Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

worm-detection/removal ???

 
   Security Forums (Home) -> General Discussions RSS
Next:  Whats up with Nod32 updates?  
Author Message
Hans Pesata

External


Since: Jun 02, 2004
Posts: 10



(Msg. 1) Posted: Tue Jan 13, 2004 8:14 am
Post subject: worm-detection/removal ???
Archived from groups: alt>comp>anti-virus (more info?)

Hi!

I would like to know how I can get rid of any worm that has infected a
WINDOWS XP-system.
I know about the worm removal tools, but there is just 1 tool for every worm
and you have to run ALL of them to find which worm has infected your system.
this takes A LOT of time with a nearly full 80GB hard-disc ...

My only solution so far was to to do a clean new install of WINDOWS-XP
with the appropriate MS-RPC-patch, but this is pretty time-consuming too...

What about NAV 2003/2004, can I use it for the worm-detection/cleaning ?

Any help with this would be greatly appreciated,
thanx in advance!

best regards,
Hans Pesata

------------------------------------------------------

My eMail-address has been changed due to spam.
eMail-replies can be sent to hpesata DeleteThis @chello.at

 >> Stay informed about: worm-detection/removal ??? 
Back to top
Login to vote
Boyd Williston

External


Since: Jul 04, 2003
Posts: 52



(Msg. 2) Posted: Wed Jan 14, 2004 12:56 am
Post subject: Re: worm-detection/removal ??? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Hans Pesata" <dummy.user.TakeThisOut@dummy.com> wrote in
news:ONNMb.103077$Tz1.86871@news.chello.at:

> Hi!
>
> I would like to know how I can get rid of any worm that has infected a
> WINDOWS XP-system.
> I know about the worm removal tools, but there is just 1 tool for every
> worm and you have to run ALL of them to find which worm has infected
> your system. this takes A LOT of time with a nearly full 80GB hard-disc
> ...
>
> My only solution so far was to to do a clean new install of WINDOWS-XP
> with the appropriate MS-RPC-patch, but this is pretty time-consuming
> too...
>
> What about NAV 2003/2004, can I use it for the worm-detection/cleaning
> ?
>
> Any help with this would be greatly appreciated,
> thanx in advance!
>
> best regards,
> Hans Pesata
>
> ------------------------------------------------------
>
> My eMail-address has been changed due to spam.
> eMail-replies can be sent to hpesata.TakeThisOut@chello.at
>
>
>
>
>
>

Well, it seems that you are trying to do things backward.

First, develop habits that make infections less likely.

Second, install software that blocks malware from getting installed in the
first place. NAV will work, but you probably can find something else that
is less expensive and has less overhead.

Third, regularly scan with good detection software (with recent definition
updates).

THEN check into removal tools for anything that's found, or if you have
symptoms of something specific. I certainly wouldn't use a removal tool
for (as an example) Swen unless I were pretty sure that I had been
infected with it.

 >> Stay informed about: worm-detection/removal ??? 
Back to top
Login to vote
Hans Pesata

External


Since: Jun 02, 2004
Posts: 10



(Msg. 3) Posted: Wed Jan 14, 2004 1:59 pm
Post subject: Re: worm-detection/removal ??? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi!

> Well, it seems that you are trying to do things backward.
> First, develop habits that make infections less likely.

my job is to help people with their computer-problems and a lot of
problems are related to viruses/worms. I try to teach people how to protect
their PCs, but first I have to fix them.

> Second, install software that blocks malware from getting installed in the
> first place. NAV will work, but you probably can find something else that
> is less expensive and has less overhead.

I have seen a lot of PCs with NAV runing and worms disturbing everything in
the system.
it seems that the only way to fight this is the MS-RPC-patch and a firewall.

> Third, regularly scan with good detection software (with recent definition
updates).
> THEN check into removal tools for anything that's found, or if you have
> symptoms of something specific. I certainly wouldn't use a removal tool
> for (as an example) Swen unless I were pretty sure that I had been
> infected with it.

I need a way to repair infected systems with minimal time-effort.
I cant know which worm has infected a system, to use a specific tool to fix
it.
I just see that something is pretty wrong. therefore I need good tools to
help me with this.

best regards,
Hans
 >> Stay informed about: worm-detection/removal ??? 
Back to top
Login to vote
kurt wismer

External


Since: Jul 04, 2003
Posts: 1562



(Msg. 4) Posted: Wed Jan 14, 2004 1:59 pm
Post subject: Re: worm-detection/removal ??? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hans Pesata wrote:
[snip]
> I need a way to repair infected systems with minimal time-effort.
> I cant know which worm has infected a system,

*STOP*

think to yourself, you want to repair the damage done by a worm but you
can't be bothered to figure out which worm it was - thereby completely
skipping the step about finding out exactly what damage was done...

does that sound reasonable to you? if it does, then you're in the wrong
line of work...

> to use a specific tool to fix
> it.
> I just see that something is pretty wrong. therefore I need good tools to
> help me with this.

use an anti-virus product to figure out what it was, then use a
dedicated removal tool if one exists or the anti-virus product itself
if no dedicated removal tool exists... dedicated removal tools are
preferable over the av itself as the av will often times simply
neutralize the worm/virus/whatever...

--
"hungry people don't stay hungry for long
they get hope from fire and smoke as the weak grow strong
hungry people don't stay hungry for long
they get hope from fire and smoke as they reach for the dawn"
 >> Stay informed about: worm-detection/removal ??? 
Back to top
Login to vote
Hans Pesata

External


Since: Jun 02, 2004
Posts: 10



(Msg. 5) Posted: Fri Jan 16, 2004 2:36 pm
Post subject: Re: worm-detection/removal ??? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi!

> use an anti-virus product to figure out what it was, then use a
> dedicated removal tool if one exists or the anti-virus product itself
> if no dedicated removal tool exists... dedicated removal tools are
> preferable over the av itself as the av will often times simply
> neutralize the worm/virus/whatever...

that was exactly what I have been asking when I posted my question in this
newsgroup,
but I didnt get a clear answer, do you known if I can use NAV2003/2004 to
detect worms ?
I understand that using a dedicated worm-.removal-tool afterwards is the way
to go.

this is important for me to know, because I have to check a probably
infected system with a pretty full 80GB hard disc
and it will take NAV VERY LONG to scan all the files. If it doesnt work and
I therefore have to do a new, clean XP-setup,
I will lose quite some time my customer would have to pay for.
if I start with the clean XP-setup instead, it will cost less.

thanx for your comments!

best regards,
Hans Pesata
 >> Stay informed about: worm-detection/removal ??? 
Back to top
Login to vote
Gabriele Neukam

External


Since: Sep 14, 2004
Posts: 462



(Msg. 6) Posted: Fri Jan 16, 2004 7:01 pm
Post subject: Re: worm-detection/removal ??? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On that special day, Hans Pesata, (dummy.user@dummy.com) said...

> but I didnt get a clear answer, do you known if I can use NAV2003/2004 to
> detect worms ?
> I understand that using a dedicated worm-.removal-tool afterwards is the way
> to go.

NAV and current signatures, yes. The problem is, modern worms place
themselves in the _restore or other corners where they can't be easily
reached. In fact, they abuse the system self repair and protection
features by disguising themselves as "system files".

The specific tools are there to cancel this system protection and render
the respective methods of the worms useless. But this strategy might
change from worm family to worm family, and require different approaches
according to the specific infection. This is the reason why there are
separate tools there for removing worms.

But first you have to know *which* worm is in the system, in order to
know which removal tool will be effective.

I hope that now you understand it.


Gabriele Neukam

Gabriele.Spamfighter.Neukam.TakeThisOut@t-online.de


--
Ah, Information. A good, too valuable these days, to give it away, just
so, at no cost.
 >> Stay informed about: worm-detection/removal ??? 
Back to top
Login to vote
kurt wismer

External


Since: Jul 04, 2003
Posts: 1562



(Msg. 7) Posted: Sat Jan 17, 2004 12:54 am
Post subject: Re: worm-detection/removal ??? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hans Pesata wrote:
> Hi!

>>use an anti-virus product to figure out what it was, then use a
>>dedicated removal tool if one exists or the anti-virus product itself
>>if no dedicated removal tool exists... dedicated removal tools are
>>preferable over the av itself as the av will often times simply
>>neutralize the worm/virus/whatever...
>
>
> that was exactly what I have been asking when I posted my question in this
> newsgroup,
> but I didnt get a clear answer, do you known if I can use NAV2003/2004 to
> detect worms ?

yes... for all intents and purposes you can consider worms equivalent
to viruses and use the same software to detect them...

