PPRuNe Forums - View Single Post - Bloodhound.Exploit.131
View Single Post
Old 14th Apr 2007, 19:28
  #11 (permalink)  
tallsandwich
PersonalTitle to help support PPRuNe against legal bullying.
 
Join Date: Sep 2005
Location: France
Posts: 134
Likes: 0
Received 0 Likes on 0 Posts
Yeah Root Kits are quite new to me too - my next door neighbour got a problem which was a browser hijack that did not go away and I was stumped. He used Blacklight by F-Secure which is another Root Kit tool to resolve it.

Part of the procedure was the removal of previously hidden files, that in his case were in the temp directory - which sounded a bit like what you did - the Root Kit toolkit simply higlighted objects in the filesystem that would not normally be visible in Windows Explorer. He renamed them, rebooted then deleted them etc. I thought that root kits, by definition, had to pretend to be (or replace) OS programs, which surely means the fix for the problem must include the recovering of one or more files that actually belong to the OS, not just deleting things in temp. Maybe the definition of a Root Kit has grown somewhat.

Anyway, re the name - when I was a student on a 4 year course, we did the third year working in industry - and I did my "Sandwich Year" in a company with another student. Normally this company only had one Sandwich Student each year, but as we were two, they now needed a way to discriminate between us, they couldn't just refer to both of us as "the Sandwich Student" anymore. Well I was tall, and my mate had long hair - he was called "Hairy Sandwich" (sounds way too much like 'the bearded clam' for my liking!) and you already know the name I got. Finally after many months our names were abbreviated to "Tall" and "Hairy". All in the name of education of course.

Anyway, glad all is well.
tallsandwich is offline