|
|||||||||||
|
Re: Backdoor.IRC.Flood.E & Backdoor.Dvldr
From: Curt Snow <csnow(at)westerlyhospital.org>
Date: Fri Jun 20 2003 - 10:06:48 EDT
The machine was a Windows 2000 Professional PC. There was no file sharing software on this machine such as KaZaa, etc. and she doesn't use any chat groups or chat programs at all. Her internet connection is via Dial-up The user was logging in as Administrator, with no password (very dangerous thing to do!) After becoming bogged down by the Backdoor stuff, she also got infected with a variant of the lovgate virus. This particular virus brought the machine to its knees. Very little would function correctly once it became infected with this one. I cleaned the lovgate virus and did a backup of all of her critical data, then partitioned and formatted the drive. The OS and apps were then reinstalled and the machine was setup with 2 user accounts. The Administrator account, which now has a strong password (something other than 123456 or "password"), and a user account for her, which is passworded and is a member of the Power Users group (on the local machine... the machine is not on a network). She has been instructed as to how to login using her password and seemed to be OK with the fact that she has to actually login to the machine. A software firewall has also been installed. These steps should prevent all of this mayhem from happening again. Passwords, especially for Administrator accounts, are critical to the security of these machines! >>> NC Agent <NC_Agent@kueppers-familie.de> 06/20 12:01 PM >>>
Kindest of regards, Hamish Stanaway
-= KoRe WoRkS =- Internet Security / Absolute Web Hosting Network
Owner/Operator
http://www.koreworks.com/ http://www.webhosting.net.nz/ http://www.buywebhosting.co.nz/ >From: "Curt Snow" <csnow@westerlyhospital.org>
STOP MORE SPAM with the new MSN 8 and get 2 months FREE* http://join.msn.com/?page=features/junkmail Received on Fri Jun 20 10:27:35 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:39 EDT |
||||||||||
|
|||||||||||