Re: Virus cleanup - fix compromised windows firewall settings



In article <1187709590.202986.120610@xxxxxxxxxxxxxxxxxxxxxxxxxxx>,
sean.blaes@xxxxxxxxxx says...

I am running Windows 2003 R2 and had the box compromised by a virus.

Unless you're just trying to clean it for the experience and fun, wipe
it and rebuild it.

There is no way to be sure that a machine is 100% clean using any
automated tools and certainly not by even a skilled network admin.

While I've cleaned some, I've never "certified" them as clean for
customers, and I never will. The only "SECURE" way to clean a
compromised box is to wipe (flatten) completely and rebuild in a clean
area.

You need to keep your servers behind a proper firewall too, do not
connect them without an appliance in front of them - and I'm not talking
some cheap NAT router that claims to be a firewall.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@xxxxxxxxxx (remove 999 for proper email address)
.



Relevant Pages