Showing posts with label Win PE. Show all posts
Showing posts with label Win PE. Show all posts

Monday, May 30, 2016

Windows “Service Pack”, Slipstreaming, ISO files, misc.

Wow.  Big thanks to Lavie for being patient with me while I hammered out all these blog posts.

I’ve still got quite a lot more, but it has been a very productive – non-productive day off.

Cheers!

Claus Valca

More PowerShell Fun

PowerShell and Windows To Go USB stick building

PowerShell and WinPE USB stick building

Tips

Cheers,

Claus Valca

Saturday, April 30, 2016

Call Me Burned but Recovered: Windows 10 Upgrade Failure

Hope springs eternal, but upgrading my vintage 2012 Dell XPS 17” L702X Windows 7 Pro laptop to Windows 10 Pro seems futile.

Despite what the cheerfuly positive Windows 10 Upgrade assistant says, Windows 10 just will not work on it.

Dell says the same thing.

Last weekend I was feeling bored so I decided to give it another go. I figured they’ve had a few months to fix some of the bugs and maybe make a more stable release version. I had it mostly working at least one time in the past before rolling back to Windows 7.

As a precaution I first uninstalled all my AV/AM/AE programs in case any of them gave the installation process the blues.

Then I let it run.  When I checked back the next morning (because the upgrade was still running overnight when I went to bed) it had “finished” and presented a BSOD type message amost illegibilly painted on the wigged out laptop display.

I booted from a Win 10 CD and tried to do both repairs and roll-backs but the loaded Windows 10 was having nothing of it and said it couldn’t. Seriously?

I had already been considering a “clean install” of Windows 10 based on my previous Windows 10 failure and thought that might present a better chance of getting a stable installation of Windows 10 on this laptop.

So I went through those paces too; How to do a Clean Install of Windows 10, the Easy Way via How-To Geek.

Only that just left me at a blinking cursor on a black screen when the Windows 10 installation was done. Seriously!

I did some cursory troubleshooting like taking the 2nd HDD out of the laptop but it didn’t make any difference. The primary drive is a SSD Samsung EVO 840 and maybe I need to change some options in BIOS. Don’t know and really don’t care.

At this point I had no Windows 7 and no Windows 10.

How to “roll back” now?

Fortunately I had taken out two insurance policies on just this kind of failure.

I used Disk2vhd to make a VHD “image” of my Windows 7 system’s primary HDD to an external USB HDD in case I needed to mount it and pull off any files after the Windows 10 upgrade had finished.

I also considered a plethora of Windows-based backup drive software options, but in the end just used OSFClone to simply and easily take an image of that same Win 7 primary HDD before turning the Windows 10 upgrader loose on it.

I also have a prepped and dead-useful Easy2Boot built USB stick that contains the OSFClone ISO image. So I had booted my Windows 7 system with Easy2Boot and selected the OSFCLone ISO I had copied there.

The whole configuration recognized my WD 2 TB external USB 3.0 HDD so I just wrote the IMG format file there.

So I had two “backup” images of my original system system drive.

Now how did I want to put them back?

In the end I decided to go simple.

I first booted with my custom WinPE boot USB stick and used DiskPart to rebuild the system’s primary HDD, “Clean” it, create a single primary partition, set it Active, assign it a drive letter, and then format it to NTFS.

Then, using my Easy2Boot USB stick I selected a pre-loaded ISO of Linux Mint (Cinnamon version) and booted my system with it.

I used the Ubuntu Disk Image Writer already integrated in the Mint OS build shell to browse to my IMG file on the external USB drive and simply selected my system’s primary HDD to write the image back to, after first confirming I was selecting the correct one with gParted.

Screenshot from 2016-04-24_2016-04-30_15-41-48

Once the image had been applied I shut down the system, removed all the USB drives, and rebooted.

I was prepared to need to do some repairs to the MBR post image reapplication, however they weren’t needed.

Up came my Windows 7 system just like I had left it…as if that entire unfortunate series of Windows 10 upgrade events had never happened.

I liked this whole-drive based backup/restore method as both the imaging and restoration were light and simple and didn’t require any system-based software installations.

I later found this application Drive Snapshot that looked like a great alternative as it is portable, says it is compatible with all Windows RAID types, and dead tiny/light.

There is a free 30-day trial version but since the product is offered over in Germany, I’m not sure just how easy it would be to order and try the full version from here in the States.  I would love to give it a shot.

I’ll do a follow up post with a bunch of Windows 10 rollback/restore information (for normal people) soon, but this method worked best for techie me.

Cheers,

--Claus Valca

Saturday, October 31, 2015

Updating Dell BIOS using WinPE

TinyApps.org blog recently posted his interesting situation.

Short post shorter, after a recent hardware change, issues were encountered on a Dell system until the BIOS was updated.

I’ve been seeing an increased pattern of issues after hardware is replaced or upgraded on Dell systems. They usually clear up after the BIOS gets updated.

Unfortunately, Dell seems to only be offering BIOS update files for most systems via an EXE deployment solution.

The idea is that you would download the Dell BIOS EXE update file to your Windows system, run the file, then the system reboots and the BIOS gets flashed/updated.

That makes sense unless you are sitting on a system (or hundreds) that don’t yet have a Windows OS installed, or have replaced the HDD in the system and don’t have an OS on it. Or maybe you do have a flaky system with a Windows OS but can’t keep it stable enough to run the BIOS EXE update file.

This week I had that very problem and wondered if I could perhaps deploy the BIOS EXE file via a WinPE environment and bypass the “installed” Windows need totally.

In my case…for the particular Dell systems I was working on, I could, I did, and it worked perfectly.

