RE: [H] Suggested tools for helping a friend with badvirus infestation

2006-02-13 Thread Thane Sherrington (S)

At 10:02 PM 10/02/2006, Mesdaq, Ali wrote:

I can guarantee that a infected system is unclean-able by you! Not to
question your intelligence but I think you question the malware authors
intelligence. I have setup honeypots as a matter of fact I operate
several for my company and within 1 minute a system is so infected with
unknown malware you would be astonished. And don't think I am just
checking malware against one or two AV companies. Go to
www.virustotal.com and see all the vendors. I collect malware that is
not recognized by any of all those vendors and I have to reverse
engineer it just to know that it does.


Ok, how about you send me an DVD with an image of one of these 
infected systems?  I'd be interested in seeing how badly my system 
fares against worst case scenario.


T 



RE: [H] Suggested tools for helping a friend with bad virusinfestation

2006-02-13 Thread Thane Sherrington (S)

At 06:47 PM 10/02/2006, Christopher Fisk wrote:

On Fri, 10 Feb 2006, Thane Sherrington (S) wrote:


At 04:04 PM 10/02/2006, Christopher Fisk wrote:
Here is the thing, I do this for a living, and the never being 
defeated thing is fine, but when you spend 10 hours on something 
that you could have fixed in 3 or less with a reformat how happy 
#1 are you, and #2 is your customer when you bill them those 7 extra hours?


I bill flat rate for virus removal, so they're never unhappy.  They 
are unhappy with the place down the road that fixed their problem 
by reinstalling Windows and then left them with three days of work 
finding their CDs and reinstalling and configuring their programs.


So you answered #2, how about #1?


I haven't starved to death in the street yet, so I guess I'm still 
reasonably happy. :)


And you sidestepped, we already assumed that you were doing the data 
and software reinstalls...


So when you reinstall Windows, do you reinstall all their apps and 
transfer data as part of the regular job?  If so, what sort of cost 
would I be looking at to bring in a computer and have Windows XP with 
three users and six apps and data restored?  I'm just wondering if 
I'm charging way too little.


Hell, if I can make more money and spend less on AV software and 
removal tools, then perhaps I'm insane to keep doing what I'm doing.


T 



RE: [H] Suggested tools for helping a friend with badvirus infestation

2006-02-13 Thread Thane Sherrington (S)

At 10:02 PM 10/02/2006, Mesdaq, Ali wrote:

That whole nothing can stop me attitude I don't buy it and I don't
respect it in this context. If the issue is a system crash or a bug in
configuration that's where the never quite attitude is good. But in a
case where you could possibly not clean out a system and leave a
password stealing Trojan on a system the payoff is not very much when
the alternative is a reformat and 100% safe system.


Except that if it takes only minutes to be reinfected with tons of 
unknown malware then does it make any difference if I miss one piece 
or the customer reinstalls it by surfing the net?  What is your 
solution for people who want to be safe?  Is there one?


T 



RE: [H] Suggested tools for helping a friend with badvirus infestation

2006-02-13 Thread Thane Sherrington (S)

At 10:02 PM 10/02/2006, Mesdaq, Ali wrote:

unknown malware you would be astonished. And don't think I am just
checking malware against one or two AV companies. Go to
www.virustotal.com and see all the vendors. I collect malware that is
not recognized by any of all those vendors and I have to reverse
engineer it just to know that it does.


Is VirusTotal the company you work for?  What does this company 
do?  Can I use your site to see if my AV is keeping up with new threats?


I'm looking at the charts, but I don't understand them.

http://www.virustotal.com/xhtml/graficas/grafica4_en.html

In this one, it seems to suggest that in the last seven days, 16,986 
viruses were missed by at least one AV and only 344 were caught by 
all of them.  That number doesn't seem useful to me - I'd be 
interested in seeing how many were missed by all the AVs.


T  



Re: [H] Suggested tools for helping a friend with badvirus infestation

2006-02-13 Thread Thane Sherrington (S)

At 06:37 PM 11/02/2006, warpmedia wrote:

Anyone checked this out yet?

http://www.f-secure.com/blacklight/


Yes, I've been using it for about two months.  Easier to use than 
Rootkit Revealer, but I'm not sure if it's as thorough.


T 



RE: [H] Suggested tools for helping a friend with badvirus infestation

2006-02-13 Thread Anthony Q. Martin
Exactly what are the calling malware?  If no AV system is 100% effective,
then how can they be 100% sure of these numbers?

