<?xml version="1.0"?>
<rss version="2.0"><channel><title>Advice and solutions Latest Topics</title><link>https://forum.kaspersky.com/forum/advice-and-solutions-122/</link><description>Advice and solutions Latest Topics</description><language>en</language><item><title>Hardening the Low Restricted Group</title><link>https://forum.kaspersky.com/topic/hardening-the-low-restricted-group-37065/</link><description><![CDATA[<p>
	Hi guys! I'm back with a new guide, this time giving some tips of how to harden <strong>Low Restricted</strong> group.
</p>

<p>
	 
</p>

<p>
	Without further delay, these are the steps to follow:
</p>

<p>
	 
</p>

<p>
	1.- Go to <strong>Settings </strong>-&gt; <strong>Security Settings</strong> -&gt; <strong>Advanced Protection</strong> -&gt; <strong>Intrusion Prevention</strong>, and set:
</p>

<p>
	 
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="13885" href="https://forum.kaspersky.com/uploads/monthly_2023_11/IP.png.179ac1fb85176714e4551b96d6c60a42.png" rel=""><img alt="IP.thumb.png.c4c96e199a538100f054db06e017921b.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13885" data-ratio="78.00" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_11/IP.thumb.png.c4c96e199a538100f054db06e017921b.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p>
	 
</p>

<p>
	This may be a bit aggressive, so for newbies and / or standard users, probably better to leave <strong>Trust digitally signed applications</strong> enabled. That will lead to get less blocking in legit applications.
</p>

<p>
	 
</p>

<p>
	2.- Go to <strong>Settings </strong>-&gt; <strong>Security Settings</strong> -&gt; <strong>Advanced Settings</strong> -&gt; <strong>Exclusions and actions on object detections</strong>, and set:
</p>

<p>
	 
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="13886" href="https://forum.kaspersky.com/uploads/monthly_2023_11/INTERACTIVEMODE.png.91b82b8a4a92797d3121dfbce1abc1e6.png" rel=""><img alt="INTERACTIVEMODE.thumb.png.a085004f44f79ef74dd52d58e648f4ec.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13886" data-ratio="101.45" style="height:auto;" width="690" data-src="https://forum.kaspersky.com/uploads/monthly_2023_11/INTERACTIVEMODE.thumb.png.a085004f44f79ef74dd52d58e648f4ec.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p>
	 
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us">3.- Now We are going to hard a bit also <strong><span style="font-family:Arial, sans-serif;">Trusted group</span></strong>, so go to <strong><span style="font-family:Arial, sans-serif;">Settings </span></strong>-&gt; <strong><span style="font-family:Arial, sans-serif;">Security Settings</span></strong> -&gt; <strong><span style="font-family:Arial, sans-serif;">Advanced Protection</span></strong> -&gt; <strong><span style="font-family:Arial, sans-serif;">Intrusion Prevention</span></strong> -&gt;<strong><span style="font-family:Arial, sans-serif;"> Manage Applications.</span></strong></span>
</p>

<p>
	<strong><span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span></strong>
</p>

<p>
	<strong><span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span></strong><img alt="T1.png.42e743c67bb8a9d84a9f896df3ce013b.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13890" data-ratio="83.62" style="height:auto;" width="458" data-src="https://forum.kaspersky.com/uploads/monthly_2023_11/T1.png.42e743c67bb8a9d84a9f896df3ce013b.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
</p>

<p>
	 
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us">Once <b>Manage Applications</b> window is open, select <b>Trusted group</b> with Your mouse pointer, then 1 click on mouse right button -&gt; <b>Details and Rules</b>, and in the new window, go to tab <b>Rights</b>:</span>
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span>
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="13891" href="https://forum.kaspersky.com/uploads/monthly_2023_11/T2.png.a6497b172521798283f9be2ad87eaa46.png" rel=""><img alt="T2.thumb.png.4f96ecb6f1196fff939f1009e6ae467f.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13891" data-ratio="58.57" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_11/T2.thumb.png.4f96ecb6f1196fff939f1009e6ae467f.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span>
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us">In this new window We have to change the selected rights in orange color, to do so, again just select with Your mouse pointer in <b>Shut down Microsoft Windows </b>(1), then 1 click on the small arrow down on the right (2), then select <b>Ask User </b>(3), and later repeat the same to enable <b>Log events </b>(4):</span>
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span>
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span><a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="13892" href="https://forum.kaspersky.com/uploads/monthly_2023_11/T3.png.d790892ca4ab249e4459cdf7a50c2afe.png" rel=""><img alt="T3.thumb.png.412a2db107a0ebec11df24e399101f46.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13892" data-ratio="42.43" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_11/T3.thumb.png.412a2db107a0ebec11df24e399101f46.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p>
	 
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us">Repeat the same to change the remaining orange rights shows in previous capture, once ended, click on <b>Save </b>(and allow<b> </b>saving the changes in the next Kaspersky prompt window)<b>.</b></span>
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span>
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us">4.- And finally going to harden <b>Low Restricted</b> <strong><span style="font-family:Arial, sans-serif;">group. </span></strong><strong><span style="font-family:Arial, sans-serif;font-weight:normal;">We are going to</span></strong><strong><span style="font-family:Arial, sans-serif;"> r</span></strong><strong><span style="font-family:Arial, sans-serif;font-weight:normal;">epeat all the steps in previous point to harden </span></strong><strong><span style="font-family:Arial, sans-serif;">Trusted group</span></strong><strong><span style="font-family:Arial, sans-serif;font-weight:normal;">, but this time with </span></strong><strong><span style="font-family:Arial, sans-serif;">Low Restricted group</span></strong><strong><span style="font-family:Arial, sans-serif;font-weight:normal;">:</span></strong></span>
</p>

<p>
	 
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us">Go to <strong><span style="font-family:Arial, sans-serif;">Settings </span></strong>-&gt; <strong><span style="font-family:Arial, sans-serif;">Security Settings</span></strong> -&gt; <strong><span style="font-family:Arial, sans-serif;">Advanced Protection</span></strong> -&gt; <strong><span style="font-family:Arial, sans-serif;">Intrusion Prevention</span></strong> -&gt;<strong><span style="font-family:Arial, sans-serif;"> Manage Applications.</span></strong></span>
</p>

<p>
	 
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us">Once <b>Manage Applications</b> window is open, select <b>Low Restricted group</b> with Your mouse pointer, then 1 click on mouse right button -&gt; <b>Details and Rules</b>, and in the new window, go to tab <b>Rights</b>:</span>
</p>

<p>
	 
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span><a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="13894" href="https://forum.kaspersky.com/uploads/monthly_2023_11/LR1.png.6f8175a7911501a0fbe7182ffa2887c7.png" rel=""><img alt="LR1.thumb.png.e0a8372e04854e9c7891929aff9ee3d8.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13894" data-ratio="47.57" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_11/LR1.thumb.png.e0a8372e04854e9c7891929aff9ee3d8.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span>
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="13893" href="https://forum.kaspersky.com/uploads/monthly_2023_11/LR2.png.0aa6e0fc20bf840a2a93c7e71bd13971.png" rel=""><img alt="LR2.thumb.png.099b5b789cb2be700af63e073a438a00.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13893" data-ratio="58.00" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_11/LR2.thumb.png.099b5b789cb2be700af63e073a438a00.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p>
	 
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us">And then set all the changes in the rights inside red squares, don’t forget to click on <b>Save</b> once you're done.</span>
</p>

<p>
	 
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us">5.- Additionally and to finish, I also added some restrictions in <b>Intrusion Prevention</b> -&gt; <b>Manage Resources</b>:</span>
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span>
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span><a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="13895" href="https://forum.kaspersky.com/uploads/monthly_2023_11/MR.png.5ccde5086ec5b57419a2ea51c0162eaf.png" rel=""><img alt="MR.thumb.png.4e23cc0c4945faf4a10d3fc8d2c5758a.png" class="ipsImage ipsImage_thumbnailed" data-fileid="13895" data-ratio="53.86" style="height:auto;" width="700" data-src="https://forum.kaspersky.com/uploads/monthly_2023_11/MR.thumb.png.4e23cc0c4945faf4a10d3fc8d2c5758a.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p>
	 
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us">Added my user folder (Windows account located in C:\Users\&lt;Your account&gt;\) with those hardened restrictions, if you don’t know how to do so, check my previous guide, also in this community section:</span>
</p>

<p>
	 
</p>

<p>
	<b><span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"><a href="https://forum.kaspersky.com/topic/implementing-protected-folders-via-manage-resources-anti-exe-default-deny-7694/" rel="">Implementing Protected Folders via Manage Resources + Anti-Exe / Default Deny</a></span></b>
</p>

<p>
	<span lang="en-us" style="font-family:Arial, sans-serif;" xml:lang="en-us"> </span>
</p>

<p>
	Feel free to ask questions and / or doubts!
</p>

<p>
	 
</p>

<p>
	Thanks all folks!!!! <span class="ipsEmoji">😊</span>
</p>
]]></description><guid isPermaLink="false">37065</guid><pubDate>Sat, 04 Nov 2023 11:49:17 +0000</pubDate></item><item><title>How to get a memory dump of a virtual machine from its hypervisor</title><link>https://forum.kaspersky.com/topic/how-to-get-a-memory-dump-of-a-virtual-machine-from-its-hypervisor-36407/</link><description><![CDATA[<h1 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:24px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36463/?do=getNewComment" rel="" style="background-color:transparent;color:#23d1ae;" title="Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. (Click and hold to edit title)"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h1>

<h1 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:24px;padding:0px;">
	<span style="color:#339966;">Description and cautions</span>
</h1>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span style="color:#003366;">This article explains how to save a virtual machine memory dump in different hypervisor environments. You may find this information useful if you need to save a memory dump of an unresponsive or non-booting virtual machine.</span>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span style="color:#003366;">Instructions for each hypervisor environment: </span>
</p>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		<span><span style="color:#000000;">VMware ESXi/vSphere</span></span>
	</li>
	<li>
		<span><span style="color:#000000;">Microsoft Hyper-V</span></span>
	</li>
	<li>
		<span><span style="color:#000000;">Proxmox VE</span></span>
	</li>
	<li>
		<span><span style="color:#000000;">KVM</span></span>
	</li>
	<li>
		<span><span style="color:#000000;">Citrix Hypervisor</span></span>
	</li>
</ul>

<h1 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:24px;padding:0px;">
	<span style="color:#339966;">VMware vSphere</span>
</h1>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	You can do this either via vCenter Client or ESXi host client.
</p>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			Create a snapshot of the VM
		</h4>
		1.1. Right click on the VM in the list of all virtual machines →<span> </span><strong>Snapshots</strong><span> </span>→<span> </span><strong>Take snapshot</strong><br />
		<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.0257d2a71d0afd6be39ce1651b8dc24f.png" data-fileid="13028" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="13028" data-ratio="52.54" width="571" alt="image.thumb.png.c3e8e79a39364008f6dc75535c2167a9.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.c3e8e79a39364008f6dc75535c2167a9.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a><br />
		<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.207c531442782e9de6955d418afd81b2.png" data-fileid="13029" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="13029" data-ratio="25.00" width="700" alt="image.thumb.png.3d7a3d6a7da34705b1c659fde4be4a38.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.3d7a3d6a7da34705b1c659fde4be4a38.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a><br />
		1.2. Check the<span> </span><strong>Snapshot the virtual machine's memory</strong><span><span> </span>checkbox</span>
	</li>
	<li>
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			Download snapshot file.
		</h4>
		2.1. For ESXi:<br />
		2.1.1. Right-click on<span> </span><strong>Storage</strong><span><span> </span>→<span> </span></span><strong>Browse datastores</strong><br />
		2.1.2. Select VM's datastore<br />
		2.1.3. Open VM's folder<br />
		<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.b8b096be1bff0a1937565e55ac5f8d17.png" data-fileid="13030" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="13030" data-ratio="40.43" width="700" alt="image.thumb.png.2f993a3a2b84c076eee61fa6fa85d906.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.2f993a3a2b84c076eee61fa6fa85d906.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a><br />
		2.1.4. Right-click on the newest<span> </span><strong><code>.vmsn</code></strong><span><span> </span>file →<span> </span></span><strong>Download</strong><br />
		2.1.5. Right-click on the newest<span> </span><strong><code>.vmem</code></strong><span><span> </span>file →<span> </span></span><strong>Download</strong><br />
		2.2. For vCenter:<br />
		2.2.1. Open<span> </span><strong>Datastores</strong><span><span> </span>tab of the VM view and click on the datastore listed</span><br />
		<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.4940bac2008ec793fb7adfa29d80a21a.png" data-fileid="13031" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="13031" data-ratio="24.29" width="700" alt="image.thumb.png.20ef6ae1fd68089f06d88187d885bceb.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.20ef6ae1fd68089f06d88187d885bceb.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a><br />
		2.2.2. Open<span> </span><strong>Files</strong><span><span> </span>tab of the datastore view and find the folder of the virtual machine</span><br />
		2.2.3. Select newest<span> </span><code><strong>.vmem</strong></code><span> and<span> </span></span><strong><code>.vmsn</code></strong><span><span> </span>files and click<span> </span></span><strong>Download</strong><a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.fad3f464fd6a3e01797cfe8e0c059eb2.png" data-fileid="13032" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="13032" data-ratio="24.86" width="700" alt="image.thumb.png.702d5d96ba576c291d2c85b6dfd1b8b6.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.702d5d96ba576c291d2c85b6dfd1b8b6.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
	</li>
</ol>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	 
</p>

<h4 style="background-color:#ffffff;color:#000000;font-size:14px;padding:0px;">
	3. Download vmss2core utility.
</h4>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	vmss2core is included with VMWare Workstation, and is available in<span> </span><strong><code>C:\Program Files(x86)\VMware\VMware Workstation\</code></strong><span> </span>on 64-bit versions of Windows<br />
	vmss2core:<span> </span><u><a href="https://flings.vmware.com/vmss2core" rel="external nofollow" style="color:#265951;">https://flings.vmware.com/vmss2core</a></u>
</p>

<h4 style="background-color:#ffffff;color:#000000;font-size:14px;padding:0px;">
	4. Extract the memory dump from downloaded snapshot.
</h4>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	For a snapshot of a VM running:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span>1. Windows 8/Server 2012 and newer </span>
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&lt;path to vmss2core's folder&gt;\vmss2core -W8 &lt;.vmsn file path&gt; &lt;.vmem file path&gt;</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	2. Older versions of Windows 
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&lt;path to vmss2core's folder&gt;\vmss2core -W &lt;.vmsn file path&gt; &lt;.vmem file path&gt;</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	3. Linux 
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&lt;path to vmss2core's folder&gt;\vmss2core -N &lt;.vmsn file path&gt; &lt;.vmem file path&gt;</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	It should save the dump file to the working directory.
</p>

