|
-
July 19th, 2004, 07:12 PM
#13
Junior Member
graemejaxx, normally I would recommend that you backup any data that you need, wipe the hard drive, and do a complete re-install. That is pretty much a "best practice" kind of thing to do after an attack, theory being that the attacker may have installed or done something that at this time you can not detect. However, I understand that this may not be an option for everyone, including your self...
So, assuming that you are on a home network I would recommend that you run a sniffer such as tcpdump or ethereal this should give you a good idea of what is being broadcast from or sent to your box. Next, I would recommend that you take a visit to http://www.rootkit.com. Download the windows rootkit detection utility, and let it run. I say this, because I recall hearing about a rootkit that infected Norton's various utilities. I hope this helped a little.
P.S. Just because you deleted a file, and no longer see a process when you "Ctrl-Alt-Del" does not mean you dont have a hidden process still running at kernel level.
-Shell_Coder
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|