Antimalware for the Bench

article #162, updated 39 days ago

Just recently I have had to bump Kaspersky Labs LiveCD to number one:

http://www.softpedia.com/get/Antivirus/Kaspersky-Rescue-Disk.shtml

It has been working on a wider variety of hardware than the rest, and it is very thorough. If its graphical mode doesn’t come up, go to its text mode, do the update, and then go to the console, and use this command:

scan -all -i3 -fa

That will examine every file as well as boot sector etcetera, and will delete anything infected which it cannot disinfect. There is a whole lot of flexibility too; try “help scan” at the same prompt to see it all.

Second on this list is VBA32 LiveCD. 

ftp://anti-virus.by/pub/vbarescue.iso

Another is Dr. Web:

http://download.geo.drweb.com/pub/drweb/livecd/

And there is also the AVG:

http://www.avg.com/us-en/avg-rescue-cd-download

Softpedia gives us this list containing several:

http://www.softpedia.com/hubs/Rescue-Disks

And finally, some very special non-liveCD tools, from bleepingcomputer.com quite a large community devoted to helping handle malware situations. Bearing strongly in mind, that they recommend against using these unless their people are directly involved…

…here is ComboFix.

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

ComboFix removes a large proportion of malware, but even if it cannot remove everything, it is good to use it (if possible) before anything else, because it fixes damage done by malware, which other tools generally do not.

And also from the BC folks, we have UnHide:

http://download.bleepingcomputer.com/grinler/unhide.exe

UnHide is very useful for certain attacks, including “Vista Recovery Malware”, in which most or all relevant files are turned to ‘hidden’. UnHide reverses this, and properly.

And a good emergency tool, also from BleepingComputer, we have RKill:

http://www.bleepingcomputer.com/download/anti-virus/rkill

RKill is especially neat, it will kill ‘rogue antivirus products’ and similar nasties, so that you can rip them out before they start up again! And if you can’t run a .EXE, rename it to .SCR, it will probably run just as well, as if it were a screen saver :-) Many different filenames are available at the above link, just in case.

Categories: