Security Basics mailing list archives

Re: Hacked (...still cleaning)


From: Matan Peled <chaosite () gmail com>
Date: Tue, 19 Apr 2005 23:56:05 +0300

Mauricio Fernandez wrote:
One thing I am trying to do is to hide the cmd.exe file to avoid the
possibility of running some programs. I searched the file on the hole
system and deleted from \system32\ and \I386\ folders, copied into a
folder no included on the system path with a different name. But if I
invoke cmd.exe, it appears again on \system32\

Does anyone knows how to remove it?

I don't believe you can remove it. Windows has a feature intended to keep you
from deleting needed system files, and will simply replace this file from a
backup if you delete it.


-- 
[Name      ]   ::  [Matan I. Peled    ]
[Location  ]   ::  [Israel            ]
[Public Key]   ::  [0xD6F42CA5        ]
[Keyserver ]   ::  [keyserver.kjsl.com]
encrypted/signed  plain text  preferred

Attachment: signature.asc
Description: OpenPGP digital signature


Current thread: