| View previous topic :: View next topic |
| Author |
Message |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6301 Location: USA
|
Posted: Fri Aug 11, 2006 7:43 pm Post subject: Samples for research |
|
|
I am testing various antimalware apps and their effectiveness when scanning and removing malware on a slaved drive that also has its registry hives imported into my own . Once disinfected the hives are exported and the drive is rescanned in its home system for remnants . I am doing a writeup (for advanced users and techs) on the techniques that I have found useful when troubleshooting windows systems . I have noticed many useful guides pertaining to troubleshooting systems while the system is active . This guide will only be about what can be done to fix a system without ever turning it on (all work is performed with the problem drive slaved to a working system) . At this point I am covering antimalware , registry editing , clutter cleanup , setting up for a repair install or SFC when the home system has a malfunctioning cd rom drive , making a replacement registry from a recent restore point and xp cd key recovery from unbootable drives . I might include data recovery but I don't consider myself an expert at that so I might let someone else that is handle that part .
I have loads of samples for all kinds of common malware (vundo , cws , smitfraud , .....) but I am not getting many rootkit type infections into my shop at this point . I am also not a rootkit expert .
I am looking for installers for what would be considered a nasty rootkit and a nasty rootkit that also uses ADS (two separate installers) .
If anyone can help PM me and we can make arrangements .
Thanks
PS .
I might also do a follow up with two system builds (hardware and software for both the home enthusiast and for a professional tech shop) that would be good for this type of troubleshooting .
|
|
| Back to top |
|
 |
wng_z3r0
MRU Teacher
 Joined: Mar 21, 2005 Posts: 1248
|
Posted: Sat Aug 19, 2006 7:31 pm Post subject: |
|
|
Hehe
That is what I am doing at the moment. Rootkit comparisons.
Shoot me a PM and maybe we can work something out. _________________ Proud member of Alliance of Security Analysis Professionals since 2005
Microsoft MVP-2006
|
|
| Back to top |
|
 |
wng_z3r0
MRU Teacher
 Joined: Mar 21, 2005 Posts: 1248
|
Posted: Sat Aug 19, 2006 9:45 pm Post subject: |
|
|
I finished one of my articles today:
http://spyware-free.us _________________ Proud member of Alliance of Security Analysis Professionals since 2005
Microsoft MVP-2006
|
|
| Back to top |
|
 |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6301 Location: USA
|
Posted: Thu Sep 14, 2006 2:53 am Post subject: |
|
|
I should check my own posts a little more often .
I will PM you my email address .
|
|
| Back to top |
|
 |
|
|