There is a project that has been in the back of my head for a while, and I recently had someone ask for something similar. A sort of branded rescue CD (or preinstalled on client’s system by you) to enable a remote support technician to connect to an existing client who may suffer from a malware attack and cannot execute your remote support software… the point being so that you can get connected and finish the job. Granted this won’t work with ALL malware out there, it will help out with some of it. Here are my current thoughts…
Modified KillEmAllPlus
• Start as service
• Automatically end and run next app
• Auto-Delete “Out of Place” *.exe and *.dll files after kill
• Reporting!
ZeroAccess Check
• KillZA -auto
• If infected reboot and restart app (normally)
• Reporting!
Check for Internet Access
• If available, launch remote support software / display message & email tech
• Else, run Optional or Repair
Optional
• Offer to launch system restore?
• 3rd party apps – prefer automated ones but others can be used with a tech on the phone
• fully automate MBAM Pro if installed
Repair
• Fix File Association routines
• Remove Policy settings
• Windows Repair / network repair routines
• Delete Temp Files
• Reboot & restart one final time
Check for Internet Access
• If available, launch remote software / display message & email tech
• Else, show client message – call for repairs.
I have absolutely ZERO time to start on the project right now, but if interest is high enough I will make getting started a priority in the near future.
12 Comments
Leave your reply.