Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: NT Partitions

From: Dave <dauern(at)cox.net>
Date: Wed May 14 2003 - 12:06:05 EDT

Dave,

Agreed... something smells fishy here. The most important questions I would have are:

Who, if anyone, was responsible while you were away, and what is their level of expertise?

Who is telling you a virus is responsible, and what is their level of expertise? Did they even tell you which virus? Apparently not, or you wouldn't be asking this question. There's no way they can be sure it was a virus unless they ID'd it.

Is there anything left to do any analysis on, or did someone reinstall or restore everything onto the supposedly infected disk?

What sort of a system was this? Workstation, server...? Was anyone using it, or was it supposed to just do it's job until you got back without any interaction? Was it running anything that has been exploited recently? Was it exposed the the internet?

Dave

Do you need help?X

>
> Hello David,
>
> Sometimes, we have to take the qualification of the person who claims "a
virus
> attack is an easy way to
"Format
> C" itself and didn't
Protection,
> you would probably need
determine
> what might includes analysing
<dave@mrbonzi.co.uk>
> arker.org> cc:
focus-virus@securityfocus.com
> Subject: Re: NT Partitions
readable,
> but blank, or inaccessible? Because another behavior of malware is to
access
> to the decryption routines and, therefore, can't access the hard drive.
have
> > virus protection running to download new dats in the morning and to
scan
> > at night and now am getting the blame for the crash. The crash
happened
> > on 28th February.
> >
> > Dave
>

>
> ------------------------------------------------------------------------

---

> Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam,
the
> world's premier event for IT and network security experts. The two-day
professionals.
> The two-day Briefings on May 14-15 features 24 top speakers with no
vendor
> sales pitches. Deadline for the best rates is April 25. Register today
to
>
> ensure your place. http://www.securityfocus.com/BlackHat-focus-virus
----
>
>
>
>
>
>
>
>
>
> ------------------------------------------------------------------------
---
> *** Wireless LAN Policies for Security & Management - NEW White Paper
***
> Just like wired networks, wireless LANs require network security
policies
> that are enforced to protect WLANs from known vulnerabilities and
threats.
> Learn to design, implement and enforce WLAN security policies to
lockdown enterprise WLANs.
>
> To get your FREE white paper visit us at:
----
>
>
--------------------------------------------------------------------------- *** Wireless LAN Policies for Security & Management - NEW White Paper *** Just like wired networks, wireless LANs require network security policies that are enforced to protect WLANs from known vulnerabilities and threats. Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs. To get your FREE white paper visit us at: http://www.securityfocus.com/AirDefense-focus-virus ----------------------------------------------------------------------------
Received on Wed May 14 12:17:56 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:39 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library