:-Original Message-
:From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]
:On Behalf Of Thane Sherrington (S)
:Sent: Monday, February 13, 2006 7:03 AM
:To: The Hardware List
:Subject: RE: [H] Suggested tools for helping a friend with badvirus
infestation
:
:At 10:02 PM 10/02/2006, Mesdaq, Ali wrote:
:unknown malware you would be astonished. And don't think I am just
:checking malware against one or two AV companies. Go to
:www.virustotal.com and see all the vendors. I collect malware that is
:not recognized by any of all those vendors and I have to reverse
:engineer it just to know that it does.
:
:Is VirusTotal the company you work for?  What does this company
:do?  Can I use your site to see if my AV is keeping up with new threats?
:
:I'm looking at the charts, but I don't understand them.
:
:http://www.virustotal.com/xhtml/graficas/grafica4_en.html
:
:In this one, it seems to suggest that in the last seven days, 16,986
:viruses were missed by at least one AV and only 344 were caught by
:all of them.  That number doesn't seem useful to me - I'd be
:interested in seeing how many were missed by all the AVs.
:
:T


RE: [H] Suggested tools for helping a friend with badvirus infestation

2006-02-13 Thread Mesdaq, Ali
Well the difference is that you spent a resonable amount of time trying to 
clean a system that you could possibly leave infected. I would recommend 
reformatting then making sure you customers have a resonable level of layers of 
defense firewall, software firewall , some av, alternative browser, and also 
some end user education . 

-Original Message-
From: Thane Sherrington (S)[EMAIL PROTECTED]
Sent: 2/13/06 3:52:26 AM
To: The Hardware Listhardware@hardwaregroup.com
Subject: RE: [H] Suggested tools for helping a friend with badvirus 
infestation

At 10:02 PM 10/02/2006, Mesdaq, Ali wrote:
That whole nothing can stop me attitude I don't buy it and I don't
respect it in this context. If the issue is a system crash or a bug in
configuration that's where the never quite attitude is good. But in a
case where you could possibly not clean out a system and leave a
password stealing Trojan on a system the payoff is not very much when
the alternative is a reformat and 100% safe system.

Except that if it takes only minutes to be reinfected with tons of 
unknown malware then does it make any difference if I miss one piece 
or the customer reinstalls it by surfing the net?  What is your 
solution for people who want to be safe?  Is there one?

T 




RE: [H] Suggested tools for helping a friend with badvirus infestation

2006-02-13 Thread Mesdaq, Ali
Its not a company I work for its a tool we use. You can upload a file and check 
it against all av pretty sad coverage because no av ever gets it all or even 
close

-Original Message-
From: Thane Sherrington (S)[EMAIL PROTECTED]
Sent: 2/13/06 3:56:24 AM
To: The Hardware Listhardware@hardwaregroup.com
Subject: RE: [H] Suggested tools for helping a friend with badvirus 
infestation

At 10:02 PM 10/02/2006, Mesdaq, Ali wrote:
unknown malware you would be astonished. And don't think I am just
checking malware against one or two AV companies. Go to
www.virustotal.com and see all the vendors. I collect malware that is
not recognized by any of all those vendors and I have to reverse
engineer it just to know that it does.

Is VirusTotal the company you work for?  What does this company 
do?  Can I use your site to see if my AV is keeping up with new threats?

I'm looking at the charts, but I don't understand them.

http://www.virustotal.com/xhtml/graficas/grafica4_en.html

In this one, it seems to suggest that in the last seven days, 16,986 
viruses were missed by at least one AV and only 344 were caught by 
all of them.  That number doesn't seem useful to me - I'd be 
interested in seeing how many were missed by all the AVs.

T  




RE: [H] Suggested tools for helping a friend with badvirus infestation

2006-02-13 Thread Anthony Q. Martin

:
:Its not a company I work for its a tool we use. You can upload a file and
check it against all av
:pretty sad coverage because no av ever gets it all or even close

Then how can you believe the results?  Some can be reporting false
positives, etc.


RE: [H] Suggested tools for helping a friend with badvirus infestation

2006-02-13 Thread Thane Sherrington (S)

At 10:03 AM 13/02/2006, Mesdaq, Ali wrote:
Its not a company I work for its a tool we use. You can upload a 
file and check it against all av pretty sad coverage because no av 
ever gets it all or even close


How do you know that?  According to their charts, it appears that if 
they scan with all the AVs then then catch all the malware, but no 
one program gets them all.


T 



Re: [H] ok, how about this...

