Full Disclosure mailing list archives

Re: suspicion of rootkit


From: valdis.kletnieks () vt edu
Date: Wed, 11 Jul 2012 16:51:13 -0400

On Wed, 11 Jul 2012 22:42:42 +0200, phocean said:
I have a lab virtual machine that behaves as if it was owned by a
rootkit: weird behavior with system certificates and keyboard driver.

Out of curiosity, why are you guessing it's a rootkit, rather than just another
case of Windows being messed up and needing fixing?

What release of Windows?  When did it start misbehaving?  Was that
anytime near Patch Tuesday?

Attachment: _bin
Description:

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: