Microsoft: recovery from Windows malware becoming impossible; better to to wipe and rebuild

“In a rare discussion on the severity of the Windows malware scourge, a Microsoft security official said businesses should consider investing in an automated process to wipe hard drives and reinstall operating systems as a practical way to recover from malware infestation. ‘When you are dealing with rootkits and some advanced spyware programs, the only solution is to rebuild from scratch. In some cases, there really is no way to recover without nuking the systems from orbit,’ Mike Danseglio, program manager in the Security Solutions group at Microsoft, said in a presentation at the InfoSec World conference here,” Ryan Naraine reports for eWeek.

“He cited a recent instance where an unnamed branch of the U.S. government struggled with malware infestations on more than 2,000 client machines. ‘In that case, it was so severe that trying to recover was meaningless. They did not have an automated process to wipe and rebuild the systems, so it became a burden. They had to design a process real fast,’ Danseglio added,” Naraine reports. “Danseglio, who delivered two separate presentations at the conference—one on threats and countermeasures to defend against malware infestations in Windows, and the other on the frightening world on Windows rootkits—said anti-virus software is getting better at detecting and removing the latest threats, but for some sophisticated forms of malware, he conceded that the cleanup process is ‘just way too hard.’ …In February alone, [Microsoft’s] free Malicious Software Removal Tool detected a social engineering worm called Win32/Alcan on more than 250,000 unique machines.”

Full article here.

MacDailyNews Take: Most of the world picked the wrong platform, that much is obvious.

Advertisements:
Apple’s brand new iPod Hi-Fi speaker system. Home stereo. Reinvented. Available now for $349 with free shipping.
Apple’s new Mac mini. Intel Core, up to 4 times faster. Starting at just $599. Free shipping.
MacBook Pro. The first Mac notebook built upon Intel Core Duo with iLife ’06, Front Row and built-in iSight. Starting at $1999. Free shipping.
iMac. Twice as amazing — Intel Core Duo, iLife ’06, Front Row media experience, Apple Remote, built-in iSight. Starting at $1299. Free shipping.
iPod Radio Remote. Listen to FM radio on your iPod and control everything with a convenient wired remote. Just $49.
iPod. 15,000 songs. 25,000 photos. 150 hours of video. The new iPod. 30GB and 60GB models start at just $299. Free shipping.
Connect iPod to your television set with the iPod AV Cable. Just $19.

32 Comments

  1. He cited a recent instance where an unnamed branch of the U.S. government struggled with malware infestations on more than 2,000 client machines.

    There goes your tax dollars folks…

  2. Well, while the world fusses over Micro$hite and all their horrendous products, I’ve just been and upgraded my Nokia 6230 firmware and can now Sync with my PowerBook thatnks to OS X 10.4.6.

    Apple Computers. Why Struggle?

  3. OMG. It’s even worse than I thought.

    So now you need to buy software to periodically wipe your hard drive just to keep your Windows machine in a “reduced malware” state (malware-free and Windows being polar opposites).

  4. Just because 90% of the world use Windhoes doesn’t mean it is good.

    This is proof that most people are lemmings and just follow and don’t ‘think different’.

    The enlightened few are persecuted and called cultist but WE know, Oh boy how we know!

    As a side line there are over 6 billion people on this planet and it is 2006 and at least 80% of those souls still believe in sharmans magic, black magic, voodoo, and other supernatural rubbish.

    Think about that folks. Pretty scarry isn’t it?

    A lot of them actually use PC’s as well. Now that is scarry!!!!!!!

    Leo

  5. Ever been to those CNET, ZDNET talkback forums where there is always the obligatory “I’ve never had viruses/malware” Windows user. They always come up with the remark “it’s not that hard, you have to know what you’re doing”. Well, the joke is on them.

    From the article:

    “Offensive rootkits, which are used hide malware programs and maintain an undetectable presence on an infected machine, have become the weapon of choice for virus and spyware writers and, because they often use kernel hooks to avoid detection, Danseglio said IT administrators may never know if all traces of a rootkit have been successfully removed.”

    Also…””We’ve seen the self-healing malware that actually detects that you’re trying to get rid of it. You remove it, and the next time you look in that directory, it’s sitting there. It can simply reinstall itself,” he said.”

    BTW, I’m a Sys Admin in a Windows shop and re-imaging is a typical occurrence. We also use Deep Freeze by Faronics. All this is extra TCO of course. Never had to do so much when I supported Macs in my previous job. So, any Winblows troll that comes here , is full of it. They always were.

  6. “He cited a recent instance where an unnamed branch of the U.S. government struggled with malware infestations on more than 2,000 client machines. ‘In that case, it was so severe that trying to recover was meaningless. They did not have an automated process to wipe and rebuild the systems, so it became a burden”

    Ahhh. Now we know the reason for FEMA’s slow response to Katrina.

  7. I am a Windows developer. This is something we all knew for YEARS. It’s about time someone from inside took the risk of standing up and speaking the truth. Windows is a clunker and Vista will be worse.

    What really pisses me off is how Apple is not capitalizing on this. Are they that worried that MS will pull the plug on the MBU that they would rather be silent? Apple passed on a chance to be the leaders years ago. Now they are making great inroads into the consumer market, and they are passing up a chance to expand on that through better marketing. Further, they could take on the business market more now than ever given MS’s security flops. I hope Apple steps up – it’s simply a better operating system. ” width=”19″ height=”19″ alt=”cool grin” style=”border:0;” />

  8. I just “rebuilt” (or reinstalled – pick your poison) my Gateway last night over some crappy malware issues… And then I spent $18 on eBay for Norton Antivirus… I wonder how long before I have to rebuild it again.