2006-02-13 Thread j m g
it's the nature of the 'sport compact' - I've got an '04 WRX and nope
no creature comforts, but everything is in easy reach :)

I've had this arguement ad naseum with friends, many of who have bmw
330xl's - the awd, and while comfortable, feel like a slug to drive :)

On 2/12/06, Christopher Klein [EMAIL PROTECTED] wrote:
 It handles nicelybut I'm talking about the seats, dash, etc.  I just get
 the feeling that I'm riding in a tin can with a powerful engine.  There are
 no creature comforts

 -Original Message-
 From: [EMAIL PROTECTED]
 [mailto:[EMAIL PROTECTED] On Behalf Of Bryan Seitz
 Sent: Sunday, February 12, 2006 10:27 PM
 To: The Hardware List
 Subject: Re: [H] ok, how about this...

 I own one ;)  I actually like the way it handles/feels.
 (I have an '05).  I guess each to their own though.

 On Sun, Feb 12, 2006 at 09:54:22PM -0500, Christopher Klein wrote:
  It's fairly quickbut have you been in one?  It feels like a
  plastic bucket.  There isn't anything nice about the inside at all.  I
  could see picking one up if money was no object and you were into
  weekend racing at the trackbut driving that thing for anything
  more than 20 minutes is just painful.
 

 --

 Bryan G. Seitz




--
-jmg
-sapere aude



Re: [H] ok, how about this...

2006-02-13 Thread Bryan Seitz
On Mon, Feb 13, 2006 at 10:05:34AM -0500, j m g wrote:
 it's the nature of the 'sport compact' - I've got an '04 WRX and nope
 no creature comforts, but everything is in easy reach :)
 
 I've had this arguement ad naseum with friends, many of who have bmw
 330xl's - the awd, and while comfortable, feel like a slug to drive :)

And and don't mention the uhm... massive price tag increase on them :)
(I admit, the 330 XI is hot)

-- 
 
Bryan G. Seitz


RE: [H] Suggested tools for helping a friend with bad virusinfestation

2006-02-13 Thread Wayne Johnson

At 06:56 AM 2/13/2006, Thane Sherrington (S) typed:
So when you reinstall Windows, do you reinstall all their apps and 
transfer data as part of the regular job?


Most mom/pop shops do NOT putting the onus on the owner to have 
sufficient backups when everyone knows that home lusers don't backup 
nearly enough. Heck even MSFT doesn't install a shortcut to ntbackup 
on the start menu  XP Home does NOT have ASR [automatic system 
recovery] feature anyway so what good is it?


If so, what sort of cost would I be looking at to bring in a 
computer and have Windows XP with three users and six apps and data 
restored?  I'm just wondering if I'm charging way too little.


You probably are. There is a shop here in this little town that sells 
systems without AV software knowing that the client is going on the 
internet as a nOOb so they know that they'll get the machine back. 
They'll do a re-install for $50 but the client loses everything from 
Internet setup, email, pics of the grandkids  etc. but what do they 
care? Another shop charged a chiropractor $250 to cleanup Happy99 by 
doing a wipe  re-install without telling him that he was going to 
lose all his data then sent the laptop back at 640x480 when the 
native res was 800x600 so it looked like crap. He took the laptop 
back  they soaked him for another $200  still gave the machine at 
640x480. While bidding on a small 5 workstation network for him he 
asked me if I could fix his laptop display while he ran out to get 
the snail mail  coffee. He thought he was testing me. I had it fixed 
before he was out of the driveway but he didn't believe me until he 
saw it for himself and when he did he asked me how much I wanted for 
the network job [I should've upped my price right there] then he 
wrote me a check on the spot. I told him I could've fixed Happy99 for 
$50  he wouldn't have lost all his data nor would the screen have 
gotten messed up. In this little college town with 4 or 5 mom/pop 
shops you'd think that I wouldn't have anything to do yet I get calls 
everyday  if the people that call can't give a reference from a 
previous client then I refuse to do business with them. FWIW I don't 
advertise in the Yellow Pages  I don't even list Svenska Computing 
in the white pages but the calls still keep coming in. Darned word of 
mouth anyway. ;-)


So while in a few rare cases a wipe  re-install is necessary it 
certainly is NOT req'd in all cases. I never charge more than $200 
USD to cleanup a system even if that means doing a wipe  re-install 
but I also re-install as many of the apps as I can salvaging as much 
of their data as I can but only after I try to clean the sucker as 
thoroughly as I can.  This is what I would do for my own machine(s) 
[even tho I don't surf the shady sites  have more than 1 backup] 
therefore I believe the clients deserve the same treatment.


Heck the reason I developed XpPe was so I could clean up NTFS systems 
but why would I bother do that if I was going to take the wipe  
re-install route every time? There are bugs that shut down AV apps  
websites that I can cleanup in 5 min with my XpPe disk that I could 
never clean on the system otherwise without having to pull the HD  
put it in another system on the bench.