Your mileage may vary, proceed at your own risk, etc.

The “trick” seems to be that you have to use an x86 WinPE OS architecture build, rather than a x64 WinPE flavor. More details on “why” here if you are curious.

If you already have a working WinPE build and want to confirm (maybe you didn’t build it yourself) just run the following command in your loaded WinPE environment from a command prompt:

wmic OS get OSArchitecture

Sadly, the Dell LTI bootable flash drive I had was running a x64 version.

Luckily I still had one of my trusty custom WinPE CD disks I built a long time ago and I had built it using the x86 package so I was set.

So here is what I did to flash the Dell BIOS with no loaded HDD:

  1. I downloaded the BIOS update needed for my specific Dell system from Drivers & Downloads | Dell US using another system after confirming by entering the system’s ServiceTag/Serial number on the page.
  2. I copied it to a USB drive.
  3. I booted the target Dell system with my (x86) WinPE boot CD and had the USB flash drive with the BIOS update file also connected to the system.
  4. Once WinPE had loaded, I navigated to the BIOS EXE file on the USB drive and ran it.
  5. It executed with no errors and the system rebooted, applied the update, and rebooted again.
  6. I hit F12 and confirmed the BIOS version updated, the hardware was detected in the BIOS, and that the ePSA diagnostics all ran normally.

Done!

That saved almost 1.5 hours of otherwise deploying (if I could) an image to the system and getting it configured enough to be operational for just a BIOS EXE deployment run.

I’ve posted a lot of write-ups here on GSD blog regarding custom WinPE disks. You can go crazy or super-simple.

If you don’t feel like reviewing all those posts, here are some tools or basic steps in building your own WinPE boot tool:

It’s been quite a while since I built a WinPE disk/USB. The ones I’ve made in the past still keep on loading and working for my off-line system booting needs I really haven’t had a need to update them at all.

I think the last one I built was based on a pre-release WAIK version for Windows 8 (WinPE 4.0).

I might need to add making a fresh Win10 WAIK-based WinPE build to my considerable “to-do” list so I can try out the changes to WinBuilder and some of these other “newer” WinPE building tools that have come along since I last fiddled with things.

Hope this helps.

Cheers,

Claus Valca

Sunday, March 08, 2015

Sundry Sunday Sysadmin Links

As we face a multi-day rain deluge, and adjust to the “spring-forward” cycle of DST I’ve got a smidgen of new linkages of possible interest to sysadmins.

Take off those Wellingtons and pop open some hard-cider with me and find solace in the warmth from humming computer equipment and a good HDTV screen.

Enjoy.

I’m a bit late to the IE10/11 party for enterprise with the “Enterprise Mode” feature. We are still (yes) running IE 8 at the hot-dog factory and more than most in-house applications still require IE 8 platform compatibility – so here we stay for now. I’m hoping we can do some pilot testing of IE 11 and leverage these new IE technologies; Enterprise Mode, Enterprise site List, and Enterprise Site discovery. Hence the linkage below for additional research on my part.

Speaking of web-browsers and compatibility, careful and reflective readers of the GSD blog may recall quite the technical post (rant) a while back on Firefox and malware-detection/download monitoring that got my hackles all up and bothered.

Well, it looks like an upcoming (Firefox 39) version release will include a much-needed “bypass” option for the Safe Browsing security feature.

I get the core security concerns Safe Browsing was supposed to provide, but as a technical user, not having an easy override option was seriously frustrating. I’m glad to hear about this development.

Other Mozilla security features on the way or tips for addressing current issues from the Mozilla Security blog.

As a Samsung SSD EVO 840 user (and loving every minute of that upgrade decision), I’m always on the watch for news updates on firmware of software upgrades, and here is some tantalizing news. According to the Samsung Magician software used to manage the drive, I’ve currently got the most current firmware available; EXT0BB6Q. So I’m watching these like a hawk.

BETA: Windows Assessment and Deployment Kit (Windows ADK) for Windows 10 Technical Preview - Kurt Shintaku's Blog – Previously mentioned. I finally got around to downloading it alongside my Windows 8.1 ADK set and my Windows 7 AIK set and pulled out all the performance assessment, USMT, and deployment (WinPE) tools. Nice and sweet! Playtime continues with these upgraded Windows 10 toolsets.

INFO: Blogs, Sites & Social about Surface - Kurt Shintaku's Blog – I’m starting to familiarize myself with the Surface Pro 3 unit we got into the shop a while back. I’ve not fiddled with the stylus just yet, but the general usage is pretty straightforward. Kurt’s got some great linkage to additional blogs and sites for Surface Pro users so the best of these will be added into my RSS feed piles. The following in particular seemed quite good from a technical-support aspect (in contrast to product placement and cheerleading news).

Fixing Cisco AnyConnect Failed to Initialize Connection Subsystem on Windows 8.1 - Next of Windows – so basically a recent Windows Update may have hosed Cisco AnyConnect just a bit on Win 8.1 systems. The fix (workaround) is to just configure it to run in compatibility mode for Windows 8.

Windows: Black screen after February 2015 Update – Borns IT and Windows Blog (Google Translated from original) – I’ve seen this more than a few times at work after Windows Updates going back to at least December. The updates go on, the system reboots, and just seems to “hang” on a black screen forever. Rebooting doesn’t help and no visual indications present to let you know “something” is happening on the system. Like Gunter Born says, my experience is with some patience and waiting (from a few minutes to hours) the system finally resolves what it is doing and the “loading Windows” graphics appear and the system comes up. I’ve had techs who were too impatient and couldn’t wait and just wiped/reimaged the system so there is that approach as well, but patience goes a long way. I just wish this trend would be addressed on the next round of Windows Updates. It’s annoying at the worst and frustrating at best.

