 | Microsoft Says Recovery from Malware Becoming Impossible... |  |
Posted: 04/07/2006 2:04 AM |
|
|
|
|
|
| Site Admin |
| Posts |
30757 |
| Word Cnt. |
2,628,690 |
| BDay |
Jul 28 |
| Sign |
Leo |
| Sex |
 |
|
|
|
Joined: Sep 25, 2004
Local time: 10:36 PM
Location: St Pete, FL
|

|
|
|
|
 |
Microsoft Says Recovery from Malware Becoming Impossible
LAKE BUENA VISTA, Fla.—In a rare discussion about the severity of the Windows malware scourge, a Microsoft security official said businesses should consider investing in an automated process to wipe hard drives and reinstall operating systems as a practical way to recover from malware infestation.
"When you are dealing with rootkits and some advanced spyware programs, the only solution is to rebuild from scratch. In some cases, there really is no way to recover without nuking the systems from orbit," Mike Danseglio, program manager in the Security Solutions group at Microsoft, said in a presentation at the InfoSec World conference here.
Offensive rootkits, which are used hide malware programs and maintain an undetectable presence on an infected machine, have become the weapon of choice for virus and spyware writers and, because they often use kernel hooks to avoid detection, Danseglio said IT administrators may never know if all traces of a rootkit have been successfully removed.
He cited a recent instance where an unnamed branch of the U.S. government struggled with malware infestations on more than 2,000 client machines. "In that case, it was so severe that trying to recover was meaningless. They did not have an automated process to wipe and rebuild the systems, so it became a burden. They had to design a process real fast," Danseglio added.
Danseglio, who delivered two separate presentations at the conference—one on threats and countermeasures to defend against malware infestations in Windows, and the other on the frightening world on Windows rootkits—said anti-virus software is getting better at detecting and removing the latest threats, but for some sophisticated forms of malware, he conceded that the cleanup process is "just way too hard."
Microsoft says stealth rootkits are bombarding Windows XP SP2 machines..
"We've seen the self-healing malware that actually detects that you're trying to get rid of it. You remove it, and the next time you look in that directory, it's sitting there. It can simply reinstall itself," he said.
"Detection is difficult, and remediation is often impossible," Danseglio declared. "If it doesn't crash your system or cause your system to freeze, how do you know it's there? The answer is you just don't know. Lots of times, you never see the infection occur in real time, and you don't see the malware lingering or running in the background."
More... |
|
|
 |
 |
| Back to Top |
|
|
 | Re: Microsoft Says Recovery from Malware Becoming Impossible... |  |
Posted: 04/07/2006 9:50 PM |
|
|
|
|
|
| Citation |
| Posts |
940 |
| Word Cnt. |
48,215 |
| BDay |
Mar 4 |
| Sign |
Pisces |
| Sex |
 |
|
|
|
Joined: Mar 20, 2006
Local time: 9:36 PM
|

|
|
|
|
 |
| Hummmm I know if malware gets thru on my system I don't fight it just wipe and go. I thought I jsut wasn't smart enough to get the stuff out in less than 3 months. |
|
|
 |
 |
| Back to Top |
|
|
 | Re: Microsoft Says Recovery from Malware Becoming Impossible... |  |
Posted: 04/07/2006 11:55 PM |
|
|
|
|
|
| Citation |
| Posts |
3489 |
| Word Cnt. |
137,488 |
| BDay |
Mar 5 |
| Sign |
Pisces |
| Sex |
 |
|
|
|
Joined: Oct 14, 2004
Local time: 9:36 PM
Location: Texas
|

|
|
|
|
 |
| Quote:
|
|
In a rare discussion about the severity of the Windows malware scourge, a Microsoft security official said businesses should consider investing in an automated process to wipe hard drives and reinstall operating systems as a practical way to recover from malware infestation.
|
And how many times can you re-activate Win XP before it won't install? Then you have to call Microsoft. What is MS doing about that detail? |
|
|
 |
 |
| Back to Top |
|
|
 | Microsoft Says Recovery from Malware Becoming Impossible... |  |
Posted: 04/09/2006 4:47 PM |
|
|
|
|
|
| Site Admin |
| Posts |
49593 |
| Word Cnt. |
2,756,445 |
| BDay |
Apr 22 |
| Sign |
Taurus |
| Sex |
 |
|
|
|
Joined: Sep 25, 2004
Local time: 8:36 PM
Location: Texas
|

|
|
|
|
 |
| Quote:
|
|
And how many times can you re-activate Win XP
|
I have often wonder about how that works. Or doesn't work.
I thought Nightrider might have been over reacting to XP when he told me to stick with W2K but I have thanked my lucky stars many times for listening to him. I know XP has some nice features but I'm very happy with W2K and have no plans to upgrade to any other OS. Will have to see what the new one will be like but so far it's not off to a good start!
 |
|
|
 |
 |
| Back to Top |
|
|
 | Microsoft Says Recovery from Malware Becoming Impossible... |  |
Posted: 04/12/2006 8:47 AM |
|
|
|
|
|
| Citation |
| Posts |
4814 |
| Word Cnt. |
427,902 |
| BDay |
Oct 23 |
| Sign |
Scorpio |
| Sex |
 |
|
|
|
Joined: Feb 09, 2005
Local time: 10:36 AM
Location: Sterling IL
|

|
|
|
|
 |
rb, what is WK2?
Thats why I like to nuc my pc everyone once in awhile, I had a feeling this was going on. Hp puts one in and this white icon shows itself every 2 minutes to take snapshots of my pc, and I don't like it.
Backup, backup, backup! I do this twice a month. |
|
|
 |
 |
| Back to Top |
|
|
 | Microsoft Says Recovery from Malware Becoming Impossible... |  |
Posted: 04/12/2006 2:33 PM |
|
|
|
|
|
| Site Admin |
| Posts |
49593 |
| Word Cnt. |
2,756,445 |
| BDay |
Apr 22 |
| Sign |
Taurus |
| Sex |
 |
|
|
|
Joined: Sep 25, 2004
Local time: 8:36 PM
Location: Texas
|

|
|
|
|
 |
Fishead, W2K is Windows 2000. I can load it and reload it all I want and don't have to answer to anyone. LOL
| Quote:
|
|
this white icon shows itself every 2 minutes to take snapshots of my pc
|
That does not sound good, fishead!! Man I would worry about that. Do you know what it is and what it's doing with the snap shots?
Backing up is good but you need to be careful what you back up. You might be just backing up your problems. I try to get the PC in as good a shape and cleaned up as I can before I create an image of it. If you back up serious problems you are just going to restore them later.
 |
|
|
 |
 |
| Back to Top |
|
|
 | Information |  |
Welcome to RCF - WHF Forum Index
-> Talk PC
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
All times are GMT - 5 Hours
Page 1 of 1
Add To Bookmarks
|
|
|
|
|