Lieberman & Associates? ?Cratering? Process is an Efficient Way to Detect and Defeat the MyDoom Virus
Beverly Hills, CA February 1 2004–Lieberman & Associates, a provider of mass management tools for Windows, announced today that its unique ?cratering? process can be used to quickly find, disable and overcome the effects of the MyDoom worm and its variants. Cratering disables a worm or virus via ACL (Access Control List) management, rather then simply removing it. This process renders the worm or virus harmless, and makes re-infection impossible. Cratering is done by Lieberman & Associates? User Manager Pro, which can perform this task in a simple operation to all managed systems in a Windows environment. In addition, User Manager Pro can easily search for and remove registry entries created by the worm or virus, and correct other problems created by an infection. A white paper with step-by-step instructions on how to use cratering to defeat the MyDoom worm is available on the Lieberman & Associates? web site - www.lanicu.com.
Many viruses cause the infected machine to carry out processor-consuming and/or network-intensive operations in order to infect other systems or cause other effects. For example, with MyDoom, the worm adds registry entries to the machine it is invading to carry out operations for the hacker (i.e. the Denial of Service attack against www.sco.com). Many times a machine will get so overloaded by a virus? activities that the patch required to stop infection cannot be downloaded and/or applied. When this occurs many administrators find that they must pull the network cable from the machine and manually terminate the virus process using the Window Task Manager. Only then will the machine activity subside enough to accept the patch. This process can take up to an hour or more per machine. Cratering can defeat the virus in a matter of minutes.
Disabling the virus via ACL modification uses the operating system?s built-in mechanisms for marking files as ?not executable.? This will lock out all access to everyone, including the operating system. The virus will be unable to start because its executable components will not able to run. Furthermore, a new infection will be unable to take hold since the disabled virus file cannot be overwritten.
?We developed the cratering process while helping our customers who were having a tough time cleansing their systems of the Blaster virus,? said Phil Lieberman, owner of Lieberman & Associates. ?Although the MyDoom worm is much more destructive and complex, we have found that the cratering process is able to rapidly defeat all of its actions.?
About User Manager Pro
Cratering is just one of many tasks that User Manager Pro can perform. The tool provides a complete user management package for Windows 2000, Server 2003, XP, NT that gives system administrators more control over what is happening in their environment. Armed with User Manager Pro, system administrators can mass manage users, groups, rights, registry settings, and security policies (including password changes and virus management) simultaneously, without agents, on all of their machines, with just a few mouse clicks.
About Lieberman & Associates
Lieberman & Associates, a Microsoft Gold Certified Partner, builds administration tools for Microsoft Windows NT, 2000, XP and Server 2003 operating systems that execute vital tasks simultaneously on every managed system with just a few mouse clicks. These functionally advanced tools not only automate time consuming ongoing network maintenance, but also accomplish important tasks that are often ignored due to high cost or complexity. Lieberman & Associates’ tools return control of Windows environments to IT departments. Founded in 1978, Lieberman & Associates has helped thousands of customers with their network administration needs, including the top names in the Fortune 100, educational institutions and governmental agencies. Located in Beverly Hills, CA, Lieberman & Associates’ products are sold worldwide. For more information, please visit our web site at www.lanicu.com or call 800-829-6263 (US/Canada) or 310-550-8575 (Worldwide).












