virus.rst
author Oleksandr Gavenko <gavenkoa@gmail.com>
Mon, 11 Oct 2010 16:53:49 +0300
changeset 600 8b94117ba807
parent 466 2c0786a63050
child 602 fc01fedc5b17
permissions -rw-r--r--
newest home of the Cygwin Ports project

-*- mode: outline; coding: utf-8 -*-

* Rootkit.

** Debian.

  $ sudo apt-get install rkhunter chkrootkit

*** rkhunter.

  $ sudo rkhunter -c
...

  http://www.rootkit.nl/projects/rootkit_hunter.html

***

  $ sudo chkrootkit
...

* Virus.

** Debian.

*** ClamAV.

anti-virus utility for Unix.

  $ sudo apt-get install clamav

** Windows.

*** Nod32.

**** Nod32 removal.

Disable nod32 services by 'msconfig' utility.

Remove such keys from registry by 'regedit':

  HKEY_LOCAL_MACHINE\SOFTWARE\ESET
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NOD32DRV
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eamon  ==>
                ... easdrv easdrv EhttpSrv ekrn epfw Epfwndis epfwtdi

* Free online virus scaner.

  http://virscan.org
  http://virusscan.jotti.org/ru
  http://www.virustotal.com