<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Rootkit In Spyware?</title>
	<atom:link href="http://www.lockergnome.com/windows/2005/09/12/rootkit-in-spyware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lockergnome.com/windows/2005/09/12/rootkit-in-spyware/</link>
	<description>Technology News, Reviews &#38; How-To</description>
	<lastBuildDate>Sat, 18 Feb 2012 05:52:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Fabio Passaro</title>
		<link>http://www.lockergnome.com/windows/2005/09/12/rootkit-in-spyware/#comment-8774</link>
		<dc:creator>Fabio Passaro</dc:creator>
		<pubDate>Fri, 25 May 2007 21:12:36 +0000</pubDate>
		<guid isPermaLink="false">http://wp3.lockergnome.com/windows/2005/09/12/rootkit-in-spyware/#comment-8774</guid>
		<description>Well I have news for you - after a bona fide (or so i thought) windows update on 3 machines 2 days ago - AVG was disabled and then a browsing tool bar and a pop up software kit was installed after the update restart. In the background root-kits and trojan down loaders and key loggers were later found to have been installed.

Better still group policies were edited disabling access to task manager and to even turn the PC off - User file was corrupted beyond repair and had to be destroyed as XP Home has no group policy editor to rectify the situation.

Subsequent Safe Mode boot scans found 67 root kits installed on one of the machines. Of real note is that one of the infected machines was a bare virgin windows install with NO 3rd party software added aside from legit MS updates.

One machine now still has a very benign version of sasser still on it that is proving really troublesome to get rid of.

I have now disabled automatic updates on all machines and disabled the BITS service and will update manually from now on.</description>
		<content:encoded><![CDATA[<p>Well I have news for you &#8211; after a bona fide (or so i thought) windows update on 3 machines 2 days ago &#8211; AVG was disabled and then a browsing tool bar and a pop up software kit was installed after the update restart. In the background root-kits and trojan down loaders and key loggers were later found to have been installed.</p>
<p>Better still group policies were edited disabling access to task manager and to even turn the PC off &#8211; User file was corrupted beyond repair and had to be destroyed as XP Home has no group policy editor to rectify the situation.</p>
<p>Subsequent Safe Mode boot scans found 67 root kits installed on one of the machines. Of real note is that one of the infected machines was a bare virgin windows install with NO 3rd party software added aside from legit MS updates.</p>
<p>One machine now still has a very benign version of sasser still on it that is proving really troublesome to get rid of.</p>
<p>I have now disabled automatic updates on all machines and disabled the BITS service and will update manually from now on.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 11/19 queries in 0.465 seconds using disk: basic
Content Delivery Network via Amazon Web Services: CloudFront: s3.lockergnome.com

Served from: www.lockergnome.com @ 2012-02-18 09:42:57 -->
