AumHa Forums

Supporting Users of Windows Desktop Systems
It is currently Thu 7/29/10 04:30 pm

All times are UTC - 8 hours [ DST ]




Post new topic Reply to topic  [ 2 posts ] 
Author Message
 Post subject: Malware Removal: When to Flatten and Reinstall
PostPosted: Thu 8/9/07 04:18 pm 
Offline
AH-VSOP & MS-MVP
AH-VSOP & MS-MVP
User avatar

Joined: Mon 9/18/06 12:32 pm
Posts: 16048
Location: Chevy Chase, MD
I read this recently by our Forum pal, CalamityJane, MS-MVP, and it so fully reflects my own thinking and the issues involved that I am rendering an edited verion here. Used with permission.

Malware Removal: When to Flatten and Reinstall Windows

So, you didn’t protect the system and it got hacked. What to do? Well, let’s see:
  • You can’t clean a compromised system by patching it. Patching only removes the vulnerability. Upon getting into your system, the attacker probably ensured that there were several other ways to get back in.
  • You can’t clean a compromised system by removing the back doors. You can never guarantee that you found all the back doors the attacker put in. The fact that you can’t find any more may only mean you don’t know where to look, or that the system is so compromised that what you are seeing is not actually what is there.
  • You can’t clean a compromised system by using some “vulnerability remover.” Let’s say you had a system hit by Blaster. A number of vendors (including Microsoft) published vulnerability removers for Blaster. Can you trust a system that had Blaster after the tool is run? I wouldn’t. If the system was vulnerable to Blaster, it was also vulnerable to a number of other attacks. Can you guarantee that none of those have been run against it? I didn’t think so.
  • You can’t clean a compromised system by using a virus scanner. To tell you the truth, a fully compromised system can’t be trusted. Even virus scanners must at some level rely on the system to not lie to them. If they ask whether a particular file is present, the attacker may simply have a tool in place that lies about it. Note that if you can guarantee that the only thing that compromised the system was a particular virus or worm and you know that this virus has no back doors associated with it, and the vulnerability used by the virus was not available remotely, then a virus scanner can be used to clean the system. For example, the vast majority of e-mail worms rely on a user opening an attachment. In this particular case, it is possible that the only infection on the system is the one that came from the attachment containing the worm. However, if the vulnerability used by the worm was available remotely without user action, then you can’t guarantee that the worm was the only thing that used that vulnerability. It is entirely possible that something else used the same vulnerability. In this case, you can’t just patch the system.
  • You can’t clean a compromised system by reinstalling the operating system over the existing installation. Again, the attacker may very well have tools in place that tell the installer lies. If that happens, the installer may not actually remove the compromised files. In addition, the attacker may also have put back doors in non-operating system components.
  • You can’t trust any data copied from a compromised system. Once an attacker gets into a system, all the data on it may be modified. In the best-case scenario, copying data off a compromised system and putting it on a clean system will give you potentially untrustworthy data. In the worst-case scenario, you may actually have copied a back door hidden in the data.
  • You can’t trust the event logs on a compromised system. Upon gaining full access to a system, it is simple for an attacker to modify the event logs on that system to cover any tracks. If you rely on the event logs to tell you what has been done to your system, you may just be reading what the attacker wants you to read.
  • You may not be able to trust your latest backup. How can you tell when the original attack took place? The event logs cannot be trusted to tell you. Without that knowledge, your latest backup is useless. It may be a backup that includes all the back doors currently on the system.
  • The only way to clean a compromised system is to flatten and rebuild. That’s right. If you have a system that has been completely compromised, the only thing you can do is to flatten the system (reformat the system disk) and rebuild it from scratch (reinstall Windows and your applications).
--------------------------------------------------------------------------------
The above quote taken from this page:
Jesper M. Johansson, Ph.D., CISSP, MCSE, MCP+I
Formerly, Security Program Manager, Microsoft Corporation, Published: May 7, 2004
http://www.microsoft.com/technet/commun ... m0704.mspx

Continuing to use this PC on the internet as a trusted machine is a risk for future use. It might be time for a new computer and retire this one.
Please read:
Invasion of the Computer Snatchers
http://www.washingtonpost.com/wp-dyn/co ... 01342.html

That is the reality of what we are dealing with here. This PC has been so seriously compromised that I do not want to mislead you into thinking that this malware "cleaning" will reverse the potential of the damage already done. The fact that it was hosting Multiple rootkits and backdoor trojans makes the breach pretty much a worst case scenerio. I have a really bad feeling that by helping you remove the infected files, that I'm giving you a false sense of security about how serious this breach of this computer has been and the security implications with running this as a trusted machine in the future.

Help: I Got Hacked. Now What Do I Do? Part II
Security Management - July 2004
http://www.microsoft.com/technet/commun ... m0704.mspx
Quote:
... with a rootkit on the system that makes the system no longer trustworthy. Windows Explorer and the command line will no longer show you the files that are actually on the system. The registry editor is now lying. Account manager tools will not show you all the users. At this stage of an intrusion, you can no longer trust the system to tell you about itself. That’s where you get into a flatten and rebuild (some people call it "nuke and pave") scenario. The system is now completely compromised.


Article Source: http://www.dslreports.com/forum/r18606240-

---------------------
CalamityJane, MS-MVP
It takes a disaster to make a woman out of a female
Microsoft MVP/Windows Security 2003-2007
Proud Member of ASAP (Alliance of Security Analysis Professionals)

__________________________________________________

Review: "How to partition and format a hard disk in Windows XP": http://support.microsoft.com/kb/313348

Create a "Slipstream" of XP Service Pack 3. This will save you two days of online time at Microsoft Updates.
http://www.winsupersite.com/showcase/xp ... stream.asp

Now Flatten and Reinstall -- Links offering step-by-step instructions
"Clean Install Windows XP": http://www.michaelstevenstech.com/cleanxpinstall.html
"Reformat & Clean Install Windows": http://rcc.bgsu.edu/info/Windows_Installation
"XP Clean Install Interactive Setup": http://www.winsupersite.com/showcase/wi ... _clean.asp

_________________
Users Helping Users
MS-MVP 2003 -- 2010 / ASAP Member / BBR MVM, VIP


Last edited by Bill Castner on Wed 8/15/07 10:24 pm, edited 2 times in total.

Top
 Profile  
 
 Post subject:
PostPosted: Sat 1/19/08 12:54 pm 
Offline
Site Admin
Site Admin
User avatar

Joined: Tue 3/11/03 09:02 pm
Posts: 21065
Location: NW ChesCo, Pennsylvania, USA
When should I re-format? How should I reinstall?
http://www.dslreports.com/faq/10063

_________________
~Robear Dyer (PA Bear)
AumHa VSOP, Admin & Moderator
MS MVP-Internet Explorer, Mail, Consumer Security, Windows Desktop Experience - since 2002
Steely-eyed Missile Man, Sensei, & Mule Skinner
Errabundi Saepe, Semper Certi
:L) Your donations help keep this site going & are very much appreciated: http://aumha.org/donate.htm


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

All times are UTC - 8 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group