Re: scanning for windows spywear with linux

From: Stephen J. Smoogen (smooge_at_gmail.com)
Date: 09/07/05

  • Next message: Maik Holtkamp: "Re: scanning for windows spywear with linux"
    Date: Wed, 7 Sep 2005 08:21:23 -0600
    To: Mailing List <maillist@freedomsoftware.co.uk>
    
    

    I do not know of any software that does this. I am currently trying to
    get a bunch of spyware so that I could try and make 'signatures' for
    clamav. Some of the keystroke and backdoor spyware does get detected
    by clamav from my logs. If you find any already projects.. I would
    appreciate it to add to my testing list, and if I can get my project
    going.. I will do the same.

    On 9/5/05, Mailing List <maillist@freedomsoftware.co.uk> wrote:
    > Can anyone recommend any tools which will allow me scan for spywear on
    > windows drives/partitions/shares etc?
    >
    > What I'm thinking of is having a linux live cd which I can boot then use
    > clam-av to scan for viruses and some other app which will scan for
    > spywear.
    >
    > Thanks
    >
    >

    -- 
    Stephen J Smoogen.
    CSIRT/Linux System Administrator
    

  • Next message: Maik Holtkamp: "Re: scanning for windows spywear with linux"

    Relevant Pages

    • snort-inline capabilities ( WAS: Re: Fortinet IDS )
      ... ClamAV allows for custom ... virus detection so even if there is no detection for the spyware you ... > updates for the IDS system several times a week. ...
      (Focus-IDS)
    • Re: Must ASk Twice
      ... Spwear is different to viruses. ... Most spywear asked permission to install so different companies have different guidelines. ... >> Norton is not designed to find spyware. ...
      (microsoft.public.windowsxp.general)
    • Re: amazingautossearch
      ... Try all of the following programs to see if there is any spyware on your system: ... virus scan your system using the latest definitions for your AV program. ... | my cookie folder gets loaded with a bunch of their crap! ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • debian and the malware problem
      ... installed and running and would like to know if debian packages exist that ... handle spyware the way clamav handles viruses or does clamav actually do ... The bastille package doesn't mention spyware or make any ... dump the lame windows junk that gets thrown onto debian systems then fails ...
      (Debian-User)
    • Re: Weird things happening to address book
      ... To be specific, tools, options, send, uncheck "Automatically add people..." ... > No spywear. ... I've checked for spyware with no results ... Outgoing mail is certified Virus Free. ...
      (microsoft.public.windowsxp.general)