[snip]
> this is important for me to know, because I have to check a probably
> infected system with a pretty full 80GB hard disc
> and it will take NAV VERY LONG to scan all the files. If it doesnt work and
> I therefore have to do a new, clean XP-setup,
> I will lose quite some time my customer would have to pay for.
> if I start with the clean XP-setup instead, it will cost less.

cost less how? what about the value of the data that will be lost when
you do that, is that figured into your cost/benefit analysis?

--
"hungry people don't stay hungry for long
they get hope from fire and smoke as the weak grow strong
hungry people don't stay hungry for long
they get hope from fire and smoke as they reach for the dawn"
 >> Stay informed about: worm-detection/removal ??? 
Back to top
Login to vote
David W. Hodgins

External


Since: Jan 28, 2004
Posts: 133



(Msg. 8) Posted: Sun Jan 18, 2004 3:25 am
Post subject: Re: worm-detection/removal ??? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On Fri, 16 Jan 2004 14:36:43 GMT, Hans Pesata <dummy.user.TakeThisOut@dummy.com> wrote:

> that was exactly what I have been asking when I posted my question in this
> newsgroup,
> but I didnt get a clear answer, do you known if I can use NAV2003/2004 to
> detect worms ?

AV software will detect worms, that it knows about. So, if you're looking
to clean a system of worms that have been around for a while, it'll work,
or at least, should find them. Make sure you're booting from a known
clean boot disk or cd, just in case the malware is stealth, or can prevent
the av from running.

Don't rely on it to block new worms. Keep the software updated, and try
to teach the user's about safe hex.

> I understand that using a dedicated worm-.removal-tool afterwards is the way
> to go.

Unless you enjoy doing things manually, I'd say it's the only way to go.

> this is important for me to know, because I have to check a probably
> infected system with a pretty full 80GB hard disc
> and it will take NAV VERY LONG to scan all the files. If it doesnt work and
> I therefore have to do a new, clean XP-setup,

Make sure you limit the scanning to executables, and try to get the user to
clean up stuff they don't need, before you visit.

> I will lose quite some time my customer would have to pay for.
> if I start with the clean XP-setup instead, it will cost less.

Why not let the customer decide? Give them an estimate of the cost
of a clean install, versus cleanup.

Regards, Dave Hodgins

--
Change nomail.afraid.org to rogers.com to reply by email.
(nomail.afraid.org has been set up specfically for
use in usenet. Feel free to use it yourself.)
 >> Stay informed about: worm-detection/removal ??? 
Back to top
Login to vote
Hans Pesata

External


Since: Jun 02, 2004
Posts: 10



(Msg. 9) Posted: Sun Jan 18, 2004 11:04 am
Post subject: Re: worm-detection/removal ??? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi!

Thanx a lot for all the useful information and hints!
This is very valueable for me and helps me to learn how to deal with this
nasty topic.

Best Regards,
Hans Pesata
 >> Stay informed about: worm-detection/removal ??? 
Back to top
Login to vote
Hans Pesata

External


Since: Jun 02, 2004
Posts: 10



(Msg. 10) Posted: Sun Jan 18, 2004 11:05 am
Post subject: Re: worm-detection/removal ??? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi!

> cost less how? what about the value of the data that will be lost when
> you do that, is that figured into your cost/benefit analysis?

of course I would backup the users important files/documents BEFORE I do a
new system-setup.

Best Regards,
Hans
 >> Stay informed about: worm-detection/removal ??? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Win XP worm.agobot.14ap removal - Worm.agobot.14ap is reported by AVG but not removed. There seems to be very little information specific to this variant accessible through google. It seems to have infected windows\system32\nysyskrnl.exe and AVG repeatedly warns about this during us...

symnantec worm removal tool - has anyone been able to run the worm removal tool succesfully ? I am having a problem with the tool stopping the scan on the icwdial.ch file in the i386 folder and the Windows Error Reporting Tool popping up and telling me there is an error in..

Heuristics detection? - Does anyone know which AV scanners managed to detect Netsky (or other similar viruses) without the relevant sig update i.e. on the basis of heuristic detection? Gareth.

Intrusion Detection for NAV - I have NAV 2004 with my WinXP SP2. There's an Urgent Attention warning sign at the system status on the Norton Internet Security box. I tried to click on the 'Turn On' switch box but it keeps telling me that it: "Failed to save setting. Plea...

consistency in virus detection - I had a problem with the Blaster worm on my XP partition and got it removed by the procedure dexcribed by Computer Associates and immunized the system with the MS patch. Then I just made check if the ME partition had also any infection with Norton, after...
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]