2nd question TDS and BARTPE

Discussion in 'Trojan Defence Suite' started by tuatara, Jun 19, 2005.

    A few weeks ago, another person was looking for a working plugin for a BARTPE and TDS-3 (only for on demand file scan of course!)

    There was no answer then,

    perhaps someone is using TDS-3 filescanner with BARTPE already successfull?

    I am working for a while to get it running, but no success yet.

    What is BARTPE ?

    Hoi/hallo/hello Dolf,
    Simply said, if your a a Windows system admin, you can't live without it.

    If your pc gets infected, you can boot a BARTPE cdrom which uses
    the same Windows key that you already have payed for.

    If you boot this BARTPE windowsXP you have no problems, that there are
    malware in your systems memory.
    So you have a clean OS to investigate your harddisk.

    If a virus is the problem that causes your system to autoreboot etc.
    You can run NOD32 from PARTPE with a plugin that is created herefor.

    Adaware SE can also be runned from BARTPE.

    The idea is, IF you are a licensed user for a program or application
    for a certain pc, you must be able to user this if XP is not run from the harddisk, but from a bootable CDROM.

    I personally think it is essential for a antimalware program to run from
    such a bootable media.

    Because if your system is infected, this is (often) the only to get it cleaned.

    For system admins who have a roving license, this is a lifesaver.
    You can't trust a system that a customer has brought to you,
    perhaps the Antivirus that is installed on that is patched by a AntiMalware
    in is in fact not working, although it appears to work and clean.

    Further more there are persons like me, to use BARTPE as a multi-boot
    environment, to be sure that a honeypot can't be hacked.

    Hope you can imagine now, why it is a very great improvement
    to TDS if it could be runned from BARTPE-windows XP

    BARTPE is a way to use your original Windows XP install cdrom,
    to create a lite version of Windows XP on a bootable media (CDROM/DVD)

    Try it yourself and you be amazed.

    BTW 'BART' is a Dutch name like DOLF from Dutch person who created this.

    Yep, Bart's rocks; I'm currently building my own toolset and scouting for tools that will work with it, and my attempts to get TDS-3 to work have been abandoned.

    Without the ability to operate from Bart's, I wouldn't consider buying a malware intervention tool, much less paying extra for a roving license.

    Have you checked out the Bart PE forum at the CD forums?

    Yes, i know, it is almost unbelieveable that there are no other security specialists here,
    which have tried to run TDS-3 from BARTPE.

    Perhaps, they will in a few years ;)

    And yes, i've checked the forum you've mentioned, and they did not have the solution yet.

    There is a plugin available, but that one is not working.

    I bet there is not a TDS-3 user here that can give a good reason,
    why he would not like to have TDS-3 running from BARTPE,
    other then not knowing what BARTPE is

    For those who doesn't know what BARTPE is ..

    BARTPE creates a bootable Windows XP cdrom, from the original Windows XP cdrom that you have.
    You can run several tools (also/like ANTI MALWARE) from this cdrom.
    This makes is possible to run this software from a CLEAN Windows XP
    to solve problems with your (malware infected?) PC's harddisk.

    BARTPE has network features built-in, can be used with a webbrowser
    disk tools etc. etc.

    BARTPE is also a nice way to test if problems are in hardware or in your PC's software (if this is uncertain).

    As you know, certain malware can disable ...or even worse, infect your Anti Malware tools
    f.i. Make it look as if your Anti Virus is working, but in reallity, it will not clean the infections.

    That is another reason, to check from a clean XP (OS).
    Because you can never be sure that when your computer boots from harddisk, the OS on disk and memory is infected or not.

    There is no product in de market yet, which can find all virusses,trojans,adware,dailers,spyware etc. etc.

    So, why have we not running TDS-3 from BARTPE yet?

    ok, i am working on it, but it takes too much time ...

    and eh .. is difficult :doubt:
