2008/6/17 <forensicist_at_gmail.com>:
> I have scanned Sebek-WIN32 v3.0.3 & Sebek-WIN32 v3.0.4 but both are infected and AV detected it as a Malware.
Hi there,
Can you tell us which AV software you are using, and what malware it
claims to detect?
I guess it's just detecting it as a generic rootkit-type package.
> Also, when I restarted my PC1 after installation of Sebek-WIN32 v3.0.3 and restarted my PC2 after installation of Sebek-WIN32 v3.0.4, BLUE screen error occur.
>
> I am using Win 2003 server Enterprise Edition with Sp2 and HoneyNet CD-ROM roo-1.4.hw-20080423134017.
I doubt it's been tested with Win 2K3 Enterprise Edition, because EE
1) is expensive and 2) has features which aren't particularly needed
for honeypots.
I wouldn't run AV software at the same time as sebek, if that's what
you're doing. If so, try disabling the AV and see what happens.
Hopefully someone can say if they've got it working with plain Win 2K3 or not.
cheers,
Jamie
--
Jamie Riden / jamesr_at_europe.com / jamie_at_honeynet.org.uk
UK Honeynet Project: http://www.ukhoneynet.org/
Received on Jun 17 2008