<h1 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:24px;padding:0px;">
	<span style="color:#339966;">Microsoft Hyper-V</span>
</h1>

<div style="border:1px solid #91c89c;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			This method is only applicable to Windows VMs.
		</p>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	To get a memory dump of a Hyper-V virtual machine, you need the kernel debugger included in the Windows SDK.
</p>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			Download Windows SDK Installer and LiveKD to the Hyper-V host.
		</h4>
		Windows SDK Installer:<span> </span><u><a href="https://go.microsoft.com/fwlink/?linkid=2237387" rel="external nofollow" style="color:#265951;">https://go.microsoft.com/fwlink/?linkid=2237387</a></u><br />
		LiveKD:<span> </span><u><a href="https://download.sysinternals.com/files/LiveKD.zip" rel="external nofollow" style="color:#265951;">https://download.sysinternals.com/files/LiveKD.zip</a></u>
	</li>
	<li>
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			Run Windows SDK installer in Powershell:
		</h4>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">.\winsdksetup.exe /features OptionId.WindowsDesktopDebuggers /q /norestart</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			To check if the installation has completed, check the Task Manager while installing the Windows SDK. It should look like the one shown in this screenshot:<br />
			<img class="ipsImage ipsImage_thumbnailed" data-fileid="13033" data-ratio="29.88" width="676" alt="image.png.a0b64e30cc56714b52a411b3eb0a2859.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.a0b64e30cc56714b52a411b3eb0a2859.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /><br />
			Once the SDK installation is complete, the winsdksetup.exe process should disappear.<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.30f9c88434d8eb161e965008fc598e58.png" data-fileid="13034" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="13034" data-ratio="42.92" width="699" alt="image.thumb.png.2579e50d7a3c07289f79b0155d3c04f3.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.2579e50d7a3c07289f79b0155d3c04f3.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
		</p>
	</li>
	<li>
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			Unpack LiveKD.zip by running the following in Powershell:
		</h4>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Expand</code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-Archive</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">LiveKD.zip</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			Set _NT_SYMBOL_PATH environment variable.
		</h4>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">xset _NT_SYMBOL_PATH<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"srv*c:\symbols*<a href="http://msdl.microsoft.com/download/symbols" rel="external nofollow" style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">http://msdl.microsoft.com/download/symbols</a>"</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			Relogin to make the variable available to LiveKD.
		</h4>
	</li>
	<li>
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			Run following to save a memory dump to a specified path on Hyper-V server's storage:
		</h4>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">.\LiveKD\livekd64.exe<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-hv</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&lt;VM Name&gt;<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-k</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&lt;Path to Windows SDK install&gt;\Debuggers\x64<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-p</code><span> </span><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-o</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&lt;Path to save memory dump&gt;</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			 Default Windows SDK path is<span> </span><code><strong>C:\Program Files(x86)\Windows Kits\10.</strong></code>
		</p>
	</li>
	<li>
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			One way to copy the dump is to mount a network drive in Powershell and copy the file to it.
		</h4>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">$cred</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">Get-Credential</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&lt;Domain\username&gt;</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			<span>Get-Credential asks for the password of the specified user and stores the credential used by New-PSDrive in a variable. New-PSDrive mounts an SMB/CIFS share at specified network path as a network drive.</span>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">New-PSDrive</code><span> </span><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-Name</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&lt;Drive Letter&gt;<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-Persist</code><span> </span><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-PSProvider</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">FileSystem<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-Root</code><span> </span><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"&lt;network path&gt;"</code><span> </span><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-Credential</code><span> </span><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">$cred</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
</ol>

<h1 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:24px;padding:0px;">
	<span style="color:#339966;">Proxmox VE</span>
</h1>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			Open<span> </span><strong>Monitor</strong><span> </span>tab of the VM.
		</h4>
	</li>
	<li>
		<h4 style="color:#000000;font-size:14px;padding:0px;">
			To create a dump in ELF format, execute the following:
		</h4>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">dump-guest-memory -d &lt;path to save the<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">file</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&gt;</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.3086c993f10ccc3b48f30fe798d65e88.png" data-fileid="13035" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="13035" data-ratio="35.43" width="700" alt="image.thumb.png.ac753c326a0fb7792a7979b1da04c1d2.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.ac753c326a0fb7792a7979b1da04c1d2.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
		</p>

		<div style="border:1px solid #aab8c6;color:#333333;padding:10px 10px 10px 36px;">
			<div style="padding:0px;">
				<p style="padding:0px;">
					<span>-d detaches the process from the shell, that is needed, which is necessary because Proxmox has a time limit on monitor operations.</span>
				</p>
			</div>
		</div>

		<p style="padding:0px;">
			<span>To create a dump in Windows crashdump format, VM has to be started with a vmcoreinfo device and have latest virtio-win drivers installed. The VM can be started with vmcoreinfo device by running the following in the node's shell:</span>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">echo</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">$(</code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">qm showcmd &lt;VMID&gt;) -device vmcoreinfo |<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo</code><span> </span><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">bash</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-s --</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			<span>If the VM has a TPM configured:</span>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">export</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">VMID=&lt;VMID&gt; &amp;&amp; swtpm socket --tpmstate backend-uri=</code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">file</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">:</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">//</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&lt;path to tpm state<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">file</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&gt;,mode=0600 --ctrl<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">type</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=unixio,path=</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/var/run/qemu-server/</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">$VMID.swtpm,mode=0600 --pid<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">file</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/var/run/qemu-server/</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">$VMID.swtpm.pid --terminate --daemon --log<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">file</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/run/qemu-server/</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">$VMID-swtpm.log,level=1,prefix=[</code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">id</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">=$(</code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">date</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">+%s)] --tpm2 &amp;&amp;<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">echo</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">$(</code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">qm showcmd $VMID) -device vmcoreinfo |<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo</code><span> </span><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">bash</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-s --</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			<span>By default Proxmox creates a Thin provisioned LVM storage, called local-lvm, which path is<span> </span><strong><code>/dev/pve</code></strong><br />
			After that a dump can be created by running the following<span>:</span></span>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">dump-guest-memory -d -w &lt;path to save the file&gt;</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			<span>2.1. Wait until dump file size reaches the amount of ram allocated to the VM, if it is stuck at 0 bytes, it means that the VM couldn't load the vmcoreinfo driver and the only way is to create an ELF dump</span><br />
			<span>To check it run following in Proxmox node's shell, which can be accessed via<span> </span><strong>Shell</strong> tab in node's view:</span>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">watch</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-n 1<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ls</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-al --block-size=M &lt;dump<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">file</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">path&gt;</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.c7ddd5fe050399f6318ca96815c88d25.png" data-fileid="13036" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="13036" data-ratio="17.57" width="700" alt="image.thumb.png.81dc37b9c3a03efbd284ead7982cdbaa.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.81dc37b9c3a03efbd284ead7982cdbaa.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a><br />
			<span>This command will run ls every second showing file's size, it may take some time to show anything, because of the way Proxmox is saving the dump.</span><br />
			<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.63e42cc48391c0172f26c47a6b743894.png" data-fileid="13037" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="13037" data-ratio="6.00" width="700" alt="image.thumb.png.30dd1c36ed37dd49700428b94ab7407a.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.thumb.png.30dd1c36ed37dd49700428b94ab7407a.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
		</p>
	</li>
</ol>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Copy the dump from the node, one way it can be done is by using scp:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">scp</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&lt;user&gt;@&lt;KVM host ip&gt;:&lt;dump<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">file</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">path&gt; &lt;</code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">local</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">path&gt;</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<h1 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:24px;padding:0px;">
	<span style="color:#339966;">KVM</span>
</h1>

<div style="border:1px solid #91c89c;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			This part is applicable for generic KVM servers with libvirt, Alt Server-V, OpenStack, OpenNebula and any other virtualization environments based on them.
		</p>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	To save a memory dump in ELF format to the KVM host, run as root:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">virsh dump --memory-only &lt;name of the vm&gt; &lt;path to dump&gt;</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<div style="border:1px solid #91c89c;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			All virsh commands can be run without sudo, if the user is in libvirt group
		</p>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<img class="ipsImage ipsImage_thumbnailed" data-fileid="13038" data-ratio="18.38" width="691" alt="image.png.5bb9ffe22d142a5f86af12baa5b61a76.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_10/image.png.5bb9ffe22d142a5f86af12baa5b61a76.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	To save a dump in Windows crashdump format, VM has to have latest virtio-win drivers installed and vmcoreinfo feature has to be enabled in VM's configuration file:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">export</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">VMID=&lt;vm name&gt;;<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">export</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">xml_path=</code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"/etc/libvirt/qemu/$VMID.xml"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">;<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo</code><span> </span><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">grep</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">vmcoreinfo $xml_path;<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">if</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">[ $? -</code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ne</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">0 ]; virsh<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">shutdown</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">$VMID;<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">systemctl stop libvirtd;<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">then</code><span> </span><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo</code><span> </span><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sed</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-i<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"s/&lt;features&gt;/&amp;\n    &lt;vmcoreinfo state=\"on\"\/&gt;/"</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">$xml_path;<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">systemctl start libvirtd;<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">virsh start $VMID;<span> </span></code><code style="border:0px;color:#336699;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">fi</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">;</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	After VM boots up (or crashes), run the following to create the dump:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">virsh qemu-monitor-</code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">command</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">dump-guest-memory -w &lt;path to save the<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">file</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">&gt;</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Check dump file size, if it is 0 bytes, it means that the VM couldn't load the vmcoreinfo driver and the only way is to create an ELF dump
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ls</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-al &lt;dump<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">file</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">path&gt;</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Copy the dump from the node, one way it can be done is by using scp:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">scp &lt;user&gt;@&lt;KVM host ip&gt;:&lt;dump file path&gt; &lt;local path&gt;</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<h1 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:24px;padding:0px;">
	<span style="color:#339966;">Citrix Hypervisor</span>
</h1>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	The only way to capture a memory dump in a virtual machine running on Citrix Hypervisor is to use memory dump mechanisms built into the guest OS, but a crash of the guest can be triggered from the hypervisor by running:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">xen-hvmcrash &lt;id&gt;</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<div style="border:1px solid #aab8c6;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			<span>How to collect a full memory dump on Windows:<span> </span><u><a href="https://support.kaspersky.com/common/diagnostics/10659" rel="external nofollow" style="color:#265951;" title="https://support.kaspersky.com/common/diagnostics/10659">https://support.kaspersky.com/common/diagnostics/10659</a></u></span>
		</p>
	</div>
</div>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">36407</guid><pubDate>Fri, 06 Oct 2023 09:58:05 +0000</pubDate></item><item><title>How to create a memory dump in Linux</title><link>https://forum.kaspersky.com/topic/how-to-create-a-memory-dump-in-linux-36406/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/advice-and-solutions-forum-knowledgebase-disclaimer-read-before-using-materials-36463/?do=getNewComment" rel="" style="background-color:transparent;color:#23d1ae;" title="Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. (Click and hold to edit title)"><span style="color:#e74c3c;">Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.</span></a></span>
</h2>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="color:#339966;">Description and cautions</span>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span style="color:#3b3b3b;">This article describes how to configure dump for capturing memory dumps, including application memory.</span>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span style="color:#3b3b3b;">To create a memory dump of a virtual machine:<span> </span><u><a href="https://forum.kaspersky.com/topic/howto-get-a-memory-dump-of-a-virtual-machine-from-its-hypervisor-36407/" rel="">HOWTO: Get a memory dump of a virtual machine from its hypervisor.</a></u></span>
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="color:#339966;">Details</span>
</h2>

<div style="border:1px solid #91c89c;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			The recommended text editor is nano, below is a quick tutorial on how to use it if you are using it for the first time.
		</p>

		<div style="padding:0px;">
			<div style="padding:0px;">
				<span style="border:none;font-size:0px;padding:0px;text-align:left;vertical-align:text-bottom;"> </span><span style="color:#0052cc;vertical-align:top;">Quick description of nano's basic functions</span>
			</div>
		</div>
	</div>
</div>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		Configure kdump
		<ul>
			<li>
				<strong><span style="color:#339966;">Altlinux</span></strong><br />
				There is no kdump-tools package in the default repository, so it has to be downloaded from the sisyphus repository:
				<ul>
					<li>
						Go to<span> </span><u><a href="https://packages.altlinux.org/en/sisyphus/srpms/kdump-tools/" rel="external nofollow" style="color:#265951;">https://packages.altlinux.org/en/sisyphus/srpms/kdump-tools/</a> </u>
					</li>
					<li>
						In<span> </span><strong>List of rpms provided by this srpm</strong><span> </span>select the kdump-tools package for the required architecture (can be checked by running<span> </span><code>uname -m</code>)
					</li>
					<li>
						Download the package from the<span> </span><strong>Download</strong><span> </span>link
					</li>
					<li>
						<p style="padding:0px;">
							Install it by running 
						</p>

						<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
							<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
								<div style="padding:0px;">
									<div style="background-color:#ffffff;font-size:1em;padding:0px;">
										<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
											<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
												<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
													<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
														<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">apt-get update &amp;&amp; apt-get install &lt;path to the downloaded rpm&gt;</code>
															</div>
														</div>
													</td>
												</tr>
											</tbody>
										</table>
									</div>
								</div>
							</div>
						</div>
					</li>
					<li>
						After that, follow the Debian instruction from<span> </span><strong>Edit /etc/default/kdump-tools</strong><span> </span>step
					</li>
				</ul>
			</li>
			<li>
				<span style="color:#339966;"><strong>Red Hat based distributions</strong><span> </span>(tested on Fedora 38, Rocky Linux 9, Red OS)</span>
				<ul>
					<li>
						<p style="padding:0px;">
							Install kexec-tools
						</p>

						<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
							<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
								<div style="padding:0px;">
									<div style="background-color:#ffffff;font-size:1em;padding:0px;">
										<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
											<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
												<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
													<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
														<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo dnf install kexec-tools</code>
															</div>
														</div>
													</td>
												</tr>
											</tbody>
										</table>
									</div>
								</div>
							</div>
						</div>
					</li>
					<li>
						Edit<span> </span><strong><code>/etc/kdump.conf.<span> </span></code></strong><code>I</code>n the configuration file edit the<span> </span><strong>core_collector<span> </span></strong>setting: option -d should be set to 17 instead of 31
					</li>
					<li>
						Edit<span> </span><strong><code>/etc/default/grub.</code></strong><span> </span>Edit<span> </span><strong>GRUB_CMDLINE_LINUX</strong>, add<span> </span><code>crashkernel=256M</code><span> </span>to reserve enough RAM for the dump kernel to run, and<span> </span><code>nmi_watchdog=1</code>, to capture a dump in case of a system hang
					</li>
					<li>
						<p style="padding:0px;">
							Run 
						</p>

