Re: Win32/RAMNIT.A Anyone?
David_B <[email protected]> Mon, 21 Dec 2020 17:37:45 +0000
| Newsgroups | alt.comp.virus,alt.comp.anti-virus,microsoft.public.security.virus,ba.internet |
|---|---|
| Organization | blocknews - www.blocknews.net |
| Message-ID | <[email protected]> |
On 02/08/2010 01:38, FromTheRafters wrote: > "~BD~" <[email protected]> wrote in message > news:[email protected]... >> ~BD~ forgot to add the link showing support for his view! >> >> http://technet.microsoft.com/en-us/library/cc512587.aspx > > He added a qualifier here: > > "If you have a system that has been completely compromised, the only thing > you can do is to flatten the system (reformat the system disk) and rebuild > it from scratch (reinstall Windows and your applications)." > > I can agree with that. The thing is, what do you consider to be a compromise > and what do you consider to be a complete compromise? > > If I discover a downloader downloaded some adware, I might just remove the > adware. If it downloaded some various and sundry other malware then the > "unknown" factor becomes prevalent - and flatten and rebuild becomes the > best route. A known trojan application for fake-AV scareware probably > doesn't require such drastic measures. If I figure the ingress vector was a, > since patched, vulnerability exploit worm, I wouldn't just automatically > assume that hackers have also used that exploits zero-day window to increase > the "unknown" factor - I would just address the worm. > > Not that he's wrong, a healthy paranoia is a good security asset. The value > of the protected resource figures in heavily as well. I notice I didn't reply to this post! My apologies, FTR. Is there anywhere on the physical hard drive, OTHER than on the spinning platter, where malware could hide? So that if the hard drive platter is 'wiped clean', and a completely new operating system is installed on the drive, it could be re-infected without the user of the computer noticing? The police advised me not to use the same hardware at all after my computer had been compromised. I never have discovered why - but I bought a new Apple iMac 'just in case'!