Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | InUse Destroyer script |
|---|---|
| Date: | Mon, 6 Dec 2004 20:16:32 +0100 |
Hello, I've written the "InUse Destroyer.vbs" script (IUD). IUD allows in-use files to be scheduled for deletion or replacement at reboot. Yes, there are other utilities that do that, but AFAIK, unlike IUD, they don't work under all Windows versions (W95, W98, NT4, W2K & WXP). I wrote IUD to easily schedule registry hives to be replaced at boot by versions in which spyware launch points have been suppressed. I also use it to delete spyware files, including AppInit_DLLs infectors. The IUD script: 1. will replace but won't delete a registry hive 2. accepts any number of deletions and replacements 3. appends its instructions to any existing instructions 4. detects if an append is in progress and displays this in all windows with the ">>" symbol 5. optionally reboots the system when done. The script is written in VBScript and requires WMI (and Admin rights) for NT4 or higher. (WMI is not required under W98.) Please note that it does *not* handle Unicode file names. The GUI is in VBScript -- I opted to avoid an IE interface because the script targets infected systems and use of IE on an infected system is reckless. IUD can be downloaded here: http://www.silentrunners.org/InUse%20Destroyer.vbs or here: http://tinyurl.com/6qjah Its MD5 hash is: C9D1BF1ED265365C65737B08BDC1017A regards, Andy ---------- To identify everything that starts up with Windows, download "Silent Runners.vbs" at www.silentrunners.org ---------- -- Editor's Note: The 43rd Most Powerful Person in Networking says... Register today to take the TruSecure ICSA exam by 12/31/04 at <http://www.2test.com> , use promo code "CT1204" and you will pay just $221.25 US Dollars for domestic exam delivery and $296.25 US Dollars for international delivery. Visit <https://ticsa.trusecure.com> for complete details regarding the TICSA credential and to take the free sample exam. --
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | AppInit_DLLs revisited, Andrew Aronoff |
|---|---|
| Next by Date: | Address Bar Spoophing for the Pheeshies: IntotheNet Explorer 6, http-equiv@excite.com |
| Previous by Thread: | AppInit_DLLs revisited, Andrew Aronoff |
| Next by Thread: | Address Bar Spoophing for the Pheeshies: IntotheNet Explorer 6, http-equiv@excite.com |
| Indexes: | [Date] [Thread] [Top] [All Lists] |