Author Topic: A Trojan Question  (Read 6117 times)

Offline Zazen

  • Cactus Zombie
  • *****
  • Posts: 380
  • 1337 13V3L: +34/-14
Re: A Trojan Question
« Reply #15 on: September 30, 2008, 11:23:47 AM »
Have you considered building yourself a bootable OS environment for doing all these scans? It'd be faster than running with whatever gunk comes on the machine and you'd be guaranteed that malware isn't running (safe mode isn't always good enough for that, as you've seen). You'd never have to reboot for a scan to do its job either.

Offline trevelyn

  • Administrator
  • Elite Cactus Squad
  • Ninja Phone Loser
  • *****
  • Posts: 1687
  • 1337 13V3L: +183/-22
  • He likes cans and taking pictures in cans!
    • WeakNet Labs
Re: A Trojan Question
« Reply #16 on: September 30, 2008, 02:47:14 PM »
one of the security deployment guys here made one, it's pretty sweet.  He gave me links on how to make my own as well, I just never got around to it.  Have you made a Win32 based Live disk before? I have only made *nix. 

Offline Zazen

  • Cactus Zombie
  • *****
  • Posts: 380
  • 1337 13V3L: +34/-14
Re: A Trojan Question
« Reply #17 on: September 30, 2008, 11:51:43 PM »
No, I've never had the need. In the rare case that there's an infection at work I just eliminate it using my quick method. If the infection did any kind of damage then I just reinstall the machine with my big scripted OS install that does everything in about 20 minutes.

In your case why not use a nix disc? Add in whatever you need to mount ntfs and you're in good shape. It'd be really convenient to script the crap out of it so it does all of those scans and stuff automatically.

Offline trevelyn

  • Administrator
  • Elite Cactus Squad
  • Ninja Phone Loser
  • *****
  • Posts: 1687
  • 1337 13V3L: +183/-22
  • He likes cans and taking pictures in cans!
    • WeakNet Labs
Re: A Trojan Question
« Reply #18 on: October 10, 2008, 02:14:49 PM »
 :D WeakNet Linux!  I was going to release my Unix Passwd Cracker "Perlwd" about 2 weeks ago, but now I decided to wait and just release it on my own snazzy version of Linux instead.