Re: Restoring WindowsXP SP2 Firewall service after malicious software attack
- From: Gary Flynn <flynngn@xxxxxxx>
- Date: Fri, 14 Jul 2006 14:27:22 -0400
Polanski24 wrote:
Hello!
After few days spent on investigating my system I have detected rootkit
presence with only one tool -> SVV by Joanne Rutkowska. All other tools
(I have tested dozens of them) have failed to do so. My only luck with
infection is that programmer who wrote or rather adapted rootkit made
some lousy job so I can see its presence by some very easy to spot
system behaviour abnormalities.
Seems that flattening the system and reinstalling it is coming closer
:).
Definitely. That fact that all tools but one failed to find
the malware is an indication of the trust you should place
in those types of tools.
I'm not sure if the system in question was a desktop or a
server but if it was a desktop, operating it using an
unprivileged account will prevent future mistakes and locally
run software from being able to foul up firewalls, anti-virus
software, and other critical sections of the computer. It will
also significantly reduce the ways the malware can hide itself
or its modifications making recovery, or at least forensics,
easier if something should get through.
--
Gary Flynn
Security Engineer
James Madison University
www.jmu.edu/computing/security
.
- References:
- Restoring WindowsXP SP2 Firewall service after malicious software attack
- From: Polanski24
- Re: Restoring WindowsXP SP2 Firewall service after malicious software attack
- From: B . Nice
- Re: Restoring WindowsXP SP2 Firewall service after malicious software attack
- From: Polanski24
- Re: Restoring WindowsXP SP2 Firewall service after malicious software attack
- From: Polanski24
- Restoring WindowsXP SP2 Firewall service after malicious software attack
- Prev by Date: Re: Short List of Security Questions
- Next by Date: Re: Short List of Security Questions
- Previous by thread: Re: Restoring WindowsXP SP2 Firewall service after malicious software attack
- Next by thread: Remote Desktop and Terminal Services
- Index(es):
Relevant Pages
|