | 359 size_t first_space = module->version.find_first_of(L" "); |
| 384 if (first_space != base::string16::npos) | 360 if (first_space != base::string16::npos) |
| 385 module->version = module->version.substr(0, first_space); | 361 module->version = module->version.substr(0, first_space); |
| 386 | 362 |
| 387 module->normalized = true; | 363 module->normalized = true; |
| 388 } | 364 } |
| 389 | 365 |
| 390 // static | |
| 391 ModuleEnumerator::ModuleStatus ModuleEnumerator::Match( | |
| 392 const ModuleEnumerator::Module& module, | |
| 393 const ModuleEnumerator::BlacklistEntry& blacklisted) { | |
| 394 // All modules must be normalized before matching against blacklist. | |
| 395 DCHECK(module.normalized); | |
| 396 // Filename is mandatory and version should not contain spaces. | |
| 397 DCHECK(strlen(blacklisted.filename) > 0); | |
| 398 DCHECK(!strstr(blacklisted.version_from, " ")); | |
| 399 DCHECK(!strstr(blacklisted.version_to, " ")); | |
| 400 | |
| 401 base::win::Version version = base::win::GetVersion(); | |
| 402 switch (version) { | |
| 403 case base::win::VERSION_XP: | |
| 404 if (!(blacklisted.os & XP)) return NOT_MATCHED; | |
| 405 break; | |
| 406 default: | |
| 407 break; | |
| 408 } | |
| 409 | |
| 410 std::string filename_hash, location_hash; | |
| 411 GenerateHash(base::WideToUTF8(module.name), &filename_hash); | |
| 412 GenerateHash(base::WideToUTF8(module.location), &location_hash); | |
| 413 | |
| 414 // Filenames are mandatory. Location is mandatory if given. | |
| 415 if (filename_hash == blacklisted.filename && | |
| 416 (std::string(blacklisted.location).empty() || | |
| 417 location_hash == blacklisted.location)) { | |
| 418 // We have a name match against the blacklist (and possibly location match | |
| 419 // also), so check version. | |
| 420 Version module_version(base::UTF16ToASCII(module.version)); | |
| 421 Version version_min(blacklisted.version_from); | |
| 422 Version version_max(blacklisted.version_to); | |
| 423 bool version_ok = !version_min.IsValid() && !version_max.IsValid(); | |
| 424 if (!version_ok) { | |
| 425 bool too_low = version_min.IsValid() && | |
| 426 (!module_version.IsValid() || | |
| 427 module_version.CompareTo(version_min) < 0); | |
| 428 bool too_high = version_max.IsValid() && | |
| 429 (!module_version.IsValid() || | |
| 430 module_version.CompareTo(version_max) >= 0); | |
| 431 version_ok = !too_low && !too_high; | |
| 432 } | |
| 433 | |
| 434 if (version_ok) { | |
| 435 // At this point, the names match and there is no version specified | |
| 436 // or the versions also match. | |
| 437 | |
| 438 std::string desc_or_signer(blacklisted.desc_or_signer); | |
| 439 std::string signer_hash, description_hash; | |
| 440 GenerateHash(base::WideToUTF8(module.digital_signer), &signer_hash); | |
| 441 GenerateHash(base::WideToUTF8(module.description), &description_hash); | |
| 442 | |
| 443 // If signatures match (or both are empty), then we have a winner. | |
| 444 if (signer_hash == desc_or_signer) | |
| 445 return CONFIRMED_BAD; | |
| 446 | |
| 447 // If descriptions match (or both are empty) and the locations match, then | |
| 448 // we also have a confirmed match. | |
| 449 if (description_hash == desc_or_signer && | |
| 450 !location_hash.empty() && location_hash == blacklisted.location) | |
| 451 return CONFIRMED_BAD; | |
| 452 | |
| 453 // We are not sure, but it is likely bad. | |
| 454 return SUSPECTED_BAD; | |
| 455 } | |
| 456 } | |
| 457 | |
| 458 return NOT_MATCHED; | |
| 459 } | |
| 460 | |
| 461 ModuleEnumerator::ModuleEnumerator(EnumerateModulesModel* observer) | 366 ModuleEnumerator::ModuleEnumerator(EnumerateModulesModel* observer) |
| 462 : enumerated_modules_(NULL), | 367 : enumerated_modules_(nullptr), |
| 463 observer_(observer), | 368 observer_(observer) { |
| 464 limited_mode_(false), | |
| 465 callback_thread_id_(BrowserThread::ID_COUNT) { | |
| 466 } | |
| 467 | |
| 468 void ModuleEnumerator::ScanNow(ModulesVector* list, bool limited_mode) { | |
| 469 enumerated_modules_ = list; | |
| 470 | |
| 471 limited_mode_ = limited_mode; | |
| 472 | |
| 473 if (!limited_mode_) { | |
| 474 CHECK(BrowserThread::GetCurrentThreadIdentifier(&callback_thread_id_)); | |
| 475 BrowserThread::PostTask(BrowserThread::FILE, FROM_HERE, | |
