系統rhel7.5
clamav-0.100.2.tar.gz 官網下載clamav:http://www.clamav.net
開始安裝:
根據本身的系統版本下載相應的epel安裝文件ide
#wget https://dl.fedoraproject.org/pub/epel/epel-release-latest-6.noarch.rpm
#wget https://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm
安裝epel:
rpm -ivh epel-release-latest-7.noarch.rpm
#yum install clamav clamav-server clamav-data clamav-update clamav-filesystem clamav-scanner-systemd clamav-devel clamav-lib clamav-server-systemd
這種方法安裝後,病毒庫默認地址是/var/lib/clamav
#tar zxvf clamav-0.99.2.tar.gz
#cd clamav-0.99.2
#要帶pcre,要否則執行clamscan會報錯
#./configure --prefix=/usr/local/clamav --with-pcre
#make
#make install
#cd /usr/local/clamav/etc/
#cp clamd.conf.sample clamd.conf
#cp freshclam.conf.sample freshclam.conf
註釋掉clamd.conf和freshclam.conf中的.net
2、更新病毒庫
#cd /usr/local/clamav/share/clamav
#wget http://database.clamav.net/main.cvd
#wget http://database.clamav.net/daily.cvd
#wget http://database.clamav.net/bytecode.cvdcode
clamscan:
用clamscan掃描,不須要開始服務就能使用。速度慢,要帶-r,纔會遞歸掃描子目錄
#clamscan -r /usr
這個命令不只會顯示找到的病毒,正常的掃描文件也會顯示出來。server
能夠用下面這個命令,只顯示找到的病毒信息遞歸
-r 遞歸掃描子目錄
-i 只顯示發現的病毒文件
--no-summary 不顯示統計信息
[root@huojin181 clamav]# clamscan /var/
LibClamAV Warning: **
LibClamAV Warning: The virus database is older than 7 days!
LibClamAV Warning: Please update it as soon as possible.
LibClamAV Warning: **
/var/run: Symbolic link
/var/lock: Symbolic link
/var/mail: Symbolic link
/var/.updated: OKrem
----------- SCAN SUMMARY -----------
Known viruses: 6668589
Engine version: 0.100.2
Scanned directories: 1
Scanned files: 1
Infected files: 0
Data scanned: 0.00 MB
Data read: 0.00 MB (ratio 0.00:1)
Time: 10.251 sec (0 m 10 s)get
[root@huojin181 clamav]# clamscan --no-summary -ri /tmp
使用–remove選項,會直接刪除檢測出來的文件。
clamscan --remove /rootit