Unsolved
This post is more than 5 years old
2 Intern
•
2.5K Posts
0
610
December 19th, 2006 19:00
Random thoughts - No HijackThis log
I am posting this here because this posting is directed to those processing Hijackthis logs. While commenting on thread http://forums.us.dell.com/supportforums/board/message?board.id=si_virus&message.id=58078 I noticed something I have not though of and wish to share my thoughts. I believe after cleaning a system of "bad" things there is a second issue to be resolved. The issue is prevention, which has two components. The first is use of third party tools, Anti-Virus tools, Anti-Spyware tools, and maybe firewalls. These issues are fairly well covered. The other issue keeping a system updated. That appears to be where there is still may be a problem. There is no tool generally used that list all the patches applied to a system and then validates that that list, insuring that all patches have been applied. Although enumerating the patch list would not be too difficult, I am not sure what the list could be resolved against.
0 events found


dalem29
2 Intern
•
2.2K Posts
0
December 19th, 2006 21:00
Message Edited by dalem29 on 12-19-200604:43 PM
msgale
2 Intern
•
2.5K Posts
0
December 19th, 2006 22:00
Bugbatter
3 Apprentice
•
20.5K Posts
0
December 19th, 2006 23:00
YES. This forum is for HijackThis logs to be posted.
After working on logs and cleaning systems, we post prevention tips which include keeping the operating system and security updated. Furthermore, most of us do not handle logs that are posted from unpatched systems until a user gets the required updates. It is up to the users to follow our suggestions.
zbestwun2001
3 Apprentice
•
8.8K Posts
0
December 20th, 2006 00:00
zb1
dalem29
2 Intern
•
2.2K Posts
0
December 20th, 2006 01:00
1972vet
3.3K Posts
0
December 20th, 2006 03:00
I believe after cleaning a system of "bad" things there is a second issue to be resolved. The issue is prevention, which has two components. The first is use of third party tools, Anti-Virus tools, Anti-Spyware tools, and maybe firewalls. I disagree...not "maybe firewalls"...absolutely firewalls. To be without a firewall is equal to leaving the keys in your front door while you go away on vacation.
These issues are fairly well covered. The other issue keeping a system updated. That appears to be where there is still may be a problem. There is no tool generally used that list all the patches applied to a system and then validates that that list, insuring that all patches have been applied. Although enumerating the patch list would not be too difficult, I am not sure what the list could be resolved against.
There are tools that will validate hotfixes that you have installed. Qfecheck.exe will tell you if an update you have chosen to install is in fact properly installed. What it will not tell you is that there is a patch you need...It's still up to you to determine if an update is needed for your particular situation...we do that when we visit Windows Update.
In addition there is the Belarc Advisor that lists Hotfixes you've installed and verifies the integrity of the installation. If the installation cannot be confirmed, Belarc will show a Red X next to that hotfix.
As far as enumerating patches installed and resolving that list against all that are available I assume is what you mean...again, that is something that occurs when we visit Windows Update.
Do you think we've failed to cover something that's not covered Here