ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Offline virus scanner - what do you use?

    Scheduled Pinned Locked Moved IT Discussion
    virus
    29 Posts 8 Posters 5.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • coliverC
      coliver
      last edited by

      Have you checked the IP's they are talking to? When I was running SW it did the same thing and generally they were legitimate IPs that had been flagged by a third party for malicious adware.

      DashrenderD 1 Reply Last reply Reply Quote 1
      • travisdh1T
        travisdh1
        last edited by

        You mean nobody has a PXE boot to scanner option setup? What are we coming to? Actually, I'm guessing by the time we're considering an off-line scan it's past time to nuke-it-from-orbit.

        1 Reply Last reply Reply Quote 1
        • NicN
          Nic
          last edited by

          There's a bunch of good recovery CD options out there. Plus it looks like MBAM has a rootkit scanner now:

          http://www.techrepublic.com/blog/smb-technologist/two-portable-rootkit-tools-no-smb-should-be-without/
          https://www.malwarebytes.org/antirootkit/
          http://www.techsupportalert.com/best-free-rootkit-scanner-remover.htm

          1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender @coliver
            last edited by

            @coliver said:

            Have you checked the IP's they are talking to? When I was running SW it did the same thing and generally they were legitimate IPs that had been flagged by a third party for malicious adware.

            Yeah, I'm guessing this is probably the situation, but I figure it's better to be safe than sorry and run an outside of norm scan on them.

            1 Reply Last reply Reply Quote 1
            • scottalanmillerS
              scottalanmiller @Nic
              last edited by

              @Nic said:

              What's the use case for scanning offline? Isn't that like asking what brand of condom you like wearing when you aren't having sex? 🙂

              Quote of the Day right there.

              1 Reply Last reply Reply Quote 3
              • DashrenderD
                Dashrender
                last edited by

                So what's your thought on the issue Scott? Should I not even bother? If my running AV seems clean, just move on?

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller
                  last edited by

                  I agree with MBAM as a good secondary scanner. I use that as a "backup" to Webroot. By offline, do you mean booting into a Linux LiveCD and scanning when the Windows kernel is not loaded? If so, yes, that's a good way to go if you are concerned and ClamAV should be fine for that.

                  1 Reply Last reply Reply Quote 2
                  • DashrenderD
                    Dashrender
                    last edited by

                    OK wow, no love for Defender offline here.

                    I guess I'll have to get a live CD with Clam AV on it.

                    dafyreD 1 Reply Last reply Reply Quote 0
                    • dafyreD
                      dafyre @Dashrender
                      last edited by

                      @Dashrender said:

                      OK wow, no love for Defender offline here.

                      I guess I'll have to get a live CD with Clam AV on it.

                      You mean BitDefender?

                      DashrenderD 1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @dafyre
                        last edited by

                        @dafyre said:

                        @Dashrender said:

                        OK wow, no love for Defender offline here.

                        I guess I'll have to get a live CD with Clam AV on it.

                        You mean BitDefender?

                        No, MS Defender offline.

                        windows.microsoft.com/en-us/windows/what-is-windows-defender-offline

                        dafyreD 1 Reply Last reply Reply Quote 0
                        • dafyreD
                          dafyre @Dashrender
                          last edited by

                          @Dashrender Never heard of it.... runs off to read

                          DashrenderD 1 Reply Last reply Reply Quote 0
                          • DashrenderD
                            Dashrender @dafyre
                            last edited by

                            @dafyre said:

                            @Dashrender Never heard of it.... runs off to read

                            I've been using it for at least 2 years, if not more like 4.

                            dafyreD 1 Reply Last reply Reply Quote 0
                            • dafyreD
                              dafyre @Dashrender
                              last edited by

                              @Dashrender said:

                              @dafyre said:

                              @Dashrender Never heard of it.... runs off to read

                              I've been using it for at least 2 years, if not more like 4.

                              Does it work well?

                              DashrenderD 1 Reply Last reply Reply Quote 0
                              • DashrenderD
                                Dashrender @dafyre
                                last edited by

                                @dafyre said:

                                @Dashrender said:

                                @dafyre said:

                                @Dashrender Never heard of it.... runs off to read

                                I've been using it for at least 2 years, if not more like 4.

                                Does it work well?

                                It does find things from time to time. I will have to do double scans for the next few times, once with Clam and again with Defender Offline and see if they show different things - though now that i think about that.. that won't work.. as the first AV should get rid of any badies on there.

                                travisdh1T 1 Reply Last reply Reply Quote 0
                                • travisdh1T
                                  travisdh1 @Dashrender
                                  last edited by

                                  @Dashrender said:

                                  @dafyre said:

                                  @Dashrender said:

                                  @dafyre said:

                                  @Dashrender Never heard of it.... runs off to read

                                  I've been using it for at least 2 years, if not more like 4.

                                  Does it work well?

                                  It does find things from time to time. I will have to do double scans for the next few times, once with Clam and again with Defender Offline and see if they show different things - though now that i think about that.. that won't work.. as the first AV should get rid of any badies on there.

                                  If you do it a number of times, reversing which one you use first, it would be an indication if one is missing things.

                                  1 Reply Last reply Reply Quote 2
                                  • AmbarishrhA
                                    Ambarishrh
                                    last edited by

                                    I've used http://www.sarducd.it/rescue-cd-antivirus.html once and used kaspersky from there to remove. Not sure if its still as effective as it used to be!

                                    Basically this gives you an option to boot and use most of the free AV rescue disk and if your machine is connected to internet, it will download the latest signature updates to the temp storage and use it for scanning

                                    dafyreD DashrenderD 2 Replies Last reply Reply Quote 1
                                    • dafyreD
                                      dafyre @Ambarishrh
                                      last edited by

                                      @Ambarishrh I forgot about that one. I haven't had to use it in ages.

                                      1 Reply Last reply Reply Quote 0
                                      • DashrenderD
                                        Dashrender @Ambarishrh
                                        last edited by

                                        @Ambarishrh said:

                                        Basically this gives you an option to boot and use most of the free AV rescue disk and if your machine is connected to internet, it will download the latest signature updates to the temp storage and use it for scanning

                                        I would assume ClamAV would have to do the same thing.

                                        Defender online can often get online as well, but I generally just make a new disk with the latest definition files on it.

                                        1 Reply Last reply Reply Quote 1
                                        • A
                                          Alex Sage
                                          last edited by

                                          Tron

                                          DashrenderD 1 Reply Last reply Reply Quote 0
                                          • DashrenderD
                                            Dashrender @Alex Sage
                                            last edited by

                                            @anonymous said:

                                            Tron

                                            Lightcycle

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2 / 2
                                            • First post
                                              Last post