On Tuesday, February 24, 2004 09:17 am, Brian Densmore wrote: > The rootkit they hit me with takes tripwire down too. You should still be able to run Tripwire using the signature file you saved to off-line media and come up with a list of all the files they changed. (That's why you save a sig file off-line. You did do that, didn't you?)