Great Post Guys
That Is Brilliant
Does that apply the same rule for target
ie: r00t computer and the r00tkit installs this service anyways
so i then could do the following remoteley ?
1: install psexec as a service with manual start and stop it.
2: delete the file the psexec service points at
"et voila"
or other method:
point the service to set as disabled,
and then delete the files,
same shit,
only you cant start it with net start
And This Would work right ?
so would that also act as a deterient from people trying to r00t your r00ted comps ?
Best Regards
Adam
Vast Gsm Team
Da Sick Crew