						<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
							<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
								<div style="padding:0px;">
									<div style="background-color:#ffffff;font-size:1em;padding:0px;">
										<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
											<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
												<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
													<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
														<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo grub2-mkconfig -o /boot/grub2/grub.cfg</code>
															</div>
														</div>
													</td>
												</tr>
											</tbody>
										</table>
									</div>
								</div>
							</div>
						</div>
					</li>
					<li>
						Reboot
					</li>
					<li>
						<p style="padding:0px;">
							Enable kdump service 
						</p>

						<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
							<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
								<div style="padding:0px;">
									<div style="background-color:#ffffff;font-size:1em;padding:0px;">
										<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
											<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
												<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
													<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
														<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo systemctl enable --now kdump.service</code>
															</div>
														</div>
													</td>
												</tr>
											</tbody>
										</table>
									</div>
								</div>
							</div>
						</div>
					</li>
				</ul>
			</li>
			<li>
				<span style="color:#339966;"><strong>Debian based distributions</strong><span> </span>(tested on Debian, Astra CE, Alt Linux)</span>
				<ul>
					<li>
						<p style="padding:0px;">
							Install kdump-tools 
						</p>

						<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
							<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
								<div style="padding:0px;">
									<div style="background-color:#ffffff;font-size:1em;padding:0px;">
										<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
											<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
												<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
													<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
														<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo apt update &amp;&amp; sudo apt install kdump-tools -y</code>
															</div>
														</div>
													</td>
												</tr>
											</tbody>
										</table>
									</div>
								</div>
							</div>
						</div>
					</li>
					<li>
						Edit<span> </span><code><strong>/etc/default/kdump-tools.<span> </span></strong>I</code>n the configuration file edit the<span> </span><strong>MAKEDUMP_ARGS</strong><span> </span>variable: option -d should be set to 17 instead of 31
					</li>
					<li>
						Configure the bootloader
						<ul>
							<li>
								In<span> </span><strong><code>/etc/default/grub</code></strong><span> </span>edit<span> </span><strong>GRUB_CMDLINE_LINUX_DEFAULT</strong>, add<span> </span><code>nmi_watchdog=1</code> to capture a dump in case of a system hang
							</li>
							<li>
								In<span> </span><strong><code>/etc/default/grub.d/kdump-tools.cfg</code></strong><span> </span>change<span> </span><code>crashkernel</code><span> </span>value to 384M-:256M (default is 384M-:128M)<br />
								Expected result:<span> </span><code>GRUB_CMDLINE_LINUX_DEFAULT="$GRUB_CMDLINE_LINUX_DEFAULT crashkernel=384M-:256M"</code>
							</li>
							<li>
								ave and run<span> </span><code>sudo update-grub</code>
							</li>
						</ul>
					</li>
				</ul>
			</li>
			<li>
				<p style="padding:0px;">
					<span style="color:#339966;"><strong>SUSE Linux</strong></span>
				</p>

				<ul>
					<li>
						<p style="padding:0px;">
							<span style="color:#3b3b3b;">Install kdump</span>
						</p>

						<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
							<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
								<div style="padding:0px;">
									<div style="background-color:#ffffff;font-size:1em;padding:0px;">
										<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
											<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
												<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
													<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
														<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo zypper in kdump kexec-tools</code>
															</div>
														</div>
													</td>
												</tr>
											</tbody>
										</table>
									</div>
								</div>
							</div>
						</div>
					</li>
					<li>
						<span style="color:#3b3b3b;">Edit<span> </span><strong><span style="color:#800000;"><span style="color:#003366;">/etc/sysconfig/kdump</span></span></strong></span><br />
						Change<span> </span><strong><span style="color:#000080;">KDUMP_DUMPLEVEL</span></strong><span style="color:#3b3b3b;"> variable to 17</span>
					</li>
					<li>
						<p style="padding:0px;">
							<span style="color:#3b3b3b;">Edit<span> </span></span><span style="color:#800000;"><code><strong><span style="color:#003366;">/etc/default/grub</span></strong></code></span><br />
							<span style="color:#3b3b3b;">Edit<span> </span></span><strong><span style="color:#000080;">GRUB_CMDLINE_LINUX_DEFAULT</span></strong><span style="color:#3b3b3b;">, add<span> </span><code>crashkernel=256M</code><span> </span>to reserve enough RAM for the dump kernel to run, and<span> </span><code>nmi_watchdog=1</code>, to capture a dump in case of a system hang</span>
						</p>
					</li>
					<li>
						<p style="padding:0px;">
							<span style="color:#3b3b3b;">Update the bootloader configuration</span>
						</p>

						<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
							<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
								<div style="padding:0px;">
									<div style="background-color:#ffffff;font-size:1em;padding:0px;">
										<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
											<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
												<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
													<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
														<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo grub2-mkconfig -o /boot/grub2/grub.cfg</code>
															</div>
														</div>
													</td>
												</tr>
											</tbody>
										</table>
									</div>
								</div>
							</div>
						</div>
					</li>
					<li>
						<p style="padding:0px;">
							<span style="color:#3b3b3b;">Reboot</span>
						</p>
					</li>
					<li>
						<p style="padding:0px;">
							<span style="color:#3b3b3b;">Enable kdump service</span>
						</p>

						<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
							<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
								<div style="padding:0px;">
									<div style="background-color:#ffffff;font-size:1em;padding:0px;">
										<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
											<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
												<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
													<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
														<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
															<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
																<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo systemctl enable --now kdump.service</code>
															</div>
														</div>
													</td>
												</tr>
											</tbody>
										</table>
									</div>
								</div>
							</div>
						</div>
					</li>
				</ul>
			</li>
		</ul>
	</li>
	<li>
		<p style="padding:0px;">
			Configure SysRq dump trigger<br />
			To enable SysRq trigger, these key combinations 'kernel.sysrq = 8'(without quotes) has to be added  to<span> </span><span style="color:#003366;"><code><strong>/etc/sysctl.conf</strong></code></span><span style="color:#3b3b3b;">.</span>
		</p>

		<div style="border:1px solid #d04437;color:#333333;padding:10px 10px 10px 36px;">
			<div style="padding:0px;">
				<p style="padding:0px;">
					<span style="color:#3b3b3b;">In SUSE the value of kernel.sysrq has to be changed in<span> </span></span><span style="color:#003366;"><code><strong>/usr/lib/sysctl.d/50-default.conf</strong></code></span><span style="color:#3b3b3b;"><span> </span>instead of<span> </span></span><span style="color:#003366;"><code><strong>/etc/sysctl.conf</strong></code></span>
				</p>
			</div>
		</div>
	</li>
	<li>
		<p style="padding:0px;">
			<span style="color:#3b3b3b;">Reboot or run </span>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo sysctl --system</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<p style="padding:0px;">
			After the set up above is complete, to manually trigger a dump press Alt+SysRq, Alt+C. Alternatively:
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">echo<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">8</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">| sudo tee /proc/sys/kernel/sysrq</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			<span>(Command above is only needed if kernel.sysrq is not set in<span> </span></span><strong><code>/etc/sysctl.conf</code></strong><span>)</span>
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">echo c | sudo tee /proc/sysrq-trigger</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			 
		</p>
	</li>
	<li>
		<p style="padding:0px;">
			<span>Location of the dump files may vary between different Linux versions, it is configurable in the kdump configuration file. In Debian based distributions it is set by<span> </span></span><strong>KDUMP_COREDIR</strong><span><span> </span>variable. In Red Hat based distributions it is set by the<span> </span></span><strong>path</strong><span><span> </span>setting, generally the default location is /var/crash. Make sure that the dump folder has enough free space for the dump to be written. You may search by filemask: vmcore.</span>
		</p>
	</li>
</ul>
]]></description><guid isPermaLink="false">36406</guid><pubDate>Fri, 06 Oct 2023 09:52:21 +0000</pubDate></item><item><title>&#x41A;&#x430;&#x43A; &#x443;&#x434;&#x430;&#x43B;&#x438;&#x442;&#x44C; AV Blocker &#x441; Windows &#x438; &#x437;&#x430;&#x449;&#x438;&#x442;&#x430; &#x43E;&#x442; &#x437;&#x430;&#x440;&#x430;&#x436;&#x435;&#x43D;&#x438;&#x44F;</title><link>https://forum.kaspersky.com/topic/%D0%BA%D0%B0%D0%BA-%D1%83%D0%B4%D0%B0%D0%BB%D0%B8%D1%82%D1%8C-av-blocker-%D1%81-windows-%D0%B8-%D0%B7%D0%B0%D1%89%D0%B8%D1%82%D0%B0-%D0%BE%D1%82-%D0%B7%D0%B0%D1%80%D0%B0%D0%B6%D0%B5%D0%BD%D0%B8%D1%8F-35477/</link><description><![CDATA[<h2>
	<span style="font-size:16px;">Как удалить AV Blocker, проверить компьютер на вирусы?</span>
</h2>

<ol>
	<li>
		Скачайте утилиту <a href="https://www.kaspersky.ru/downloads/free-virus-removal-tool" title="Переход на сайт «Лаборатории Касперского» для скачивания утилиты Kaspersky Virus Removal Tool" rel="external nofollow">Kaspersky Virus Removal Tool</a> и выполните проверку системы по <a href="https://support.kaspersky.ru/15671" title="15671 :: Как скачать и запустить Kaspersky Virus Removal Tool" rel="external nofollow">инструкции</a>.
	</li>
</ol>

<p>
	<em>Если утилита не запускается, измените название файла на любое другое и попробуйте запустить еще раз. Если проблема сохранится, проверьте систему с помощью Kaspersky Rescue Disk <a href="https://support.kaspersky.ru/14229" title="14229 :: Как проверить компьютер с помощью Kaspersky Rescue Disk 18" rel="external nofollow">по инструкции</a>.</em>
</p>

<ol start="2">
	<li>
		Дождитесь завершения работы утилиты.
	</li>
</ol>

<h2>
	<span style="font-size:16px;">Как защитить компьютер от вирусов?</span>
</h2>

<p>
	Вот основные способы, которые помогут вам в обеспечении безопасности компьютера:
</p>

<ul>
	<li>
		Используйте антивирус. Например <strong><a href="https://www.kaspersky.ru/premium?icid=ru_community_oth_ona_oth__onl_b2c__buylink____kpr___" rel="external nofollow">Kaspersky Premium</a></strong><strong> </strong>(доступен бесплатный триал)
	</li>
	<li>
		Загружайте приложения и программное обеспечение только с доверенных сайтов.
	</li>
	<li>
		Никогда не нажимайте на непроверенные ссылки в спам-сообщениях, почте и на незнакомых веб-сайтах.
	</li>
	<li>
		Не открывайте вложения в спам-сообщениях на ваших устройствах.
	</li>
	<li>
		Вовремя устанавливайте новую версию антивируса и обновляйте установленные приложения и саму операционную систему.
	</li>
	<li>
		Никогда не подключайте к вашему компьютеру неизвестные USB-флешки, не вставляйте неизвестные диски.
	</li>
</ul>

<p>
	 
</p>

<p>
	© Kaspersky
</p>
]]></description><guid isPermaLink="false">35477</guid><pubDate>Fri, 11 Aug 2023 06:34:15 +0000</pubDate></item><item><title><![CDATA[How to remove AV Blocker from Windows & preventing infection]]></title><link>https://forum.kaspersky.com/topic/how-to-remove-av-blocker-from-windows-preventing-infection-35476/</link><description><![CDATA[<h2>
	<span style="font-size:16px;">How to remove AV Blocker? Run a virus scan first</span>
</h2>

<ol>
	<li>
		Download <a href="https://www.kaspersky.com/downloads/free-virus-removal-tool" rel="external nofollow">Kaspersky Virus Removal Tool</a> and run the system check using <a href="https://support.kaspersky.com/15671" rel="external nofollow">the instructions</a>.
	</li>
</ol>

<p>
	<em>If the tool does not start, change the file name and run it once again. If the issue persists, check the system using Kaspersky Rescue Disk according to <a href="https://support.kaspersky.com/14229" rel="external nofollow">the instructions</a>.</em>
</p>

<ol start="2">
	<li>
		Wait until the tool completes its work.
	</li>
</ol>

<h2>
	<span style="font-size:16px;">How to preventing infection?</span>
</h2>

<p>
	<span style="color:#444444;">Here are some basic ways how you can protect your computer from viruses:</span>
</p>

<ul>
	<li>
		Use an antivirus software for malware protection. <span style="color:#444444;"> For example, </span><strong><a href="https://www.kaspersky.com/premium?icid=gl_community_oth_ona_oth__onl_b2c__buylink____kpr___" rel="external nofollow">Kaspersky Premium</a></strong> (free trial available).
	</li>
	<li>
		<span style="color:#444444;">Download applications and software only from trusted websites.</span>
	</li>
	<li>
		<span style="color:#444444;">Never click on any untrusted links in spam messages, emails, or unfamiliar websites.</span>
	</li>
	<li>
		<span style="color:#444444;">Don't open attachments in spam emails.</span>
	</li>
	<li>
		<span style="color:#444444;">Keep your anti-virus up to date and keep your installed applications and operating system up to date.</span>
	</li>
	<li>
		<span style="color:#444444;">When using public Wi-Fi networks, use a secure VPN connection such as </span> <strong><a href="https://www.kaspersky.com/vpn-secure-connection?icid=gl_community_oth_ona_oth__onl_b2c__buylink____ksec___" rel="external nofollow">Kaspersky VPN Secure Connection</a></strong> (free version available).
	</li>
	<li>
		<span style="color:#444444;">Never connect unknown USB sticks to your computer or insert unknown drives.</span>
	</li>
</ul>

<p>
	 
</p>

<p>
	© Kaspersky
</p>
]]></description><guid isPermaLink="false">35476</guid><pubDate>Fri, 11 Aug 2023 06:29:11 +0000</pubDate></item><item><title>Kaspersky does not start after installation of KB5013943</title><link>https://forum.kaspersky.com/topic/kaspersky-does-not-start-after-installation-of-kb5013943-24444/</link><description><![CDATA[<p>
	On May 10th Microsoft released <strong><a href="https://support.microsoft.com/en-gb/topic/may-10-2022-kb5013943-os-build-22000-675-14aa767a-aa87-414e-8491-b6e845541755" rel="external nofollow">KB5013943</a></strong>, <span style="color:rgb(0,0,0);">once installed on <strong>Windows 11</strong>, it may disable .Net 3.5 and the user will not be able to start the Kaspersky product </span>or have trouble installing/uninstalling the product.
</p>

<p>
	<strong>Workarounds</strong>:
</p>

<p>
	Install any available updates for Windows. Perhaps this will solve the problem.
</p>

<p>
	If that doesn't work:
</p>

<p>
	1) Activate .Net using instruction:
</p>

<p>
	<a href="https://docs.microsoft.com/en-us/dotnet/framework/install/dotnet-35-windows#enable-the-net-framework-35-in-control-panel" rel="external nofollow">Activate .NET Framework 3.5 on Windows 11, 10, 8.1, 8 - .NET Framework | Microsoft Docs</a>
</p>

<p>
	2) Or run in CMD (run CMD as administrator):
</p>

<p>
	dism /online /enable-feature /featurename:netfx3 /all
</p>

<p>
	dism /online /enable-feature /featurename:WCF-HTTP-Activation
</p>

<p>
	dism /online /enable-feature /featurename:WCF-NonHTTP-Activation
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">24444</guid><pubDate>Fri, 13 May 2022 06:43:23 +0000</pubDate></item><item><title>Comment effectuer une installation propre d'une application Kaspersky</title><link>https://forum.kaspersky.com/topic/comment-effectuer-une-installation-propre-dune-application-kaspersky-24110/</link><description><![CDATA[<p>
	Pour effectuer une installation propre de Kaspersky , veuillez procéder comme suit svp :<br />
	→ Télécharger votre version Kaspersky → <a href="https://forum.kaspersky.com/topic/acheter-et-t%C3%A9l%C3%A9chargement-des-produits-kaspersky-92/" rel="">Liens de téléchargement</a> <br />
	→ Quitter Kaspersky → Désinstaller Kaspersky → Reboot<br />
	→ Installer Kaspersky → Mise à jour des bases de données →  Reboot
</p>

<p>
	<u>IMPORTANT</u> :<br />
	Si vous désinstallez et réinstallez Kaspersky , ou si vous procédez avec une nouvelle installation durant la période dans laquelle un Patch  est progressivement mis a disposition sur les serveurs K-Lab,  il peut y avoir quelques jours de délai avant que vous obtenez le nouveau Patch.
</p>
]]></description><guid isPermaLink="false">24110</guid><pubDate>Mon, 18 Apr 2022 08:07:35 +0000</pubDate></item><item><title>FAQ on Kaspersky business, solutions and services</title><link>https://forum.kaspersky.com/topic/faq-on-kaspersky-business-solutions-and-services-23712/</link><description><![CDATA[<p>Dear users!</p><div class="notification__content-wrapper">We have prepared <a href="https://support.kaspersky.com/faq/2022hotline" target="_blank" rel="noreferrer noopener">an FAQ page</a> on the status of Kaspersky’s solutions and services.</div>]]></description><guid isPermaLink="false">23712</guid><pubDate>Mon, 21 Mar 2022 10:28:56 +0000</pubDate></item><item><title>Como remover um v&#xED;rus de PC com Windows</title><link>https://forum.kaspersky.com/topic/como-remover-um-v%C3%ADrus-de-pc-com-windows-21836/</link><description><![CDATA[<h3>
	<strong>Ferramenta gratuita de verificação de vírus e remoção de malware.</strong>
</h3>

<p>
	 
</p>

<p>
	Você está preocupado com a possibilidade de haver um vírus no seu computador? Se o seu computador estiver infectado, é importante saber como se livrar de um vírus de computador.
</p>

<p>
	<a href="https://forum.kaspersky.com/topic/como-remover-ransomware-do-windows-pc-21835/" rel="">Leia como remover Ransomware, descriptografar arquivos, proteção de criptografia -&gt;</a>
</p>

<p>
	 
</p>

<h2>
	Como se livrar de um vírus de computador? Execute uma verificação de vírus primeiro
</h2>

<p>
	 
</p>

<p>
	Antes de limpar o seu PC com Windows de vírus, você deve primeiro fazer uma varredura.
</p>

<p>
	Aqui está como fazer isso:
</p>

<ol>
	<li>
		Se você tiver um software de segurança que não seja da Kaspersky instalado, execute uma verificação de vírus em seu PC usando a Ferramenta de Remoção de Vírus Kaspersky. <a href="https://support.kaspersky.com/15674" rel="external nofollow">Veja as instruções</a>.
	</li>
</ol>

<ol start="2">
	<li>
		Se você tiver o software de segurança Kaspersky instalado:
	</li>
</ol>

<ul>
	<li>
		Verifique se a “Detecção de software que pode ser usado por criminosos” em nossas configurações de produto está habilitada.
	</li>
</ul>

<ul>
	<li>
		Atualize os bancos de dados do produto.
	</li>
</ul>

<ul>
	<li>
		Execute uma verificação completa. Assim que a verificação for concluída, remova todas as ameaças ou malware encontrados. Se você for solicitado a executar um tratamento com uma reinicialização, selecione esta opção.
	</li>
</ul>

<p>
	 
</p>

<table>
	<tbody>
		<tr>
			<td style="width:471px;">
				<p>
					<strong>Deseja remoção profissional de vírus com um especialista da Kaspersky?</strong> Consulte nossas opções de <strong>Suporte Premium</strong> que incluem remoção de vírus, serviços de <strong>suporte remoto</strong> e muito mais <strong><a href="https://cart.kaspersky.com.br/checkout/add?products=63681dd3-9ebc-412a-b9b0-fd7dc715e294&amp;icid=br_community_oth_ona_oth__onl_b2c__buylink____kpss___" rel="external nofollow">aqui</a></strong>.
				</p>
			</td>
		</tr>
	</tbody>
</table>

<p>
	 
</p>

<p>
	 
</p>

<h2>
	Como proteger seu computador contra vírus
</h2>

<p>
	 
</p>

<p>
	Aqui estão algumas maneiras básicas de como você pode proteger seu computador contra vírus:
</p>

<ul>
	<li>
		Use uma solução antivírus ou de classe de segurança da Internet. Por exemplo, <strong><a href="https://www.kaspersky.com.br/premium?icid=br_community_oth_ona_oth__onl_b2c__buylink____kpr___" rel="external nofollow">Kaspersky Premium</a></strong>.
	</li>
</ul>

<ul>
	<li>
		Baixe aplicativos e software apenas de sites confiáveis.
	</li>
</ul>

<ul>
	<li>
		Nunca clique em links não confiáveis em mensagens de spam, e-mails ou sites desconhecidos.
	</li>
</ul>

<ul>
	<li>
		Não abra anexos em e-mails de spam.
	</li>
</ul>

<ul>
	<li>
		Mantenha o seu antivírus atualizado e os aplicativos instalados e o sistema operacional atualizados.
	</li>
</ul>

<ul>
	<li>
		Ao usar redes Wi-Fi públicas, use uma conexão VPN segura, como <strong><a href="https://www.kaspersky.com.br/vpn-secure-connection?icid=br_community_oth_ona_oth__onl_b2c__buylink____ksec___" rel="external nofollow">Kaspersky VPN Secure Connection</a></strong>.
	</li>
</ul>

<ul>
	<li>
		Nunca conecte pen drives desconhecidos ao seu computador ou insira drives desconhecidos.
	</li>
</ul>

