Re: [Full-Disclosure] Tools for checking for presence of adware remotely
From: John Lampe (jwlampe_at_aceryder.com)
To: Harlan Carvey <firstname.lastname@example.org> Date: Wed, 30 Jun 2004 10:00:25 -0400 (EDT)
On Wed, 30 Jun 2004, Harlan Carvey wrote:
> > Does anyone out there know of any tools available to
> > probe network workstations for the presence of
> > adware/spyware?
> Sure...Perl scripts. As a security admin in an FTE
> position, I had scripts that checked all systems
> within the domain for entries in the ubiquitous 'Run'
> key, as well as for BHOs. Easy stuff, pretty trivial, actually.
And, using a similar methodology, Nessus checks for the top 20
spyware/adware progs. Of course, as most of these checks involve looking
for a dll, exe, or registry entry, you'll need to configure Nessus with a
domain, account, and passwd.
jwlampe -at- nessus.org
"Truth is one, but error proliferates. Man tracks it down and cuts it up
into little pieces hoping to turn it into grains of truth. But the
ultimate atom will always essentially be an error, a miscalculation."
Full-Disclosure - We believe in it.