| 476 base::Bind(&ModuleEnumerator::ScanImpl, this)); | |
| 477 } else { | |
| 478 // Run it synchronously. | |
| 479 ScanImpl(); | |
| 480 } | |
| 481 } | 369 } |
| 482 | 370 |
| 483 ModuleEnumerator::~ModuleEnumerator() { | 371 ModuleEnumerator::~ModuleEnumerator() { |
| 484 } | 372 } |
| 485 | 373 |
| 374 void ModuleEnumerator::ScanNow(ModulesVector* list) { |
| 375 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 376 enumerated_modules_ = list; |
| 377 |
| 378 // This object can't be reaped until it has finished scanning, so its safe |
| 379 // to post a raw pointer to another thread. |
| 380 BrowserThread::PostTask(BrowserThread::FILE, FROM_HERE, |
| 381 base::Bind(&ModuleEnumerator::ScanImpl, |
| 382 base::Unretained(this))); |
| 383 } |
| 384 |
| 486 void ModuleEnumerator::ScanImpl() { | 385 void ModuleEnumerator::ScanImpl() { |
| 487 base::TimeTicks start_time = base::TimeTicks::Now(); | 386 base::TimeTicks start_time = base::TimeTicks::Now(); |
| 488 | 387 |
| 489 enumerated_modules_->clear(); | 388 enumerated_modules_->clear(); |
| 490 | 389 |
| 491 // Make sure the path mapping vector is setup so we can collapse paths. | 390 // Make sure the path mapping vector is setup so we can collapse paths. |
| 492 PreparePathMappings(); | 391 PreparePathMappings(); |
| 493 | 392 |
| 494 // Enumerating loaded modules must happen first since the other types of | 393 // Enumerating loaded modules must happen first since the other types of |
| 495 // modules check for duplication against the loaded modules. | 394 // modules check for duplication against the loaded modules. |
| 496 base::TimeTicks checkpoint = base::TimeTicks::Now(); | 395 base::TimeTicks checkpoint = base::TimeTicks::Now(); |
| 497 EnumerateLoadedModules(); | 396 EnumerateLoadedModules(); |
| 498 base::TimeTicks checkpoint2 = base::TimeTicks::Now(); | 397 base::TimeTicks checkpoint2 = base::TimeTicks::Now(); |
| 499 UMA_HISTOGRAM_TIMES("Conflicts.EnumerateLoadedModules", | 398 UMA_HISTOGRAM_TIMES("Conflicts.EnumerateLoadedModules", |
| 500 checkpoint2 - checkpoint); | 399 checkpoint2 - checkpoint); |
| 501 | 400 |
| 502 checkpoint = checkpoint2; | 401 checkpoint = checkpoint2; |
| 503 EnumerateShellExtensions(); | 402 EnumerateShellExtensions(); |
| 504 checkpoint2 = base::TimeTicks::Now(); | 403 checkpoint2 = base::TimeTicks::Now(); |
| 505 UMA_HISTOGRAM_TIMES("Conflicts.EnumerateShellExtensions", | 404 UMA_HISTOGRAM_TIMES("Conflicts.EnumerateShellExtensions", |
| 506 checkpoint2 - checkpoint); | 405 checkpoint2 - checkpoint); |
| 507 | 406 |
| 508 checkpoint = checkpoint2; | 407 checkpoint = checkpoint2; |
| 509 EnumerateWinsockModules(); | 408 EnumerateWinsockModules(); |
| 510 checkpoint2 = base::TimeTicks::Now(); | 409 checkpoint2 = base::TimeTicks::Now(); |
| 511 UMA_HISTOGRAM_TIMES("Conflicts.EnumerateWinsockModules", | 410 UMA_HISTOGRAM_TIMES("Conflicts.EnumerateWinsockModules", |
| 512 checkpoint2 - checkpoint); | 411 checkpoint2 - checkpoint); |
| 513 | 412 |
| 514 MatchAgainstBlacklist(); | 413 // TODO(chrisha): Annotate any modules that are suspicious/bad. |
| 414 |
| 415 ReportThirdPartyMetrics(); |
| 515 | 416 |
| 516 std::sort(enumerated_modules_->begin(), | 417 std::sort(enumerated_modules_->begin(), |
| 517 enumerated_modules_->end(), ModuleSort); | 418 enumerated_modules_->end(), ModuleSort); |
| 518 | 419 |
| 519 if (!limited_mode_) { | |
| 520 // Send a reply back on the UI thread. | |
| 521 BrowserThread::PostTask(callback_thread_id_, FROM_HERE, | |
| 522 base::Bind(&ModuleEnumerator::ReportBack, this)); | |
| 523 } else { | |
| 524 // We are on the main thread already. | |
| 525 ReportBack(); | |
| 526 } | |
| 527 | |
| 528 UMA_HISTOGRAM_TIMES("Conflicts.EnumerationTotalTime", | 420 UMA_HISTOGRAM_TIMES("Conflicts.EnumerationTotalTime", |
| 529 base::TimeTicks::Now() - start_time); | 421 base::TimeTicks::Now() - start_time); |
| 422 |
| 423 // Send a reply back on the UI thread. The |observer_| outlives this |
| 424 // enumerator, so posting a raw pointer is safe. This is done last as |
| 425 // DoneScanning will then reap this ModuleEnumerator. |
| 426 BrowserThread::PostTask(BrowserThread::UI, FROM_HERE, |
| 427 base::Bind(&EnumerateModulesModel::DoneScanning, |
| 428 base::Unretained(observer_))); |