Update Error 8024001F by Microsoft FREAK workaround – Borns IT and Windows Blog (Google Translated from original) – I’ve been watching and monitoring the FREAK situation but haven’t been posting on it here. That said, Gunter Born’s post is worth reading for sysadmins, even if you aren’t directly in charge of working on the FREAK issues in your shop. For some cribbing on FREAK see below:

How to Remove uTorrent’s EpicScale Crapware From Your Computer – How-To Geek – I can’t really fault uTorrent as the installer seems to clearly indicate an option to install EpicScale “add-on” software but one wonders how many people were paying attention carefully during the installation process. That’s how lots and lots of third-party “I don’t really want or need it” enhancement-ware packages get pummeled into users’ systems. Anyway…here’s the discussion summarized and how to get it off your system if  you use uTorrent.

D-Link fixes the latest flaw in its routers, more patches on the way – Betanews – My DIR-655 router from D-Link is a hardware type “A” and as right now, I’m still running the most current (06/1/2013) firmware release version 1.37 so alas, no updates yet. Fingers crossed one will be offered in the near future. I’m not ready to pick up a new router yet as this one continues to work super-great and is more than fast enough.

DelFix deletes portable disinfection tools from your system automatically - gHacks Tech News – As someone who advocates use of free and portable adware and security tools, it’s nice to know there is a utility DelFix that can do some post-adware cleanup of the adware-cleaning software remnants. I like the concept but per Martin Brinkmann’s article on gHacks, it doesn’t currently offer a log advising you in advance what is going to get cleaned/nuked so you may be taking a risk to use it and I have to agree that I’d look forward to a future version that include some ability to review the actions to be taken (and selectivity accept them first) before execution.

Program launcher SyMenu integrates Nirsoft, Sysinternals and other programs - gHacks Tech News – I really like the SyMenu application. It is in my “projects” pile to fiddle with to see if it can help me manage my portable USB application folder. I’m sure it would do a wonderful job rather than my current method of just rummaging around in my utility folders for the tool I’m looking for. That said, it also includes the ability to integrate the NirSoft suite and the Sysinternals Suite. Pretty cool. Other tools that help with that process are:

Finally, every so often I drop in over at NoVirusThanks to check out some of their free tool offering and to see what they have been up to for new portable security and system utilities. Besides their free tools, they also offer some free network tools. Most may be replicated in other local utilities but it still may be worthwhile to bookmark them for reference just in case your USB stick isn’t handy.

Cheers!

Claus Valca

Sunday, February 08, 2015

Links for the Sysadmin crowd

Here is the last push linkfest for the day.

Mostly geared to system administrators but – hey – who knows, even you might find something useful here!

Have a brilliant week!

Cheers.

--Claus Valca

Misc PXE/USB/HDD booting tips and tricks – Linkfest

Here is a mini linkfest of articles I have collected over the past month.

They generally deal with “specialized” booting of Windows systems.

Note: I love Kanguru flash drives, primarily because of the physical read/write lock switch their models provide. It is IMHO a must-have when responding to incidents or cleaning infected systems.

The last link above is more of a product announcement but it does claim to address one new trend in USB technology – BadUSB attacks where the USB firmware is compromised when the USB stick is attached to an infected host. What I don’t know is if their FlashTrust technology still allows the drive to be configured as a “bootable” USB drive or not. I’ve found that some natively (firmware/hardware based) encrypted USB flash drives cannot be used as bootable USB drives for – say – WinPE building and boot usage.

I don’t have a Kanguru FlashTrust drive to test drive or review for you but I’ll be looking to add one to my collection since my trusted 16 GB Kanguru Flashblu II 2.0 device is getting filled close to max capacity. This new USB 3.0 drive looks really nice and a 32 GB version should do nicely.

Cheers!

--Claus Valca.

Saturday, October 04, 2014

New and Improved Utilities

Network Stuff Found and Updated

Which brings me back to the pretty cool Windows “firewall” application GlassWire. Previously featured via tinyapps.org, I spotted a new review of it that had some fresh examples of its usefulness; illustrating alert event marking for later examination. In one case, it helped a user discover network activity from malware that had gone undetected.

Then in those comments there was a reference to the KDE application KNemo - Network Monitor.

Utilities of Usefulness

  • AOMEI PE Builder - I’m always keeping one eye open on new WinPE building tools and this seems useful for the non-tech crowd who may not be up to taking on a project from the WinBuilder tool or one of the many specialized building sets at reboot.pro. For someone just getting their feet wet, this might be a good place to get started.
  • OPSWAT AppRemover - I keep rediscovering this tool every year or so. It is updated regularly and can aid in the removal of many Supported Applications. Good for a first-pass on a new OEM system.
  • GEGeek Tech Toolkit - Considering the work I do finding and maintaining all the tools and utilities on my own USB stick, this seems like a cheat, but if you are lazy, here you go. Related are the NirLauncher package builder and KLS Soft’s WSCC - Windows System Control Center (also update to version 2.3.0.1 as of Sept 2014).
  • OpenSaveFilesView - NirSoft - new utility that displays files previously opened with the open/save dialog box. More on NirBlog.  Spotted via this Betanews post.
  • FixWin v 2 for Windows 8, Windows 8.1 - The Windows Club - Easy but powerful tool to fix common Windows issues. Use with caution. Similar tool may be (the no longer developed but still available) d7 Free tool from Foolish IT LLC.

