Network World
Saturday, November 22, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Security

Navigation

Just format it, and learn from the loss...

Just format it, and learn from the loss. Once spyware/virii get that deep, you can't get it out. Soon you too can be part of a botnet!

Click to read the article this is in response to.

check running services also........

0

run msconfig and check the currently active services. Any suspicious item seen go to that source and remove it.also keep ur Temp Files clean.

Sometimes that's just quicker

0

Not to mention at least then you're SURE there is nothing left from an infestation. From a corporate standpoint, once the system is compromised, it's hard to trust, due to the commonality of rootkits, and VERY sneaky installation/survival mechanisms.

A system usually CAN be cleaned completely, but it WILL take some time, especially if it's heavily infested. It's often easier (and you can be more confident it's clean) if you just pull off your files (and scan them THOROUGHLY), and reload the OS. Not to mention, oftimes the infestation has damaged the OS as part of it's survival tricks, and the repair is harder/longer than a simple re-install.

I have seen it many times, a system appears to be clean, only to have it revert within days to a zombie.

An Even Better Idea...

0

For corporate environments, create a Norton Ghost (or open-source alternative) image of a clean system. Update it periodically with patches and new apps. Once a system is compromised, dump the known-good image onto the PC. This technique lets me get a system up and running within about 30 minutes. Quick, simple and minimum down-time for the user.

I disagree with the necessity of flatten & rebuild until efforts

0

I disagree with the necessity of flatten & rebuild until efforts to clean have been tried.

There are plenty of tools to help out there, like IceSword & RootKitRevealer.

One thing which I strongly recommend is to run HijackThis on the system when it is clean and save its log. Makes it much easier to compare against a suspected infected system.

Return to known good but analyze

0

If you suspect that your system has been compromised, regardless of the INITIAL or APPARENT vector, you should be starting from a known good state. You need to trust your system, and if someone else has had control of it for any given period of time, there is no telling what else besides the vectors that you detect may be present. Read up on rootkits, stealth malware and the like. If you have the time, inclination, and resources, do a Ghost image of the INFECTED system. Then wipe it out and use a clean Ghost image to restore it to a good state. When you have time, restore the bad image to a sacrificial PC or VM session and follow the other advice above regarding sniffers and such. It is always good to know what the malware was, (could be keylogger, password capture, spam generator, who knows!) and take action to change anything that may have been compromised.
MadMark

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: