|
|||||||||||
|
RE: Backdoor.Redkod
From: Fab Siciliano <fsiciliano(at)optiumcorp.com>
Date: Thu Feb 27 2003 - 15:07:27 EST
Like I was saying to HC: WFP can be disabled...it's not a good practice, b/c im "sure" that it will break things... I quote myself:
"> > Editing
All the trojan needs is access to that key, reboot, access the box, overwrite netstat.exe. Either way....once the trojan is there..."overwriting netstat.exe" should be the least of worries. Thanks, Fab > -----Original Message-----
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:38 EDT |
||||||||||
|
|||||||||||