---+--
  a Windows Xp based
Diagnostic  Recovery CD
 http://www.xppe.com/ 



[H] Smallish LCD TV...

2006-02-13 Thread Bobby Heid
Hey,

My wife mentioned something about putting a small TV in the kitchen.  I am
looking at something in the 13-17 range.  Anyone have any pointers?  At
that size, would buying one of the computer monitors that has a TV tuner in
it do what I need?

Thanks,
Bobby



RE: [H] Suggested tools for helping a friend with badvirus infestation

2006-02-13 Thread Hayes Elkins
On a side note, I have wasted more time/money/resources dealing with false 
positives than with actual viruses. Many enterprises have strict email 
policies these days prohibiting any forwarding of virus warnings exactly 
because of the hysteria a false positive causes.




From: Anthony Q. Martin [EMAIL PROTECTED]
Reply-To: The Hardware List hardware@hardwaregroup.com
To: 'The Hardware List' hardware@hardwaregroup.com
Subject: RE: [H] Suggested tools for helping a friend with 
badvirus	infestation

Date: Mon, 13 Feb 2006 09:08:53 -0500


:
:Its not a company I work for its a tool we use. You can upload a file and
check it against all av
:pretty sad coverage because no av ever gets it all or even close

Then how can you believe the results?  Some can be reporting false
positives, etc.





RE: [H] Smallish LCD TV...

2006-02-13 Thread Hayes Elkins

Yeah. Cheap too.

I noticed on Costco's website there is a 37 1080p LCD flat panel for $1499. 
Next year, a 45 should cost that amount.


Very nice :)



From: Bobby Heid [EMAIL PROTECTED]
Reply-To: [EMAIL PROTECTED], The Hardware List 
hardware@hardwaregroup.com

To: 'The Hardware List' hardware@hardwaregroup.com
Subject: [H] Smallish LCD TV...
Date: Mon, 13 Feb 2006 14:27:47 -0500

Hey,

My wife mentioned something about putting a small TV in the kitchen.  I am
looking at something in the 13-17 range.  Anyone have any pointers?  At
that size, would buying one of the computer monitors that has a TV tuner in
it do what I need?

Thanks,
Bobby






RE: [H] Smallish LCD TV...

2006-02-13 Thread Anthony Q. Martin
I recently bought a 19 Westinghouse Widescreen LCD TV for my exercise room.
Thing is HDTV and has DVI inputs, S-video, 3:2 pull-down, progressive scan,
NSTV tuner, etc.  Very nice on hi-def and DVD.  BestBuy.  I'm going to add a
PC in that room, next.

:
:Hey,
:
:My wife mentioned something about putting a small TV in the kitchen.  I am
:looking at something in the 13-17 range.  Anyone have any pointers?  At
:that size, would buying one of the computer monitors that has a TV tuner in
:it do what I need?
:
:Thanks,
:Bobby


RE: [H] British TV: The IT Crowd

2006-02-13 Thread Hunter, Gary



Its a great program even my wife likes it. For those not in 
the UK you can grab it from www.uknova.com


From: [EMAIL PROTECTED] 
[mailto:[EMAIL PROTECTED] On Behalf Of Chris 
ReevesSent: Friday, February 10, 2006 9:43 PMTo: 'The 
Hardware List'Subject: [H] British TV: "The IT 
Crowd"


Anyone seen this? Its typical 
british over the top humor, but there are moments that kill 
me.

Seems to me like one of those shows 
like The Office that could transition over here in short 
order.

The information in this electronic mail message is sender's 
business Confidential and may be legally privileged.  It is 
intended solely for the addressee(s).  Access to this Internet 
electronic mail message by anyone else is unauthorized.  If 
you are not the intended recipient, any disclosure, copying, 
distribution or any action taken or omitted to be taken in 
reliance on it is prohibited and may be unlawful. The sender 
believes that this E-mail and any attachments were free of 
any virus, worm, Trojan horse, and/or malicious code when 
sent. This message and its attachments could have been 
infected during  transmission. By reading the message and 
opening any attachments, the recipient accepts full 
responsibility for taking protective and remedial action about 
viruses and other defects. Cendant is not liable for any loss 
or damage arising in any way from this message or its 
attachments.


RE: [H] British TV: The IT Crowd

2006-02-13 Thread Chris Reeves
It’s just British comedy, but the bit of:

“Dear Sir / Madam:

FIRE!

FIRE!

Help Me!

I’m at 231 Browns Lane.

I look forward to hearing from you.”

As an email to the emergency services killed me.




