Re: Ping Malke

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 06/08/05

  • Next message: Zvi Netiv: "Re: Ping Malke"
    Date: Wed, 8 Jun 2005 11:00:22 -0400
    
    

    From: "Zvi Netiv" <support@replace_with_domain.com>

    | "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote:
    |
    >> Hi Malke:
    |
    | Would you mind for others' comments? ;-)
    |
    >> I have a NEW utility. It combines; Trend Sysclean, the McAfee Command Line Scanner and
    >> the Sophos Command Line Scanner all in one menu driven utility.
    >>
    >> http://www.ik-cs.com/programs/virtools/Multi_AV.exe
    >>
    >> After tou execute and extract the files, look at the PDF help file.
    >> "C:\AV-CLS\Multi AV Command Line Scanner.PDF"
    >>
    >> Let me know what you think and how it can be improved.
    |
    | Nice!
    |
    | A couple of comments, to consider for further versions:
    |
    | I personally hold that cleaning under Windows should be conducted from self
    | boot, from the installed OS. Yet since you mention the option of clean booting
    | for Win 9x/Me, by aid of boot disk made from www.bootdisk.com, then be aware
    | that there exists a free (for private use) bootdisk to NTFS from DOS, with full
    | read-write access, from http://www.datapol-technologies.com/dpe/recovery/ntfs/
    |
    | In your instructions (PDF file), I would recommend that anything you suggest
    | running from safe mode, be run from safe mode WITH COMMAND PROMPT instead.
    | The reason is that many malware load by injecting through Explorer, that loads
    | in safe mode just as well. You have my permission to include the ToggleMode
    | utility in your package, if required. You may need it to start Win 9x/Me in
    | safe mode with command prompt (a mode they lack inherently). From
    | www.invircible.com/item/80
    |
    | Regards, Zvi
    | --
    | NetZ Computing Ltd. ISRAEL www.invircible.com www.ivi.co.il (Hebrew)
    | InVircible Virus Defense Solutions, ResQ and Data Recovery Utilities

    Hi Zvi:

    I relish your comments. Thanx !
    I'll look into those ideas you have provided.

    You mentioned -- "...malware load by injecting through Explorer..." The script will look at
    the "shell=explorer.exe" directive of the Registry in NT and in SYSTEM.INI in Win9x/ME. If
    there is malware being chained off of explorer such as...
    shell=exlorer.exe malware.exe
    When you run the script in Normal Mode to update the Command Line Scanner (CLS), it will
    properly set the shell= directives back to "shell=explorer.exe" and should not load the
    malware again when rebooted into Safe Mode.

    -- 
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    http://www.ik-cs.com/got-a-virus.htm
    

  • Next message: Zvi Netiv: "Re: Ping Malke"

    Relevant Pages

    • Re: ssk.exe surfsidekick
      ... you did not have load of 'virii' or 'viri' as there is no such terminolgy. ... It is HIGHLY suggested that you get the administrator password so you can logon in Safe Mode ... You can choose to go to each menu item and just download the needed files or you can ... needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key ...
      (microsoft.public.windowsxp.general)
    • Re: Cant handle infected PC. Please Help!
      ... windows does not recognise them). ... Probably you'll have the same troubles in Safe Mode, ... If you can get into Safe Mode, try doing a System Restore to before ... booting into Safe Mode Command Prompt. ...
      (microsoft.public.security)
    • Re: Cant handle infected PC. Please Help!
      ... windows does not recognise them). ... Probably you'll have the same troubles in Safe Mode, ... If you can get into Safe Mode, try doing a System Restore to before ... booting into Safe Mode Command Prompt. ...
      (microsoft.public.security)
    • Re: Cant handle infected PC. Please Help!
      ... windows does not recognise them). ... Probably you'll have the same troubles in Safe Mode, ... If you can get into Safe Mode, try doing a System Restore to before ... booting into Safe Mode Command Prompt. ...
      (microsoft.public.security)
    • Re: Cant handle infected PC. Please Help!
      ... windows does not recognise them). ... Probably you'll have the same troubles in Safe Mode, ... If you can get into Safe Mode, try doing a System Restore to before ... booting into Safe Mode Command Prompt. ...
      (microsoft.public.security)