virus.rst
author Oleksandr Gavenko <gavenkoa@gmail.com>
Sun, 01 Aug 2010 16:41:40 +0300
changeset 476 feaa4d64ad4e
parent 466 2c0786a63050
child 602 fc01fedc5b17
permissions -rw-r--r--
To start X application.
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
119
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     1
-*- mode: outline; coding: utf-8 -*-
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     2
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     3
* Rootkit.
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     4
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     5
** Debian.
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     6
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     7
  $ sudo apt-get install rkhunter chkrootkit
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     8
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
     9
*** rkhunter.
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    10
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    11
  $ sudo rkhunter -c
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    12
...
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    13
120
4cc04042bf86 Added url.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 119
diff changeset
    14
  http://www.rootkit.nl/projects/rootkit_hunter.html
4cc04042bf86 Added url.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 119
diff changeset
    15
119
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    16
***
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    17
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    18
  $ sudo chkrootkit
a35784f89969 Added list of rootkit searching programm.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents:
diff changeset
    19
...
121
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    20
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    21
* Virus.
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    22
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    23
** Debian.
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    24
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    25
*** ClamAV.
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    26
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    27
anti-virus utility for Unix.
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    28
4d651112fdca About ClamAV.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 120
diff changeset
    29
  $ sudo apt-get install clamav
466
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    30
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    31
** Windows.
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    32
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    33
*** Nod32.
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    34
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    35
**** Nod32 removal.
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    36
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    37
Disable nod32 services by 'msconfig' utility.
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    38
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    39
Remove such keys from registry by 'regedit':
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    40
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    41
  HKEY_LOCAL_MACHINE\SOFTWARE\ESET
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    42
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NOD32DRV
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    43
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eamon  ==>
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    44
                ... easdrv easdrv EhttpSrv ekrn epfw Epfwndis epfwtdi
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    45
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    46
* Free online virus scaner.
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    47
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    48
  http://virscan.org
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    49
  http://virusscan.jotti.org/ru
2c0786a63050 Nod32 removal.
Oleksandr Gavenko <gavenkoa@gmail.com>
parents: 121
diff changeset
    50
  http://www.virustotal.com