Back to Forums








View Full Version : Wouldn't it be nice if......


Curio
November 14th, 2008, 23:53 PM
...Kaspersky made a tool that you could run from a bartpe / vistape / erd2007 or in safe mode on a PC that would remove viruses and spyware - and updated it several times a day - and it was free to use.

http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/

It must be nearly christmas time :)

Dehcbad25
November 14th, 2008, 23:56 PM
cOOL
Do you have some info in how to use it?

Curio
November 15th, 2008, 00:08 AM
Self explanatory - download it and run it - it has full GUI.

Dehcbad25
November 16th, 2008, 22:47 PM
lol
Got it, it is a stand alone tool similar to Stinger, right? I downloaded it but I havent run it yet. It was kind of chaotic at work on Friday

cash_site
November 17th, 2008, 00:31 AM
The app looks good, but if you're using a PE burnt to DVD how do you update the virus detection definitions? Or can you use the Tool from USB and update on another PC first?

phishhead
November 17th, 2008, 07:41 AM
the PE will create a ram drive for temp files and it allows you to set up your network settings at bootup via manual or dhcp.

cash_site
November 18th, 2008, 01:58 AM
the PE will create a ram drive for temp files and it allows you to set up your network settings at bootup via manual or dhcp.

Thanks Phish :)

Curio
November 19th, 2008, 00:22 AM
Unlike stinger, MRT and similar apps it has a full database of all signatures for spyware and virus/trojan apps and is not just a targeted subset of the latest or most prevalent. I would suggest that good practice is to burn to CD or boot from a PE disk of some description and use because multi-infected machines will infect your USB sticks with various nastyware and you will go around happily infecting other machines via your sticks.

It is a tool which can be used whatever way you like, but along with things like roguefix and MBAM will enable you to clean a machine of active threats in a relatively quick manner compared to a full AV scan with a resident program (which may already be compomised). I would also use standard manual techniques like checking the windows\system32 dir and the drivers dir for the most recently created files. One of your problems with rootkit type infections is they will intercept system calls and return false information so booting from a PE environment is always favourite for me personally.

Unfortunately many newer threats use a multi level infection system which can involve many components and it is usually a toss up between recovery or re-install depending on the system's importance and value. For a home PC you are probably looking at a wipe/reload being economically the better solution as the time involved can be pretty much predicted. Any RK infected machine may have also legit backdoor configuration like opening remote desktop, adding GoToMyPC or LogMeIn software or reverse shell connection through telnet and SSH. These will not usually be picked up by an AV tool as they are legit files bent to a illegit purpose. For a real nasty infection only wipe and reload can be considered a real clean up.

rik
November 19th, 2008, 16:59 PM
I thought this was gonna be a Beach Boys thread... :o

cash_site
November 20th, 2008, 00:43 AM
I thought this was gonna be a Beach Boys thread... :o

We have a cadbury chocolate TV advert that has this song... hmm Chocolate!

veronica
November 21st, 2008, 01:59 AM
Self explanatory - download it and run it - it has full GUI.What is Vista PE?

How did you get that many viruses?

Thanks in advance.

rik
November 21st, 2008, 03:43 AM
http://en.wikipedia.org/wiki/VistaPE

veronica
November 21st, 2008, 04:34 AM
Thank you rik.

Why would anyone want to use vista PE? You could not write a CD with vista PE. At 200 MB, you could not do much with it. Is it for diagnostic purposes?

Thanks in advance.

Curio
November 21st, 2008, 20:55 PM
Veronica

Vista PE is a bootable windows disk, you can do many things with one including diagnostic tests. It will be of most interest to people that work with computers for their jobs - network admins, technicians etc...

veronica
November 21st, 2008, 23:22 PM
Thank you very much Curio.