
|
| Auteur |
Message |
jjcojax Helper

Inscrit le: 18 Juin 2006 Message(s): 270 Localisation: Belgique
|
Posté le: 15 Déc 2007 18:00 Sujet du message: Antivirus via Ubuntu [Résolu] |
|
|
Bonjour,
Je cherche quelques conseils pour avoir un antivirus qui roule sous Ubuntu.
Le but est de pouvoir scanner les partitions de Windows.
J'ai téléchargé et installé une version java pour Linux , et j'espérais utiliser l'antivirus trend micro
-> Refusé
--------
Si je me contente de Clam ...
Il existe la commande avscan ( the Clam AntiVirus scanner (ClamAV) ) pour Linux, mais je ne sais pas si il est capable de retrouver les malwares de tous poils (programmes espions, rootkit ..)
Et puis j'ai déjà vu que pour les mises à jours, je vais passer au minimum 3 semaines pour trouver comment il faut faire
Merci de vos lumières (et rien ne presse,)
 |
|
| Revenir en haut de page |
|
 |
Sév VIP

Inscrit le: 26 Mai 2005 Message(s): 2032
|
Posté le: 15 Déc 2007 18:18 Sujet du message: |
|
|
Salut JJ
Ben... J'ai posé la questions à des experts Linuxiens, je te fais signe dès que j'ai une réponse.
 _________________
> Soutenez le Tibet < |
|
| Revenir en haut de page |
|
 |
jjcojax Helper

Inscrit le: 18 Juin 2006 Message(s): 270 Localisation: Belgique
|
Posté le: 15 Déc 2007 18:56 Sujet du message: |
|
|
Merci,
 |
|
| Revenir en haut de page |
|
 |
Sév VIP

Inscrit le: 26 Mai 2005 Message(s): 2032
|
Posté le: 15 Déc 2007 20:43 Sujet du message: |
|
|
Re JJ,
Antivir : http://www.free-av.com/
Il y a un PDF qui t'explique tout ICI en anglais.
Merci à Pitcat ;)
[Edit] « pitccat » a écrit: apres install il faut faire en root :
/usr/sbin/usermod -G dialout,cdrom,floppy,audio,video,plugdev,"nom de session",antivir "nom de session" _________________
> Soutenez le Tibet < |
|
| Revenir en haut de page |
|
 |
jjcojax Helper

