How to check inside install.esd/.wim if thers anything suspicious (virus) ?

Discussion in 'Windows 10' started by xhemal1325, Oct 22, 2018.

  1. RideTheLightning

    RideTheLightning MDL Member

    Sep 20, 2018
    180
    183
    10
    There is not much more that can be said on this matter, if people want bloat free operating systems I suggest they make their own.

    Microsoft is an old, rather respectable company and their first Windows release was 20th November 1985, while I trust them (to some extent) there is certainly choices in recent years that can be highly questionable.

    Official releases is the only way to go, they are from Microsoft and Microsoft only despite what people think of the staff and workers who work on Microsoft products these days.

    These so called "SUPER LITE OS" is not recommended to anyone, hardware is relatively cheap and I suggest people invest in better hardware than to take dangerous shortcuts.

    Home brew ISO's is forbidden to post here at MDL so in theory the support for installed systems with "SUPER LITE OS" should be nil/nada/zip/zero.
     
  2. TairikuOkami

    TairikuOkami MDL Expert

    Mar 15, 2014
    1,172
    1,055
    60
    Honestly, have you ever seen an infected ISO? This FUD has been around for ages, just like that people can get infected via p2p, but they never do, unless they download something infected.
    It is too much work for nothing, just to infect like a few dozens of people. Hackers can get an access to accounts by simply asking the person in 50% cases without any hacking involved at all.
    Even if someone would bother to do it, it would be very short-term, since some part of it would be detected eventually. Malware does not work in mysterious ways, it is pretty straightforward.
     
  3. AveYo

    AveYo MDL Expert

    Feb 10, 2009
    1,836
    5,693
    60
    #23 AveYo, Oct 23, 2018
    Last edited: Oct 23, 2018
    Yes, I've seen plenty in the XP / 7 / 8 time!
    It was in such lite iso hosted on tpb that I've tracked a case of file-less wmi persistence with inline scripts - after being pwned - at that time autoruns and other tools did not support it.
    Now it's trendy to use wnf with clever payloads and com callbacks so a casual user is oblivious to that.
    Proof of concepts released at BlackHat have been removed and Microsoft is working on mitigations, but the damage is already done.
    It's not something to be taken lightly, as it is not only stealth, but also on a layer above stuff like defender application guard or commercial av heuristics.
    And it was not just "invented" this summer - it has been available and even documented for a very long time (just check your system tasks for WnfStateChangeTrigger).

    And btw it's not possible to offline check such Frankensteinbuild even if you extract all files, since stuff can reside in registry hives and data files in various inconspicuous forms. As for using a virtual machine, guess what, clever bastards have foreseen that too and can simply not load the heavy payloads. That is if any AV would even catch them.
    One more thing: most of these are up on unreliable file hosting sites and less so via torrents on purpose - due to large sizes, will expire pretty quickly. Will also not be quickly tested online via virustotal for example - all in all a perfect botnet vector since you already know your "users" are dumb enough to run "lite os" - and will have plenty of free resources available to exploit :D.

    So again, do your own via renowned tools, by following already made tutorials.
    Stay away from these like the plague.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. xhemal1325

    xhemal1325 MDL Member

    May 24, 2014
    124
    10
    10
    Well End of Conversation :

    You cant find if a ISO has a virus or not , so make yours !

    Thank You All !
     
  5. MS_User

    MS_User MDL Guru

    Nov 30, 2014
    4,630
    1,343
    150
    adguard has a windows 10 thin X86 that u can check out is safe to use.
     
  6. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    47,220
    94,595
    450
    Who nows for sure? That's the whole subject of this thread. Just create your own modified iso.
     
  7. MS_User

    MS_User MDL Guru

    Nov 30, 2014
    4,630
    1,343
    150
    a friend of mine install it in a old dell laptop and he never told about any issues so i assume is safe to use.
     
  8. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    47,220
    94,595
    450
    I can tell you a lot of fake info too, the matter is, nobody can know for sure if the files are modified/tinkered with, so that's why we prefer to show how people can create things themselves instead of sharing all kinds of modified iso's.

    If it's not malware/virusses it mostly is instable crappy iso's shared by people who don't even know how to mount or pre-enable dotnetfx3 without the use of any tool (just one example from the past).