    My wife uses it for FrontPage (she says she is comfortable with it, despite the fact that she has a brand new iMac intel core-duo).

  9. M$ Mac Business Unit has the largest group of Apple Developers outside of Apple. If they shut the doors a huge group of them would be available to Apple and others. Many would probably team up for startups.

    Pages & keynote are not perfect, but represent enough of a base to develop a replacement for Office quickly. Open Office could also be used as a base, such as Apple’s use of KDE’s Webkit for the Safari Browser. Also don’t forget that Apple owns FileMaker and they could easily develop tools for a Mac Office suite as well.

    MBU is not serving Apple well. No Outlook, Access, Live Meeting, One Note, Front Page, Publisher, etc. There will be no Mac version of Expression even though it started life as a Mac application. A crippled MSN client, no Windows Media Client, no Internet Explorer. VPC is about to become a non-issue. About the only thing they do is Office and it is a bloated, resource hogging mess.

    Without Office, more Mac users would support companies making great productivity apps like Mellel, Mariner Write & Calc, NoteBook, NoteTaker, etc. With more sales they can further develop their programs.

    SUPPORT ORIGINAL MAC DEVELOPERS.
    The software they make integrates better into the OS, draws more on system features, runs better, etc. Remember, it’s the software- not the hardware.

  10. 1) They are to big their employees are all money driven there is no such thing as ‘PASSION’ for PERFECTION.

    2) They hire unqualified people, managers in charge of hiring and firing are not able managers.

    3) The company is to big, and it tries to be everything for everyone, you cant do XBOX and windowsXP at the same time if you want to be serious. Thats like mixing chicken soup with chocolate ice cream and sand, doesnt taste good.

    All these things will inevitably give an edge to a microsoft competitor.

  11. Don’t buy this FUD which is cleverly coming out of MS. This article is their first step in a multi-prong approach to get people to throw away their existing computers in favor of buying a new computer with the “new and improved (and now safe) version of Windows – Vista”. (The text in quotes should be read with sarcasm.) MS knows most people do not know how to erase a hard drive and reinstall the OS. MS is banking on people upgrading to a new computer with Vista. This article is nothing more than MS propaganda. Don’t promote it.

    Instead, we – the Mac Community – needs to help get the word out that MS will NEVER produce a computer as safe and secure as a Mac. As we all know, in order for people to have a safe and productive computing experience, all they need to do is buy a Mac. We need to help spread the word.

    Peace.

  12. “M$ Mac Business Unit has the largest group of Apple Developers outside of Apple”

    you what? if that’s actually true, what the feck they playing at? release a decent version of msn messenger I DARE YOU!

    the thing is this is precisely what we do at my work, on a massive scale

    and what’s it say about an operating system that the hackers know better than microsoft? i mean honestly so many holes and nooks and cranies for this shit to get into, of course your not going to be able to get rid of it oh and then charges you extra to try and protect you, what makes you think it’s gonna get better by throwing more money at

    magic word = common as in what sense m$ lacks

  13. I am done trying to convince people… let them wallow in thier sorrows for as long as it takes. It has been proven with all the switchers that finally woke up to REALITY and bought a mac. Let the others take as long as it takes… let them get thier identities get taken. If someone else makes a better computing experience other that APPLE I would gladly switch. When and if it EVER happens. Until then I will stick with my mac and the trolls can lick my ass as they bow down to the mercy of Microshite.

    MDN word= having, as in having the right tools for my taste: APPLE

  14. 1. Weird, I just tried looking for the XP install for thisnew HP at work, so I could wipe the disk and re-install, but all I could find was a piece of paper in the shape of a CD that stated something like “OS CD is not required. If you need to re-install your system, please use System Restore”.

    So, I dug up an XP CD, and it turns out you can’t format a drive using the CD.

    So, now we’re looking at building a win98 boot floppy, and using FDISK, then installing the OS from an XP CD that did not come with the HP, then trying to load the drivers that should have at least been on an OEM Restore set. WTF?!

    So, really, Microsoft is saying that the best way to fix your PC is to actually go ahead and remove Windows altogether.

    As Ballmer might vomit: “I…..LOVE……THIS……COMPANY!!!”

    :/

  15. $20 says that guy will be unemployed real soon

    Heh, the same says he gets promoted!

    Look at it from a marketing executive’s point of view. Why, you could make TONS of money charging for such a service! If people need to invest in automated reinstallers, why not invest in MS products that do it?

    (Heh, if that ain’t a roller: You pay MS to mask around the problems in the garbage they sold you to begin with. Brilliant. If that really flies, MS has every reason to make Vista the worst Windows yet).

  16. I’ve been pretty good with my Win2003 server after I got both it and my hardware firewall locked down good and tight. Before that however, I had to totally scrub my web server using Wins NT/ 2000 and the first install of 2003 at least five times due to hackers breaking in and taking full control. It is a horrible experience to lose control of your own box and then have to reformat and rebuild system, apps and databases back. Now I’ve keep a cloned disc ready to hot swap, but 5 years ago that wasn’t as easy for me.

Reader Feedback

This site uses Akismet to reduce spam. Learn how your comment data is processed.