Wednesday, October 22, 2008

Disposable anti-virus!

One of the quick ways to check the acquired image for presence of malware is to mount it with Mount Image Pro or Smart Mount and run your favourite anti- virus. Using two different anti-virus solutions is usually a good idea. However, running on the isolated forensic network two anti-viruses and keep them up-to-date may require some extra effort.

Kaspersky® Virus Removal Tool that also often referred to as AVPTool is a virus scanning and removal utility that employs very effective virus detection algorithms from Kaspersky Lab. Kaspersky is one of my favourite anti-virus solution and it rated fairly high amongst other anti-virus solutions.

AVPTool is rebuild every 2 hours and contain the latest virus signatures.
It installs into a folder on your desktop and upon finishing the scan, an uninstall prompt appears and removes the tool if you answer yes to the prompt. It can produce virus scan reports and doesn't leave much behind after it uninstalled.


CON: It is 25Mb file that you will have to download every time you need an up-to-date scanner.

AVPTool is available for free on HTTP and FTP.



3 comments:

H. Carvey said...

I highly recommend having at least 2 AV tools to scan images with, as well as using other techniques. It's important to use an AV scanner that is not already installed on the system, so checking the logs of the existing AV tool, the Event Log, and MRT.log are all great places to start.

eco said...

Thanks for the input Harlan.

eco said...

Here is a very nice write up re: AV solutions. http://grandstreamdreams.blogspot.com/2008/11/portable-anti-virusmalware-security.html