Re: Klone Virus
- From: "Stefan Kanthak" <postmaster@[127.0.0.1]>
- Date: Mon, 27 Nov 2006 17:50:45 +0100
"Gary S. Terhune" <grystnews@xxxxxxxx> wrote:
Thank you, again. I assumed that some of the scanners kill processes in
order to excise files, and PestPatrol, for example, creates a script that
runs at startup, in order to excise files before they load. But there are
layers upon layers to this whole business. I know some who suggest pretty
much always using Bart's for formal malware scanning, but I kind of figure
that's taking things a bit far.
Right, this is way to far (although it's the only reliable way to run any
scanner; but don't forget that you NEVER can prove the absence of malware)!
http://www.microsoft.com/technet/community/columns/secmgmt/sm0504.mspx
http://www.microsoft.com/technet/archive/community/columns/security/essays/10imlaws.mspx
A simple clean reinstall wiping all disks (by formatting them with NTFS)
cleans all those malware for sure*.
Any other means are just RIDICULOUS: "better be safe than sorry"!
You, and Joe Average too, can't clean a compromised system. Especially in
case of a Trojan it's NOT sufficient to remove the Trojan, you'll have to
find ALL the Greeks that swamped the system!
[braindead fullquote removed]
Stefan
* Don't forget to install XP Service Pack 2 BEFORE you connect the fresh
installed system to ANY network.
AND: create "restricted user" accounts for EVERY user of the system,
NEVER use the initially created "administrator" account for any work
except system administration.
Also consider to turn on SRP and allow execution only in %SystemRoot% and
beyond as well as %ProgramFiles% and beyond.
.
- Follow-Ups:
- Re: Klone Virus
- From: David H. Lipman
- Re: Klone Virus
- References:
- Re: Klone Virus
- From: David H. Lipman
- Re: Klone Virus
- From: Gary S. Terhune
- Re: Klone Virus
- From: David H. Lipman
- Re: Klone Virus
- From: Gary S. Terhune
- Re: Klone Virus
- From: David H. Lipman
- Re: Klone Virus
- From: Gary S. Terhune
- Re: Klone Virus
- Prev by Date: Re: Password too long
- Next by Date: Re: What kind of conspiracy is this?
- Previous by thread: Re: Klone Virus
- Next by thread: Re: Klone Virus
- Index(es):
Relevant Pages
|