Lights, Sound, Action!

Cheers,

Claus Valca

Sunday, March 09, 2014

Boot Me: LiveCD’s/WinPE/WinFE and other things…

Quick-post for the offline system booting and LiveCD/USB-booting crowd.

“One of our goals when developing Kali Linux was to provide multiple metapackages that would allow us to easily install subsets of tools based on their particular needs. Until recently, we only had a handful of these meta packages but we have since expanded the metapackage list to include far more options:

  • kali-linux
  • kali-linux-all
  • kali-linux-forensic
  • kali-linux-full
  • kali-linux-gpu
  • kali-linux-pwtools
  • kali-linux-rfid
  • kali-linux-sdr
  • kali-linux-top10
  • kali-linux-voip
  • kali-linux-web
  • kali-linux-wireless

“These metapackages allow for easy installation of certain tools in a specific field, or alternatively, for the installation of a full Kali suite. “

Cheers!

--Claus Valca

Sunday, February 16, 2014

Windows Assessment and Deployment Kit (Windows ADK)

Yes. Yes. I know.

It has actually been out for quite a while now.

(I’m specifically referring to the release version for Windows 8 & 8.1.

For some reason this small bundle of ADK links got lost in the pile I’d planned to post here as a reference.

But then I just found it so here they are.

…moving on…

--Claus V.

Monday, November 11, 2013

Anti-Malware Response “Go-Kit”

I don’t know how many of my readers feel when it comes to performing a malware response.

I tend to get very frustrated, regardless of the response situation. A very wise person said to me that of all the challenges I am constantly wrestling against with myself, the core issue from their perspective is that I am a problem solver. Got a problem? I can and will step up and try to solve it; often by the book (as best I can muster) and then taking it beyond.

What I should be doing is learning to execute well, execute efficiently, and then walk away when done.

In other words, there are some bones I just need to bury and stop digging back up and chewing on again.

That’s often the problem I face with dealing with malware infections.

At work the response calls almost always come in from an automated alert. Some AV client on a system alerted when it found some binaries that matched something in its DAT collection. That client talks to the mother-ship program which is monitored by an admin who sends and email requesting the system be responded.

In almost every case, the required (per operational policy and procedures) response is to recover user data, wipe and reimage the system, scan the user data, restore the user data. Move on.

While we don’t probably have the resources available to do a full-blown incident response on every end-user system we get an infection alert on, I shudder to consider that we could be consistently missing out on understanding and identifying potential data-leakage off our user’s systems not to mention the lost opportunity to learn how the infection occurred and how take-aways from a in-depth analysis could help be used to better harden the protection systems in place; and educate the end users.

Sigh.

The case generally doesn’t get any easier in the home front. More than many times have friends and family approached to me explain they have some sinister problem on their home system and need some advice. What they generally are asking is, “Can you fix it for me?”

What they aren’t asking is, “Can you perform an in-depth analysis on what I have on my system, what data I may have lost in the process, how it got on there, and how I can keep it clean in the future?”

Nope.

They are in a panic, and want the system restored to a functional state so they can go back to their old habits.

So despite the tons of material out there from awesomely good-at-their-jobs malware and incident response experts, we generally continue the same fruitless routine of getting infected, getting the system cleaned, walking away, and getting infected again.

In my frustration, I wanted to spin it to the positive and try to share some of my “go-kit” for malware responses. It isn’t really geared to enterprise incident response and cleanup where a whole host of organized protocols, processes, and tools should (hopefully) come to bear on an issue; though there is some linkage that could support/supplement it perhaps.  It’s what I carry on my personal USB stick when I’m responding to family and friends who get themselves into trouble.

My USB stick is a Kanguru 16 GB Flashblu. I like it in that it has a physical write-lock switch so I can control USB infection when connecting it to a potentially hostile system. Because it is an otherwise “simple” USB stick, I can configure it for use as bootable USB device and load a custom WinPE system on it for off-line booting of an infected Windows system. Some more advanced USB drives (IronKey) have additional cryptographic security embedded in them that is good for file security, but a real nuisance in trying to make the device bootable. I do wish the storage size was greater but on the other hand it keeps me honest with stripping down my file and tool set on it to critical ones.

Most of these get regular version updates, so I have to check back frequently to download the newest versions.

One final note, tools listed are generally in alphabetical order rather than order of preference.

Stage One…Hone your Skills

The very first tool that should be used when responding to a potential malware infection is your brain.

Being familiar with Windows system operations, incident response techniques, and malware busting moves is critical. If you don’t get this part down first, the rest is just spinning your wheels and could lead to reinfection or infection spread.

Some resources you may want to review are:

And, from a previous GSD blog post,

Linkz 4 Free Infosec and IT Training - Journey Into Incident Response - Corey Harrell goes above and beyond with an outstanding listing of trainings, exercises, and learning resources that are ForSec focused and absolutely-friggin-free for the taking!  Corey promises to keep the listing updated so bookmark the page and check back often. I’m particularly interested in the CSIRT-like topics and materials listed like those in the ENISA CERT linkage. I’ve downloaded most all of the PDF versions already to review this week as time allows!

Many of these trainings have supplemental videos and VM’s for download.

Other specific courses from Corey’s post.

Stage Two…My Core Tools

In almost every case, I will use these tools as part of my initial assessment. They will also very likely come into play as part of the malware track down and removal. I consider use and drilling in these tools my IT counterpart of “3-gun shooting”.

  • Process Explorer - Windows Sysinternals - Shows me what is running on a Windows system, where it is running from, and why.
  • Autoruns - Windows Sysinternals - Shows me what caused some of the “auto-start” execution of software on a Windows system, where it was called to run from from, and why.
  • Process Monitor - Windows Sysinternals - Also shows me what is running on a Windows system, where it was called to run from from, and why. The logging is great for post analysis.
  • ESET SysInspector - This tool does some of the things listed above but also performs advanced logging as well as heuristic coding to results. This helps me get a quick reconnoiter on the system which is critical when it is one I may not be familiar with. From there I can better plan points of focus.

Stage Three…Packaged Sweeps

As I said before, I really want to do full-blown reviews of systems to understand just what happened and how it happened, so I can then respond to make sure it doesn’t happen again.

But with non-technical users hovering over me in their (or my) living room this can be a frustrating situation for both of us.

One technique that I have found helpful is to run one or more advanced triaging tools on the system before starting the cleaning process. Most all of these tools help to automate the incident response and data collection process. These let me run a slew of individual tools at a single command and package the findings up for later review. If the end-user is agreeable (sometimes some personal information and data can get collected in the process so trust and integrity is critical) I’ll run some captures on the system for later review and post-mortem work after the system has made its way back home.

These resources are great starting points before we hit the tool sets.

Now the collection tool sets. Note that “some assembly is required” in most packages due to licensing restrictions of some of the leveraged utilities. One other consideration is that they can be “high maintenance.” Most depend on third-party tools -- like NirSoft or Sysinternals. As those get updated then you may find benefit in dropping the updated version into your sweep sets. That’s a lot of work and depending on the change made, might add/break certain functionality. Just something to consider.

  • Confessor - Home - “Confessor is a Windows Application that utilizes WMI or PsExec along with standard tools to quickly gather live forensic information from any number of hosts." Confessor v.10 User Guide & Confessor v.10 download.
  • Mandiant Redline - Mandiant - “…provides host investigative capabilities to users to find signs of malicious activity through memory and file analysis, and the development of a threat assessment profile.”
  • MIR-ROR - Home - “…MIR-ROR is a security incident response specialized, command-line script that calls specific Windows Sysinternals tools, as well as some other useful utilities, to provide live capture data for investigation.” MIR-RORv2.0 download
  • rapier - First Responders Info Gathering Tool - Google Project Hosting - “…RAPIER is a security tool built to facilitate first response procedures for incident handling. It is designed to acquire commonly requested information and samples during an information security event, incident, or investigation. RAPIER automates the entire process of data collection and delivers the results directly to the hands of a skilled security analyst.”
  • RegRipper - Google Project Hosting - Tool developed by Harlan Carvey that allows parsing of Windows registry hives via plugins depending on the targeted information sought. Plugins are developed by the community so there are a lot out there now. Pretty amazing stuff and the logging results with just some of the standard “"
  • TR3 Tool Kit v2 - Journey Into Incident Response Blog Resources - Google Project Hosting - See the post Tr3Secure Data Collection Script Reloaded for more information.
  • triage-ir - Triage: Incident Response - Google Project Hosting - More details from project author Michael Ahrendt here in his blog post Student of Security: Automated Triage Utility
  • ThreatExpert Memory Scanner - Like the previously mentioned ESET Sysinspector tool, this is a tool that allows you scan the live system memory and look for potentially rogue memory modules.

Finally, both the DEFT Linux live CD & CAINE Live CD/DVD have Windows-side packages (DART and WinTaylor/NirLaucher) available that can easily be ported to a USB stick.

The CAINE team is partnering with WIN-UFO (Ultimate Forensics Outflow) for a packaged multi-tool launcher that is pretty interesting and worth checking out. Win-UFO Beta (PDF link) has detailed tool information.

Stage Four…Rootkit Sweeps

After the first sweep and assessment, I generally want to confirm if there is a root kit running on the system. All the hard work after is for naught if a rootkit just re-infects the system once you have “cleaned” it.

Rootkits and other APT (Advanced Persistent Threats) are constantly evolving and detection tools must keep pace. Certainly no one tool here can identify every threat out there, but it is a good starting place.

Also, read carefully the supported OS of the tools, it doesn’t do much good to run a tool designed only for XP x32-bit on a Windows 8.1 x64-bit system!

I do have quite a number of additional anti-rootkit tools that are a bit more advanced, but they aren’t really suitable for average home users…so I’ve left them out of this list for now.

Stage Five…General Malware Sweeps

Now that we have (hopefully) established we are not dealing with rootkit activity, next comes the general scan.

Again there are an incredible number of tools to help purge a system of a malware infection. Some are designed to be run “live” on the system, and others work “off-line” against the system files by running from a “pre-boot” alternative OS environment. I have found that in most cases, the latter works better and more effectively than the former.

Be aware that depending on the scan engine and the system hardware, these scans can take a considerable amount of time…I often have to let them run overnight.

Pick and use judiciously.

Also, you must keep them current either by freshly downloading the latest version before using, or downloading a DAT file package or two. Failure to do that may miss the most current iterations of the virus!

Stage Six…Highly Specialized Responses…

In some cases, even if you are able to clean up a system and “de-infect” it, the remaining mess it has made can still cause untold headaches. Registry keys are changed, EXE’s don’t execute, the internet sockets have been screwed up.

Use these tools ONLY if you know what you are doing and have a specific reason to be doing so. Use of them where not warranted may only exacerbate the mess you are trying to clean up.

  • AdwCleaner - General Changelog Team FR - How to use AdwCleaner version 3.x
  • ComboFix Download - Bleeping Computer hosted by author “sUBs”
  • CryptoPrevent - Foolish IT LLC - to be clear this doesn’t “clean” CryptoLocker infections, but it prevents it from executing in the first place.
  • exeHelper from Raktor - Cannot execute .exe, .reg, regedit? - Am I infected? What do I do?
  • AntiVirus Utilities - Kaspersky Lab has a ton of specialized tools
  • MBRWizard CLI - This free utility is a command line version only - you can pay $ for the GUI version if that is what you want. It’s under $10 if that’s your thing. It may be able to restore and repair your MBR.
  • Remove Fake Antivirus 1.93 - Yes, Yes, Yes…the website does have that “is this dodgy?” vibe, but based on the testimony of many users whose systems were infected with fake AV malware, it’s the real deal. Cheers to the author for working tireless at keeping it effectively updated!
  • RKill Download - Bleeping Computer
  • Unhide Download - Bleeping Computer
  • Windows Security Utilities - BleepingComputer - 20 specialized programs listed over two pages for your review and selection when needed.
  • Download WinSock XP Fix - MajorGeeks - used to repair damages WinSock files after an infection. I don’t see this very much any more. Now days, the malware does all it can to keep the system online and communicating so it can be a RAT/Zombie/span-factory/APT.
  • XP TCP/IP Repair 2.2 - WareSoft Software - Likewise.

GSD Field Dispatches…

In closing, here are some Grand Stream Dream blog posts that may be worth a re-read (or first read) that touched upon malware-busting.

Cheers,

--Claus Valca

Sunday, October 20, 2013

Forensic News Flashes - New Projects and learning opportunities galore!

It’s late and has been a super-long weekend.

Lavie isn’t too impressed I’m still sitting at my desk working on posts.

In the meantime, I’m commited to getting this last bit of ForSec linkage collected over the past few weeks out the door so you can have fun reviewing it this week.

Those young and crazy pups over at the Computer & Digital Forensics at Champlain program have clearly caught their dean napping. In an interesting series of posts, they attempt to wreak havoc on different hard-drives and then try to put humpty-dumpty back together again.

MantaRay Forensics - anTech Triage & Analysis System. As far as I can tell, this is the first time I have posted any mention of MantaRay Forensics here at GSD.  Spotted in this C&DF@C post Swimming with MantaRay Forensics

MantaRay was designed to automate processing forensic images, directories and individual files with open source tools. With support for numerous image formats, this tool provides a scalable base to utilize open source and custom exploitation tools. MantaRay was developed by two forensic analysts, Doug Koster and Kevin Murphy.

ForGe Forensic test image generator v1.1 - Git Hub project page. from the Overview description:

ForGe is a tool designed to build computer forensic test images. It was done as a MSc project for the University of Westminster. Its main features include:

  • Web browser user interface
  • Rapid batch image creation (only NTFS supported)
  • Possibility to define a scenario including trivial and hidden items on images
  • Variance between images. For example, if ForGe was told to put 10-20 picture files to a directory /holiday and create 10 images, all these images would have random pictures pulled from repository.
  • Variance in timestamps. Each trivial and hidden file can be timestamped to a specific time. Each scenario is given a time variance parameter in weeks. If this is set to 0, every image receives an identical timeline. If nonzero, a random amount of weeks up to the maximum set is added to each file on each image
  • Can modify timestamps to simulate certain disk actions (move, copy, rename, delete)
  • Implements several data hiding methods: Alternate data streams, extension change, file deletion, concatenation of files and file slack space.
  • New data hiding methods can be easily implemented. Adding a new file system is also documented.

Developer Hannu Visti goes shares a great post over the features and background of this tool over at Forensic Focus. ForGe – Computer Forensic Test Image Generator.  This could be a really fresh and innovative tool to help with both simulating forensic images for training and drill purposes. Very interesting and well worth the time to check out. It’s beyond my skill set to review and comment on but if any of the ForSec pros out there have any thoughts or comments, please feel free to drop them in the comments here for our community education.

Linkz 4 Free Infosec and IT Training - Journey Into Incident Response - Corey Harrell goes above and beyond with an outstanding listing of trainings, exercises, and learning resources that are ForSec focused and absolutely-friggin-free for the taking!  Corey promises to keep the listing updated so bookmark the page and check back often. I’m particularly interested in the CSIRT-like topics and materials listed like those in the ENISA CERT linkage. I’ve downloaded most all of the PDF versions already to review this week as time allows!

Many of these trainings have supplemental videos and VM’s for download too!

Other specific courses from Corey’s post I’m listing below so I can find them quickly…

What 'tier 2' & 'tier 3' tools do you load on your forensic workstation(s)? - ForensicKB blog - Lance Mueller has a great list of Tier 2 and Tier 3 apps he considers. I’m pleased to find more than a few in my toolkit already. Note that not all of the software listed here is necessarily free or open-source. More than a few are commercial applications. That’s not at all a bad thing, but just something to be aware of.

 Windows Incident Response: Shell Item Artifacts, Reloaded - Harlan Carvey undertakes some very methodical validation exercises on Windows shell item artifacts. Definitely worth reading.

Meanwhile, from another ForSec guy who appears to never sleep… Brett Shavers has been in a posing frenzy over at his Windows Forensic Environment blog site.

Best publicly available testing of WinFE I’ve seen to date - Windows Forensic Environment (Note post info is good but link in it has been superseded by one found in post below.

Updated link on the Mistype project - Windows Forensic Environment

WinFE - direct link to the article mentioned. I agree, it is a truly fascinating read for WinFE aficionados. I’m coming back to read this one carefully this week.

Mini-WinFE - Windows Forensic Environment - This post has tons and tons of screenshots to illustrate the new Mini-WinFE project as well as an introduction that goes over the project features. Very basically, this specific project (1 of 3 promised for alternative WinFE building) allows you to roll your own WinFE boot disk in a “minimal” configuration with FAU utilities, FTK Imager and support for X-Ways Forensics. Total build time is estimated at 10 minutes from start to media in your hand.

Mini-WinFE is out of beta! - Windows Forensic Environment - See you waited too long! The first link was requesting Beta testers. Now it is released!  Direct project link here via Reboot.pro and extensive Mini-WinFE project documentation from Misty is linked here.

Quick video on building a Mini-WinFE - Windows Forensic Environment - a very short (3:33 min) YouTube video is available on this post page for those who want to check out the building process.

Since we are on a WinFE bender, let’s shift gears slightly and use that excuse to post a link on the WinFE’s kissable cousin for sysadmins who aren’t quite as focused on disk read-only preservation, WinPE.

How to Customize Windows PE Boot Images to Use in Configuration Manager - Chris Nackers Blog. Chris links to this Microsoft TechNet resource How to Customize Windows PE Boot Images to Use in Configuration Manager

New website and project roadmap - DEFT Linux - Computer Forensics live CD - The DEFT development team has put some fresh paint on their website as well as outlined where they plan to head in the coming months. Congratulations to DEFTA President Stefano Fratepietro and all the community and project contributors who have worked hard to make DEFT Linux a premiere Forensic live CD resource! From that post..

Here follows the forthcoming milestones concerning the new versions of DEFT 8, Virtual Appliance and User Manual.

  • DEFT Linux 8.1 with relevant news for Mobile Forensics – November 2013
  • DEFT 8 VMware Virtual Appliance – late November 2013
  • Roadmap of projects supported by donations – December 2013
  • DEFT 8 User Manual – February 2014
  • Third Italian National Conference DEFTCON 2014  – Polytechnic of Milano, April 11, 2014

Installing VMware Tools on Kali Linux and Some Debugging Basics - SpiderLabs Anterior - Christophe De La Fuente goes to the mat to show some advanced debugging skills in getting VMware Tools onto Kali Linux. As is pointed out in the comments, there are easier ways to do it, but the experience shared of the road taken makes us all a bit wiser. Which this post then led me to discover and add to my RSS feed pile…

Computer Howto's by Lewis Encarnacion - Lewis’s posts are great. Covering not just Windows 7 topics, but also some of the finer points in using and getting comfortable in Kali Linux.

FAU -version 1.3.0.2464 - Speaking of the Forensic Acquisition Utilities (FAU) it seems a new version came out in August 2013. I don’t think I caught that release. The link has a “what’s new” jump as well as the new binary set download link but for the lazy…from that source:

  • Volume_dump and DD now recognize drives with BusTypeSata as devices supporting the ATA feature set.  ATA specific attributes are reported for these drives.
  • Fixed a problem with the DD --verify option when writing an image to certain to certain drives.  Under certain circumstances the DD --verify option reported a spurious failure even though the reimaging of the target drive succeeded and the cryptographic checksum of the destination drive was in fact identical to the cryptographic checksum source image file or drive.  This problem did not affect the accuracy of the reimaged drive but required that the user to validate the target drive after the imaging process was complete.  Thanks to Suman Beros for reporting this problem.
  • When acquiring a physical drive DD now drops the block size down to the device block size when approaching the putative end of the source drive.  Hard drives often misreport their capacity either by over estimating or under estimating the true size.  The only reliable way to image a hard drive is to attempt to acquire beyond the purported end of the drive and see if valid data is returned.  However, we have encountered a few drives that freeze or hang the imaging process if you attempt to read beyond the end of the drive with a block size that is greater than the device block size.  Needless to say, this can be disconcerting when you have already read 1 TiB of data only to have the whole process hang on the last few sectors.  Dropping down to the device block size when approaching the end of a drive should produce more reliable acquisitions.  A disadvantage is that drive acquisition will be slower at the end of the drive.
  • Examples have been added to the DD help text which show how to acquire a physical drive.

That’s all for tonight!

Cheers my friends.

Claus Valca

Sunday, July 14, 2013

File under “That’s one way to do it.”

A KACE solution is used to produce a multi-platform image of our systems.

I’m not exactly sure how they make the master editions. The Home Office works behind closed doors once every few months when the moon cannot be seen at midnight. I guess it’s an “eye of newt, toe of toad” thing.

Anyway, we get the master USB stick, deploy it with much chanting and spinning to a local system, then pass some Latin command-line FU to the all powerful “Run" box. About 3-4 hours later a completely built KACE system (re)imaging stick spawn results. Then we have to repeat to build the next storm trooper clone.

It’s a time consuming process, and since I don’t have a physical multi-USB drive replication device, it can take up to a week (while multi-tasking) to update all the drives our team carry for system reimaging when a new refresh occurs.

So what I do is to to build a single updated one, then use Alex’s awesome USB Image Tool to capture a full image of the built stick. For the standard 16 GB stick we use, it doesn’t take too long to capture the “IMG” file back to the system HDD.

Once I have that, I just turn around and write that image back to each of the follow-on USB sticks. The process still takes up to an hour per stick to write back out, but that’s several hours faster than the standard process takes.

One alternative is OSForensics - ImageUSB. I like it and USB Image Tool as they allow you to take an image and write an image all with the same tool.  I also found Flash Drive Image Creator which just lets you take an image, and Win32 Disk Imager or USBWriter which then allow you to write that image to a USB drive. I haven’t used them unlike ImageUSB or USB Image Tool so YMMV.

All this is well and good until recently we got some 64 GB USB sticks to use.

