virus.rst
author Oleksandr Gavenko <gavenkoa@gmail.com>
Fri, 15 Oct 2010 14:04:05 +0300
changeset 605 639aaf15fe93
parent 602 fc01fedc5b17
child 703 8860b7ae6253
permissions -rw-r--r--
About screensaver.
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
119
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     1
-*- mode: outline; coding: utf-8 -*-
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     2
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     3
* Rootkit.
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     4
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     5
** Debian.
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     6
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     7
  $ sudo apt-get install rkhunter chkrootkit
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     8
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     9
*** rkhunter.
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    10
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    11
  $ sudo rkhunter -c
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    12
...
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    13
120
4cc04042bf86 Added url.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 119
diff changeset
    14
  http://www.rootkit.nl/projects/rootkit_hunter.html
4cc04042bf86 Added url.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 119
diff changeset
    15
119
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    16
***
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    17
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    18
  $ sudo chkrootkit
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    19
...
121
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    20
602
fc01fedc5b17 Microsoft Security Essentials.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 466
diff changeset
    21
* Debian.
121
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    22
602
fc01fedc5b17 Microsoft Security Essentials.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 466
diff changeset
    23
** ClamAV.
121
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    24
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    25
anti-virus utility for Unix.
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    26
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    27
  $ sudo apt-get install clamav
466
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    28
602
fc01fedc5b17 Microsoft Security Essentials.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 466
diff changeset
    29
* Windows.
fc01fedc5b17 Microsoft Security Essentials.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 466
diff changeset
    30
fc01fedc5b17 Microsoft Security Essentials.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 466
diff changeset
    31
** Free.
fc01fedc5b17 Microsoft Security Essentials.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 466
diff changeset
    32
fc01fedc5b17 Microsoft Security Essentials.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 466
diff changeset
    33
*** Microsoft Security Essentials.
fc01fedc5b17 Microsoft Security Essentials.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 466
diff changeset
    34
fc01fedc5b17 Microsoft Security Essentials.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 466
diff changeset
    35
  http://en.wikipedia.org/wiki/Microsoft_Security_Essentials
fc01fedc5b17 Microsoft Security Essentials.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 466
diff changeset
    36
fc01fedc5b17 Microsoft Security Essentials.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 466
diff changeset
    37
** Non free.
466
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    38
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    39
*** Nod32.
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    40
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    41
**** Nod32 removal.
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    42
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    43
Disable nod32 services by 'msconfig' utility.
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    44
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    45
Remove such keys from registry by 'regedit':
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    46
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    47
  HKEY_LOCAL_MACHINE\SOFTWARE\ESET
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    48
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NOD32DRV
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    49
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eamon  ==>
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    50
                ... easdrv easdrv EhttpSrv ekrn epfw Epfwndis epfwtdi
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    51
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    52
* Free online virus scaner.
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    53
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    54
  http://virscan.org
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    55
  http://virusscan.jotti.org/ru
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    56
  http://www.virustotal.com