<p>
	 
</p>

<p>
	© Kaspersky
</p>
]]></description><guid isPermaLink="false">21836</guid><pubDate>Wed, 01 Dec 2021 05:47:24 +0000</pubDate></item><item><title>Como remover Ransomware do Windows PC</title><link>https://forum.kaspersky.com/topic/como-remover-ransomware-do-windows-pc-21835/</link><description><![CDATA[<h3><strong>Proteção e Remoção de Ameaças de Ransomware.</strong></h3><p> </p><p>A infecção por ransomware significa que seus dados foram criptografados ou seu sistema operacional está sendo bloqueado por cibercriminosos. Esses criminosos geralmente exigem um resgate em troca de descriptografar os dados. O <a href="https://www.kaspersky.com/resource-center/threats/ransomware" rel="noreferrer noopener" target="_blank">ransomware</a> pode entrar em um dispositivo de muitas maneiras diferentes. As rotas mais comuns incluem infecções de sites maliciosos, add-ons indesejados em downloads e spam. Os alvos de ataques de ransomware incluem indivíduos e empresas. Várias medidas podem ser tomadas <a href="https://www.kaspersky.com/resource-center/threats/how-to-prevent-ransomware" rel="noreferrer noopener" target="_blank">para proteger contra ataques de ransomware</a>, com um olhar atento e o software certo sendo passos importantes na direção certa. Um ataque de ransomware significa perda de dados, gasto de grandes somas de dinheiro ou ambos.</p><p> </p><h2>Como detectar ransomware e se proteger contra ele</h2><p> </p><p>Quando se trata de proteção contra ransomware, é melhor prevenir do que remediar. Para conseguir isso, um olhar atento e o <a href="https://www.kaspersky.com/anti-ransomware-tool" rel="noreferrer noopener" target="_blank">software de segurança correto</a> são essenciais. As varreduras de vulnerabilidades também podem ajudá-lo a encontrar intrusos em seu sistema. Primeiro, é importante certificar-se de que seu computador não seja um alvo ideal para ransomware. O software do dispositivo deve estar sempre atualizado para se beneficiar dos patches de segurança mais recentes. Além disso, uma ação cuidadosa, especialmente em relação a sites desonestos e anexos de e-mail, é vital. Mas mesmo as melhores medidas preventivas podem falhar, tornando ainda mais essencial ter um plano de contingência. No caso do ransomware, um plano de contingência consiste em fazer um backup dos seus dados. Para saber como criar um backup e quais medidas adicionais você pode adotar para proteger seu dispositivo, leia o artigo <a href="https://www.kaspersky.com/resource-center/threats/how-to-prevent-ransomware" rel="noreferrer noopener" target="_blank">Proteção contra ransomware: como manter seus dados seguros em 2021</a>.</p><p> </p><h2>Removendo cavalos de Troia criptografados e descriptografando dados - como isso é feito</h2><p> </p><p> Se o ransomware for detectado antes de um resgate ser exigido, você tem a vantagem de poder excluir o malware. Os dados que foram criptografados até este ponto permanecem criptografados, mas o vírus ransomware pode ser interrompido. A detecção precoce significa que o malware pode ser impedido de se espalhar para outros dispositivos e arquivos.</p><p> </p><p>Se você fizer backup de seus dados externamente ou no armazenamento em nuvem, poderá recuperar seus dados criptografados. Mas o que você pode fazer se não tiver um backup de seus dados? Recomendamos que você entre em contato com o provedor de sua solução de segurança na Internet. Pode já haver uma ferramenta de descriptografia para o ransomware do qual você foi vítima. Você também pode visitar o site do projeto <a href="https://www.nomoreransom.org/" rel="noreferrer noopener" target="_blank">No More Ransom</a>. Esta iniciativa de todo o setor foi lançada para ajudar todas as vítimas de ransomware.</p><p> </p><p>&#x00a9; Kaspersky</p>]]></description><guid isPermaLink="false">21835</guid><pubDate>Wed, 01 Dec 2021 05:39:26 +0000</pubDate></item><item><title>C&#xF3;mo eliminar Ransomware de una PC con Windows</title><link>https://forum.kaspersky.com/topic/c%C3%B3mo-eliminar-ransomware-de-una-pc-con-windows-21011/</link><description><![CDATA[<h3><strong>Protección y eliminación de amenazas de ransomware.</strong></h3><p> </p><p>La infección por ransomware significa que sus datos se han cifrado o que los ciberdelincuentes están bloqueando su sistema operativo. Estos delincuentes suelen exigir un rescate a cambio de descifrar los datos. El <a href="https://www.kaspersky.com/resource-center/threats/ransomware?_ga=2.123618253.79669725.1630689632-895289328.1621160621" rel="noreferrer noopener" target="_blank">ransomware</a> puede llegar a un dispositivo de muchas formas diferentes. Las rutas más comunes incluyen infecciones de sitios web maliciosos, complementos no deseados en descargas y spam. Los objetivos de los ataques de ransomware incluyen tanto a personas como a empresas. Se pueden tomar varias medidas para <a href="https://www.kaspersky.com/resource-center/threats/how-to-prevent-ransomware?_ga=2.123618253.79669725.1630689632-895289328.1621160621" rel="noreferrer noopener" target="_blank">protegerse contra los ataques de ransomware</a>, con ojo avizor y el software adecuado como pasos importantes en la dirección correcta. Un ataque de ransomware significa la pérdida de datos, el gasto de grandes sumas de dinero o ambas cosas.</p><p> </p><p><strong>Cómo detectar ransomware y protegerse de él</strong></p><p> </p><p>Cuando se trata de protegerse contra el ransomware, es mejor prevenir que curar. Para lograrlo, es fundamental contar con ojo avizor y el <a href="https://www.kaspersky.com/anti-ransomware-tool" rel="noreferrer noopener" target="_blank">software de seguridad adecuado</a>. Los análisis de vulnerabilidades también pueden ayudarlo a encontrar intrusos en su sistema. Primero, es importante asegurarse de que su computadora no sea un objetivo ideal para el ransomware. El software del dispositivo debe mantenerse siempre actualizado para poder beneficiarse de los últimos parches de seguridad. Además, es vital actuar con cuidado, especialmente con respecto a los sitios web fraudulentos y los archivos adjuntos de correo electrónico. Pero incluso las mejores medidas preventivas pueden fallar, por lo que es aún más esencial tener un plan de contingencia. En el caso del ransomware, un plan de contingencia consiste en tener una copia de seguridad de tus datos. Para saber cómo crear una copia de seguridad y qué medidas adicionales puede implementar para proteger su dispositivo, lea el artículo <a href="https://www.kaspersky.com/resource-center/threats/how-to-prevent-ransomware?_ga=2.48263136.79669725.1630689632-895289328.1621160621" rel="noreferrer noopener" target="_blank">Protección contra ransomware: cómo mantener sus datos seguros en 2021</a>.</p><p> </p><p><strong>Eliminación de troyanos de cifrado y descifrado de datos: cómo se hace</strong></p><p> </p><p>Si el ransomware se detecta antes de que se exija un rescate, tiene la ventaja de poder eliminar el malware. Los datos cifrados hasta este momento permanecen cifrados, pero el virus ransomware puede detenerse. La detección temprana significa que se puede evitar que el malware se propague a otros dispositivos y archivos.</p><p> </p><p>Si realiza una copia de seguridad de sus datos externamente o en un almacenamiento en la nube, podrá recuperar sus datos cifrados. Pero, ¿qué puede hacer si no tiene una copia de seguridad de sus datos? Le recomendamos que se ponga en contacto con el proveedor de su solución de seguridad de Internet. Es posible que ya exista una herramienta de descifrado para el ransomware del que ha sido víctima. También puede visitar el sitio web del proyecto <a href="https://www.nomoreransom.org/es/index.html" rel="noreferrer noopener" target="_blank">No More Ransom</a>. Esta iniciativa de toda la industria se lanzó para ayudar a todas las víctimas del ransomware.</p><p> </p><p>&#x00a9; Kaspersky</p>]]></description><guid isPermaLink="false">21011</guid><pubDate>Tue, 19 Oct 2021 14:08:32 +0000</pubDate></item><item><title>&#x5982;&#x4F55;&#x4ECE; Windows &#x8BA1;&#x7B97;&#x673A;&#x4E2D;&#x79FB;&#x9664;&#x52D2;&#x7D22;&#x8F6F;&#x4EF6;&#xFF0C;&#x89E3;&#x5BC6;&#x6587;&#x4EF6;&#x4EE5;&#x53CA;&#x6570;&#x636E;&#x52A0;&#x5BC6;&#x9632;&#x62A4;&#xFF1F;</title><link>https://forum.kaspersky.com/topic/%E5%A6%82%E4%BD%95%E4%BB%8E-windows-%E8%AE%A1%E7%AE%97%E6%9C%BA%E4%B8%AD%E7%A7%BB%E9%99%A4%E5%8B%92%E7%B4%A2%E8%BD%AF%E4%BB%B6%EF%BC%8C%E8%A7%A3%E5%AF%86%E6%96%87%E4%BB%B6%E4%BB%A5%E5%8F%8A%E6%95%B0%E6%8D%AE%E5%8A%A0%E5%AF%86%E9%98%B2%E6%8A%A4%EF%BC%9F-21010/</link><description><![CDATA[<p>勒索软件感染的迹象就是您的数据文件均被加密或者操作系统被犯罪分子锁定。这些犯罪分子通常要求赎金来换取解密数据。勒索软件可以通过多种不同方式进入设备。最常见的途径包括来自恶意网站的感染、下载安装不需要的浏览器加载项和垃圾邮件。勒索软件攻击的目标包括个人和公司。可以采取各种措施来防止勒索软件攻击，仔细甄别与正确的使用软件习惯，是朝着防勒索方向迈出的重要一步。 勒索软件攻击意味着您数据丢失、花费大量资金，或两者兼而有之。</p><p> </p><h2>如何检测勒索软件并保护自己免受感染</h2><p> </p><p>在防范勒索软件方面，预防胜于治疗。 为了实现这一目标，仔细甄别与使用正确的安全软件至关重要。漏洞扫描还可以帮助您找到系统中的薄弱环节。首先，确保您的计算机不是勒索软件的理想目标，这点很重要。设备软件应始终保持最新状态，以便从最新的安全补丁中受益。此外，谨慎的行动，尤其是针对流氓网站和电子邮件附件的行动，也至关重要。但即使是最好的预防措施也可能失败，因此制定应急计划变得更加重要。对于勒索软件，应急计划包括备份您的数据。要了解如何创建备份以及您可以采取哪些其他措施来保护您的设备，请阅读文章 <a href="https://www.kaspersky.com/resource-center/threats/how-to-prevent-ransomware" rel="noreferrer noopener" target="_blank">勒索软件保护：如何在 2021 年确保您的数据安全</a>。</p><h2> <br />删除加密木马和解密数据 - 这是是如何做到的？</h2><p> </p><p>如果在索要赎金界面出现之前检测到勒索软件，您就可以删除恶意软件。 到目前为止已加密的数据仍保持加密状态，但可以阻止勒索软件病毒进一步加密文件。早期检测意味着可以防止恶意软件传播到其它设备和文件。</p><p>如果您在外部或云存储中备份您的数据，您将能够恢复被加密的数据。 但是，如果您没有数据备份，您能做什么？ 我们建议您联系您的互联网安全解决方案提供商。在那里可能已经有了解密工具来帮助那些成为勒索软件的受害者们。 您还可以访问 <a href="https://www.nomoreransom.org/" rel="noreferrer noopener" target="_blank">No More Ransom</a> 项目的网站。 这项全行业倡议旨在帮助勒索软件的所有受害者们。</p><p>&#x00a9; Kaspersky</p>]]></description><guid isPermaLink="false">21010</guid><pubDate>Tue, 19 Oct 2021 14:06:40 +0000</pubDate></item><item><title>Hoe ransomware van een Windows-PC verwijderen</title><link>https://forum.kaspersky.com/topic/hoe-ransomware-van-een-windows-pc-verwijderen-21009/</link><description><![CDATA[<h3><strong>Bescherming en verwijdering van Ransomware bedreigingen.</strong></h3><p> </p><p>Ransomware-infectie betekent dat uw gegevens zijn versleuteld of dat uw besturingssysteem wordt geblokkeerd door cybercriminelen. Deze criminelen eisen meestal losgeld in ruil voor het ontsleutelen van de gegevens. <a href="https://www.kaspersky.nl/resource-center/threats/ransomware" rel="noreferrer noopener" target="_blank">Ransomware</a> kan op veel verschillende manieren zijn weg naar een apparaat vinden. De meest voorkomende routes zijn infecties afkomstig van kwaadaardige websites , ongewenste add-ons in downloads en spam . Doelwitten van ransomware-aanvallen zijn zowel individuen als bedrijven. Een  waakzaam oog en de juiste software zijn belangrijke stappen in de goede richting om zich te <a href="https://www.kaspersky.nl/resource-center/threats/how-to-prevent-ransomware" rel="noreferrer noopener" target="_blank">beschermen tegen ransomware-aanvallen</a> . Een ransomware-aanval betekent ofwel het verlies van gegevens , het uitgeven van grote sommen geld, of beide .</p><p> </p><h2>Hoe u ransomware kan detecteren en uzelf ertegen  beschermen?</h2><p> </p><p>Als het gaat om bescherming tegen ransomware, is voorkomen beter dan genezen. Om dit te bereiken zijn een waakzaam oog en de <a href="https://www.kaspersky.nl/anti-ransomware-tool" rel="noreferrer noopener" target="_blank">juiste beveiligingssoftware</a> cruciaal. Kwetsbaarheidsscans kunnen u ook helpen om indringers in uw systeem te vinden. Het is vooral belangrijk om ervoor te zorgen dat uw computer geen ideaal doelwit is voor ransomware. Apparaatsoftware moet altijd up-to-date worden gehouden dit om te kunnen beschikken over de nieuwste beveiligingspatches . Daarbovenop is zorgvuldige actie, vooral met betrekking tot malafide websites en e-mailbijlagen, van vitaal belang. Maar zelfs de beste preventieve maatregelen kunnen mislukken, waardoor het des te belangrijker is om een ​​noodplan te hebben. In het geval van ransomware is een essentiëel noodplan de beschikbaarheid  van een back-up van uw gegevens. Voor meer informatie over het maken van een back-up en welke aanvullende maatregelen u kan nemen om uw apparaat te beschermen, kan u dit artikel raadplegen <a href="https://www.kaspersky.nl/resource-center/threats/how-to-prevent-ransomware" rel="noreferrer noopener" target="_blank">Bescherming tegen ransomware: hoe u uw gegevens in 2021 veilig houdt</a> .</p><p> </p><h2>Versleutelde Trojaanse paarden verwijderen en gegevens ontsleutelen – zo werkt het</h2><p> </p><p>Als de ransomware wordt gedetecteerd voordat er losgeld wordt geëist, heeft u het voordeel dat u de malware kunt verwijderen. De gegevens die tot nu toe zijn versleuteld, blijven versleuteld, maar het ransomware-virus kan worden gestopt. Vroege detectie betekent dat kan worden voorkomen dat de malware zich naar andere apparaten en bestanden verspreidt.</p><p>Als u een externe back-up van uw gegevens of in cloudopslag maakt, kunt u uw versleutelde gegevens herstellen. Maar wat kunt u doen als u geen back-up van uw gegevens heeft? We raden u aan contact op te nemen met de provider van uw internetbeveiligingsoplossing . Er is mogelijks reeds een decoderingstool berschikbaar voor de ransomware waarvan u het slachtoffer bent geworden. U kan ook de website van het <a href="https://www.nomoreransom.org/nl/index.html" rel="noreferrer noopener" target="_blank">No More Ransom</a>  project bezoeken. Dit  branchebreed initiatief is gelanceerd om alle slachtoffers van ransomware te helpen.</p><p> </p><p>&#x00a9; Kaspersky</p>]]></description><guid isPermaLink="false">21009</guid><pubDate>Tue, 19 Oct 2021 14:05:08 +0000</pubDate></item><item><title>Comment supprimer Ransomware sur un PC Windows</title><link>https://forum.kaspersky.com/topic/comment-supprimer-ransomware-sur-un-pc-windows-21008/</link><description><![CDATA[<h3>Protection et suppression des menaces de ransomware.</h3><p> </p><p>Une infection par ransomware signifie que vos données ont été cryptées ou que votre système d'exploitation est bloqué par des cybercriminels. Ces criminels demandent généralement une rançon en échange du décryptage des données. <a href="https://www.kaspersky.fr/resource-center/threats/ransomware" rel="noreferrer noopener" target="_blank">Les ransomwares</a> peuvent se frayer un chemin sur un appareil de différentes manières. Les voies les plus courantes incluent les infections provenant de sites Web malveillants , les modules complémentaires indésirables dans les téléchargements et le spam . Les cibles des attaques de ransomware incluent à la fois les particuliers et les entreprises. Diverses mesures peuvent être prises pour se <a href="https://www.kaspersky.fr/resource-center/threats/ransomware" rel="noreferrer noopener" target="_blank">protéger contre les attaques de ransomware</a> , avec un œil vigilant et le bon logiciel sont les pas importants dans la bonne direction. Une attaque de ransomware signifie soit la perte de données , le déboursment d’une grosse sommes d'argent, soit les deux .</p><p> </p><h2>Comment détecter les ransomwares et s'en protéger</h2><p> </p><p>Lorsqu'il s'agit de se protéger contre les ransomwares, mieux vaut prévenir que guérir. Pour y parvenir, un œil vigilant et le <a href="https://www.kaspersky.com/anti-ransomware-tool" rel="noreferrer noopener" target="_blank">bon logiciel de sécurité</a> sont essentiels. Les analyses de vulnérabilité peuvent également vous aider à trouver des intrus dans votre système. Tout d'abord, il est important de vous assurer que votre ordinateur n'est pas une cible idéale pour les ransomwares. Le logiciel de l'appareil doit toujours être mis à jour afin de bénéficier des derniers correctifs de sécurité . En outre, une action prudente, en particulier en ce qui concerne les sites Web malveillants et les pièces jointes aux e-mails, est vitale. Mais même les meilleures mesures préventives peuvent échouer, ce qui rend d'autant plus essentiel un plan d'urgence. Dans le cas d'un ransomware, un plan d'urgence consiste à avoir une sauvegarde de vos données. Pour savoir comment créer une sauvegarde et quelles mesures supplémentaires vous pouvez mettre en place pour protéger votre appareil, lisez l'article <a href="https://www.kaspersky.fr/resource-center/threats/how-to-prevent-ransomware" rel="noreferrer noopener" target="_blank">Protection contre les ransomwares : comment protéger vos données en 2021</a> .</p><p> </p><h2>Supprimer les chevaux de Troie de chiffrement et déchiffrer les données – comment procéder</h2><p> </p><p>Si le ransomware est détecté avant qu'une rançon ne soit demandée, vous avez l'avantage de pouvoir supprimer le malware. Les données qui ont été cryptées jusqu'à présent restent cryptées, mais le virus ransomware peut être arrêté. La détection précoce signifie que le malware peut être empêché de se propager à d'autres appareils et fichiers.</p><p>Si vous sauvegardez vos données sur un support externe ou dans un stockage cloud, vous pourrez récupérer vos données cryptées. Mais que pouvez-vous faire si vous n'avez pas de sauvegarde de vos données ? Nous vous recommandons de contacter le fournisseur de votre solution de sécurité Internet . Il existe peut-être déjà un outil de décryptage pour le ransomware dont vous avez été victime, vous pouvez à ce sujet visiter le site Web du projet <a href="https://www.nomoreransom.org/fr/index.html" rel="noreferrer noopener" target="_blank">No More Ransom</a> . Cette initiative à l'échelle de l'industrie a été lancée pour aider toutes les victimes de ransomware.</p><p> </p><p>&#x00a9; Kaspersky</p>]]></description><guid isPermaLink="false">21008</guid><pubDate>Tue, 19 Oct 2021 14:03:11 +0000</pubDate></item><item><title>Wie wird Ransomware von einem Windows-PC entfernt</title><link>https://forum.kaspersky.com/topic/wie-wird-ransomware-von-einem-windows-pc-entfernt-21007/</link><description><![CDATA[<h3>Schutz und Beseitigung von Ransomware-Bedrohungen.</h3><p> </p><p>Eine Ransomware-Infektion bedeutet, dass <strong>Ihre Daten verschlüsselt wurden</strong> oder <strong>Ihr Betriebssystem</strong> von Cyberkriminellen blockiert wird. Diese Kriminellen verlangen in der Regel ein Lösegeld als Gegenleistung für die Entschlüsselung der Daten. <a href="https://www.kaspersky.com/resource-center/threats/ransomware" rel="noreferrer noopener" target="_blank">Ransomware</a> kann auf vielen verschiedenen Wegen auf ein Gerät gelangen. Zu den häufigsten gehören <strong>Infektionen über bösartige Websites</strong>, unerwünschte Add-ons in <strong>Downloads</strong> und <strong>Spam</strong>. Zu den Zielen von Ransomware-Angriffen gehören sowohl Privatpersonen als auch Unternehmen. Zum <a href="https://www.kaspersky.com/resource-center/threats/how-to-prevent-ransomware" rel="noreferrer noopener" target="_blank">Schutz vor Ransomware-Angriffen</a> können verschiedene Maßnahmen ergriffen werden, wobei <strong>ein wachsames Auge</strong> und <strong>die richtige Software</strong> wichtige Schritte in die richtige Richtung sind. Ein Ransomware-Angriff bedeutet entweder den <strong>Verlust von Daten</strong>, die <strong>Ausgabe hoher Geldsummen</strong> oder <strong>beides</strong>.</p><h2> <br />Wie man Ransomware erkennt und sich vor ihr schützt</h2><p> </p><p>Wenn es um den Schutz vor Ransomware geht, ist Vorbeugen besser als Heilen. Um dies zu erreichen, sind ein <strong>wachsames Auge</strong> und <a href="https://www.kaspersky.com/anti-ransomware-tool" rel="noreferrer noopener" target="_blank">die richtige Sicherheitssoftware</a> von entscheidender Bedeutung. Auch Schwachstellen-Scans können Ihnen helfen, Eindringlinge in Ihrem System zu finden. Zunächst ist es wichtig sicherzustellen, dass Ihr Computer kein ideales Ziel für Ransomware ist. Die Gerätesoftware sollte immer auf dem neuesten Stand gehalten werden, um von den neuesten Sicherheits-Patches zu profitieren. Darüber hinaus ist ein vorsichtiges Vorgehen, insbesondere im Hinblick auf unseriöse Websites und E-Mail-Anhänge, unerlässlich. Aber auch die besten Präventivmaßnahmen können versagen, weshalb es umso wichtiger ist, einen Notfallplan zu haben. Im Falle von Ransomware besteht ein Notfallplan darin, ein Backup Ihrer Daten zu erstellen. Wie Sie ein Backup erstellen und welche zusätzlichen Maßnahmen Sie ergreifen können, um Ihr Gerät zu schützen, erfahren Sie im Artikel <a href="https://www.kaspersky.com/resource-center/threats/how-to-prevent-ransomware" rel="noreferrer noopener" target="_blank">Ransomware-Schutz: So sind Ihre Daten im Jahr 2021 sicher</a>.</p><h2> <br />Entfernen von Verschlüsselungs-Trojanern und Entschlüsseln von Daten - so wird's gemacht</h2><p> </p><p>Wenn die Ransomware erkannt wird, bevor ein Lösegeld gefordert wird, haben Sie den Vorteil, dass Sie die Malware löschen können. Die bis zu diesem Zeitpunkt verschlüsselten Daten bleiben verschlüsselt, aber der Ransomware-Virus kann gestoppt werden. Durch eine frühzeitige Erkennung kann verhindert werden, dass sich die Malware auf andere Geräte und Dateien ausbreitet.</p><p>Wenn Sie Ihre Daten extern oder in einem Cloud-Speicher sichern, können Sie Ihre verschlüsselten Daten wiederherstellen. Aber was können Sie tun, wenn Sie keine Sicherungskopie Ihrer Daten haben? Wir empfehlen, dass Sie sich an den Anbieter Ihrer <strong>Internet-Sicherheitslösung</strong> wenden. Möglicherweise gibt es bereits ein <strong>Entschlüsselungstool</strong> für die Ransomware, der Sie zum Opfer gefallen sind. Sie können auch die Website des <a href="https://www.nomoreransom.org/" rel="noreferrer noopener" target="_blank">No More Ransom</a>-Projekts besuchen. Diese branchenweite Initiative wurde ins Leben gerufen, um allen Opfern von Ransomware zu helfen.</p><p> </p><p>&#x00a9; Kaspersky</p>]]></description><guid isPermaLink="false">21007</guid><pubDate>Tue, 19 Oct 2021 14:00:59 +0000</pubDate></item><item><title>Come rimuovere un Ransomware dal PC Windows</title><link>https://forum.kaspersky.com/topic/come-rimuovere-un-ransomware-dal-pc-windows-21006/</link><description><![CDATA[<div class="post__content js-content--original qa-topic-post-content post__content--new-editor"><h3><strong>Protezione e rimozione delle minacce Ransomware.</strong></h3><p> </p><p>Un infezione ransomware significa che i tuoi <strong>dati sono stati crittografati</strong> o il tuo <strong>sistema operativo</strong> è stato <strong>bloccato</strong> dai criminali informatici. Questi criminali di solito richiedono un riscatto in cambio della decrittografia dei dati. <a href="https://www.kaspersky.com/resource-center/threats/ransomware" rel="noreferrer noopener" target="_blank">Il ransomware</a> può infettare un dispositivo in modi diversi. I percorsi più comuni includono <strong>infezioni da siti Web dannosi</strong>, componenti aggiuntivi indesiderati nei <strong>download</strong> e <strong>spam</strong>. Gli obiettivi degli attacchi ransomware includono sia gli utenti privati che le aziende. Varie misure possono essere prese per <a href="https://www.kaspersky.com/resource-center/threats/how-to-prevent-ransomware?_ga=2.151499760.819634960.1632983771-680390782.1632983771" rel="noreferrer noopener" target="_blank"><strong>proteggersi dagli attacchi ransomware</strong></a>, con un occhio <strong>vigile</strong> e con il <strong>software giusto</strong> sono i primi  passi importanti nella giusta direzione. Un attacco ransomware significa  <strong>perdita di dati</strong>, <strong>spendendo grandi somme di denaro o</strong> <strong>entrambi</strong>.</p><p> </p><h2>Come rilevare il ransomware e proteggersi da esso</h2><p> </p><p>Quando si tratta di proteggere dal ransomware, prevenire è meglio che curare. Per raggiungere questo obiettivo, un <strong>occhio vigile</strong> e il <a href="https://www.kaspersky.com/anti-ransomware-tool" rel="noreferrer noopener" target="_blank"><strong>giusto software di sicurezza</strong> </a>sono fondamentali. Le scansioni delle vulnerabilità possono anche aiutarti a trovare intrusi nel tuo sistema. Innanzitutto, è importante assicurarsi che il computer non sia un bersaglio ideale per il ransomware. Il software del dispositivo deve essere sempre aggiornato per poter beneficiare delle <strong>ultime patch di sicurezza.</strong> Inoltre, un'azione attenta, in particolare per quanto riguarda i siti Web canaglia e gli allegati e-mail, è vitale. Ma anche le migliori misure preventive possono fallire, rendendo ancora più essenziale avere un piano di emergenza. Nel caso di ransomware, un piano di emergenza consiste nell'avere <strong>un backup dei tuoi dati</strong>. Per sapere come creare un backup e quali misure aggiuntive puoi mettere in atto per proteggere il tuo dispositivo, leggi l'articolo <a href="https://www.kaspersky.com/resource-center/threats/how-to-prevent-ransomware" rel="noreferrer noopener" target="_blank"><strong>Protezione da ransomware: come mantenere i tuoi dati al sicuro nel 2021</strong></a>.</p><p> </p><h2>Rimozione di Trojan di crittografia e decrittografia dei dati - come funziona</h2><p> </p><p>Se il ransomware viene rilevato prima che venga richiesto un riscatto, si ha il vantaggio di poter eliminare il malware. I dati che sono stati crittografati fino a questo punto rimangono crittografati, ma il virus ransomware può essere fermato. Il rilevamento precoce significa che il malware può essere impedito di diffondersi ad altri dispositivi e file.</p><p>Se si eseguire il backup dei dati esternamente o nel cloud storage, sarà possibile recuperare i dati crittografati. Ma cosa puoi fare se non hai un backup dei tuoi dati? Ti consigliamo di contattare il fornitore della tua soluzione di <strong>sicurezza Internet</strong>. Potrebbe già esserci uno <strong>strumento di decrittazione</strong> per il ransomware di cui sei caduto vittima. Puoi anche visitare il sito web del progetto <a href="https://www.nomoreransom.org/" rel="noreferrer noopener" target="_blank"><strong>No More Ransom.</strong> </a>Questa iniziativa a livello di settore è stata lanciata per aiutare tutte le vittime del ransomware.</p><p> </p><p>&#x00a9; Kaspersky</p></div>]]></description><guid isPermaLink="false">21006</guid><pubDate>Tue, 19 Oct 2021 13:58:13 +0000</pubDate></item><item><title>C&#xF3;mo eliminar un virus de una PC con Windows</title><link>https://forum.kaspersky.com/topic/c%C3%B3mo-eliminar-un-virus-de-una-pc-con-windows-20744/</link><description><![CDATA[<h3>
	<strong>Escáner de virus y herramienta de eliminación de malware gratuitos.</strong>
</h3>

<p>
	 
</p>

<p>
	¿Le preocupa que pueda haber un virus en su computadora? Si su computadora está infectada, es importante saber cómo deshacerse de un virus informático.
</p>

<p>
	En este artículo aprenderá todo sobre cómo eliminar virus informáticos.
</p>

<p>
	 
</p>

<h2>
	<strong>Cómo deshacerse de un virus informático, verifique su computadora en busca de virus </strong>
</h2>

<p>
	 
</p>

<p>
	En esta hilo, le indicaremos cómo verificar su computadora (con Windows) en busca de virus y cómo eliminar un virus informático.
</p>

<ol>
	<li>
		Si tiene otro software de seguridad instalado, verifique su computadora en busca de malware con Kaspersky Virus Removal Tool. Para obtener instrucciones, <a href="https://support.kaspersky.com/15674" rel="external nofollow">consulte este artículo</a>.
	</li>
	<li>
		Si tiene instalado el software de seguridad de Kaspersky:
	</li>
</ol>

<ul>
	<li>
		Compruebe que la opción "Otro software que pueden utilizar los delincuentes para dañar su equipo o sus datos personales" en la configuración <a href="https://support.kaspersky.com/KIS/21.3/es-ES/201385.htm" rel="external nofollow">Amenazas y Exclusiones</a> de nuestro producto está habilitada.
	</li>
	<li>
		<a href="https://support.kaspersky.com/KIS/21.3/es-ES/70772.htm" rel="external nofollow">Actualice</a> las bases de datos del producto.
	</li>
	<li>
		Ejecute un análisis completo. Una vez que se complete el análisis, elimine las amenazas encontradas. Si se le solicita que realice un tratamiento con un reinicio, seleccione esta opción.
	</li>
</ul>

<p>
	 
</p>

<h2>
	<strong>Cómo proteger su computadora de virus</strong>
</h2>

<p>
	 
</p>

<p>
	Estas son algunas formas básicas en las que puede proteger su computadora de los virus:
</p>

<ul>
	<li>
		Utilice un antivirus o una solución de seguridad de Internet. Por ejemplo, <strong><a href="https://www.kaspersky.es/premium?icid=es_community_oth_ona_oth__onl_b2c__buylink____kpr___" rel="external nofollow">Kaspersky Premium</a>.</strong>
	</li>
	<li>
		Descargue aplicaciones y software solo de sitios web confiables.
	</li>
	<li>
		Nunca haga clic en enlaces que no sean de confianza en mensajes de spam, correos electrónicos o sitios web desconocidos.
	</li>
	<li>
		No abra archivos adjuntos en correos electrónicos no deseados.
	</li>
	<li>
		Mantenga actualizado su antivirus y mantenga actualizadas las aplicaciones instaladas y el sistema operativo.
	</li>
	<li>
		Cuando utilice redes Wi-Fi públicas, utilice una conexión VPN segura como <strong><a href="https://www.kaspersky.es/vpn-secure-connection?icid=es_community_oth_ona_oth__onl_b2c__buylink____ksec___" rel="external nofollow">Kaspersky VPN Secure Connection</a>.</strong>
	</li>
	<li>
		Nunca conecte memorias USB desconocidas a su computadora ni inserte unidades desconocidas.
	</li>
</ul>

<p>
	 
</p>

<p>
	© Kaspersky
</p>
]]></description><guid isPermaLink="false">20744</guid><pubDate>Wed, 06 Oct 2021 12:07:45 +0000</pubDate></item><item><title>Come rimuovere un virus da un PC Windows</title><link>https://forum.kaspersky.com/topic/come-rimuovere-un-virus-da-un-pc-windows-20743/</link><description><![CDATA[<h3>
	<strong>Scanner gratuito di virus e strumento di rimozione di malware.</strong>
</h3>

<p>
	 
</p>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;">Sei preoccupato che ci possa essere un virus sul tuo computer? Se il tuo computer è infetto è importante sapere come sbarazzarsi di un virus informatico.</span></span>
</p>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;">In questo articolo imparerai tutto su come rimuovere i virus informatici.</span></span>
</p>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;"> </span></span>
</p>

<h2>
	<span style="color:#444444;"><span style="background-color:#ffffff;">Come sbarazzarsi di un virus informatico, controllare la presenza di un virus sul tuo computer</span></span>
</h2>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;"> </span></span>
</p>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;">In questo argomento ti diremo come controllare se tuo computer Windows è infetto  e come rimuovere un virus informatico.</span></span>
</p>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;"> </span></span>
</p>

<ol>
	<li>
		Se è installato un altro software di sicurezza, verificare la disponibilità di malware nel computer utilizzando <strong>Kaspersky Virus Removal Too</strong>l. Per istruzioni, vedere <a href="https://support.kaspersky.com/15674" rel="external nofollow">questo articolo</a>.
	</li>
	<li>
		Se è installato il software di sicurezza Kaspersky:
	</li>
</ol>

<ul>
	<li>
		Verifica che il "Rilevamento di software che può essere utilizzato da criminali" nelle impostazioni del nostro prodotto sia abilitato.
	</li>
	<li>
		Aggiornare i database dei prodotti.
	</li>
	<li>
		Eseguire una scansione completa. Una volta completata la scansione, rimuovere eventuali minacce rilevate. Se viene richiesto di eseguire un trattamento con un riavvio, selezionare questa opzione.
	</li>
</ul>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;"> </span></span>
</p>

<h2>
	<span style="color:#444444;"><span style="background-color:#ffffff;">Come proteggere il computer dai virus</span></span>
</h2>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;"> </span></span>
</p>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;">Ecco alcuni modi di base per proteggere il computer dai virus:</span></span>
</p>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;"> </span></span>
</p>

<ul>
	<li>
		Utilizzare una soluzione antivirus o superiore,  tipo Internet Security. Ad esempio <strong><a href="https://www.kaspersky.it/premium?icid=it_community_oth_ona_oth__onl_b2c__buylink____kpr___" rel="external nofollow">Kaspersky Premium</a></strong>.
	</li>
	<li>
		Scarica applicazioni e software solo da siti Web attendibili.
	</li>
	<li>
		Non fare mai clic su collegamenti non attendibili in messaggi di spam, e-mail o siti Web sconosciuti.
	</li>
	<li>
		Non aprire allegati nelle e-mail di spam.
	</li>
	<li>
		Mantieni aggiornato il tuo antivirus e mantieni aggiornate le applicazioni installate e il sistema operativo.
	</li>
	<li>
		Quando si utilizzano reti Wi-Fi pubbliche, utilizzare una connessione VPN sicura, ad esempio <strong><a href="https://www.kaspersky.it/vpn-secure-connection?icid=it_community_oth_ona_oth__onl_b2c__buylink____ksec___" rel="external nofollow">Kaspersky VPN Secure Connection</a></strong>.
	</li>
	<li>
		Non collegare mai chiavette USB sconosciute al computer o inserire unità sconosciute.
	</li>
</ul>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;"> </span></span>
</p>

<p>
	<span style="color:#444444;"><span style="background-color:#ffffff;"><span style="color:#444444;"><span style="background-color:#ffffff;">©</span></span> Kaspersky</span></span>
</p>
]]></description><guid isPermaLink="false">20743</guid><pubDate>Wed, 06 Oct 2021 12:05:57 +0000</pubDate></item><item><title>Hoe een virus van een Windows-PC verwijderen</title><link>https://forum.kaspersky.com/topic/hoe-een-virus-van-een-windows-pc-verwijderen-20742/</link><description><![CDATA[<h3>
	<strong>Gratis virusscanner en malware verwijderaar.</strong>
</h3>

