Scanning for Viruses-1.

Scanning for Viruses-1.

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Scanning for Viruses-1. Kayman 05-27-2006
Posted by Kayman on May 27, 2006, 11:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have a couple of questions with respect to scanning modes.

1.Should routine scanning for viruses/malware be performed in safe mode or
is normal mode adequate?

If a virus is found, I understand that it is highly advisable to scan in
safe mode to
remove viruses more effectively.

2.Should the safe-mode scan *include* clean-boot operation, and if so, are
the succeeding steps acceptable?

Follow instructions as per http://support.microsoft.com/kb/31053 **AND**
click on tab BOOT.INI and check /SAFEBOOT.

Thanks in advance for response.



Posted by kurt wismer on May 28, 2006, 12:31 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Kayman wrote:
> I have a couple of questions with respect to scanning modes.
>
> 1.Should routine scanning for viruses/malware be performed in safe mode or
> is normal mode adequate?

ideally it would be done after booting from a known clean bootable
medium (like a bartpe disk)... barring that, safe mode is probably
better than normal mode but that's not always a sufficient precaution...

the idea is to scan in an environment where the malware can't be running
so that the malware can't interfere with the scanning process or
actively hide itself... there's a somewhat reduced chance of the malware
running when you boot into safe mode, but if you execute anything off of
the suspect drive there is a chance that whatever malware you suspect is
on it will be executed as well...

> If a virus is found, I understand that it is highly advisable to scan in
> safe mode to
> remove viruses more effectively.

running in a 'safe' environment is just as important for detection as it
is for recovery...

> 2.Should the safe-mode scan *include* clean-boot operation, and if so, are
> the succeeding steps acceptable?
>
> Follow instructions as per http://support.microsoft.com/kb/31053 **AND**
> click on tab BOOT.INI and check /SAFEBOOT.
>
> Thanks in advance for response.

??? are you sure that's the right url? that seems to be something about
quickbasic..

--
"it's not the right time to be sober
now the idiots have taken over
spreading like a social cancer,
is there an answer?"

Posted by Kayman on May 28, 2006, 2:11 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for informative response.
With respect to the URL, I omitted by mistake the number 3.
The correct URL is http://support.microsoft.com/kb/310353
Regards,

> Kayman wrote:
>> I have a couple of questions with respect to scanning modes.
>>
>> 1.Should routine scanning for viruses/malware be performed in safe mode
>> or is normal mode adequate?
>
> ideally it would be done after booting from a known clean bootable medium
> (like a bartpe disk)... barring that, safe mode is probably better than
> normal mode but that's not always a sufficient precaution...
>
> the idea is to scan in an environment where the malware can't be running
> so that the malware can't interfere with the scanning process or actively
> hide itself... there's a somewhat reduced chance of the malware running
> when you boot into safe mode, but if you execute anything off of the
> suspect drive there is a chance that whatever malware you suspect is on it
> will be executed as well...
>
>> If a virus is found, I understand that it is highly advisable to scan in
>> safe mode to
>> remove viruses more effectively.
>
> running in a 'safe' environment is just as important for detection as it
> is for recovery...
>
>> 2.Should the safe-mode scan *include* clean-boot operation, and if so,
>> are the succeeding steps acceptable?
>>
>> Follow instructions as per http://support.microsoft.com/kb/31053 **AND**
>> click on tab BOOT.INI and check /SAFEBOOT.
>>
>> Thanks in advance for response.
>
> ??? are you sure that's the right url? that seems to be something about
> quickbasic..
>
> --
> "it's not the right time to be sober
> now the idiots have taken over
> spreading like a social cancer,
> is there an answer?"



Posted by kurt wismer on May 28, 2006, 11:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Kayman wrote:
> Thanks for informative response.
> With respect to the URL, I omitted by mistake the number 3.
> The correct URL is http://support.microsoft.com/kb/310353

ah, yes, that's much better...

the answer is that microsoft's idea of what a clean boot is is
completely borked... it's a suped up version of safe mode, disabling as
much as possible but still booting from the suspect media, which means
it's running code off the suspect drive and therefore possibly running
malware...

--
"it's not the right time to be sober
now the idiots have taken over
spreading like a social cancer,
is there an answer?"

Posted by Kayman on May 29, 2006, 1:44 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks Kurt, I really appreciate your explanation.
With very best regards,

> Kayman wrote:
>> Thanks for informative response.
>> With respect to the URL, I omitted by mistake the number 3.
>> The correct URL is http://support.microsoft.com/kb/310353
>
> ah, yes, that's much better...
>
> the answer is that microsoft's idea of what a clean boot is is completely
> borked... it's a suped up version of safe mode, disabling as much as
> possible but still booting from the suspect media, which means it's
> running code off the suspect drive and therefore possibly running
> malware...
>
> --
> "it's not the right time to be sober
> now the idiots have taken over
> spreading like a social cancer,
> is there an answer?"



Similar ThreadsPosted
Virus Scanning - Write Only Scanning September 6, 2008, 12:24 pm
Scanning from a CD March 29, 2007, 1:18 pm
PST scanning February 27, 2008, 1:34 pm
Scanning a port September 24, 2005, 2:27 am
Scanning for viruses-2. May 27, 2006, 11:14 pm
Multi AV scanning tool December 29, 2005, 2:10 pm
security software scanning / sweep times... September 26, 2006, 5:53 pm
Virus scanning apps that can be started from the DOS prompt? July 5, 2007, 5:00 am
Symantec Antivirus Corporate 10 not scanning all files on the drive January 22, 2007, 11:35 am
Antivirus choice: F-Secure's rootkit scanning vs Trend Micro April 7, 2006, 4:17 am

The site map in XML format XML site map

Contact Us | Privacy Policy