PowerShell Script to Copy OUs and Groups from AD Including Group Membership

There is an updated version of this AD Administration PowerShell script that is much simpler. I couldn’t find a clean method to export group membership from AD. LDIF notoriously does not allow importing the MemberOf attribute, so I began looking for a way through PowerShell. I found a method using Quest’s AD Tools SnapIn. The code below … [Read more…]

Removing a Windows Rootkit Using RootkitRevealer and The Avenger

After posting about how to remove a rootkit using SystemRescueCd, I encountered a rootkit that I could not eradicate using my method.  Fortunately, I was able to discover a different method using Windows tools.  SysInternals (aka Microsoft) developed a tool called RootkitRevealer that is very useful in determining the symptoms, thus the identity, of a rootkit.  After determining … [Read more…]

Removing a Windows Rootkit Using SystemRescueCd

The past few weeks have taught me a lot about rootkits: They are insanely difficult to remove from a Windows installation This is because they disable all the best anti-malware tools They hide themselves from even the most diligent searching Instead of spending hours trying to trick a rootkit into letting an anti-malware software to run, … [Read more…]