Cleaning up after WMF exploit – is it clean?



So, I’ve got most of the baddies cleaned out and I’m not getting popups anymore. No nags on boot, the boot process is quicker, but is it really clean? I found a few files (winlogon.exe, alg.exe in particular) that could be legitimate windows file names. Am I running the good one, or the trojan? That is exactly why a clean install is usually the best treatment for a badly infested system. Ultimately to trust this cleaned system a bit better I would need to. Watch it for signs of peculiar network ports open or peculiar processes…..


Replace the suspected system files with known good copies from the Windows install disc or similar source (sp2 install), etc. ultimately I don’t know how long it would take to really say you could “trust” the platform again until it was wiped clean and reinstalled. The best advice if you’re considering a clean up like this is to think of it as a temporary step to control the infestation and get important files off.

Also, I would need to run antivirus scans on and off for some time (with updates) to increase my confidence that it’s clean. Anti-Spyware scans would be good as well.

There is at least one of step that I have failed to document in this series so far… I’ll deal with that in the next article.

Related Posts

Blog Traffic Exchange Related Posts
  • Version 2 of the WMF exploit vs Windows 98 SE Ok, I wasn't quite satisfied with the results of the tests against the first version of the WMF (Windows Metafile) zero day exploit that's now up to 4 or 5 days or so... Windows 98 is listed as being vulnerable, but there are no patches or workarounds currently available for......
  • Qemu Windows XP install Well, I alluded yesterday to a struggle with installing Windows XP under Qemu. Here are some details on the long and (still winding) road. At this point I have a working XP install running under Qemu but, I've run out of disk space (2G) and need more space before I......
  • Virtual Machine of a real hard drive This incidents.org article the other day caught my eye. It talked of a utility calledliveview that could take a hard drive (or image of a drive) and make it into a virtual machine for use in vmware (saving all changes to a temporary file so the original structure of the......
Blog Traffic Exchange Related Websites
  • How to Do Home Window Installation Replacing and installing windows can seem like a daunting and expensive task, but it can actually be incredibly simple to do yourself. When you do your own home window installation, you’ll be greatly cutting down on the costs since most of the cost of having windows installed is the labor.......
  • How to Install Bathroom Tile Your choice of bathroom tile is extremely important for establishing the décor of your bathroom. However, no matter what fancy pattern and color scheme you choose, it won’t look good unless it’s installed properly. It can cost a fortune to have a contracted install bathroom tile for you, so you......
  • Guide to Gun Cleaning The first step to good gun cleaning is to scrub out the bore of your gun using the correct Phosphor bronze brush size, and use a bore solvent like Bor-Solv Supreme for the greatest possible results. This will remove all powder fouling and residue from the bore of your gun......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site