Home
Username:
Password:
Using Security Tools Tutorials

Host Security / Anti-Virus pt. 2

Subtitles of the Movie

Now we're logging into our Windows box but we're actually logging in in safe mode and I've rebooted the computer and we're in safe mode now and there's a reason why I want to do that. A lot of anti-virus products, when they get infected or when a piece of malware or virus is able to disable them, they're not going to run in normal mode and unfortunately sometimes you need to be in safe mode to actually clean some things and the reason I suggest using safe mode is because most Windows services are turned Off, there's a very minimal amount of services, device drivers and so forth that are running so it actually makes it very easy to clean malware. The problem with this is most anti-virus software packages do not run in safe mode so you've got to find something that will run in safe mode that has not been compromised by malware or viruses and I'm going to show you a couple of instances of those software. We're in safe mode command prompt and what I want to do is show you a product called a2cmd. It is actually a full-fledged anti-virus and anti-malware program and it runs at the Command Line. And this is useful for a couple of reasons. You might think well, Command Line, that's kind of old Windows. That's old school. But there's still a lot of good things you can still do with the Windows command prompt, especially in safe mode. If we use this program, it can actually run in safe mode so it can eliminate viruses and malware and so forth and clean the computer so that when we reboot, maybe our other anti-virus program or other things are running properly. The good thing about this particular program, a2cmd, is that, or a squared cmd, however you want to say it, is that it does not require installation. You can download this and put it on a USB stick and then at the appropriate time, whenever you're infected, you can actually update this and then reboot in safe mode and then run it from the command prompt. And if you look at some of the options here, you can see that it actually does quite a bit of things. A squared Command Line scanner and what it does, it can scan particular file paths. It can look in active memory, traces, spyware traces, it can scan for cookies. It can also do heuristic scanning, scanning for patterns of malware and so forth. It can look in archives, look in executables and they can do a wide variety of things. It's actually an extremely good Command Line scanner and it can take out a lot of viruses and malware that you might not otherwise be able to remove from regular Windows mode. It's actually very easy to use. We're going to start it with a couple of options here. If you want to update it I would suggest you update it before you go into safe mode because your normally won't have networking capability in the safe mode, Command Line safe mode but you simply have to use a couple of switches to get it going and you can use whichever switches you like. It can also look at NTSF streams to see if there's any Trojan programs that are in some of your Windows executables. So we can just start off with just a few of these different options and start it up and it's going to start up and it's going to give us some status as it goes. It'll go ahead and run through the entire path of, if we like, the entire hard drive and it's going to go ahead and start and it's, lists our options here and it's going to go file by file until it finds whatever it needs to find and it'll tell us if it finds things wrong with various files, if it finds they're infected at all. Now, while this is running, we also can go ahead and go into Explorer and I haven't started Windows Explorer yet and what we want to do is just go ahead and run a new test, let's go ahead and run Explorer and get it up and going and another tool I'll show you that you can use in Windows Explorer is called Stinger and Stinger is actually a product from McAfee and the cool thing about it is it's not a full-fledged anti-virus at all but it does scan for really key infections; really difficult infections and it's updated from McAfee and it's a single, standalone download. You don't have to install it at all. You can just run it and it's updated periodically and it doesn't give you a lot that it scans for but it can detect and get rid of some of the really tough ones. So you can look at it, preferences, you can look at processes, boot sectors and so forth and it can do different things and it's actually a very effective little scanner. It can get rid of a lot of serious infections. Let's say OK and we can actually list the viruses that it will find and these could be some of the more serious ones out there. So if you think you've got something, some of these, it can scan and detect these from real mode or from safe mode and go a long way toward helping you clean your computer out if you need to do that if something's already infected. Now, these are anti-virus programs that are above and beyond your normal anti-virus, such as MacAfee or Symantec or so forth so these are cool tools that a security professional should be aware of and these aren't the only ones out there either. There's other really good tools out there to do what we're doing now. These are just a couple of examples, so you can use Stinger and you can use a squared cmd and it's actually it's already completed scanning and you can see that it went through and grabbed a, looked at a lot of things and it's detected some tracking cookies and so forth so it's actually detected some things. More or less just cookies traces and things like that, so two very good tools that you can use in safe mode to detect viruses and malware.

Tutorial Information

Course: Using Security Tools
Author: Bobby Rogers
SKU: 34068
ISBN: 1-935320-88-2
Release Date: 2009-12-04
Duration: 9 hrs / 91 lessons
Captions: Available on CD and Online University
Compatibility: Vista/XP/2000, OS X, Linux
QuickTime 7, Flash 8

VTC Sign up & Benefits

  • Unlimited Access
  • 98,729 Video Tutorials (23,265 free)
  • Video Available as Flash or QuickTime
  • Over 1026 Courses
  • $30 for One Month Access
  • Multi-User Discounts Available