D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] viruses and protecting against them

 

On 05/11/2018 10:33, Pentiddy wrote:
> Thanks Eion,
> I had already found that web page, amongst others. I do have a netbook 
> with an older version of Win installed...(8?)
> I have however, since writing the e-mail this morning, got a working 
> installation of SOPHOS- at least from the CLI, the Web UI doesn't appear 
> to work.
> Scanning as I type!
> I had thought of using an online scan, or one of the recovery scanners 
> run from a USB or DVD, but couldn't get clarity on if they would scan 
> EXT filesystems...
> Will let everyone know how SOPHOS fares as it seems interesting to me 
> that Virus scanners for Linux seem so thin on the ground given the 
> apparent increase in people choosing Linux above other OS's...

For better or worse, AV is a Windows "game" and if you want to play, use 
the right tool for the job.

Quickly setup a brand new Win10 Pro instance in a VM and install 
whichever AV tool you like the look of (or several if you want to be 
thorough). Export the entire filetree you want to scan from the Linux 
host as a read-only network share and attach it to the Windows VM and 
let the scanner do it's thing - it may take a looooong time. Don't worry 
about it failing to 'fix' anything it finds (because of the read-only 
mount), that's above Windows' paygrade - what you want is the results 
table that it spits out at the end.

Once you've found your suspect packages upload them to an online 
multi-AV scanning facility for an even better analysis. Nuke all the 
infected files and restore them from earlier backups.

If that sounds like a pain in the ass well it is, but then recovering 
from infections is a pain if you want to do it properly. All the stuff 
you need including the Windows and AV installs are completely free to 
use for trial periods that will far exceed the day or two you need to 
run them for this task and you can throw them away afterwards.

There are many other ways to do this but a lot of them require much more 
serious and expensive stuff - this is free (as in beer), easy to setup 
and run and you can have it all done relatively simply.

Cheers
-- 
The Mailing List for the Devon & Cornwall LUG
https://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq