Next: Example Applications of Anti-Virus Up: Selecting Anti-Virus Techniques Previous: Identification Tools

Removal Tools

The most dependable technique for virus removal continues to be deletion of the infected executable and restoration from a clean backup. If backups are performed regularly and in a proper manner, virus removal tools may be neglected.

In large organizations with high connectivity, automated removal tools should be obtained. Virus eradication through the removal of infected executables may require too much time and effort. Knowledge based tools will disinfect the largest number of different viruses, but proper identification of the virus prior to disinfection is critical. Even with knowledge based removal tools, disinfection of executables is not always reliable (see Sec. 3.1.3). Test all disinfected executables to be sure they appear to execute properly. There is still a chance, however, that soft errors will occur.


konczal@csrc.ncsl.nist.gov
Fri Mar 11 21:26:02 EST 1994