<p>
	 
</p>

<p>
	Vreest u dat er een virus op je computer zit? Wanneer uw computer geïnfecteerd is, is het belangrijk om te weten hoe u van een computervirus afkomt.
</p>

<div>
	<p>
		In dit artikel leert u alles over het verwijderen van computervirussen.
	</p>

	<p>
		 
	</p>

	<h2>
		Hoe een computervirus verwijderen,<br />
		controleer uw computer op virussen.
	</h2>

	<p>
		 
	</p>

	<p>
		In dit onderwerp zullen we u vertellen hoe u uw Windows-computer kunt controleren op virussen en hoe u een computervirus kan verwijderen.
	</p>

	<ol>
		<li>
			Indien u andere beveiligingssoftware hebt geïnstalleerd, controleer  uw computer op malware met <strong>Kaspersky Virus Removal Tool</strong> , zie <a href="https://support.kaspersky.com/15674" rel="external nofollow">dit artikel</a> voor gedetailleerde instructies <br />
			 
		</li>
		<li>
			Als u Kaspersky-beveiligingssoftware hebt geïnstalleerd:
		</li>
	</ol>

	<ul>
		<li>
			Controleer of de optie  “Detectie van software die door criminelen kan worden gebruikt” ingeschakeld is.
		</li>
		<li>
			Update de databases van het product.
		</li>
		<li>
			Voer een volledige scan uit. Zodra de scan is voltooid, verwijder alle gevonden bedreigingen. Als u wordt gevraagd om een actie uit te voeren met een herstart, selecteerdan deze optie.
		</li>
	</ul>

	<p>
		 
	</p>

	<h2>
		Hoe uw computer beschermen tegen virussen.
	</h2>

	<p>
		 
	</p>

	<p>
		Hier zijn enkele basismanieren waarop u uw computer tegen virussen kan beschermen:
	</p>

	<ul>
		<li>
			Gebruik een antivirus- of internet beveiliging applicatie zoals bijvoorbeeld <strong><a href="https://www.kaspersky.nl/internet-security?icid=nl_community_oth_ona_oth__onl_b2c__buylink____kis___" rel="external nofollow">Kaspersky Premium</a></strong> .
		</li>
		<li>
			Download applicaties en software uitsluitend vanop vertrouwde Websites.
		</li>
		<li>
			Klik nooit op onbetrouwbare links in spamberichten,  of onbekende Websites.
		</li>
		<li>
			Open geen bijlagen in spam E-Mails.
		</li>
		<li>
			Houd uw Kaspersky antivirus programma up-to-date, alsook uw geïnstalleerde applicaties en besturingssysteem.
		</li>
		<li>
			Gebruik bij gebruik van openbare wifi-netwerken een veilige VPN-verbinding zoals <strong><a href="https://www.kaspersky.nl/vpn-secure-connection?icid=nl_community_oth_ona_oth__onl_b2c__buylink____ksec___" rel="external nofollow">Kaspersky VPN Secure Connection</a></strong> .
		</li>
		<li>
			Stop nooit een onbekende USB-stick in de computer en verbindt nooit onbekende externe schijven.
		</li>
	</ul>

	<p>
		 
	</p>

	<p>
		© Kaspersky
	</p>
</div>
]]></description><guid isPermaLink="false">20742</guid><pubDate>Wed, 06 Oct 2021 12:04:21 +0000</pubDate></item><item><title>Comment supprimer un virus du PC Windows</title><link>https://forum.kaspersky.com/topic/comment-supprimer-un-virus-du-pc-windows-20741/</link><description><![CDATA[<h3>
	Scanner de virus et outil de suppression des logiciels malveillants gratuits.
</h3>

<p>
	 
</p>

<p>
	<span style="background-color:#ffffff;"><span style="color:#444444;">Craignez-vous qu'il y ait un virus sur votre ordinateur ?  Si votre ordinateur est infecté, il est important de savoir comment se débarrasser d'un virus informatique.</span></span>
</p>

<p>
	<span style="background-color:#ffffff;"><span style="color:#444444;">Dans cet article, vous apprendrez tout sur la façon de supprimer les virus informatiques.</span></span>
</p>

<p>
	<span style="background-color:#ffffff;"> </span>
</p>

<h2>
	<span style="background-color:#ffffff;"><span style="color:#444444;">Comment se débarrasser d'un virus informatique,<br />
	vérifiez si votre ordinateur est infecté par un virus</span></span>
</h2>

<p>
	<span style="background-color:#ffffff;"> </span>
</p>

<p>
	<span style="background-color:#ffffff;"><span style="color:#444444;">Dans cette rubrique, nous vous expliquerons comment rechercher des virus sur votre ordinateur Windows et comment supprimer un virus informatique.</span> </span>
</p>

<ol>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">Si vous avez installé d'autres logiciels de sécurité, recherchez les logiciels malveillants sur votre ordinateur à l'aide de </span></span><span style="color:#444444;"><strong>Kaspersky Virus Removal Tool</strong></span><span style="color:#000000;">.</span><span style="background-color:#ffffff;"><span style="color:#000000;"> </span><br />
		<span style="color:#444444;">Pour obtenir les instructions veuillez consultez  <a href="https://support.kaspersky.com/fr/15674" rel="external nofollow">cet article</a>.</span></span><br />
		 
	</li>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">Si vous avez installé un logiciel de sécurité Kaspersky :</span></span>
	</li>
</ol>

<ul>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">Vérifiez que la « Détection des logiciels pouvant être utilisés par des criminels » dans les paramètres de nos produits est activée.</span></span>
	</li>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">Mettre à jour les bases de données du produit.</span></span>
	</li>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">Exécutez une analyse complète. Une fois l'analyse terminée, supprimez toutes les menaces </span></span> détectées<span style="background-color:#ffffff;"><span style="color:#444444;">. Si vous êtes invité à effectuer un traitement avec redémarrage, sélectionnez cette option.</span></span>
	</li>
</ul>

<p>
	<span style="background-color:#ffffff;"> </span>
</p>

<h2>
	<span style="background-color:#ffffff;"><span style="color:#444444;">Comment protéger votre ordinateur contre les virus</span></span>
</h2>

<h2>
	<span style="background-color:#ffffff;"> </span>
</h2>

<p>
	<span style="background-color:#ffffff;"><span style="color:#444444;">Voici quelques méthodes de base pour protéger votre ordinateur contre les virus :</span> </span>
</p>

<ul>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">Utilisez une solution antivirus comme par exemple <strong><a href="https://www.kaspersky.fr/premium?icid=fr_community_oth_ona_oth__onl_b2c__buylink____kpr___" rel="external nofollow">Kaspersky Premium</a></strong> .</span></span>
	</li>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">Téléchargez des applications et des logiciels uniquement à partir de sites Web de confiance.</span></span>
	</li>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">Ne cliquez jamais sur des liens non fiables dans des messages spam, ainsi que dans des e-mails</span></span><span style="background-color:#ffffff;"><span style="color:#444444;"> ou des sites Web inconnus.</span></span>
	</li>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">N'ouvrez jamais des pièces jointes dans des messages spam.</span></span>
	</li>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">Gardez votre antivirus à jour ainsi que votre système d'exploitation et vos applications installées.</span></span>
	</li>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">Lorsque vous utilisez des réseaux Wi-Fi publics, utilisez une connexion VPN sécurisée telle que <strong><a href="https://www.kaspersky.fr/vpn-secure-connection?icid=fr_community_oth_ona_oth__onl_b2c__buylink____ksec___" rel="external nofollow">Kaspersky VPN Secure Connection</a></strong>.</span></span>
	</li>
	<li>
		<span style="background-color:#ffffff;"><span style="color:#444444;">Ne connectez jamais de clés USB inconnues à votre ordinateur et n'insérez jamais de lecteurs inconnus.</span></span><br />
		 
	</li>
</ul>

<p>
	<span style="background-color:#ffffff;"><span style="color:#444444;">© Kaspersky</span></span>
</p>
]]></description><guid isPermaLink="false">20741</guid><pubDate>Wed, 06 Oct 2021 12:02:19 +0000</pubDate></item><item><title>&#x41A;&#x430;&#x43A; &#x443;&#x434;&#x430;&#x43B;&#x438;&#x442;&#x44C; &#x432;&#x438;&#x440;&#x443;&#x441; &#x441; Windows &#x438; &#x437;&#x430;&#x449;&#x438;&#x442;&#x430; &#x43E;&#x442; &#x437;&#x430;&#x440;&#x430;&#x436;&#x435;&#x43D;&#x438;&#x44F;</title><link>https://forum.kaspersky.com/topic/%D0%BA%D0%B0%D0%BA-%D1%83%D0%B4%D0%B0%D0%BB%D0%B8%D1%82%D1%8C-%D0%B2%D0%B8%D1%80%D1%83%D1%81-%D1%81-windows-%D0%B8-%D0%B7%D0%B0%D1%89%D0%B8%D1%82%D0%B0-%D0%BE%D1%82-%D0%B7%D0%B0%D1%80%D0%B0%D0%B6%D0%B5%D0%BD%D0%B8%D1%8F-20740/</link><description><![CDATA[<h3>
	<strong>Очистка компьютера от вирусов.</strong>
</h3>

<p>
	 
</p>

<p>
	Вас беспокоит, что на ваш компьютер может быть заражен вирусом? В этом случае важно знать, как избавиться от компьютерного вируса.
</p>

<p>
	<strong><span style="color:#444444;"><a href="https://forum.kaspersky.com/topic/%D0%BA%D0%B0%D0%BA-%D1%83%D0%B4%D0%B0%D0%BB%D0%B8%D1%82%D1%8C-%D1%88%D0%B8%D1%84%D1%80%D0%BE%D0%B2%D0%B0%D0%BB%D1%8C%D1%89%D0%B8%D0%BA-%D0%B8-%D1%80%D0%B0%D1%81%D1%88%D0%B8%D1%84%D1%80%D0%BE%D0%B2%D0%B0%D1%82%D1%8C-%D1%84%D0%B0%D0%B9%D0%BB%D1%8B-20739/" rel="">Читайте как удалить шифровальщика с Windows, расшифровать ваши файлы, защитить данные от шифрования--&gt;</a></span></strong>
</p>

<p>
	 
</p>

<h2>
	Как удалить вирус, проверить компьютер на вирусы?
</h2>

<p>
	 
</p>

<p>
	В этом теме мы расскажем, как проверить компьютер с Windows на вирусы и как удалить вирус с компьютера.
</p>

<ol>
	<li>
		Если у вас установлено защитное ПО другого производителя, то проверьте компьютер на наличие вредоносных программ с помощью бесплатной программы <strong>Kaspersky Virus Removal Tool</strong>. Инструкция в <a href="https://support.kaspersky.ru/15674" rel="external nofollow">статье</a> .
	</li>
	<li>
		Если у вас установлено защитное ПО “Лаборатории Касперского”, то следуйте инструкциям, которые ниже:
	</li>
</ol>

<ul>
	<li>
		Проверьте, что установлен флажок “Обнаруживать другие программы, которые могут быть использованы злоумышленниками для нанесения вреда компьютеру или данным пользователя” в настройках нашего продукта.
	</li>
	<li>
		Обновите базы нашего продукта.
	</li>
	<li>
		Запустите Полную проверку компьютера.
	</li>
	<li>
		После ее окончания устраните найденные угрозы. Если будет предложено лечение с перезагрузкой, то нажмите на кнопку для выбора этого варианта.
	</li>
</ul>

<h2>
	 
</h2>

<h2>
	Как защитить компьютер от вирусов?
</h2>

<p>
	 
</p>

<p>
	Вот основные способы, которые помогут вам в обеспечении безопасности компьютера:
</p>

<ul>
	<li>
		Используйте антивирус. Например <strong><a href="https://www.kaspersky.ru/premium?icid=ru_community_oth_ona_oth__onl_b2c__buylink____kpr___" rel="external nofollow">Kaspersky Premium</a></strong><strong> </strong>(доступен бесплатный триал)
	</li>
	<li>
		Загружайте приложения и программное обеспечение только с доверенных сайтов.
	</li>
	<li>
		Никогда не нажимайте на непроверенные ссылки в спам-сообщениях, почте и на незнакомых веб-сайтах.
	</li>
	<li>
		Не открывайте вложения в спам-сообщениях на ваших устройствах.
	</li>
	<li>
		Вовремя устанавливайте новую версию антивируса и обновляйте установленные приложения и саму операционную систему.
	</li>
	<li>
		Никогда не подключайте к вашему компьютеру неизвестные USB-флешки, не вставляйте неизвестные диски.
	</li>
</ul>

<p>
	 
</p>

<p>
	© Kaspersky
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">20740</guid><pubDate>Wed, 06 Oct 2021 11:52:13 +0000</pubDate></item><item><title>&#x41A;&#x430;&#x43A; &#x443;&#x434;&#x430;&#x43B;&#x438;&#x442;&#x44C; &#x448;&#x438;&#x444;&#x440;&#x43E;&#x432;&#x430;&#x43B;&#x44C;&#x449;&#x438;&#x43A; &#x438; &#x440;&#x430;&#x441;&#x448;&#x438;&#x444;&#x440;&#x43E;&#x432;&#x430;&#x442;&#x44C; &#x444;&#x430;&#x439;&#x43B;&#x44B;</title><link>https://forum.kaspersky.com/topic/%D0%BA%D0%B0%D0%BA-%D1%83%D0%B4%D0%B0%D0%BB%D0%B8%D1%82%D1%8C-%D1%88%D0%B8%D1%84%D1%80%D0%BE%D0%B2%D0%B0%D0%BB%D1%8C%D1%89%D0%B8%D0%BA-%D0%B8-%D1%80%D0%B0%D1%81%D1%88%D0%B8%D1%84%D1%80%D0%BE%D0%B2%D0%B0%D1%82%D1%8C-%D1%84%D0%B0%D0%B9%D0%BB%D1%8B-20739/</link><description><![CDATA[<h3>
	<strong>Вирусы-вымогатели, шифровальщики, Ransomware.</strong>
</h3>

<p>
	 
</p>

<p>
	<strong>Программы-шифровальщики</strong> за последние годы из экзотики превратились в проблему, с которой уже столкнулись <a href="https://www.kaspersky.ru/blog/history-of-ransomware/30373/" rel="external nofollow">сотни тысяч людей</a> — и может столкнуться каждый. Кибервымогательство стало <a href="https://www.kaspersky.ru/blog/darkside-ransomware-industry/30524/" rel="external nofollow">целой массовой индустрией</a>, в которой даже сформировалось разделение труда: одни преступники пишут вредоносный код, а другие выбирают цели и используют этот код для их заражения, получая процент от выкупа.
</p>

<p>
	В последние пару лет вымогатели сосредоточились на организациях, но это не значит, что обычные пользователи могут забыть об угрозе — по-прежнему есть шанс «попасть под раздачу», в том числе случайно.
</p>

