A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #11045  by CloneRanger
 Sun Jan 15, 2012 4:53 pm
Looks like it might be useful, anybody tried it ? And if so how useful etc was it ?

*
Windows Defender Offline — old name, new use

Microsoft’s newly released beta version of Windows Defender Offline, a rootkit-sniffing and Windows-rehabilitation tool, should be the latest addition to your bag of Windows-repair tricks.

WDO should be able to catch a wide variety of nasties that evade detection by more traditional antivirus methods.
Although the name’s been around for years, don’t confuse this new version of WDO with previous incarnations — it’s a whole new animal and helps PC users in two very different situations:

http://windowssecrets.com/top-story/win ... me-new-use
Windows Defender Offline Beta: frequently asked questions

Windows Defender Offline Beta helps protect your PC by scanning it to remove rootkits and other advanced malware that can't always be detected by antimalware programs. If this type of malware is detected on your PC, you'll be prompted in Microsoft Security Essentials or Windows Defender to download and run Windows Defender Offline Beta.

The following are answers to some frequently asked questions about Windows Defender Offline Beta.

http://windows.microsoft.com/en-US/wind ... ffline-faq
 #12276  by kmd
 Fri Mar 23, 2012 6:29 am
so how realible this WDO? zeroaccess?
 #12281  by EP_X0FF
 Fri Mar 23, 2012 8:23 am
kmd wrote:so how realible this WDO? zeroaccess?
This is Windows PE + latest MSE 4 with custom GUI. Yes its capable with Sirefef removal.

Image
 #12292  by kmd
 Fri Mar 23, 2012 2:50 pm
ok, so this sort of light edition of livecd? what about TDL4?
 #12295  by EP_X0FF
 Fri Mar 23, 2012 3:42 pm
kmd wrote:ok, so this sort of light edition of livecd? what about TDL4?
Not exactly. This is software formerly known as Microsoft Standalone System Sweeper. This is special boot tool created for dealing with most complicated malware infections that are not profitable, too complicated or too dangerous to fix in runtime. It core component is next-gen MSE that you can see already in Win 8 Consumer Preview plus as you might noticed WinPE 3.1 (pending replace to 4.0 in future).

Itself MSE 2.1 > 1.1.75xx is capable with detection of TDL4 like on the picture below

Image

then you will be prompted to download WDO and reboot computer. After booting with WDO

Image

successful removal.

HTH.