virus.rst
author Oleksandr Gavenko <gavenkoa@gmail.com>
Tue, 15 Dec 2015 18:57:23 +0200
changeset 1823 fb2ead263aed
child 1824 897d88b927bc
permissions -rw-r--r--
Windows Defender
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
1823
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     1
.. -*- coding: utf-8 -*-
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     2
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     3
=================================
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     4
 Computer viruses and rootckits.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     5
=================================
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     6
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     7
Online virus scaner.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     8
====================
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     9
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    10
 * http://virusscan.jotti.org/
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    11
 * http://www.virustotal.com/
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    12
 * http://virscan.org/
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    13
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    14
Rootkit checker.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    15
================
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    16
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    17
For Debian::
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    18
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    19
  $ sudo apt-get install rkhunter chkrootkit
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    20
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    21
  $ sudo rkhunter -c
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    22
  ...
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    23
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    24
  $ sudo chkrootkit
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    25
  ...
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    26
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    27
..
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    28
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    29
  http://www.rootkit.nl/projects/rootkit_hunter.html
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    30
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    31
Antivirus software.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    32
===================
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    33
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    34
Debian.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    35
-------
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    36
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    37
ClamAV - anti-virus utility for Unix::
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    38
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    39
  $ sudo apt-get install clamav
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    40
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    41
Windows.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    42
--------
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    43
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    44
Free:
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    45
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    46
 * `Windows Defender
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    47
   <http://windows.microsoft.com/en-us/windows/using-defender>`_
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    48
 * `Avast <http://www.avast.com/>`_ - free Antivirus is free only for personal
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    49
   and non-commercial use.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    50
 * `Dr.Web CureIt! <https://free.drweb.ru/cureit/>`_
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    51
 * `Free Kaspersky security scan for your PC
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    52
   <http://www.kaspersky.com/free-virus-scan>`_
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    53
 * `Kaspersky Virus Removal Tool <www.kaspersky.com/antivirus-removal-tool>`_
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    54
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    55
Nod32 removal.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    56
~~~~~~~~~~~~~~
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    57
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    58
Disable nod32 services by 'msconfig' utility.
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    59
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    60
Remove such keys from registry by 'regedit'::
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    61
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    62
  HKEY_LOCAL_MACHINE\SOFTWARE\ESET
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    63
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NOD32DRV
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    64
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eamon  ==>
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    65
                ... easdrv easdrv EhttpSrv ekrn epfw Epfwndis epfwtdi
fb2ead263aed Windows Defender
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    66