PPRuNe Forums - View Single Post - Apple stuff - Mac, iPad, iphone
View Single Post
Old 6th Apr 2012, 22:30
  #942 (permalink)  
Milo Minderbinder
 
Join Date: Jan 2012
Location: .
Posts: 2,173
Likes: 0
Received 0 Likes on 0 Posts
So that's just like Windows then. No AV on this box, not needed.

I've just handed back to the customer today a Windows machine that "didn't need antivirus". It was given to me to sort out because all the files on the single hard drive had vanished. The machine would still boot into windows, but that was it. No A/V on it because ";it had never been needed".

So what did I find?
1) A rootkit
2) The entire contents of the drive had a "superhidden" attribute set - this had to be removed (tedious)
3) The entire contents of the drive had all user permissions and ownerships removed - so blocking access. These had to be restored
4) The entire drive contents also had the "hidden" attribute set - this had to be unflagged before any more checks could be done
5) Now a number of restrictive policies appeared whiich blocked file access - these had to be removed
6) the next stage found another rootkit, trojans, keyloggers and a couple of browser hijacks. By now I could get at her files (research thesis and supporting docs) back these up and finally nuke the machine. A tedious and expensive job, which cost the customer dearly. And she found the hard way that Windows computers DO need antivirus software.


And before anyone asks, no the contents of the drive were not visible under Linux. I booted the machine with Knoppix and nothing was visible.
Milo Minderbinder is offline