diff --git a/Alternate versions Anti-Malware List/AntiMalwareABP.txt b/Alternate versions Anti-Malware List/AntiMalwareABP.txt index a19bfe123..4cbbd3705 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareABP.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareABP.txt @@ -1,6 +1,6 @@ [Adblock Plus 3.2] ! Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for AdBlock and Adblock Plus) -! Version: 03June2019v1-Beta +! Version: 11June2019v1-Beta ! Expires: 5 days ! Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. ! For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english @@ -114,5 +114,6 @@ drivereasy.com#?#.pakb-content p:-abp-contains(click Update All) ||reward*.harddayforal*.icu^ ||reward*.whoisyourd*.icu^ ||sweeps*.whoisyourd*.live^ +||apps*.wtflife*.life^ ! Placeholder line for alternate list versions diff --git a/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt b/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt index 43491a29b..0b900d109 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt @@ -1,6 +1,6 @@ [AdGuard β‰₯6] ! Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for AdGuard) -! Version: 03June2019v1-Beta +! Version: 11June2019v1-Beta ! Expires: 5 days ! Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. ! For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english @@ -130,5 +130,6 @@ drivereasy.com#?#.pakb-content p:-abp-contains(click Update All) ||reward*.harddayforal*.icu^$empty,important ||reward*.whoisyourd*.icu^$empty,important ||sweeps*.whoisyourd*.live^$empty,important +||apps*.wtflife*.life^$empty,important ! Placeholder line for alternate list versions diff --git a/Alternate versions Anti-Malware List/AntiMalwareDomains.txt b/Alternate versions Anti-Malware List/AntiMalwareDomains.txt new file mode 100644 index 000000000..fc3bf8481 --- /dev/null +++ b/Alternate versions Anti-Malware List/AntiMalwareDomains.txt @@ -0,0 +1,87 @@ +# Title: πŸ’Š Dandelion Sprout's Anti-Malware List (Domains list version) +# Version: 11June2019v1-Beta +# Expires: 5 days +# Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. +# For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english + +# πŸ”Ά Country domains +# You can expect these domains to have an overwhelming majority of malware domains that have nothing to do with the countries in question. Nevertheless, if you are in a situation where you have to do active business in any of the countries in question, then this list may not be ideal for you. +# Tokelau + +# Gabon + +# Mali + +# Equatorial Guinea + +# Central African Republic + + +# πŸ”Ά Topical domains +# These are topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent. +# Presumably fake loans + + + +# πŸ”Ά Attempted removal of Google search result entries that lead to the above top-level domains (Advanced adblockers only) + +# πŸ”Ά You know those ultra-fraudulent websites who clutter up Google searches, who have some seemingly random ".php?" values in their URLs? These entries should remove some of them. + +# πŸ”Ά For Google Mobile +# Note for Firefox on Android users: I strongly recommend the use of https://addons.mozilla.org/firefox/addon/google-search-fixer/ for use on Firefox for Android, thus the entries are written for the Chrome version of Google Mobile. + +# πŸ”Ά Dead domains that used to host lists for adblockers or "hosts" tools, but which are now either used by malware pushers, or could potentially be snapped up by them. (Also added to "uBlock Filters - Badware Risks", except for startshop.no) +adblock.gjtech.net +spam404bl.com +hufilter.hu +fredfiber.no +startshop.no +securemecca.com + +# πŸ”Ά Old tech-related domains that have fallen into the hands of questionable new owners. +# To log in to TP-Link routers, use tplinkwifi.net instead. +tplinklogin.net +tplinkextender.net +ublock.org + +# πŸ”Ά IQ test sites that make you waste heaps of time by taking the test, and then try to charge you to see the results. +funeducation.com +iq-research.info +iq-test-online.org +iq-test.co.uk +iqtest.co.uk +iqtest.com +iqtestnow.org +iqtestonline24.com +test-iq.org +officialiqtests.com + +# πŸ”Ά Old Linux-related domains that have been snapped up for ads, adware, and/or malware. +# How these links still remain in Unetbootin, is anyone's guess. +dreamlinux.com.br +dreamlinux.net +dreamlinux.info +hacktolive.org +mandriva.com + +# πŸ”Ά ReImagePlus links (Also added to "uBlock Filters - Badware Risks") +# https://windowsreport.com/extend-windows-laptop-battery-life/ +# https://appuals.com/fix-error-0x800701e3-on-windows-7-8-1-10/ +# https://ugetfix.com/ask/how-to-fix-windows-store-error-0x8000ffff/ +# https://www.thewindowsclub.com/fix-windows-update-error-0xc1900130-on-windows-10 +# https://www.majorgeeks.com/files/details/patch_my_pc.html + + +# πŸ”Ά ScanUtilities links +# https://www.bynarycodes.com/fix-windows-10-update-error-0x80070006/ + +# πŸ”Ά Driver Easy links +# https://www.drivereasy.com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/ +# https://www.drivereasy.com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/ +# https://www.drivereasy.com/knowledge/download-gigabyte-audio-driver/ +# https://www.drivereasy.com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/ +# https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/ + +# πŸ”Ά Sites that fraudulently claim you've won a new phone + + diff --git a/Alternate versions Anti-Malware List/AntiMalwareHosts.txt b/Alternate versions Anti-Malware List/AntiMalwareHosts.txt index ab424407e..766eef8c4 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareHosts.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareHosts.txt @@ -1,5 +1,5 @@ # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (Β«hostsΒ» file version) -# Version: 03June2019v1-Alpha +# Version: 11June2019v1-Alpha # Expires: 5 days # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. # For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english diff --git a/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action b/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action index 784931163..488bb5bdf 100644 --- a/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action +++ b/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action @@ -1,6 +1,6 @@ {+block} # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for Privoxy) -# Version: 03June2019v1-Alpha +# Version: 11June2019v1-Alpha # Expires: 5 days # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. # For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english @@ -102,6 +102,7 @@ .reward*.harddayforal*.icu .reward*.whoisyourd*.icu .sweeps*.whoisyourd*.live +.apps*.wtflife*.life {-block} # Manually updated Privoxy version of the whitelisted domains from the other versions of this list. diff --git a/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl b/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl index 22d8d9ca8..2b1c06446 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl +++ b/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl @@ -1,6 +1,6 @@ msFilterList # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (Internet Explorer TPL) -# Version: 03June2019v1-Beta +# Version: 11June2019v1-Beta # expires = 5 # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. # For more information, details, helpful tools, and other lists that I've made, visit https: github.com DandelionSprout adfilt blob master Wiki General-info.md#english @@ -90,4 +90,5 @@ msFilterList + # Placeholder line for alternate list versions diff --git a/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py b/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py index 7fc40eef0..bbb8a4322 100644 --- a/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py +++ b/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py @@ -15,6 +15,7 @@ OUTPUT_ABP = 'AntiMalwareABP.txt' OUTPUT_TPL = 'AntiMalwareTPL.tpl' OUTPUT_PRIVOXY = 'AntiMalwarePrivoxy.action' OUTPUT_HOSTS = 'AntiMalwareHosts.txt' +OUTPUT_DOMAINS = 'AntiMalwareDomains.txt' # function that downloads the filter list def download_filters() -> str: @@ -524,19 +525,6 @@ def prepare_hosts(lines) -> str: line ) - line = re.sub( - "# πŸ‡¬πŸ‡§: ", - "{+block{", - line - ) - - # Note the use of parenthesises and "\1" combined. - line = re.sub( - r"(\{\+block{.*)", - r"\1}}", - line - ) - line = re.sub( "Dandelion Sprout's Anti-Malware List", "Dandelion Sprout's Anti-Malware List (Β«hostsΒ» file version)", @@ -578,6 +566,74 @@ def prepare_hosts(lines) -> str: return text +# β€”β€”β€”β€”β€” Domains list version β€”β€”β€”β€”β€” + +def is_supported_domains(line) -> bool: + for token in UNSUPPORTED_HOSTS: + if token in line: + return False + + return True + +def prepare_domains(lines) -> str: + text = '' + + # remove or modifiy entries with unsupported modifiers + for line in lines: + + line = re.sub( + "! ", + "# ", + line + ) + + line = re.sub( + r"\^.*", + "", + line + ) + + line = re.sub( + r"^\!.*", + "#", + line + ) + + line = re.sub( + "Dandelion Sprout's Anti-Malware List", + "Dandelion Sprout's Anti-Malware List (Domains list version)", + line + ) + + line = re.sub( + r"# Placeholder line.*", + "", + line + ) + + line = re.sub( + r"\|\|.*/.*", + "", + line + ) + + line = re.sub( + r"\|\|\..*", + "", + line + ) + + line = re.sub( + "\|\|", + "", + line + ) + + if is_supported_domains(line): + text += line + '\r\n' + + return text + if __name__ == "__main__": print('Starting the script') text = download_filters() @@ -589,6 +645,7 @@ if __name__ == "__main__": tpl_filter = prepare_tpl(lines) privoxy_filter = prepare_privoxy(lines) hosts_filter = prepare_hosts(lines) + domains_filter = prepare_domains(lines) with open(OUTPUT, "w") as text_file: text_file.write(text) @@ -608,4 +665,7 @@ if __name__ == "__main__": with open(OUTPUT_HOSTS, "w") as text_file: text_file.write(hosts_filter) + with open(OUTPUT_DOMAINS, "w") as text_file: + text_file.write(domains_filter) + print('The script has finished its work')