From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Hunter, Gary
Sent: Monday, February 13, 2006 3:09 PM
To: The Hardware List
Subject: RE: [H] British TV: The IT Crowd

Its a great program even my wife likes it. For those not in the UK you can
grab it from www.uknova.com


From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Chris Reeves
Sent: Friday, February 10, 2006 9:43 PM
To: 'The Hardware List'
Subject: [H] British TV: The IT Crowd
Anyone seen this?  It’s typical british over the top humor, but there are
moments that kill me.

Seems to me like one of those shows like “The Office” that could transition
over here in short order.




Re: [H] ok, how about this...

2006-02-13 Thread Julian Zottl
lol, yes  ;)  I was in Canada skiing, hence the slow reply ;)

If you think that the Subaru WRX STI feels like a plastic bucket, you obviously 
haven't been in a Saturn lately.  Now that feels like it's going to fall apart 
right from under you.

I bought a Subaru WRX STI for a couple of reasons: I regularly go through 6+'s 
of snow on the weekends, so I needed something AWD/4WD. My brother in law had a 
Forrester that went over 175k without anything other than 
oil/brakes/tune-ups/tires. Good gas milage. To summarize: Fast, great handling, 
good in the snow and reliable.

Subaru's are definitely not for everyone though.  If you want comfort, the 
Subaru Legacy GT is one hell of a car for the money, but not everyone wants to 
drive a Subaru.  For 5k more than a full outfitted Legacy GT, you can get a 
AWD 325XI.  For that you get -50HP, -75lbs/ft of torque, no limited-slip 
differential, less leg room, no lumbar support or heated seats and less of a 
warrenty.  Oh and you do get a cool little blue and white symbol, which means 
more to most people than the technical specifications.

FYI: I live in a town (DC) where every other car is a BMW, Porsche or Lexus.  
I've been in and driven a huge number of cars since I'm the preseident of the 
DC All Wheel Drive car club (www.dcawd.com).  Every time someone takes a drive 
in a STI or a Legacy, they understand where I am coming from.  Most will admit 
right then and there though that they paid extra for the status symbol.  

ok, I'll stop now ;) 

_
Julian Zottl
CTO, Radiant Network Technology, LLC
Getting ahead in the tech sector isn't about kissing butt ... you gotta sniff 
the right packets



-- Original Message --
From: Ben Ruset [EMAIL PROTECTED]
Reply-To: The Hardware List hardware@hardwaregroup.com
Date:  Sun, 12 Feb 2006 22:09:23 -0500

Paging Sabre in 5..4..3..2..

Christopher Klein wrote:
 It's fairly quickbut have you been in one?  It feels like a plastic
 bucket.  There isn't anything nice about the inside at all.  I could see
 picking one up if money was no object and you were into weekend racing at
 the trackbut driving that thing for anything more than 20 minutes is
 just painful. 
 
 -Original Message-
 From: [EMAIL PROTECTED]
 [mailto:[EMAIL PROTECTED] On Behalf Of Bryan Seitz
 Sent: Sunday, February 12, 2006 9:15 PM
 To: The Hardware List
 Subject: Re: [H] ok, how about this...
 
 WRX STI :)
 
 On Sun, Feb 12, 2006 at 07:12:11PM -0500, Christopher Klein wrote:
 New Camaro looks great.  I'm more of a domestic guyHonda/Toyota 
 does nothing for me in terms of power and looks.  I like BMW and 
 Mercedez but I'd probably never buy one.  I'll probably get a CTS-V if 
 my Impala SS ever dies.

 




Re: [H] ok, how about this...

2006-02-13 Thread Bryan Seitz
On Mon, Feb 13, 2006 at 09:44:22PM -0500, Ben Ruset wrote:
 I want the Mazdaspeed 6. Yum.

rofl, P O S.

-- 
 
Bryan G. Seitz


Re: [H] ok, how about this...

2006-02-13 Thread Ben Ruset

:(

My wife's Protege5 is an awesome car.

Bryan Seitz wrote:

On Mon, Feb 13, 2006 at 09:44:22PM -0500, Ben Ruset wrote:

I want the Mazdaspeed 6. Yum.


rofl, P O S.



Re: [H] ok, how about this...

2006-02-13 Thread Bryan Seitz
Not bad cars, just meant performance wise.

On Mon, Feb 13, 2006 at 11:34:57PM -0500, Ben Ruset wrote:
 :(
 
 My wife's Protege5 is an awesome car.
 
 Bryan Seitz wrote:
 On Mon, Feb 13, 2006 at 09:44:22PM -0500, Ben Ruset wrote:
 I want the Mazdaspeed 6. Yum.
 
 rofl, P O S.
 

-- 
 
Bryan G. Seitz