Updated version of MFTDump.
MD5 = 303C17A98F09775ED2A59FF2294C20BB
SHA-1 = 229A85938E4227FA9B1DDADCBAB528E807B86BE9
This is an update to the McAfee A/V Command Line Scanner Project (MCLSP). It allows you to boot a Windows host with a live Ubuntu Linux CD/DVD or USB Thumb drive and automatically scan all FAT/NTFS volumes for malware. The build process no longer downloads packages from the Internet. Instead, all required .deb packages are included in the download file. This ensures the size of the ISO will not exceed 700 MB. I also added two new build scripts. See documentation for details.
MD5 = 259a387d1552266d561832dcb8e7f650
SHA1 = e480d9b4ade994cb54a0347ef56497e0f48348e9
The above link contains the MCLSP v.1.2.0 docs in PDF format. It includes the FAQ, Quick-Start, and User’s Guides. These files are also included in the project download file.
MD5 = 9a98de0b9d202fbbb6d5a05f904a2306
SHA1 = cd6e6aa00479cae253bc58d84d918cc23a63e0b1
This tool dumps the contents of Windows prefetch files. Designed for forensic examiners and incident responders, PFDump is a lightweight, fast, and flexible way to examine the contents of prefetch files. It also provides a quick way to create a timeline of application load activity. Included in the download zip file is detailed documentation.
MD5 = 7ba6824482c8ed13eceb854840fad472
SHA1 = ebcfe2ddcd99aa308c08de48aa02290fa37fa0fd
This tool provides everything you need to create a custom Ubuntu Linux distribution (distro) that runs the McAfee A/V Command Line Scanner. Yup – you heard that correctly. Through the magic of the Linux Wine project, you can scan Windows boxes for malware using Linux. It allows you to boot a Windows host with a live Ubuntu Linux CD/DVD or USB Thumb drive and automatically scan all FAT/NTFS volumes for malware.
MD5 = a22e3afcc7816a4fb531d68de8ebca01
SHA1 = b3abef62d0bb8092c5b83dad5bcc53bb48374cf0
The above link contains the MCLSP v.1.0.0 docs in PDF format. It includes the FAQ, Quick-Start, and User’s Guides.
MD5 = 3870e1b6628088b5209531f74b715e1e
SHA1 = 12e7830c20c66d71a5f042c36bbf0168