The stock scripted process we follow from the master set of building files works fine with them…up to a point. See when done, it results in a 16 GB formatted partition. The remaining volume space is left unallocated in the process.

As I understand it (but haven’t verified myself) the process the KACE tool uses to create each of the sticks using the long-process uses UFDPREP.EXE to do the target USB drive’s formatting and conditioning to make it bootable to the KACE PE (just a custom WinPE) environment from which the image deployment scripts run out of.

It has been said (again I haven’t been able to find documentation to support) that UFDPREP only supports setting the formatting size for the flash drive up to 16 GB.  As I haven’t tested it independently, it might be that the script that the UFDPREP runs for in the drive building process is set somewhere to just use a 16 GB size. Changing its “/size=n” argument value to /size=65536 might work. Maybe.

(Side note: yes I know there are lots of ways and tons of tools to accomplish the formatting and boot-support prepping of a flash drive to almost whatever upper size you want limited only by the physical memory capacity of the device. The challenge here is that the official tool/process automates use of UFDPREP at the very onset of the scripted build process to the target device. So a maximum 16 GB formatted partition is what you get on the output if you want to also get the built image deployment tools and files with it.)

Anyway, I didn’t have the spare time to look into this too deeply. I needed a solution now.

So what I did was take my previously captured IMG file of a 16 GB built USB imaging stick and used “USB Image Tool” to restore it to one of the 64 GB sticks.

It went on fine and quick and resulted (as expected) in a fully functional USB stick for imaging purposes that had a 16 GB volume (just like the original it was captured from) with the remainder unallocated space. That would work “as is” for image deployments but we can’t let that unallocated space go to waste can we?

So I then booted a lab system with a Parted Magic “LiveCD”.

I attached the 64 GB stick and used the “Partition Editor” utility to first locate the device (I think it was listed as “/dev/sdb”), then went though the process to resize the 16 GB partition to take in the remaining unallocated space. I ran the operation and after a warning that it might screw up the data it completed with no fuss. See a visual walkthrough on the process concept below.

When the properties for the updated device were checked on a Windows system, the full 64 GB size available on the stick partition was now showing!  Further testing in image deployments found that no corruption to the files/data occurred. It worked great.

I understand that if instead of XP we were running Windows 7 (or Vista) -- which we are not -- then I could have accomplished the same thing natively with the Disk Management tool. Maybe that day will come soon.

I found using Parted Magic a breeze. It was super fast and has been dead-on reliable all the years I have used it to clean up and fiddle with drive partitions.

However there are some other free partition management software tools that run natively in Windows. Check the licensing requirements to make sure they are not “personal use only” and respect accordingly. Some of the free versions have stripped down feature from the “pro” paid version the same company offers.

I keep one or two of these on my USB utility stick as a “just in case” if either DISKPART or Parted Magic fail me. But they really aren’t the butter for my bread.

That said, they look like they could do the same thing that Parted magic is delivering if Linux isn’t your thing.

Like I said, file this under “that’s one way to do it” for using a USB IMG file created from a smaller sized partition on a larger sized USB flash drive, then restoring the additional unallocated space.

If any GSD readers have any additional ways to accomplish the same thing via Windows Command-Line Fu or a small GUI utility I’d love to hear your suggestions; especially if the utilities are freeware/open-source or command-line only and especially if they would work in XP.

Also, if anyone can find documentation on any formatting size limitations that UFDPREP.EXE carries, I’d love to see the linkage. My Google search skills are not too shabby but I haven’t had luck with the right key search terms just yet. I’d like to know formatting limits of the tool before I tear into the actual process to see if our method is passing it a hard-coded \size=16384 or not.

Cheers.

--Claus V.

PS: Misc links I found in the process of searching for info on UFDPREP.EXE that might be interesting to someone:

WinPE Bootable USB - Creating from XP - The CD Forum - Walkthrough on where to get the binary file (from original source) and how to extract it (note it involves Microsoft’s Windows Embedded feature pack).

A Deep Dive into USB Boot - msdn - How UFDPREP actually does it’s magic.

Monday, February 18, 2013

…and an alternative solution is confirmed

In the last post I mentioned the challenge encountered when a user set a local account password on their new Windows 8 system…and forgot it.

A factory re-image got us rolling, but in theory I should have been able to off-line boot the system with one of my WinPE USB sticks (had I had it on hand) and used a utility to blank out the password in the local user’s account.

Last night I wanted to confirm this would work.

So I booted by VMWare-hosted Windows 8 system and confirmed my local user-account did have a working account password on it.

I shut it down and tried to boot it by using one of my custom WinPE USB sticks.

Only VMWare doesn’t support booting from a physically attached USB drive.

So I had to boot from a Plop boot manager first.

Only that didn’t work too well as the VMWare BIOS booted so fast I couldn’t catch it to change my VMware boot order.

So I had to edit my Windows 8 .vmx file to increase the timeframe it allows during the BIOS boot process so I could select more options…such as boot from my mounted Plop ISO file.

That done, I was able to boot the VMWare image, select to boot from Plop, attach the bootable USB stick in VMWare, return to Plop and select the option to boot from USB, and voilà! my WinPE was running in VMware.

Once it settled down, I launched the latest version of NTPWEdit (v 0.4) released in Oct 2012 in both x32 and x64 bit versions and supports Win8.

I passed it to the SAM file location, it found my local account and I used it to blank the password.

I rebooted and let Windows 8 come up.

Sure enough, my password had been successfully removed!

I then went and restored it again.

All is well and some more confirmed techniques are filed away for future reference.

Cheers.

--Claus V.