PC Review Forums Newsgroups Hardware Anti-Virus worm-detection/removal ???

Reply

worm-detection/removal ???

 
Thread Tools Rate Thread
Old 13-01-2004, 08:14 AM   #1
Hans Pesata
Guest
 
Posts: n/a
Default worm-detection/removal ???


Hi!

I would like to know how I can get rid of any worm that has infected a
WINDOWS XP-system.
I know about the worm removal tools, but there is just 1 tool for every worm
and you have to run ALL of them to find which worm has infected your system.
this takes A LOT of time with a nearly full 80GB hard-disc ...

My only solution so far was to to do a clean new install of WINDOWS-XP
with the appropriate MS-RPC-patch, but this is pretty time-consuming too...

What about NAV 2003/2004, can I use it for the worm-detection/cleaning ?

Any help with this would be greatly appreciated,
thanx in advance!

best regards,
Hans Pesata

------------------------------------------------------

My eMail-address has been changed due to spam.
eMail-replies can be sent to hpesata@chello.at






  Reply With Quote
Old 13-01-2004, 04:19 PM   #2
Duh!
Guest
 
Posts: n/a
Default Re: worm-detection/removal ???

Have a look here ! http://www.bitdefender.com/html/free_tools.php

Stephen

"Hans Pesata" <dummy.user@dummy.com> wrote in message
news:ONNMb.103077$Tz1.86871@news.chello.at...
> Hi!
>
> I would like to know how I can get rid of any worm that has infected a
> WINDOWS XP-system.
> I know about the worm removal tools, but there is just 1 tool for every

worm
> and you have to run ALL of them to find which worm has infected your

system.
> this takes A LOT of time with a nearly full 80GB hard-disc ...
>
> My only solution so far was to to do a clean new install of WINDOWS-XP
> with the appropriate MS-RPC-patch, but this is pretty time-consuming

too...
>
> What about NAV 2003/2004, can I use it for the worm-detection/cleaning ?
>
> Any help with this would be greatly appreciated,
> thanx in advance!
>
> best regards,
> Hans Pesata
>
> ------------------------------------------------------
>
> My eMail-address has been changed due to spam.
> eMail-replies can be sent to hpesata@chello.at
>
>
>
>
>
>



  Reply With Quote
Old 13-01-2004, 04:25 PM   #3
null@zilch.com
Guest
 
Posts: n/a
Default Re: worm-detection/removal ???

On Tue, 13 Jan 2004 08:14:38 GMT, "Hans Pesata" <dummy.user@dummy.com>
wrote:

>Hi!
>
>I would like to know how I can get rid of any worm that has infected a
>WINDOWS XP-system.
>I know about the worm removal tools, but there is just 1 tool for every worm
>and you have to run ALL of them to find which worm has infected your system.
>this takes A LOT of time with a nearly full 80GB hard-disc ...
>
>My only solution so far was to to do a clean new install of WINDOWS-XP
>with the appropriate MS-RPC-patch, but this is pretty time-consuming too...


Aside from general worm removal aides, you might take a look at
Trend's Sysclean which handles a large number (hundreds) of current
malwares. See my web site for a download.

More generally, there are utilities (see a couple of links at my web
site) which show practically the entire startup axis ... the registry
run keys, running processses, ini files, etc. But the use of them
requires knowledge of what a normal system looks like in this regard.
In the case of HijackThis there is a web site forum available with
fairly expert help from what I hear.

It's best to do this work in Safe Mode, BTW.


Art
http://www.epix.net/~artnpeg
  Reply With Quote
Old 13-01-2004, 07:23 PM   #4
Bart Bailey
Guest
 
Posts: n/a
Default Re: worm-detection/removal ???

In Message-ID:<ge6800psnpn39ao285bt9cjljfgtja5bgh@4ax.com> posted on
Tue, 13 Jan 2004 16:25:41 GMT, null@zilch.com wrote:

>It's best to do this work in Safe Mode, BTW.


(facetious mode)

Is web surfing in "Safe Mode" the same as "Safe Hex"? ;-)

(/facetious mode)


--

Bart
  Reply With Quote
Old 14-01-2004, 12:56 AM   #5
Boyd Williston
Guest
 
Posts: n/a
Default Re: worm-detection/removal ???

"Hans Pesata" <dummy.user@dummy.com> wrote in
news:ONNMb.103077$Tz1.86871@news.chello.at:

> Hi!
>
> I would like to know how I can get rid of any worm that has infected a
> WINDOWS XP-system.
> I know about the worm removal tools, but there is just 1 tool for every
> worm and you have to run ALL of them to find which worm has infected
> your system. this takes A LOT of time with a nearly full 80GB hard-disc
> ...
>
> My only solution so far was to to do a clean new install of WINDOWS-XP
> with the appropriate MS-RPC-patch, but this is pretty time-consuming
> too...
>
> What about NAV 2003/2004, can I use it for the worm-detection/cleaning
> ?
>
> Any help with this would be greatly appreciated,
> thanx in advance!
>
> best regards,
> Hans Pesata
>
> ------------------------------------------------------
>
> My eMail-address has been changed due to spam.
> eMail-replies can be sent to hpesata@chello.at
>
>
>
>
>
>


Well, it seems that you are trying to do things backward.

First, develop habits that make infections less likely.

Second, install software that blocks malware from getting installed in the
first place. NAV will work, but you probably can find something else that
is less expensive and has less overhead.

Third, regularly scan with good detection software (with recent definition
updates).

THEN check into removal tools for anything that's found, or if you have
symptoms of something specific. I certainly wouldn't use a removal tool
for (as an example) Swen unless I were pretty sure that I had been
infected with it.
  Reply With Quote
Old 14-01-2004, 01:59 PM   #6
Hans Pesata
Guest
 
Posts: n/a
Default Re: worm-detection/removal ???

Hi!

> Well, it seems that you are trying to do things backward.
> First, develop habits that make infections less likely.


my job is to help people with their computer-problems and a lot of
problems are related to viruses/worms. I try to teach people how to protect
their PCs, but first I have to fix them.

> Second, install software that blocks malware from getting installed in the
> first place. NAV will work, but you probably can find something else that
> is less expensive and has less overhead.


I have seen a lot of PCs with NAV runing and worms disturbing everything in
the system.
it seems that the only way to fight this is the MS-RPC-patch and a firewall.

> Third, regularly scan with good detection software (with recent definition

updates).
> THEN check into removal tools for anything that's found, or if you have
> symptoms of something specific. I certainly wouldn't use a removal tool
> for (as an example) Swen unless I were pretty sure that I had been
> infected with it.


I need a way to repair infected systems with minimal time-effort.
I cant know which worm has infected a system, to use a specific tool to fix
it.
I just see that something is pretty wrong. therefore I need good tools to
help me with this.

best regards,
Hans



  Reply With Quote
Old 14-01-2004, 02:04 PM   #7
Hans Pesata
Guest
 
Posts: n/a
Default Re: worm-detection/removal ???

Hi!

> Have a look here ! http://www.bitdefender.com/html/free_tools.php


thanx for the hint, but these are single tools similar to the ones Symantec
provides.
I need one that is able to kill them all.

best regards,
Hans



  Reply With Quote
Old 14-01-2004, 03:43 PM   #8
Shane
Guest
 
Posts: n/a
Default Re: worm-detection/removal ???


"Hans Pesata" <dummy.user@dummy.com> wrote in message
news:L%bNb.122956$Tz1.39502@news.chello.at...
> Hi!
>
> > Have a look here ! http://www.bitdefender.com/html/free_tools.php

>
> thanx for the hint, but these are single tools similar to the ones

Symantec
> provides.
> I need one that is able to kill them all.
>
> best regards,
> Hans


Trend Micro's Sysclean: http://www.epix.net/%7Eartnpeg/SYS-UP.ZIP (via Art's
updater) and McAfee's Avert Stinger: http://vil.nai.com/vil/stinger/ sound
more like what you're after.

Shane


  Reply With Quote
Old 14-01-2004, 05:36 PM   #9
kurt wismer
Guest
 
Posts: n/a
Default Re: worm-detection/removal ???

Hans Pesata wrote:
> Hi!
>
>
>>Have a look here ! http://www.bitdefender.com/html/free_tools.php

>
>
> thanx for the hint, but these are single tools similar to the ones Symantec
> provides.
> I need one that is able to kill them all.


well then, for your purposes i suggest you think the following way...

worms = viruses

and use an anti-virus product...

--
"hungry people don't stay hungry for long
they get hope from fire and smoke as the weak grow strong
hungry people don't stay hungry for long
they get hope from fire and smoke as they reach for the dawn"

  Reply With Quote
Old 14-01-2004, 05:52 PM   #10
kurt wismer
Guest
 
Posts: n/a
Default Re: worm-detection/removal ???

Hans Pesata wrote:
[snip]
> I need a way to repair infected systems with minimal time-effort.
> I cant know which worm has infected a system,


*STOP*

think to yourself, you want to repair the damage done by a worm but you
can't be bothered to figure out which worm it was - thereby completely
skipping the step about finding out exactly what damage was done...

does that sound reasonable to you? if it does, then you're in the wrong
line of work...

> to use a specific tool to fix
> it.
> I just see that something is pretty wrong. therefore I need good tools to
> help me with this.


use an anti-virus product to figure out what it was, then use a
dedicated removal tool if one exists or the anti-virus product itself
if no dedicated removal tool exists... dedicated removal tools are
preferable over the av itself as the av will often times simply
neutralize the worm/virus/whatever...

--
"hungry people don't stay hungry for long
they get hope from fire and smoke as the weak grow strong
hungry people don't stay hungry for long
they get hope from fire and smoke as they reach for the dawn"

  Reply With Quote
Reply



Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off