View Single Post
Old 12-03-2008   #43 (permalink)
PainlessTorture


Windows Vista™ Ultimate x64
 
 

Re: Security Team

Quote  Quote: Originally Posted by Neverhavemoney View Post
Fmjc001,
How is your computer set up again? You had told me when you first started posting in this thread that you had a pretty insane set-up for security precautions.
Can you plz inform me of those again and i think i will be able to help.
Also can you provide any more information on the so-called virus

Thanks
Ben
Yeah, My computer has what I would classify as inpenetratable
security precautions, obviously I was wrong. Now, i'm not sure if it was a virus or a hacker because my AV didn't detect anything whatsoever and neither did my firewall.


Security precautions;
  • Elevation requires admin user-name and password on secure desktop
  • 256-AES HDD Encryption
  • Secpol + GP are set to the most restricted settings for every user account except mine. Most things in the secpol have been set to require admin membership for even basic things like shutdown.
  • Anti-Virus, Anti-Spyware, Anti-Malware, Anti-Adware...basically every type of protection software is running on my PC.
  • All passwords are at least 50 characters and contain upper & lower case letters, special characters and numbers. (Also expire every month)
  • Some custom scripts, for example at logon of an admin - they are removed from the admin group unless they have my username.
  • The build-in admin has had a name change and password of over 100 characters (mixed) and is disabled.
  • You cant boot from anything other than the HDD without a secure password. (Well you can, but you would have to take my computer apart and that has not happened unless I was asleep or something...) *You cant boot into safe mode either without the password.
Well I think that's all.


Virus/hacker/whatever;
  • Boots - OK.
  • Logon - OK.
  • Start something within one second of logon via taskmgr - OK.
  • Start something a few seconds later including explorer - error
  • I got a black screen instead of a desktop and when I tried to execute anything it told me it was write-protected.
Any ideas?
My System SpecsSystem Spec