|
Focus on Microsoft
More along the lines of malware disinfection Mar 18 2008 01:33PM Mike Moratz-Coppins (mike mikeymike org uk) (3 replies) RE: More along the lines of malware disinfection Mar 18 2008 06:08PM Express Web Systems, Inc. (mailinglist expresshosting net) (1 replies) Re: More along the lines of malware disinfection Mar 18 2008 06:28PM Mike Moratz-Coppins (mike mikeymike org uk) (1 replies) RE: More along the lines of malware disinfection Mar 18 2008 05:46PM Devin Ganger (DevinG 3sharp com) Re: More along the lines of malware disinfection Mar 18 2008 05:46PM Jon R. Kibler (Jon Kibler aset com) (3 replies) RE: More along the lines of malware disinfection Mar 18 2008 07:57PM Wayne S. Anderson (wfrazee wynweb net) (2 replies) Re: More along the lines of malware disinfection Mar 18 2008 08:56PM Mike Moratz-Coppins (mike mikeymike org uk) (3 replies) Re: More along the lines of malware disinfection Mar 19 2008 04:03PM Ansgar -59cobalt- Wiechers (bugtraq planetcobalt net) (1 replies) Re: More along the lines of malware disinfection Mar 19 2008 05:31PM Mike Moratz-Coppins (mike mikeymike org uk) (2 replies) Re: More along the lines of malware disinfection Mar 20 2008 09:21AM Vincent Archer (archer tms frmug org) Re: More along the lines of malware disinfection Mar 19 2008 08:33PM Ansgar -59cobalt- Wiechers (bugtraq planetcobalt net) (2 replies) RE: More along the lines of malware disinfection Mar 19 2008 11:21PM Mark Brunner (mark_brunner hotmail com) (1 replies) RE: More along the lines of malware disinfection Mar 28 2008 02:22AM Murda Mcloud (murdamcloud bigpond com) Re: More along the lines of malware disinfection Mar 19 2008 09:12PM Mike Moratz-Coppins (mike mikeymike org uk) (3 replies) RE: More along the lines of malware disinfection Mar 20 2008 08:34AM John Lightfoot (jlightfoot gmail com) (1 replies) Re: More along the lines of malware disinfection Mar 20 2008 04:54PM Ansgar -59cobalt- Wiechers (bugtraq planetcobalt net) (1 replies) Re: More along the lines of malware disinfection Mar 20 2008 12:41AM Geekwench (geekwench hotmail com) RE: More along the lines of malware disinfection Mar 18 2008 11:55PM Devin Ganger (DevinG 3sharp com) RE: More along the lines of malware disinfection Mar 18 2008 11:31PM Wayne S. Anderson (wfrazee wynweb net) Re: More along the lines of malware disinfection Mar 18 2008 06:26PM Mike Moratz-Coppins (mike mikeymike org uk) (2 replies) RE: More along the lines of malware disinfection Mar 19 2008 01:39PM Devin Ganger (DevinG 3sharp com) Re: More along the lines of malware disinfection Mar 18 2008 09:51PM Colin Copley (colin 75 btinternet com) (1 replies) RE: More along the lines of malware disinfection Mar 28 2008 01:55AM Murda Mcloud (murdamcloud bigpond com) |
|
Privacy Statement |
can set drives to be shared so that you can hook your laptop to it and run
through directories etc.
Even with a linux-based live disk like Helix you can write to ntfs too. Just
needs to be mounted right.
http://www.ntfs-3g.org/
mount -t captive-ntfs -o rw /dev/hda1 /mnt/hda1 etc
> >-----Original Message-----
> >From: listbounce (at) securityfocus (dot) com [email concealed] [mailto:listbounce (at) securityfocus (dot) com [email concealed]]
> >On Behalf Of Mike Moratz-Coppins
> >Sent: Wednesday, March 19, 2008 4:28 AM
> >To: focus-ms (at) securityfocus (dot) com [email concealed]
> >Subject: Re: More along the lines of malware disinfection
> >
> >Express Web Systems, Inc. wrote:
> >> The problem with accessing the "Documents and Settings" folder is a
> >tough
> >> one to crack, as I didn't have to deal with it in my instance (the
> >files
> >> were located in a hidden directory in C:\Windows\). You might want to
> >try
> >> liveCD that supports reading and writing to NTFS (if they are using
> >NTFS, or
> >> if you are lucky, just access the drive via FAT32).
> >
> >AFAIK most live CDs just grant read-only access to NTFS. Which one
> >would you recommend?
> >
> >> As a different avenue of approach, maybe you can accomplish something
> >with
> >> BartPE. That would allow you to boot into windows and run various apps
> >> independent of the compromised OS.
> >
> >I haven't heard of that before, I'll read up about it.
> >
> >
> >--
> >Mike Moratz-Coppins
> >mike (at) mikeymike.org (dot) uk [email concealed]
> >http://www.mikeymike.org.uk/
[ reply ]