![]() |
|
|||||||
|
XP logs off right after logging in(virus) |
![]() |
|
|
Thread Tools | Display Modes |
|
#31
|
||||||
|
||||||
|
Quote:
As others mentioned, and i agree(i do it with my own pc), every OS need to be rebuilt depends on the usage( i do mine every 6months) So even if you find the flu, i would get all those keys, data, etc, etc and re-build the system, and when it is ready make a copy of the system and find a good data backup solution. So this work seems to be unavoidable to me. (expire:?????)
|
|
#32
|
||||||
|
||||||
|
Quote:
Level 1,2,3 NVQ IT USERS (ITQ) Passed 271 - Passed 272 - Passed (MCDST) (MCP) 270 - Currently Studying - Finish by middle of March A+ - Finish by June N+ - Finish by August |
|
#33
|
||||||
|
||||||
|
Quote:
Writing a production ready virus scanner is reasonably hard and would likely take one person 6+ months, and thats without the millions man hours that must go into building a signature database and creating removal plans. Did you look at Autoruns ? Its designed to show all the common reg keys that launch apps, there are like 200+ such keys. Its a user friendly app for people that just want to see the horrendous mess the registry can be ! Registry viewing and export tools normally conform to a subset of the full API functionality, therefore there are ways people can store hidden keys or hidden suffixes on keys. Viruses can adopt other tactics as well, they can attach themselves to pucker executables, therefore they need not change the registry at all ! If its a pucker executable that runs regularly then the trojan can get into memory and start executing and doing what it wants. If the executable is not monitored by system restore and the virus signature is not in the AV then you're gonna get pwned ! Rootkits can alter filesystem drivers and make themselves totally invisible to any program that uses standard OS call's to read the filesystem! They don't just rely on the registry autorun functionality, they could change a bootsector etc. They could load a fake driver or service, yes this would appear in the registry, but possibly not where you expect, they could even share a service host with legitimate services. Wow, VB6 programmer, you must be l33t !
|
|
#34
|
||||||
|
||||||
|
Quote:
I should have known about viruses injecting themselves into the memory space of valid executables such as explorer or internet explorer. Been a while since i used to look into this in depth, actually about 6 years ago. I used to digg up the source code of well know viruses and learn how the worked. Also as you say patching valid dlls is another method, and there will be many more exploits. Just seems a pain that by being able to remove a file or two and a registry key or two you save yourselves a lot of unnecessary trouble. Ok thanks for disscussion, been a good help. |
|
#35
|
||||||
|
||||||
|
Quote:
BosonMichael MCSE+I, MCSE: Security, MCSE: Messaging, MCDST, MCDBA, MCTS, OCP, CCNP, CCDP, CCNA Security, CCNA Voice, CNE, SCSA, Security+, Linux+, Server+, Network+, A+ Served proudly, US Army, 98C Intelligence Analyst, '89-'92 Everyone else is posting their blog... guess I will too! |
|
#36
|
||||
|
||||
|
There were no system restore points, which also added to the burden.
|
|
#37
|
|||||
|
|||||
|
Why is it reading this guys posts I get the impression he is just trying to impress!? In the time it has taken to follow and reply to posts on this thread he could have done what everyone has advised three times over - backup and re-image.
dmarsh - love your l33t comment! A+ IT Technician, CCENT, CEH, CPTS, CIW Security Analyst, ITIL v3 Foundation, Master CIW Administrator, MBCS, MCSA:Security on Windows Server 2003, MCTS on Windows Server 2008 (AD, NI & Virtualization), Network+, SCNS, Security+, Server+
|
|
#38
|
||||||
|
||||||
|
Quote:
Level 1,2,3 NVQ IT USERS (ITQ) Passed 271 - Passed 272 - Passed (MCDST) (MCP) 270 - Currently Studying - Finish by middle of March A+ - Finish by June N+ - Finish by August |
|
#39
|
||||
|
||||
|
No gloating here, i haven't programmed for a few years and most of the code i used was from free code sites i just modified the code here and there.
Anyway i came up with a better solution, obvious as it is, and that would be to remove the drive and add it to another system as a secondary drive, instead of having to reset registries etc to allow me to even boot in. This still means i have to digg through the regsitry to remove the bad stuff, but it should make the process a bit quicker. The is an app called regmon which may help out here. |
|
#40
|
|||||
|
|||||
|
As the drive is a second drive the registry wont actually be doing anything here, the main drive will have the live registry so to speak.
|
|
#41
|
||||||
|
||||||
|
Quote:
Kudos. ![]() ![]() You brought two too many |
|
#42
|
|||||
|
|||||
|
Just a quick point, does the customer not want his\her laptop back yet mate?
|
![]() |
|
||||||
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Problem - Logging in Windows 2003 | Angry Dog | Software | 3 | 30-Sep-2009 11:30 AM |
| Question about router logs. | johnd | Routing & Switching | 2 | 10-Jul-2009 04:52 AM |
| ASA logging | morph | Network Security | 3 | 29-Jan-2009 02:17 PM |
| logging onto server 2003 domain wireless - GP? | rockstar6181 | Software | 2 | 03-May-2008 10:45 PM |
| logging on interactively V logging on locally | mjtibbs | Server Exams | 5 | 07-Mar-2007 01:30 PM |