| 530 } | 429 } |
| 531 | 430 |
| 532 void ModuleEnumerator::EnumerateLoadedModules() { | 431 void ModuleEnumerator::EnumerateLoadedModules() { |
| 533 // Get all modules in the current process. | 432 // Get all modules in the current process. |
| 534 base::win::ScopedHandle snap(::CreateToolhelp32Snapshot(TH32CS_SNAPMODULE, | 433 base::win::ScopedHandle snap(::CreateToolhelp32Snapshot(TH32CS_SNAPMODULE, |
| 535 ::GetCurrentProcessId())); | 434 ::GetCurrentProcessId())); |
| 536 if (!snap.Get()) | 435 if (!snap.Get()) |
| 537 return; | 436 return; |
| 538 | 437 |
| 539 // Walk the module list. | 438 // Walk the module list. |
| (...skipping 156 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 696 location.substr(prefix.length() - 1); | 595 location.substr(prefix.length() - 1); |
| 697 size_t length = new_location.length() - mapping->second.length(); | 596 size_t length = new_location.length() - mapping->second.length(); |
| 698 if (length < min_length) { | 597 if (length < min_length) { |
| 699 entry->location = new_location; | 598 entry->location = new_location; |
| 700 min_length = length; | 599 min_length = length; |
| 701 } | 600 } |
| 702 } | 601 } |
| 703 } | 602 } |
| 704 } | 603 } |
| 705 | 604 |
| 706 void ModuleEnumerator::MatchAgainstBlacklist() { | |
| 707 for (size_t m = 0; m < enumerated_modules_->size(); ++m) { | |
| 708 // Match this module against the blacklist. | |
| 709 Module* module = &(*enumerated_modules_)[m]; | |
| 710 module->status = GOOD; // We change this below potentially. | |
| 711 for (size_t i = 0; i < arraysize(kModuleBlacklist); ++i) { | |
| 712 #if !defined(NDEBUG) | |
| 713 // This saves time when constructing the blacklist. | |
| 714 std::string hashes(kModuleBlacklist[i].filename); | |
| 715 std::string hash1, hash2, hash3; | |
| 716 GenerateHash(kModuleBlacklist[i].filename, &hash1); | |
| 717 hashes += " - " + hash1; | |
| 718 GenerateHash(kModuleBlacklist[i].location, &hash2); | |
| 719 hashes += " - " + hash2; | |
| 720 GenerateHash(kModuleBlacklist[i].desc_or_signer, &hash3); | |
| 721 hashes += " - " + hash3; | |
| 722 #endif | |
| 723 | |
| 724 ModuleStatus status = Match(*module, kModuleBlacklist[i]); | |
| 725 if (status != NOT_MATCHED) { | |
| 726 // We have a match against the blacklist. Mark it as such. | |
| 727 module->status = status; | |
| 728 module->recommended_action = kModuleBlacklist[i].help_tip; | |
| 729 break; | |
| 730 } | |
| 731 } | |
| 732 | |
| 733 // Modules loaded from these locations are frequently malicious | |
| 734 // and notorious for changing frequently so they are not good candidates | |
| 735 // for blacklisting individually. Mark them as suspicious if we haven't | |
| 736 // classified them as bad yet. | |
| 737 if (module->status == NOT_MATCHED || module->status == GOOD) { | |
| 738 if (base::StartsWith(module->location, L"%temp%", | |
| 739 base::CompareCase::INSENSITIVE_ASCII) || | |
| 740 base::StartsWith(module->location, L"%tmp%", | |
| 741 base::CompareCase::INSENSITIVE_ASCII)) { | |
| 742 module->status = SUSPECTED_BAD; | |
| 743 } | |
| 744 } | |
| 745 } | |
| 746 } | |
| 747 | |
| 748 void ModuleEnumerator::ReportBack() { | |
| 749 if (!limited_mode_) | |
| 750 DCHECK_CURRENTLY_ON(callback_thread_id_); | |
| 751 observer_->DoneScanning(); | |
| 752 } | |
| 753 | |
| 754 base::string16 ModuleEnumerator::GetSubjectNameFromDigitalSignature( | 605 base::string16 ModuleEnumerator::GetSubjectNameFromDigitalSignature( |
| 755 const base::FilePath& filename) { | 606 const base::FilePath& filename) { |
| 756 HCERTSTORE store = NULL; | 607 // Try using the signature directly present in the file first. |
| 757 HCRYPTMSG message = NULL; | 608 base::string16 subject_name = GetSubjectNameInFile(filename); |
| 609 if (!subject_name.empty()) |
| 610 return subject_name; |
| 758 | 611 |
| 759 // Find the crypto message for this filename. | 612 // If that fails then look in the signed catalogs. |
| 760 bool result = !!CryptQueryObject(CERT_QUERY_OBJECT_FILE, | 613 return GetSubjectNameInCatalog(filename); |
| 761 filename.value().c_str(), | 614 } |
| 762 CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED_EMBED, | |
| 763 CERT_QUERY_FORMAT_FLAG_BINARY, | |
| 764 0, | |
| 765 NULL, | |
| 766 NULL, | |
| 767 NULL, | |
