hacking security forum

Re: [Full-Disclosure] tvm.exe / poll each.exe / blehdefyreal toolbar

From: mark <mark@edwards.org>
Date: Wed Jun 09 2004 - 13:00:02 EDT

>Suggesting that the likely best approach to "fixing" a system
> of which you have _no freaking idea whatsoever_ is ailing it
> is to reformat and reinstall (_or_ anything lelse) is clearly
> a sign of incompetence, and little else.

The idea here is to learn something from it. Reformatting the system is
a good idea, but before that takes place it'd be nice to learn what the
thing actually is and how it works.

This thing respawns itself without a reboot. Loading Tiny Personal
Firewall apparently prevents it from respawning. TPF does something
about preventing code from being injected into a process, so maybe
that's why TPF keeps it at bay.

This isn't on any system I use or manage. It's on a collegue's system
and I am trying to help find a way to figure out what it does, how to
get it shut down permanently, removed if possible.

Thanks for the suggestions to those who've provided some, including a
reformat ;-)

Mark

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Wed Jun 09 13:10:01 2004

This archive was generated by hypermail 2.1.8 : Wed Jun 09 2004 - 14:03:16 EDT

Custom Search