(Windows
7:
Lesson 6)
{ Download and Run
Kaspersky Rescue Disk (Antivirus Scan) }
Section 0. Background
Information |
- Kaspersky Rescue CD
-
Lab Notes
- In this lab we will do the following:
- Download the Kaspersky iso
- Boot Windows 7 VM into the Kaspersky
Rescue Environment
- Update Kaspersky
- Download a Virus Signature sample file
called MALWARE-TESTFILE.exe (Note:
This is not a virus, just a one-line signature)
- Run Kaspersky Antivirus Scan
- Prerequisites
- Legal Disclaimer
- As a condition of your use of this Web
site, you warrant to computersecuritystudent.com that you will not use
this Web site for any purpose that is unlawful or
that is prohibited by these terms, conditions, and notices.
- In accordance with UCC § 2-316, this
product is provided with "no warranties, either express or implied." The
information contained is provided "as-is", with "no guarantee of
merchantability."
- In addition, this is a teaching website
that does not condone malicious behavior of
any kind.
- Your are on notice, that continuing
and/or using this lab outside your "own" test environment
is considered malicious and is against the law.
- © 2012 No content replication of any
kind is allowed without express written permission.
Section 1. Download
Kaspersky |
- Open A Firefox Browser
- Notes:
- Login to the machine that has VM Player
Installed.
- Instructions:
- Click on the Windows Start Button
- Type firefox in the search box
- Click on Mozilla Firefox
- Open A Firefox Browser
- Navigate and Save
- Instructions:
- Navigate to your external USB hard
drive.
- Create a directory call Anti-Virus
Live CD on your
- Click Save
Section 2. Start
your Windows 7 VM |
- Edit Virtual Machine Settings
- Instructions:
- Click on Windows 7
- Click on Edit virtual machine
- Configure CD/DVD (IDE)
- Instructions
- Configure CD/DVD (IDE)
- Click the radio button "Use ISO
image file:"
- Click the Browse button and Navigate to
the location of the kav_rescue_10.iso
- Click the Okay button
- Start Windows 7
- Instructions:
- Click on Windows 7
- Click on Play virtual machine
- Access the Boot Menu
- Instructions
- Once you see the below vmware screen,
(1) Left Click in the screen and (2) press the <Esc> key.
- Boot from CD-ROM Drive
- Instructions
- Arrow Down to where CD-ROM Drive is
highlighted
- Press <Enter>
Section 3. Using
Kaspersky Rescue CD |
- Press any key to enter the menu
- Instructions
- Press <Enter>
- Select Language
- Instructions
- Select Language of Choice, English is
default.
- Accept Agreement
- Instructions
- Press "1"
- Select Rescue Type
- Instructions
- Select "Kaspersky Rescue Disk.
Graphic Mode"
- Press <Enter>
-
- Open a Terminal
- Instructions
- Select KDE Start Button
- Select Terminal
-
- Get IP Address
- Instructions
- ifconfig -a
- Notes (FYI)
- If you do not have an IP Address, do the
following:
- /etc/init.d/network restart
OR
- dhclient eth0
-
- Update Kaspersky
- Instructions
- Click the "My Update Center" tab
- Click Start update
Section 4. Download
MALWARE-TESTFILE.exe |
- Open A Konqueror Web Browser
- Instructions
- Click the KDE Start Button
- Click the Web Browser
- Download MALWARE-TESTFILE.exe
- Note(FYI):
- The file MALWARE-TESTFILE.exe is not a
virus.
- It contains only the below one-line
virus signature that we will use to test Kaspersky.
-
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
- Instructions:
- In the Konqueror Address Bar, place the
following web address
-
http://www.computersecuritystudent.com/WINDOWS/W7/lesson6/MALWARE-TESTFILE.exe
- Click the Save As... Button
- Navigate to C: Drive
- Instructions
- Click on the C Drive Picture
- Save MALWARE-TESTFILE.exe
- Instructions
- Click Save
- Start Objects Scan
- Instructions
- Click on All Three Check Boxes
- Click on Start Objects Scan
- Rescue Disk Alarm
- Notes (FYI):
- Kaspersky detected the c:/MALWARE-TESTFILE.exe
- Instructions
- Click on Delete
- Open Report
- Instructions
- Click the Report Link
- View Detailed Results
- Instructions:
- Click Report
- Click Detailed Report
- View Last Object Scan
- Instructions
- Click On the Last Object Scan
- View the Detected Viruses
- Open A Terminal
- Instructions
- Click on the KDE Start Button
- Click on Terminal
- Proof of Lab Instructions
- Instructions:
- find /mnt/* -name "*.exe" | grep
MALWARE | wc -l
- This command returns a "0" because
the sample virus was deleted.
- date
- Press <Enter>
- echo "Your Name"
- Replace the string "Your Name" with
your actual name.
- e.g., echo "John Gray"
- Do a PrtScn
- Paste into a word document
- Upload to Moodle
- Edit Virtual Machine Settings
- Instructions:
- From the VM Player Menu Bar do the
following:
- Select Virtual Machine
- Select Virtual Machine Settings...
- Edit CD/DVD (IDE)
- Instructions:
- Select CD/DVD (IDE)
- Select the Connection radio button: Use
physical drive, with Auto detect selected.
- Click the OK Button
- Windows 7 - VMware Player CD-ROW Disconnect
Message
- Instructions:
- Select Yes
- Power Off
- Instructions:
- Virtual Machine --> Power --> Power Off
- VMware Player Message
- Instructions:
- Select Yes
|
 
|