<p>
	 
</p>

<h2>
	Как вылечить компьютер, если я подцепил вымогателя?
</h2>

<p>
	 
</p>

<div>
	<p>
		От троянов-блокировщиков хорошо помогает бесплатная программа <a href="https://www.kaspersky.ru/blog/kaspersky-windowsunlocker/12056/" rel="external nofollow"><strong>Kaspersky WindowsUnlocker</strong></a>.
	</p>

	<p>
		С шифровальщиками бороться сложнее. Сначала нужно ликвидировать заразу — для этого лучше всего использовать антивирус. Если нет платного, то можно скачать бесплатную пробную версию с ограниченным сроком действия, для лечения этого будет достаточно. Например <strong><span style="font-size:14px;"><a href="https://www.kaspersky.ru/downloads/premium" rel="external nofollow">Kaspersky Premium</a></span></strong>
	</p>

	<p>
		Следующий этап — восстановление зашифрованных файлов.
	</p>

	<p>
		Если есть резервная копия, то проще всего восстановить файлы из нее.
	</p>

	<p>
		Если резервной копии нет, можно попробовать расшифровать файлы с помощью специальных утилит — декрипторов. Все бесплатные декрипторы, созданные «Лабораторией Касперского», можно найти на сайте <strong><a href="https://noransom.kaspersky.com/" rel="external nofollow">Noransom.kaspersky.com</a></strong>.
	</p>

	<p>
		Декрипторы выпускают и другие антивирусные компании. Только не скачивайте такие программы с сомнительных сайтов — запросто подхватите еще какую-нибудь заразу. Мы рекомендуем данный ресурс: <strong><a href="https://www.nomoreransom.org/" rel="external nofollow">No More Ransom</a></strong>
	</p>

	<p>
		Если подходящей утилиты нет, то остается единственный способ — заплатить мошенникам и получить от них ключ для расшифровки. <strong>Но не советуем это делать.</strong>
	</p>

	<p>
		 
	</p>

	<h2>
		Можно что-то настроить на компьютере, чтобы защититься от вируса шифровальщика?
	</h2>

	<p>
		 
	</p>

	<div>
		<p>
			а) Во-первых, обязательно поставьте антивирус. Но мы об этом уже говорили выше.
		</p>

		<p>
			б) Далее можно выполнить <strong><a href="https://support.kaspersky.ru/10952" rel="external nofollow">эти</a> </strong>рекомендации.
		</p>

		<p>
			 
		</p>

		<p>
			© Kaspersky
		</p>
	</div>
</div>
]]></description><guid isPermaLink="false">20739</guid><pubDate>Wed, 06 Oct 2021 11:49:07 +0000</pubDate></item><item><title><![CDATA[How to remove a virus from Windows & preventing infection]]></title><link>https://forum.kaspersky.com/topic/how-to-remove-a-virus-from-windows-preventing-infection-20737/</link><description><![CDATA[<h3>
	<strong>Free Virus Scanner &amp; Malware Removal Tool.</strong>
</h3>

<p>
	 
</p>

<p>
	<span style="color:#444444;">Are you worried that there might be a virus on your computer? If your computer is infected, it is important to know how to get rid of a computer virus.</span>
</p>

<p>
	<strong><span style="color:#444444;"><a href="https://forum.kaspersky.com/topic/how-to-remove-ransomware-from-windows-decrypt-files-20736/" rel="">Read how to remove Ransomware, decrypt files, encryption protection --&gt;</a></span></strong>
</p>

<p>
	 
</p>

<h2>
	How to remove virus? Run a virus scan first
</h2>

<p>
	 
</p>

<p>
	<span style="color:#444444;">Before cleaning your Windows PC of viruses, you have to scan it first. </span>
</p>

<p>
	<span style="color:#444444;">Here is how to do this: </span>
</p>

<ol>
	<li>
		<span style="color:#444444;">If you have non-Kaspersky security software installed, run a virus scan on your PC using <strong>Free</strong> <strong>Kaspersky Virus Removal Tool</strong>. See <a href="https://support.kaspersky.com/15674" rel="external nofollow">instructions</a>.</span>
	</li>
	<li>
		<span style="color:#444444;">If you have Kaspersky security software installed:</span>
	</li>
</ol>

<ul>
	<li>
		<span style="color:#444444;">Check that the “Detection of software that can be used by criminals” in our product settings is enabled.</span>
	</li>
	<li>
		<span style="color:#444444;">Update product's databases.</span>
	</li>
	<li>
		<span style="color:#444444;">Run a Full Scan. Once the scan is complete, remove any threats or malware found. If you are prompted to perform a treatment with a restart, select this option.</span>
	</li>
</ul>

<table>
	<tbody>
		<tr>
			<td style="width:471px;">
				<p>
					<strong><span style="color:#000000;">Want professional virus removal from a Kaspersky expert?  </span></strong><span style="color:#000000;">Please see our <strong>Premium Support</strong> options that include <strong>virus removal, remote support</strong> services, and more here:</span>
				</p>

				<p>
					 
				</p>

				<ul>
					<li>
						<span style="color:#444444;"><a href="https://shop.kaspersky.co.uk/checkout/add?products=3de8521e-6d20-4709-b026-186cf3fbe25e&amp;icid=GB_community_oth_ona_oth__onl_b2c__buylink____kpss___" rel="external nofollow">The <strong>United Kingdom and the Falkland Islands pricing</strong></a><strong> </strong></span>
					</li>
					<li>
						<span style="color:#444444;"><a href="https://shop.usa.kaspersky.com/checkout/add?productid=5567d7b7-be0d-4ff0-a822-021dde69766a&amp;icid=usa_community_oth_ona_oth__onl_b2c__buylink____kpss___" rel="external nofollow">The <strong>US &amp; Canada pricing</strong></a><strong> </strong> </span>
					</li>
				</ul>

				<p>
					 
				</p>

				<p>
					<strong><span style="color:#e74c3c;">Note:</span></strong><span style="color:#e74c3c;"> This service is not for sale or activation outside of the above regions.</span>
				</p>
			</td>
		</tr>
	</tbody>
</table>

<p>
	 
</p>

<h2>
	How to preventing infection?
</h2>

<p>
	 
</p>

<p>
	<span style="color:#444444;">Here are some basic ways how you can protect your computer from viruses:</span>
</p>

<ul>
	<li>
		Use an antivirus software for malware protection. <span style="color:#444444;"> For example, </span><strong><a href="https://www.kaspersky.com/premium?icid=gl_community_oth_ona_oth__onl_b2c__buylink____kpr___" rel="external nofollow">Kaspersky Premium</a></strong> (free trial available).
	</li>
	<li>
		<span style="color:#444444;">Download applications and software only from trusted websites.</span>
	</li>
	<li>
		<span style="color:#444444;">Never click on any untrusted links in spam messages, emails, or unfamiliar websites.</span>
	</li>
	<li>
		<span style="color:#444444;">Don't open attachments in spam emails.</span>
	</li>
	<li>
		<span style="color:#444444;">Keep your anti-virus up to date and keep your installed applications and operating system up to date.</span>
	</li>
	<li>
		<span style="color:#444444;">When using public Wi-Fi networks, use a secure VPN connection such as </span> <strong><a href="https://www.kaspersky.com/vpn-secure-connection?icid=gl_community_oth_ona_oth__onl_b2c__buylink____ksec___" rel="external nofollow">Kaspersky VPN Secure Connection</a></strong> (free version available).
	</li>
	<li>
		<span style="color:#444444;">Never connect unknown USB sticks to your computer or insert unknown drives.</span>
	</li>
</ul>

<p>
	 
</p>

<p>
	© Kaspersky
</p>
]]></description><guid isPermaLink="false">20737</guid><pubDate>Wed, 06 Oct 2021 10:56:19 +0000</pubDate></item><item><title><![CDATA[How to remove Ransomware from Windows & decrypt files]]></title><link>https://forum.kaspersky.com/topic/how-to-remove-ransomware-from-windows-decrypt-files-20736/</link><description><![CDATA[<h3>​Ransomware Threats Protection and Removal.</h3><p> </p><p>Ransomware infection means that your <strong>data has been encrypted</strong> or your <strong>operating system</strong> is being <strong>blocked</strong> by cybercriminals. These criminals usually demand a ransom in return for decrypting the data.</p><p><a href="https://www.kaspersky.com/resource-center/threats/ransomware" rel="noreferrer noopener" target="_blank">Ransomware</a> can find its way onto a device in many different ways. The most common routes include <strong>infections from malicious websites</strong>, unwanted add-ons in <strong>downloads</strong> and <strong>spam</strong> or<strong> phishing emails</strong>. Targets of ransomware attacks include both individuals and companies.</p><p>Various measures can be taken to <a href="https://www.kaspersky.com/resource-center/threats/how-to-prevent-ransomware" rel="noreferrer noopener" target="_blank"><strong>protect against ransomware attacks</strong></a>, with a <strong>watchful eye</strong> and the <strong>right software</strong> being important steps in the right direction. Attacking this form of malware means either the <strong>loss of data</strong>, <strong>spending large sums of money,</strong> or <strong>both</strong>.</p><p> </p><h2>How to detect ransomware and protect yourself from it?</h2><p> </p><p>When it comes to protecting against this type of malware, prevention is better than cure. To achieve this, a <strong>watchful eye</strong> and the <a href="https://www.kaspersky.com/anti-ransomware-tool" rel="noreferrer noopener" target="_blank"><strong>right security software</strong></a> are crucial.</p><p>Vulnerability scans can also help you to find intruders in your system. First, it's important to make sure your computer is not an ideal target for ransomware families. Device software should always be kept up to date in order to benefit from the <strong>latest security patches</strong>. In addition, careful action, especially with regard to rogue websites and email attachments, is vital. But even the best preventive measures can fail, making it all the more essential to have a contingency plan.</p><p>In the case of ransomware, a contingency plan consists of having <strong>a backup of your data</strong>. To learn how to create a data backup and what additional measures you can put in place to protect your device, read the article <a href="https://www.kaspersky.com/resource-center/threats/how-to-prevent-ransomware" rel="noreferrer noopener" target="_blank"><strong>Ransomware protection: how to keep your data safe in 2021</strong></a>.</p><p> </p><h2>Removing encryption Trojans and decrypts files – how it's done?</h2><p> </p><p>If the ransomware is detected before a ransom is demanded, you have the advantage of being able to delete the malware. The data that has been encrypted up to this point remains encrypted, but the ransomware virus can be stopped. Early detection means that the malware can be prevented from spreading to other devices and files.</p><p>If you back up your data externally or in cloud storage, you will be able to recover your encrypted files. But what can you do if you don't have a backup of your data? We recommend that you contact the provider of your <strong>internet security solution</strong>. There may already be a <strong>ransomware decryptor tool.</strong></p><p>You can also visit the website of the <a href="https://www.nomoreransom.org" rel="noreferrer noopener" target="_blank"><strong>No More Ransom</strong></a> project. This industry-wide initiative was launched to help all victims of ransomware.</p><p> </p><p>&#x00a9; Kaspersky</p><p> </p>]]></description><guid isPermaLink="false">20736</guid><pubDate>Wed, 06 Oct 2021 10:53:39 +0000</pubDate></item><item><title>&#x5982;&#x4F55;&#x4ECE; Windows &#x8BA1;&#x7B97;&#x673A;&#x4E2D;&#x79FB;&#x9664;&#x8BA1;&#x7B97;&#x673A;&#x75C5;&#x6BD2;&#xFF0C;&#x6267;&#x884C;&#x8BA1;&#x7B97;&#x673A;&#x75C5;&#x6BD2;&#x626B;&#x63CF;&#xFF0C;&#x9632;&#x6B62;&#x8BBE;&#x5907;&#x611F;&#x67D3;&#xFF1F;</title><link>https://forum.kaspersky.com/topic/%E5%A6%82%E4%BD%95%E4%BB%8E-windows-%E8%AE%A1%E7%AE%97%E6%9C%BA%E4%B8%AD%E7%A7%BB%E9%99%A4%E8%AE%A1%E7%AE%97%E6%9C%BA%E7%97%85%E6%AF%92%EF%BC%8C%E6%89%A7%E8%A1%8C%E8%AE%A1%E7%AE%97%E6%9C%BA%E7%97%85%E6%AF%92%E6%89%AB%E6%8F%8F%EF%BC%8C%E9%98%B2%E6%AD%A2%E8%AE%BE%E5%A4%87%E6%84%9F%E6%9F%93%EF%BC%9F-20734/</link><description><![CDATA[<p>您是否担忧过有计算机病毒在你的计算机中？如果您的计算机已收到感染，耽误之急就是如何摆脱被感染的局面。</p><p>在此文中，您将会学习到一些有关于如何移除计算机病毒的方法。</p><p> </p><h2>如何摆脱计算机病毒，对您的计算机如何进行计算机病毒检查？</h2><p> </p><p>在此文中，我们将告诉您如何检查在 Windows 操作系统的计算机上检查计算机病毒是否存在并且如何移除它们。<br /> </p><ol><li>如果您当前正使用其他安全软件，您可以通过使用 <strong>Kaspersky Virus Removal Tool</strong> 来检查您的计算机。有关说明，请参阅<a href="https://support.kaspersky.com/15674" rel="noreferrer noopener" target="_blank">此文章</a>。</li>	<li>如果您已经安装有卡巴斯基实验室系列产品：</li></ol><ul><li>请检查我们的产品设置中的“检测可被犯罪分子使用的软件”项目是否已启用。</li>	<li>更新产品威胁数据库。</li>	<li>执行一次全盘扫描。当扫描完成后，移除所有被检测到的威胁。如果在执行移除操作过程中提示您需要重启计算机的，请选择该选项。</li></ul><h2> </h2><h2>如何保护您的计算机免受计算机病毒感染？</h2><p> <br />以下是保护计算机免受计算机病毒感染的一些基本方法：</p><ul><li>     使用防病毒或 Internet 安全类解决方案。 例如 <strong>Kaspersky Internet Security</strong> 软件。</li>	<li>     仅从受信任的网站下载应用程序和软件。</li>	<li>     切勿点击在垃圾邮件、电子邮件或陌生网站中的任何不受信任的链接。</li>	<li>     不要打开垃圾邮件中的附件。</li>	<li>     使您的防病毒软件保持最新，并使您安装的应用程序和操作系统保持最新。</li>	<li>     切勿随意将您不知其存储何种数据的 U 盘与驱动器连接到您的计算机。</li></ul><p>&#x00a9;️ Kaspersky</p><p><span>​</span></p>]]></description><guid isPermaLink="false">20734</guid><pubDate>Wed, 06 Oct 2021 10:35:51 +0000</pubDate></item></channel></rss>