Inscrit le: 18 Juin 2006 Message(s): 270 Localisation: Belgique
|
Posté le: 16 Déc 2007 13:29 Sujet du message: |
|
|
Bonjour,
Installer la version Antivir pour Linux, c'est du sport !
Il faut installer via un terminal (et il y a un paquet de questions)
Donc je met sudo, et je fais glisser le fichier install dans la fenêtre, et c'est parti...
---
jjcojax@ubuntu-7:~$ sudo '/home/jjcojax/Desktop/antivir-workstation-pers-2.1.11-21/install'
[sudo] password for jjcojax:
Starting Avira AntiVir Workstation (UNIX) 2.1.11-21 installation...
Before installing this software, you must agree to the terms
of the license.
Use the arrow keys to scroll through the license. When you
are finished reading, press 'q' to exit the viewer.
Press <ENTER> to view the license.
Avira GmbH
End-user License Agreement (EULA)
blablabla
Do you agree to the license terms? [n] y
creating /usr/lib/AntiVir ... done
1) installing command line scanner
copying bin/antivir to /usr/lib/AntiVir/ ... done
copying vdf/antivir0.vdf to /usr/lib/AntiVir/ ... done
copying vdf/antivir1.vdf to /usr/lib/AntiVir/ ... done
copying vdf/antivir2.vdf to /usr/lib/AntiVir/ ... done
copying vdf/antivir3.vdf to /usr/lib/AntiVir/ ... done
Enter the path to your key file: [hbedv.key] /home/avira
/home/avira not found
Enter the path to your key file: [hbedv.key] /home/jjcowax
/home/jjcowax not found
Enter the path to your key file: [hbedv.key]
copying hbedv.key to /usr/lib/AntiVir/hbedv.key ... done
copying script/configantivir to /usr/lib/AntiVir/ ... done
linking /usr/bin/antivir to /usr/lib/AntiVir/antivir ... done
installation of command line scanner complete
2) installing internet update daemon
An internet update daemon is available with version 2.1.11-21 of
Avira AntiVir Workstation (UNIX). This is a program that will run in the background
and automatically check for updates (internet access is required).
Instead of installing the internet update daemon, you may also
manually check for updates using:
antivir --update
Please read the README file for more information about updating and
which method best suits you.
Would you like to install the internet update daemon? [n] y
copying script/avupdater to /usr/lib/AntiVir/ ... done
checking for existing /etc/avupdater.conf ... not found
copying etc/avupdater.conf to /etc/ ... done
Would you like to create a link in /usr/sbin for avupdater ? [y]
linking /usr/sbin/avupdater to /usr/lib/AntiVir/avupdater ... done
Would you like the internet update daemon to start automatically? [y] y
setting up startup script ... done
installation of the internet update daemon complete
3) installing AvGuard
Version 2.1.11-21 of Avira AntiVir Workstation (UNIX) is capable of on-access,
real-time scanning of files. This provides the ultimate protection
against viruses and other unwanted software. The on-access scanner
(called AvGuard) is based on Dazuko, a free software project providing
access control. In order to use AvGuard you will need to compile Dazuko
for your kernel. Please refer to contrib/dazuko/HOWTO-Dazuko for
information about how to do this. There are several ways in which you
can install AvGuard.
module - Dazuko will be loaded by the avguard script
kernel - Dazuko is always loaded
(and should not be loaded by the avguard script)
no install - do not install AvGuard at this time
Note: Dazuko currently only works with GNU/Linux, FreeBSD and Solaris
systems. If you are interested in helping us port Dazuko to
OpenBSD, feel free to check out the Dazuko Project at:
http://www.dazuko.org
available options: m k n
How should AvGuard be installed? [n] m
Enter the full path to dazuko.ko:
not found.
How should AvGuard be installed? [n] m
Enter the full path to dazuko.ko: dazuko.ko
dazuko.ko not found.
How should AvGuard be installed? [n]
AvGuard will NOT be installed. See contrib/dazuko/HOWTO-Dazuko
for more information about Dazuko.
4) installing GUI (+ SMC support)
Note: The AntiVir Security Management Center (SMC) requires this
feature, even if you do not intend to use the GUI.
This product comes with a GUI that allows you to monitor realtime
activity, view logs, and configure the product. This tool is optional
(not required) for the product to run.
The GUI requires Sun Java 1.4.x or higher.
Would you like to install the GUI (+ SMC support)? [y]
checking for existing /etc/avguard.conf ... not found
copying etc/avguard.conf-gui to /etc/avguard.conf ... done
copying common gui files to /usr/lib/AntiVir/gui ... done
copying platform dependant gui files to /usr/lib/AntiVir/gui ... done
copying script/antivir-gui to /usr/lib/AntiVir/ ... done
linking /usr/bin/antivir-gui to /usr/lib/AntiVir/antivir-gui ... done
installation of GUI complete
5) configuring AntiVir Updater
Your connection to the internet might require special configuration
settings (such as HTTP proxy settings). You may also want the
updater to log to specific files or send email notification. You
now have the opportunity to set these options.
Would you like to configure the AntiVir updater now? [y] y
EmailTo (1 of 4)
=======
You may configure the AntiVir Updater to send out an email message
whenever an update was successful or an error with the update occurred.
available options: y n
Would you like email notification about updates? [n]
LogTo (2 of 4)
=====
In addition to logging update activity through syslog, you may also
specify your own log file for messages that are generated by the.
AntiVir Updater. This can make it simpler to review past activity
without having to sift through syslog files.
available options: y n
Would you like the updater to log to a custom file? [y]
What will be the log file name with absolute path (it must begin with '/')
? [/var/log/avupdater.log]
AutoUpdateEvery2Hours/AutoUpdateDaily (3 of 4)
=====================================
AntiVir is equipped with an Internet Update Daemon. At specified
intervals, AntiVir will connect to an update server to check for newer
versions of the AntiVir engine or the data files. If a newer
version is available, AntiVir will automatically download and install
the updates without requiring any special attention. This allows AntiVir
to be kept current against attacks and problems.
AntiVir can be configured to check for updates every 2 hours (2) or
once a day (d). You can also choose to disable the Internet Update
Daemon (n).
Note: Updates can also be done manually from the command line:
antivir --update
You may prefer to disable the Internet Update Daemon and
instead perform regular updates using a cron(8) job.
Using the startup script for the Internet Update Daemon when
it is disabled will result in an error.
available options: 2 d n
How often should AntiVir check for updates? [2] d
AutoUpdateTime (3-2 of 4)
==============
The AntiVir Updater can be set to always check for updates at a
particular time of day. This is specified in a HH:MM format
(where HH is the hour and MM is the minutes). If you do not have a
permanent connection, you may set it to a time when you are usually
online. You may also let AntiVir choose a random time (r).
If you have a permanent connection then a random time may be preferred
because it will help to disperse the times when other users are
getting updates.
available options: HH:MM r
What time should updates be done? [RANDOM] 10
invalid answer: 10
What time should updates be done? [RANDOM] 10:10
HTTPProxyServer/HTTPProxyPort (4 of 4)
=============================
If this machine is sitting behind an HTTP proxy server, you will need to
configure AntiVir with the appropriate proxy settings. Internet access
is required in order to make updates.
available options: y n
Does this machine use an HTTP proxy server? [n]
AntiVir Configuration
=====================
Here are the configuration settings you have specified. Look them over
to make sure they are correct.
email notification: no
specific logfile: /var/log/avupdater.log
update frequency: daily (if update daemon is running)
update time: 10:10 (if update daemon is running)
http proxy server: none
available options: y n
Save configuration settings? [y]
* SUCCESS *
Configuration successfully saved to.
/etc/avupdater.conf
Press <ENTER> to continue.
Running Internet Update Daemon
==============================
In order for the Internet Update Daemon to be active on your
system, you must run the software. This can be done manually each
time the system is booted with the command:
/usr/lib/AntiVir/avupdater start
You can have it start automatically by adding avupdater to your
startup scripts. Depending on your system, this can vary. Consult
your system documentation on startup scripts.
During the installation, you had the option to set the updater to
start automatically.
available options: y n
Would you like to apply the new configuration? [y]
Starting AntiVir: avupdater.
AntiVir Status: avupdater running.
Here are some commands that you should remember...
configure updater: /usr/lib/AntiVir/configantivir
start update daemon: /usr/lib/AntiVir/avupdater start
stop update daemon: /usr/lib/AntiVir/avupdater stop
update daemon status: /usr/lib/AntiVir/avupdater status
Press <ENTER> to continue.
Installation of the following features complete:
AntiVir command line scanner
AntiVir Internet Update Daemon
AntiVir Guard (previously installed)
AntiVir GUI
Note: It is highly recommended that you perform an update now to
ensure up-to-date protection. This can be done by running:
antivir --update
Be sure to read the README file for additional information.
Thank you for your interest in Avira AntiVir Workstation (UNIX).
jjcojax@ubuntu-7:~$
---
Pour les mises à jour, encore un terminal avec "sudo antivir --update"
Pour scanner un disque entier, encore un terminal avec "sudo antivir -s /media/hda1"
Voici un petit scan pour montrer ce que cela donne.
---
root@ubuntu-7:/home/jjcojax# sudo antivir -s /media/hda1
AntiVir / Linux Version 2.1.11-44
Copyright (c) 2007 by Avira GmbH.
All rights reserved.
VDF version: 7.0.1.98 created 14 déc 2007
For private, non-commercial use only.
AntiVir license: 149996 for Avira AntiVir PersonalEdition Classic
auto excluding /sys/ from scans (is a special fs)
auto excluding /proc from scans (is a special fs)
checking drive/path (list): /media/hda1
/media/hda1/Program Files/Panda Security/TotalScan/pskavs.dll
Date: 26.07.2007 Time: 12:11:26 Size: 788784
ALERT: [W95/Bumble] /media/hda1/Program Files/Panda Security/TotalScan/pskavs.dll <<< Contains detection pattern of the Windows virus W95/Bumble
/media/hda1/Program Files/Panda Security/NanoScan/Engine/psnflg.dll
Date: 22.08.2007 Time: 10:51:52 Size: 38704
ALERT: [TR/Agent.bux.1] /media/hda1/Program Files/Panda Security/NanoScan/Engine/psnflg.dll <<< Is the Trojan horse TR/Agent.bux.1
| /media/hda1/winnt2/system32/mui/dispspec/040c.csv
Do you really want to abort? [y|N] n
/media/hda1/winnt2/system32/ActiveScan/pskavs.dll
Date: 18.08.2006 Time: 09:46:18 Size: 779264
ALERT: [W95/Bumble] /media/hda1/winnt2/system32/ActiveScan/pskavs.dll <<< Contains detection pattern of the Windows virus W95/Bumble
------ scan results ------
directories: 6264
scanned files: 65943
alerts: 3
suspicious: 0
repaired: 0
deleted: 0
renamed: 0
quarantined: 0
scan time: 00:22:43
--------------------------
Thank you for using AntiVir.
root@ubuntu-7:/home/jjcojax#
-------
Comme je voudrais connaitre le comportement du programme quand il trouve un virus, que puis-je faire pour tester ?
y a t'il des fichiers avec virus, espion .... pour voir ce que fait un Antivirus ?
------
Et je ne vois pas ce que fait la jolie commande de pitccat (elle est avalée, mais elle change quoi ?)
Fin  |
|
| Revenir en haut de page |
|
 |
Sév VIP

Inscrit le: 26 Mai 2005 Message(s): 2032
|
Posté le: 16 Déc 2007 13:43 Sujet du message: |
|
|
Hello JJ,
« jjcojax » a écrit: Comme je voudrais connaitre le comportement du programme quand il trouve un virus, que puis-je faire pour tester ?
y a t'il des fichiers avec virus, espion .... pour voir ce que fait un Antivirus ?
------
Et je ne vois pas ce que fait la jolie commande de pitccat (elle est avalée, mais elle change quoi ?)
Cette commande sert à utiliser l'interface graphique, elle se lance avec la commande antivir-gui.
Pour tester ton AV, tu peux essayer le test Eicar (simple fichier texte).
Citation: X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
Contente que tu aies réussi à faire ce que tu voulais.
 _________________
> Soutenez le Tibet < |
|
| Revenir en haut de page |
|
 |
| Publicité |
|
|
| Navigation |
Autres sujets similaires |
|
|
|
|
|
Vous ne pouvez pas poster de nouveaux sujets dans ce forum Vous ne pouvez pas répondre aux sujets dans ce forum Vous ne pouvez pas éditer vos messages dans ce forum Vous ne pouvez pas supprimer vos messages dans ce forum Vous ne pouvez pas voter dans les sondages de ce forum
|
|