PC Review


Reply
Thread Tools Rate Thread

Backdoor Trojans, Are They Gone?

 
 
GaryLund
Guest
Posts: n/a
 
      23rd Jun 2004
When a computer gets a backdoor type trojan or worm, and an anti-virus
program detects and cleans the program file, how can I tell whether
anyone actually used the backdoor, and what they did to or on the
computer?

I do computer support for clients, and have been finding trojans or
worms of the backdoor type that let a remote computer run commands on
the client's computer. When a virus scan finds a backdoor type file,
and deletes it, is that the end of the danger? Or could a cracker
have loaded other bad files on the computer that the antivirus program
will not detect?

How can I be sure the computer is safe after that without wipeing the
hard drive and reloading everything back from scratch? That seems
like a very drastic and expensive solution. Is there a generally
accepted practice in these situations?

Thanks for any info.
-Gary
 
Reply With Quote
 
 
 
 
kurt wismer
Guest
Posts: n/a
 
      23rd Jun 2004
GaryLund wrote:

> When a computer gets a backdoor type trojan or worm, and an anti-virus
> program detects and cleans the program file, how can I tell whether
> anyone actually used the backdoor, and what they did to or on the
> computer?


in general, you can't... there might be a few that leave traces of what
was done but most won't...

> I do computer support for clients, and have been finding trojans or
> worms of the backdoor type that let a remote computer run commands on
> the client's computer. When a virus scan finds a backdoor type file,
> and deletes it, is that the end of the danger? Or could a cracker
> have loaded other bad files on the computer that the antivirus program
> will not detect?


other files may have been loaded, otherwise secure information like
passwords or credit info could have been leaked, the owner's identity
may have been stolen, etc...

> How can I be sure the computer is safe after that without wipeing the
> hard drive and reloading everything back from scratch? That seems
> like a very drastic and expensive solution. Is there a generally
> accepted practice in these situations?


the only real solution in this kind of situation is to rebuild the
system, and have the customer change all their passwords (not just on
their computer but for things like online banking, web mail accounts,
etc) and take whatever other steps they can to regain control over
whatever information or resources may have been compromised...

--
"maxwell can tell he's in hell
just wants you to visit him there
same old game that he's playin'
his rules are never fair"
 
Reply With Quote
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojans =?Utf-8?B?U2Fs?= Windows XP General 5 8th Jun 2007 02:28 AM
Trojan.Backdoor.Small.FB(backdoor) =?Utf-8?B?d2ZtMzE2?= Security and Anti-Spyware Community 5 25th Apr 2006 12:11 PM
Trojan.backdoor.small FB. backdoor =?Utf-8?B?UGV0ZXI=?= Spyware Discussion 2 15th Mar 2006 01:01 AM
Trojans, Please help! Frank V. Anti-Virus 9 31st May 2004 04:52 PM
trojans =?Utf-8?B?c3Rhbg==?= Windows XP Security 2 11th Mar 2004 05:17 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 05:45 AM.