because ... my boss was an idiot? Note past tense, I believe I called it a
symptom of the madness of the place,  There was no COMPANY data on those
boxes, at least nothing irreplacable. Various people had downloaded
various.. things which is why their computers were infected.

>If data isn't an issue for you why are we having this conversation about
all
>the time you spent saving the data on the computer instead of wiping it and
>starting over?
Wasn't, Wasn't. Past tensense. And I did not save any data at all.
Instructed not to. That's how stupid it all was. My mission was to remove
all malware and only malware and leave everything else usable and as it was,
Don't look at me that way ;) I know. I know>

>You would have to define help.. I don't see how automating registry edits
is
>helpful when we are talking about getting rid of a virus.

Well maybe we are talking at cross-purposes here, but usually if you are not
going to format and reimage -- and I got the impression a couple of posts
ago that you or someone else there did not want to do that because of the
data ---you locate the malware files, probably with whatever virus software
does detect then, delete them, and then restore the registry keys. No? If
you do in fact want to format, disregard this whole fork, because that's
really the way to go for the sake of the IT person's sanity in my opinion

But that's what that big list of registry keys is a few posts back. Stuff
that might have been changed, causing the computer to not work well? That
was an example from one of the versions of the virus you mentioned.

> You can lock down
>a machine so registry edits cannot be done which I have and we don't have
>virus software on those machines and have no issues because of the lock
>downs we have done. Turned computers into basic dummy terminal's that can
>surf the internet essentially.
True, but these aren't the machines that are infected, right?

Anyway, if you are ghosting, carry on; if you are going to remove it by
hand, good luck to you and depending on the nimber of computers you might
find it faster to write a script is all i am saying. If that doesn't seem
faster, also fine with me. I don't have a horse in this race

-----Original Message-----
From: Dana [mailto:[email protected]]

>  Sent: Wednesday, September 02, 2009 1:51 PM
> To: cf-community
> Subject: Re: Fracking Hacking Spammers!
>
>
> yeah. Data wasn't really an issue for us  and I guess I made an assumption
> that it  wasn't for you either. I take it these are dev boxes or something
> else where it really matters?
>
> You know -- something I did not know at the time was that you can automate
> registry edits with PowerShell. Would that help?
>
> On Wed, Sep 2, 2009 at 11:25 AM, Scott Raley <[email protected]> wrote:
>
> >
> > I already have Ghost and True Image servers. That only helps on rebuild,
> it
> > doesn't help with data on the machine unless you have a real server with
> > real roaming profiles so there is nothing on the desktop to save.
> >
> > -----Original Message-----
> > From: Dana [mailto:[email protected]]
> >  Sent: Wednesday, September 02, 2009 12:22 PM
> > To: cf-community
> > Subject: Re: Fracking Hacking Spammers!
> >
> >
> > I don't know how many machines you are talking about and you have a newer
> > version (presumably nastier tho) but
> >
> > the computers I worked on took a ridiculous amont of time to fix. There
> was
> > a manual fix and it involved really long lists of registry keys that
> might
> > or might now be affected. And the users thought they could not possibly
> > have
> > done such a thing and instantly reinfected them One guy told me I did not
> > need to check his machine because he had just run virus software, Guess
> > which one he ran ;)
> >
> > I mean, a lot depends on who you are dealing with and how important any
> > data
> > on those machines might be, But I would not do that again for anything
> > short
> > of salvaging a cure for cancer,
> >
> > My suggestion is that you invest in a ghost server. For whatever that
> might
> > be worth,
> >
> > On Wed, Sep 2, 2009 at 10:08 AM, Scott Raley <[email protected]> wrote:
> >
> > >
> > > We are debating that now since the virus mutates on itself.
> > >
> > >
> > > -----Original Message-----
> > > From: Dana [mailto:[email protected]]
> > > Sent: Wednesday, September 02, 2009 11:59 AM
> > > To: cf-community
> > > Subject: Re: Fracking Hacking Spammers!
> > >
> > >
> > > awesome :) It would have been better to re-image the machines I am
> > talking
> > > about, I was told not to, well, as a sympom of the madness there, is
> the
> > > best way I can explain it. But based on what you just said it's pretty
> > much
> > > the only way to go any more?
> > >
> > > On Wed, Sep 2, 2009 at 9:49 AM, Scott Raley <[email protected]>
> wrote:
> > >
> > > >
> > > > It is now Antivirus 2010 and there is a new version call Braviax
> which
> > is
> > > > programmed to embed itself in a lot of spyware tools, spybot, malware
> > > > bytes,
> > > > superantispyware, etc so you have to rename stuff to get it to work
> > > > correctly.  It infects regedit and a lot of files in windows system
> so
> > > when
> > > > you think you fixed something you didn't.
> > > >
> > > >
> > > >
> > >
> > >
> > >
> > >
> >
> >
> >
> >
>
>
>
> 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Want to reach the ColdFusion community with something they want? Let them know 
on the House of Fusion mailing lists
Archive: 
http://www.houseoffusion.com/groups/cf-community/message.cfm/messageid:303327
Subscription: http://www.houseoffusion.com/groups/cf-community/subscribe.cfm
Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.5

Reply via email to