Windows 2k rootkit incident, files zipped for your pleasure.

From: Drew Weaver (drewat_private)
Date: Thu Jun 12 2003 - 08:57:23 PDT

  • Next message: Ken Eichman: "Spoofed TCP SYNs w/Winsize 55808 (was: Help with an odd log file...)"

        Hi, with the help or Karl Levinson I was able to detect the presence of
    a rootkit on one of my windows 2000 servers, I was able to grab the files
    and zip them, so maybe we can watch for this stuff in the future, im not
    sure if this rootkit has a particular name or what/not, you can get the
    files here:
    
    http://www.soul-fu.com/beenhaxxored.zip
    
    Thanks Karl.
    
    -Drew
    
    
    ----------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Thu Jun 12 2003 - 10:49:13 PDT