| 768 &store, | |
| 769 &message, | |
| 770 NULL); | |
| 771 if (!result) | |
| 772 return base::string16(); | |
| 773 | 615 |
| 774 // Determine the size of the signer info data. | 616 void ModuleEnumerator::ReportThirdPartyMetrics() { |
| 775 DWORD signer_info_size = 0; | 617 static const wchar_t kMicrosoft[] = L"Microsoft "; |
| 776 result = !!CryptMsgGetParam(message, | |
| 777 CMSG_SIGNER_INFO_PARAM, | |
| 778 0, | |
| 779 NULL, | |
| 780 &signer_info_size); | |
| 781 if (!result) | |
| 782 return base::string16(); | |
| 783 | 618 |
| 784 // Allocate enough space to hold the signer info. | 619 size_t signed_modules = 0; |
| 785 std::unique_ptr<BYTE[]> signer_info_buffer(new BYTE[signer_info_size]); | 620 size_t microsoft_modules = 0; |
| 786 CMSG_SIGNER_INFO* signer_info = | 621 for (const auto& module : *enumerated_modules_) { |
| 787 reinterpret_cast<CMSG_SIGNER_INFO*>(signer_info_buffer.get()); | 622 if (!module.digital_signer.empty()) { |
| 623 ++signed_modules; |
| 788 | 624 |
| 789 // Obtain the signer info. | 625 // Check if the signer name begins with "Microsoft ". Signatures are |
| 790 result = !!CryptMsgGetParam(message, | 626 // typically "Microsoft Corporation" or "Microsoft Windows", but others |
| 791 CMSG_SIGNER_INFO_PARAM, | 627 // may exist. |
| 792 0, | 628 if (module.digital_signer.compare(0, arraysize(kMicrosoft) - 1, |
| 793 signer_info, | 629 kMicrosoft) == 0) { |
| 794 &signer_info_size); | 630 ++microsoft_modules; |
| 795 if (!result) | 631 } |
| 796 return base::string16(); | 632 } |
| 797 | |
| 798 // Search for the signer certificate. | |
| 799 CERT_INFO CertInfo = {0}; | |
| 800 PCCERT_CONTEXT cert_context = NULL; | |
| 801 CertInfo.Issuer = signer_info->Issuer; | |
| 802 CertInfo.SerialNumber = signer_info->SerialNumber; | |
| 803 | |
| 804 cert_context = CertFindCertificateInStore( | |
| 805 store, | |
| 806 X509_ASN_ENCODING | PKCS_7_ASN_ENCODING, | |
| 807 0, | |
| 808 CERT_FIND_SUBJECT_CERT, | |
| 809 &CertInfo, | |
| 810 NULL); | |
| 811 if (!cert_context) | |
| 812 return base::string16(); | |
| 813 | |
| 814 // Determine the size of the Subject name. | |
| 815 DWORD subject_name_size = CertGetNameString( | |
| 816 cert_context, CERT_NAME_SIMPLE_DISPLAY_TYPE, 0, NULL, NULL, 0); | |
| 817 if (!subject_name_size) | |
| 818 return base::string16(); | |
| 819 | |
| 820 base::string16 subject_name; | |
| 821 subject_name.resize(subject_name_size); | |
| 822 | |
| 823 // Get subject name. | |
| 824 if (!(CertGetNameString(cert_context, | |
| 825 CERT_NAME_SIMPLE_DISPLAY_TYPE, | |
| 826 0, | |
| 827 NULL, | |
| 828 const_cast<LPWSTR>(subject_name.c_str()), | |
| 829 subject_name_size))) { | |
| 830 return base::string16(); | |
| 831 } | 633 } |
| 832 | 634 |
| 833 return subject_name; | 635 // Report back some metrics regarding third party modules. |
| 636 UMA_HISTOGRAM_CUSTOM_COUNTS("ThirdPartyModules.Modules.Signed", |
| 637 signed_modules, 1, 500, 50); |
| 638 UMA_HISTOGRAM_CUSTOM_COUNTS("ThirdPartyModules.Modules.Signed.Microsoft", |
| 639 microsoft_modules, 1, 500, 50); |
| 640 UMA_HISTOGRAM_CUSTOM_COUNTS("ThirdPartyModules.Modules.Total", |
| 641 enumerated_modules_->size(), 1, 500, 50); |
| 834 } | 642 } |
| 835 | 643 |
| 836 // ---------------------------------------------------------------------------- | 644 // ---------------------------------------------------------------------------- |
| 837 | 645 |
| 838 // static | 646 // static |
| 839 EnumerateModulesModel* EnumerateModulesModel::GetInstance() { | 647 EnumerateModulesModel* EnumerateModulesModel::GetInstance() { |
| 840 return base::Singleton<EnumerateModulesModel>::get(); | 648 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 649 static EnumerateModulesModel* model = nullptr; |
| 650 if (!model) { |
| 651 model = new EnumerateModulesModel(); |
| 652 ANNOTATE_LEAKING_OBJECT_PTR(model); |
| 653 } |
| 654 return model; |
| 655 } |
| 656 |
| 657 void EnumerateModulesModel::AddObserver(Observer* observer) { |
| 658 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 659 observers_.AddObserver(observer); |
| 660 } |
| 661 |
| 662 // Removes an |observer| from the enumerator. May only be called from the UI |
| 663 // thread and callbacks will also occur on the UI thread. |
| 664 void EnumerateModulesModel::RemoveObserver(Observer* observer) { |
| 665 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 666 observers_.RemoveObserver(observer); |
| 841 } | 667 } |
| 842 | 668 |
| 843 bool EnumerateModulesModel::ShouldShowConflictWarning() const { | 669 bool EnumerateModulesModel::ShouldShowConflictWarning() const { |
| 670 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 671 |
| 844 // If the user has acknowledged the conflict notification, then we don't need | 672 // If the user has acknowledged the conflict notification, then we don't need |
| 845 // to show it again (because the scanning only happens once per the lifetime | 673 // to show it again (because the scanning only happens once per the lifetime |
| 846 // of the process). If we were to run the scanning more than once, then we'd | 674 // of the process). If we were to run the scanning more than once, then we'd |
| 847 // need to clear the flag somewhere when we are ready to show it again. | 675 // need to clear the flag somewhere when we are ready to show it again. |
| 848 if (conflict_notification_acknowledged_) | 676 if (conflict_notification_acknowledged_) |
| 849 return false; | 677 return false; |
| 850 | 678 |
| 851 return confirmed_bad_modules_detected_ > 0; | 679 return confirmed_bad_modules_detected_ > 0; |
| 852 } | 680 } |
| 853 | 681 |
| 854 void EnumerateModulesModel::AcknowledgeConflictNotification() { | 682 void EnumerateModulesModel::AcknowledgeConflictNotification() { |
| 683 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 684 |
| 855 if (!conflict_notification_acknowledged_) { | 685 if (!conflict_notification_acknowledged_) { |
| 856 conflict_notification_acknowledged_ = true; | 686 conflict_notification_acknowledged_ = true; |
| 857 content::NotificationService::current()->Notify( | 687 FOR_EACH_OBSERVER(Observer, observers_, OnConflictsAcknowledged()); |
| 858 chrome::NOTIFICATION_MODULE_INCOMPATIBILITY_ICON_CHANGE, | 688 } |
| 859 content::Source<EnumerateModulesModel>(this), | 689 } |
| 860 content::NotificationService::NoDetails()); | 690 |
| 691 int EnumerateModulesModel::suspected_bad_modules_detected() const { |
| 692 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 693 return suspected_bad_modules_detected_; |
| 694 } |
| 695 |
| 696 // Returns the number of confirmed bad modules found in the last scan. |
| 697 // Returns 0 if no scan has taken place yet. |
| 698 int EnumerateModulesModel::confirmed_bad_modules_detected() const { |
| 699 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 700 return confirmed_bad_modules_detected_; |
| 701 } |
| 702 |
| 703 // Returns how many modules to notify the user about. |
| 704 int EnumerateModulesModel::modules_to_notify_about() const { |
| 705 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 706 return modules_to_notify_about_; |
| 707 } |
| 708 |
| 709 void EnumerateModulesModel::MaybePostScanningTask() { |
| 710 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 711 static bool done = false; |
| 712 if (!done) { |
| 713 BrowserThread::PostAfterStartupTask( |
| 714 FROM_HERE, |
| 715 BrowserThread::GetTaskRunnerForThread(BrowserThread::UI), |
| 716 base::Bind(&EnumerateModulesModel::ScanNow, base::Unretained(this))); |
| 717 done = true; |
| 861 } | 718 } |
| 862 } | 719 } |
| 863 | 720 |
| 864 void EnumerateModulesModel::ScanNow() { | 721 void EnumerateModulesModel::ScanNow() { |
| 865 if (scanning_) | 722 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 866 return; // A scan is already in progress. | |
| 867 | 723 |
| 868 lock->Acquire(); // Balanced in DoneScanning(); | 724 // If a module enumerator exists then a scan is already underway. |
| 725 if (module_enumerator_) |
| 726 return; |
| 869 | 727 |
| 870 scanning_ = true; | 728 // ScanNow does not block, rather it simply schedules a task. |
| 871 | 729 module_enumerator_.reset(new ModuleEnumerator(this)); |
| 872 // Instruct the ModuleEnumerator class to load this on the File thread. | 730 module_enumerator_->ScanNow(&enumerated_modules_); |
| 873 // ScanNow does not block. | |
| 874 if (!module_enumerator_.get()) | |
| 875 module_enumerator_ = new ModuleEnumerator(this); | |
| 876 module_enumerator_->ScanNow(&enumerated_modules_, limited_mode_); | |
| 877 } | 731 } |
| 878 | 732 |
| 879 base::ListValue* EnumerateModulesModel::GetModuleList() const { | 733 base::ListValue* EnumerateModulesModel::GetModuleList() { |
| 880 if (scanning_) | 734 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 881 return NULL; | |
| 882 | 735 |
| 883 lock->Acquire(); | 736 // If a |module_enumerator_| is still around then scanning has not yet |
| 737 // completed, and it is unsafe to read from |enumerated_modules_|. |
| 738 if (module_enumerator_.get()) |
| 739 return nullptr; |
| 884 | 740 |
| 885 if (enumerated_modules_.empty()) { | 741 if (enumerated_modules_.empty()) |
| 886 lock->Release(); | 742 return nullptr; |
| 887 return NULL; | |
| 888 } | |
| 889 | 743 |
| 890 base::ListValue* list = new base::ListValue(); | 744 base::ListValue* list = new base::ListValue(); |
| 891 | 745 |
| 892 for (ModuleEnumerator::ModulesVector::const_iterator module = | 746 for (ModuleEnumerator::ModulesVector::const_iterator module = |
| 893 enumerated_modules_.begin(); | 747 enumerated_modules_.begin(); |
| 894 module != enumerated_modules_.end(); ++module) { | 748 module != enumerated_modules_.end(); ++module) { |
| 895 base::DictionaryValue* data = new base::DictionaryValue(); | 749 base::DictionaryValue* data = new base::DictionaryValue(); |
| 896 data->SetInteger("type", module->type); | 750 data->SetInteger("type", module->type); |
| 897 base::string16 type_string; | 751 base::string16 type_string; |
| 898 if ((module->type & ModuleEnumerator::LOADED_MODULE) == 0) { | 752 if ((module->type & ModuleEnumerator::LOADED_MODULE) == 0) { |
| 899 // Module is not loaded, denote type of module. | 753 // Module is not loaded, denote type of module. |
| 900 if (module->type & ModuleEnumerator::SHELL_EXTENSION) | 754 if (module->type & ModuleEnumerator::SHELL_EXTENSION) |
| 901 type_string = L"Shell Extension"; | 755 type_string = L"Shell Extension"; |
| 902 if (module->type & ModuleEnumerator::WINSOCK_MODULE_REGISTRATION) { | 756 if (module->type & ModuleEnumerator::WINSOCK_MODULE_REGISTRATION) { |
| 903 if (!type_string.empty()) | 757 if (!type_string.empty()) |
| 904 type_string += L", "; | 758 type_string += L", "; |
| 905 type_string += L"Winsock"; | 759 type_string += L"Winsock"; |
| 906 } | 760 } |
| 907 // Must be one of the above type. | 761 // Must be one of the above type. |
| 908 DCHECK(!type_string.empty()); | 762 DCHECK(!type_string.empty()); |
| 909 if (!limited_mode_) { | 763 type_string += L" -- "; |
| 910 type_string += L" -- "; | 764 type_string += l10n_util::GetStringUTF16(IDS_CONFLICTS_NOT_LOADED_YET); |
| 911 type_string += l10n_util::GetStringUTF16(IDS_CONFLICTS_NOT_LOADED_YET); | |
| 912 } | |
| 913 } | 765 } |
| 914 data->SetString("type_description", type_string); | 766 data->SetString("type_description", type_string); |
| 915 data->SetInteger("status", module->status); | 767 data->SetInteger("status", module->status); |
| 916 data->SetString("location", module->location); | 768 data->SetString("location", module->location); |
| 917 data->SetString("name", module->name); | 769 data->SetString("name", module->name); |
| 918 data->SetString("product_name", module->product_name); | 770 data->SetString("product_name", module->product_name); |
| 919 data->SetString("description", module->description); | 771 data->SetString("description", module->description); |
| 920 data->SetString("version", module->version); | 772 data->SetString("version", module->version); |
| 921 data->SetString("digital_signer", module->digital_signer); | 773 data->SetString("digital_signer", module->digital_signer); |
| 922 | 774 |
| 923 if (!limited_mode_) { | 775 // Figure out the possible resolution help string. |
| 924 // Figure out the possible resolution help string. | 776 base::string16 actions; |
| 925 base::string16 actions; | 777 base::string16 separator = L" " + |
| 926 base::string16 separator = L" " + | 778 l10n_util::GetStringUTF16( |
| 927 l10n_util::GetStringUTF16( | 779 IDS_CONFLICTS_CHECK_POSSIBLE_ACTION_SEPARATOR) + |
| 928 IDS_CONFLICTS_CHECK_POSSIBLE_ACTION_SEPARATOR) + | 780 L" "; |
| 929 L" "; | |
| 930 | 781 |
| 931 if (module->recommended_action & ModuleEnumerator::INVESTIGATING) { | 782 if (module->recommended_action & ModuleEnumerator::INVESTIGATING) { |
| 783 actions = l10n_util::GetStringUTF16( |
| 784 IDS_CONFLICTS_CHECK_INVESTIGATING); |
| 785 } else { |
| 786 if (module->recommended_action & ModuleEnumerator::UNINSTALL) { |
| 932 actions = l10n_util::GetStringUTF16( | 787 actions = l10n_util::GetStringUTF16( |
| 933 IDS_CONFLICTS_CHECK_INVESTIGATING); | 788 IDS_CONFLICTS_CHECK_POSSIBLE_ACTION_UNINSTALL); |
| 934 } else { | |
| 935 if (module->recommended_action & ModuleEnumerator::UNINSTALL) { | |
| 936 if (!actions.empty()) | |
| 937 actions += separator; | |
| 938 actions = l10n_util::GetStringUTF16( | |
| 939 IDS_CONFLICTS_CHECK_POSSIBLE_ACTION_UNINSTALL); | |
| 940 } | |
| 941 if (module->recommended_action & ModuleEnumerator::UPDATE) { | |
| 942 if (!actions.empty()) | |
| 943 actions += separator; | |
| 944 actions += l10n_util::GetStringUTF16( | |
| 945 IDS_CONFLICTS_CHECK_POSSIBLE_ACTION_UPDATE); | |
| 946 } | |
| 947 if (module->recommended_action & ModuleEnumerator::DISABLE) { | |
| 948 if (!actions.empty()) | |
| 949 actions += separator; | |
| 950 actions += l10n_util::GetStringUTF16( | |
| 951 IDS_CONFLICTS_CHECK_POSSIBLE_ACTION_DISABLE); | |
| 952 } | |
| 953 } | 789 } |
| 954 base::string16 possible_resolution; | 790 if (module->recommended_action & ModuleEnumerator::UPDATE) { |
| 955 if (!actions.empty()) { | 791 if (!actions.empty()) |
| 956 possible_resolution = | 792 actions += separator; |
| 957 l10n_util::GetStringUTF16(IDS_CONFLICTS_CHECK_POSSIBLE_ACTIONS) + | 793 actions += l10n_util::GetStringUTF16( |
| 958 L" " + actions; | 794 IDS_CONFLICTS_CHECK_POSSIBLE_ACTION_UPDATE); |
| 959 } | 795 } |
| 960 data->SetString("possibleResolution", possible_resolution); | 796 if (module->recommended_action & ModuleEnumerator::DISABLE) { |
| 961 data->SetString("help_url", | 797 if (!actions.empty()) |
| 962 ConstructHelpCenterUrl(*module).spec().c_str()); | 798 actions += separator; |
| 799 actions += l10n_util::GetStringUTF16( |
| 800 IDS_CONFLICTS_CHECK_POSSIBLE_ACTION_DISABLE); |
| 801 } |
| 963 } | 802 } |
| 803 base::string16 possible_resolution; |
| 804 if (!actions.empty()) { |
| 805 possible_resolution = |
| 806 l10n_util::GetStringUTF16(IDS_CONFLICTS_CHECK_POSSIBLE_ACTIONS) + |
| 807 L" " + actions; |
| 808 } |
| 809 data->SetString("possibleResolution", possible_resolution); |
| 810 // TODO(chrisha): Set help_url when we have a meaningful place for users |
| 811 // to land. |
| 964 | 812 |
| 965 list->Append(data); | 813 list->Append(data); |
| 966 } | 814 } |
| 967 | 815 |
| 968 lock->Release(); | |
| 969 return list; | 816 return list; |
| 970 } | 817 } |
| 971 | 818 |
| 972 GURL EnumerateModulesModel::GetFirstNotableConflict() { | 819 GURL EnumerateModulesModel::GetConflictUrl() { |
| 973 lock->Acquire(); | 820 // For now, simply bring up the chrome://conflicts page, which has detailed |
| 974 GURL url; | 821 // information about each module. |
| 975 | 822 if (ShouldShowConflictWarning()) |
| 976 if (enumerated_modules_.empty()) { | 823 return GURL(L"chrome://conflicts"); |
| 977 lock->Release(); | 824 return GURL(); |
| 978 return GURL(); | |
| 979 } | |
| 980 | |
| 981 for (ModuleEnumerator::ModulesVector::const_iterator module = | |
| 982 enumerated_modules_.begin(); | |
| 983 module != enumerated_modules_.end(); ++module) { | |
| 984 if (!(module->recommended_action & ModuleEnumerator::NOTIFY_USER)) | |
| 985 continue; | |
| 986 | |
| 987 url = ConstructHelpCenterUrl(*module); | |
| 988 DCHECK(url.is_valid()); | |
| 989 break; | |
| 990 } | |
| 991 | |
| 992 lock->Release(); | |
| 993 return url; | |
| 994 } | 825 } |
| 995 | 826 |
| 996 EnumerateModulesModel::EnumerateModulesModel() | 827 EnumerateModulesModel::EnumerateModulesModel() |
| 997 : limited_mode_(false), | 828 : conflict_notification_acknowledged_(false), |
| 998 scanning_(false), | |
| 999 conflict_notification_acknowledged_(false), | |
| 1000 confirmed_bad_modules_detected_(0), | 829 confirmed_bad_modules_detected_(0), |
| 1001 modules_to_notify_about_(0), | 830 modules_to_notify_about_(0), |
| 1002 suspected_bad_modules_detected_(0) { | 831 suspected_bad_modules_detected_(0) { |
| 1003 lock = new base::Lock(); | |
| 1004 } | 832 } |
| 1005 | 833 |
| 1006 EnumerateModulesModel::~EnumerateModulesModel() { | 834 EnumerateModulesModel::~EnumerateModulesModel() { |
| 1007 delete lock; | |
| 1008 } | |
| 1009 | |
| 1010 void EnumerateModulesModel::MaybePostScanningTask() { | |
| 1011 static bool done = false; | |
| 1012 if (!done) { | |
| 1013 done = true; | |
| 1014 if (base::win::GetVersion() == base::win::VERSION_XP) { | |
| 1015 check_modules_timer_.Start(FROM_HERE, | |
| 1016 base::TimeDelta::FromMilliseconds(kModuleCheckDelayMs), | |
| 1017 this, &EnumerateModulesModel::ScanNow); | |
| 1018 } | |
| 1019 } | |
| 1020 } | 835 } |
| 1021 | 836 |
| 1022 void EnumerateModulesModel::DoneScanning() { | 837 void EnumerateModulesModel::DoneScanning() { |
| 838 DCHECK_CURRENTLY_ON(BrowserThread::UI); |
| 839 DCHECK(module_enumerator_.get()); |
| 840 |
| 1023 confirmed_bad_modules_detected_ = 0; | 841 confirmed_bad_modules_detected_ = 0; |
| 1024 suspected_bad_modules_detected_ = 0; | 842 suspected_bad_modules_detected_ = 0; |
| 1025 modules_to_notify_about_ = 0; | 843 modules_to_notify_about_ = 0; |
| 1026 for (ModuleEnumerator::ModulesVector::const_iterator module = | 844 for (ModuleEnumerator::ModulesVector::const_iterator module = |
| 1027 enumerated_modules_.begin(); | 845 enumerated_modules_.begin(); |
| 1028 module != enumerated_modules_.end(); ++module) { | 846 module != enumerated_modules_.end(); ++module) { |
| 1029 if (module->status == ModuleEnumerator::CONFIRMED_BAD) { | 847 if (module->status == ModuleEnumerator::CONFIRMED_BAD) { |
| 1030 ++confirmed_bad_modules_detected_; | 848 ++confirmed_bad_modules_detected_; |
| 1031 if (module->recommended_action & ModuleEnumerator::NOTIFY_USER) | 849 if (module->recommended_action & ModuleEnumerator::NOTIFY_USER) |
| 1032 ++modules_to_notify_about_; | 850 ++modules_to_notify_about_; |
| 1033 } else if (module->status == ModuleEnumerator::SUSPECTED_BAD) { | 851 } else if (module->status == ModuleEnumerator::SUSPECTED_BAD) { |
| 1034 ++suspected_bad_modules_detected_; | 852 ++suspected_bad_modules_detected_; |
| 1035 if (module->recommended_action & ModuleEnumerator::NOTIFY_USER) | 853 if (module->recommended_action & ModuleEnumerator::NOTIFY_USER) |
| 1036 ++modules_to_notify_about_; | 854 ++modules_to_notify_about_; |
| 1037 } | 855 } |
| 1038 } | 856 } |
| 1039 | 857 |
| 1040 scanning_ = false; | 858 module_enumerator_.reset(); |
| 1041 lock->Release(); | |
| 1042 | 859 |
| 1043 UMA_HISTOGRAM_COUNTS_100("Conflicts.SuspectedBadModules", | 860 UMA_HISTOGRAM_COUNTS_100("Conflicts.SuspectedBadModules", |
| 1044 suspected_bad_modules_detected_); | 861 suspected_bad_modules_detected_); |
| 1045 UMA_HISTOGRAM_COUNTS_100("Conflicts.ConfirmedBadModules", | 862 UMA_HISTOGRAM_COUNTS_100("Conflicts.ConfirmedBadModules", |
| 1046 confirmed_bad_modules_detected_); | 863 confirmed_bad_modules_detected_); |
| 1047 | 864 |
| 1048 // Notifications are not available in limited mode. | 865 // Forward the callback to any registered observers. |
| 1049 if (limited_mode_) | 866 FOR_EACH_OBSERVER(Observer, observers_, OnScanCompleted()); |
| 1050 return; | |
| 1051 | |
| 1052 content::NotificationService::current()->Notify( | |
| 1053 chrome::NOTIFICATION_MODULE_LIST_ENUMERATED, | |
| 1054 content::Source<EnumerateModulesModel>(this), | |
| 1055 content::NotificationService::NoDetails()); | |
| 1056 } | 867 } |
| 1057 | |
| 1058 GURL EnumerateModulesModel::ConstructHelpCenterUrl( | |
| 1059 const ModuleEnumerator::Module& module) const { | |
| 1060 if (!(module.recommended_action & ModuleEnumerator::SEE_LINK) && | |
| 1061 !(module.recommended_action & ModuleEnumerator::NOTIFY_USER)) | |
| 1062 return GURL(); | |
| 1063 | |
| 1064 // Construct the needed hashes. | |
| 1065 std::string filename, location, description, signer; | |
| 1066 GenerateHash(base::WideToUTF8(module.name), &filename); | |
| 1067 GenerateHash(base::WideToUTF8(module.location), &location); | |
| 1068 GenerateHash(base::WideToUTF8(module.description), &description); | |
| 1069 GenerateHash(base::WideToUTF8(module.digital_signer), &signer); | |
| 1070 | |
| 1071 base::string16 url = | |
| 1072 l10n_util::GetStringFUTF16(IDS_HELP_CENTER_VIEW_CONFLICTS, | |
| 1073 base::ASCIIToUTF16(filename), base::ASCIIToUTF16(location), | |
| 1074 base::ASCIIToUTF16(description), base::ASCIIToUTF16(signer)); | |
| 1075 return GURL(base::UTF16ToUTF8(url)); | |
| 1076 } | |
| OLD | NEW |