virus.rst
author Oleksandr Gavenko <gavenkoa@gmail.com>
Tue, 15 Dec 2015 23:18:08 +0200
changeset 1826 5c0e92ea4bce
parent 1824 897d88b927bc
child 1828 89380c212670
permissions -rw-r--r--
msconfig.exe
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
1823
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     1
.. -*- coding: utf-8 -*-
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     2
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     3
=================================
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     4
 Computer viruses and rootckits.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     5
=================================
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     6
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     7
Online virus scaner.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     8
====================
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     9
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    10
 * http://virusscan.jotti.org/
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    11
 * http://www.virustotal.com/
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    12
 * http://virscan.org/
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    13
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    14
Rootkit checker.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    15
================
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    16
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    17
For Debian::
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    18
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    19
  $ sudo apt-get install rkhunter chkrootkit
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    20
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    21
  $ sudo rkhunter -c
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    22
  ...
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    23
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    24
  $ sudo chkrootkit
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    25
  ...
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    26
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    27
..
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    28
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    29
  http://www.rootkit.nl/projects/rootkit_hunter.html
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    30
1824
897d88b927bc HijackThis, Sysinternals.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1823
diff changeset
    31
For Windows:
897d88b927bc HijackThis, Sysinternals.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1823
diff changeset
    32
897d88b927bc HijackThis, Sysinternals.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1823
diff changeset
    33
 * `HijackThis <http://sourceforge.net/projects/hjt/>`_
897d88b927bc HijackThis, Sysinternals.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1823
diff changeset
    34
 * `Sysinternals suite <https://technet.microsoft.com/ru-ru/sysinternals/>`_
897d88b927bc HijackThis, Sysinternals.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1823
diff changeset
    35
897d88b927bc HijackThis, Sysinternals.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1823
diff changeset
    36
Use HijackThis to detect malware registration in system.
897d88b927bc HijackThis, Sysinternals.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1823
diff changeset
    37
1826
5c0e92ea4bce msconfig.exe
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1824
diff changeset
    38
Use Sysinternals ``procexp.exe`` to find which process lock file and path to
1824
897d88b927bc HijackThis, Sysinternals.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1823
diff changeset
    39
executable images for removing unwanted software.
897d88b927bc HijackThis, Sysinternals.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1823
diff changeset
    40
1826
5c0e92ea4bce msconfig.exe
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1824
diff changeset
    41
Use ``msconfig.exe`` to investigate startup processes registration.
5c0e92ea4bce msconfig.exe
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 1824
diff changeset
    42
1823
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    43
Antivirus software.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    44
===================
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    45
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    46
Debian.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    47
-------
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    48
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    49
ClamAV - anti-virus utility for Unix::
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    50
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    51
  $ sudo apt-get install clamav
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    52
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    53
Windows.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    54
--------
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    55
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    56
Free:
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    57
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    58
 * `Windows Defender
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    59
   <http://windows.microsoft.com/en-us/windows/using-defender>`_
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    60
 * `Avast <http://www.avast.com/>`_ - free Antivirus is free only for personal
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    61
   and non-commercial use.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    62
 * `Dr.Web CureIt! <https://free.drweb.ru/cureit/>`_
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    63
 * `Free Kaspersky security scan for your PC
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    64
   <http://www.kaspersky.com/free-virus-scan>`_
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    65
 * `Kaspersky Virus Removal Tool <www.kaspersky.com/antivirus-removal-tool>`_
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    66
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    67
Nod32 removal.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    68
~~~~~~~~~~~~~~
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    69
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    70
Disable nod32 services by 'msconfig' utility.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    71
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    72
Remove such keys from registry by 'regedit'::
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    73
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    74
  HKEY_LOCAL_MACHINE\SOFTWARE\ESET
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    75
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NOD32DRV
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    76
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eamon  ==>
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    77
                ... easdrv easdrv EhttpSrv ekrn epfw Epfwndis epfwtdi
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    78