Announcement

Collapse
No announcement yet.

This guy should NOT be a tech….

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Pedersen
    replied
    Here's the layers you have to deal with on a computer, normally:

    Operating System runs Applications

    Here's the (effective) layers of a compromised system:

    Root kit runs Operating System runs Applications

    Any of the scanners you've mentioned will be an application running on top of the operating system. This makes them susceptible to any faults in the underlying operating system.

    If the rootkit says "No such file abc.exe", then the operating system will tell the application "No such file abc.exe", and the application will be unable to tell if "abc.exe" actually exists or not.

    If the rootkit says "No task running named foo.exe", then operating system tells the application "No task running named foo.exe", and the application will be unable to tell if "foo.exe" actually is running or not.

    When the application says "How much memory do I have available right now?" to the operating system, the root kit has the option of stepping in and saying "No free memory available" or "Plenty of free memory available", and only telling it to that specific application.

    When the application says "delete bar.exe" to the operating system, the root kit can tell the operating system that "bar.exe" has been removed, without actually doing anything to the file. And can even report (on subsequent runs) that the file has been deleted, even though it still exists!

    That's the point of what root kits do: They take over and subvert a chunk of your operating system. Once they've done this, there is no reliable way to use that operating system to detect them. You must use a separate operating system to check for and remove them (generally speaking, boot from a live cd or install the hard drive in another machine).

    If that is not an option for some reason, then the only option remaining to be absolutely sure of the removal of that root kit is a reformat/reinstall. It sucks, but that's the reality of malware, and the damage it actually does.

    Leave a comment:


  • sld72382
    replied
    Most of the best scanners and specialized removal tools (Smitfraudfix and SDFix come to mind) remove rootkits when they clean. My point was at least try before just going straight to a format...

    Leave a comment:


  • Pedersen
    replied
    Quoth sld72382 View Post
    First off, strike one against any tech who would rather format than spend 5 minutes of research to find a removal tool that takes 1 minute to run.
    Extremely few removal tools run their own OS. Instead, they rely on the computer having an installed and functioning OS. As a result, even though they will work well enough most of the time, they are not to be trusted themselves.

    Why? Consider this:
    If the OS has been compromised, and a root kit installed (which is the direction much malware is going these days), then the root kit is in ultimate control of the operating system. The root kit can lie to any operating system call, including those which list directories, files, running processes, even the ones that verify passwords. Not only can it be done, it has been done.

    Under such circumstances, the only safe option to ensure the removal of the malware is a reformat/reinstall.

    Strike one against any tech who isn't aware of the very real danger that poses.

    Leave a comment:


  • sld72382
    started a topic This guy should NOT be a tech….

    This guy should NOT be a tech….

    Okay this is not a tech from our call center, but this is one reason why a lot of consumers don’t trust independent repair centers and would rather bring their PC into a retail-based shop.

    Woman calls in who was told to call back after the last tech ran a couple of threat scanners, which only found cookies. I log into her system while reading the notes, and see this is clearly NOT a malware issue. To be fair to the first tech he did run CounterSpy and it picked up a Trojan but that was it, but it should have stopped there. The trojan came from the woman installing and using Limewire, which I quickly removed.

    Anyway the issue was that her many of her devices (sound, wireless NIC etc….) didn’t work and she was having trouble with a photo/video slideshow program. The client mentioned she bought the laptop to an independent repair shop where she bought in her laptop with all the CDs to fix a virus issue. The shop wiped the system clean using her restore CD. First off, strike one against any tech who would rather format than spend 5 minutes of research to find a removal tool that takes 1 minute to run.

    After looking around in the laptop, I see the issue. Other than the Ethernet adapter, NONE of the drivers were installed! That’s why nothing was working. I mean really, if you’re going to format at least install the flippin’ drivers afterwards! The sad fact is the woman gave the guy both the O/S and the driver CD, and he didn’t even touch the driver CD. Strike two against him.

    Strike three was she said she called the guy and the guy told her to do a system restore, which ended up making things worse. The guy said he’ll call her back after the restore but never did (I wonder why?).

    I undo the restore and install all the drivers, make sure there are no viruses and test her photo/video program which works fine. The woman says she’ll use us from now on, and I was tempted to tell her to go back to that shop and complain.

    This idiot gives the real competent independent techs a bad name.
Working...
X