centos6.9 离线安装clamav

1.下载安装包
[root@qhd13 soft]# wget http://www.clamav.net/downloads/production/clamav-0.99.4.tar.gz 
[root@qhd13 soft]# tar -zxvf clamav-0.99.4.tar.gz
[root@qhd13 soft]# cd clamav-0.99.4

2.创建用户和组
[root@qhd13 clamav-0.99.4]# useradd -s /sbin/nologin clamav    #创建clamav运行用户和组

3.开始配置目录
[root@qhd13 clamav-0.99.4]# ./configure --prefix=/usr/local/clamav
[root@qhd13 clamav-0.99.4]# make && make install
[root@qhd13 clamav-0.99.4]# mkdir /usr/local/clamav/logs       #(创建日志存放目录)
[root@qhd13 clamav-0.99.4]# mkdir /usr/local/clamav/updata     #(创建clamav 病毒库目录)
[root@qhd13 clamav-0.99.4]# cd /usr/local/clamav/etc
[root@qhd13 etc]# mv clamd.conf.sample clamd.conf
[root@qhd13 etc]# mv freshclam.conf.sample freshclam.conf

4.修改配置文件
[root@qhd13 etc]# vim  clamd.conf
# Example    注释掉这一行后添加下面
LogFile /usr/local/clamav/logs/clamd.log      
PidFile /usr/local/clamav/updata/clamd.pid    
DatabaseDirectory /usr/local/clamav/updata  

[root@qhd13 etc]# vim  freshclam.conf
# Example    注释掉这一行后添加下面
DatabaseDirectory /usr/local/clamav/updata
UpdateLogFile /usr/local/clamav/logs/freshclam.log
PidFile /usr/local/clamav/updata/freshclam.pid

5.创建日志文件

[root@qhd13 etc]# touch /usr/local/clamav/logs/freshclam.log
[root@qhd13 etc]# chown clamav:clamav /usr/local/clamav/logs/freshclam.log
[root@qhd13 etc]# touch /usr/local/clamav/logs/clamd.log
[root@qhd13 etc]# chown clamav:clamav /usr/local/clamav/logs/clamd.log
[root@qhd13 etc]# chown clamav:clamav /usr/local/clamav/updata


6.使用方法
[root@qhd13 etc]# cd ../bin
[root@qhd13 bin]# ./freshclam                         #(升级病毒库,离线不能升级病毒库,需要后期手动下载病毒库)
[root@qhd13 bin]# ./clamscan --no-summary -ri /tmp    #这个命令,只显示找到的病毒信息
-r 递归扫描子目录
-i 只显示发现的病毒文件
--no-summary 不显示统计信息

7.计划任务

实际生产环境应用
一般使用计划任务,让服务器每天晚上定时跟新和定时杀毒。保存杀毒日志,我的crontab文件如下
#1  3  * * *         /usr/local/clamav/bin/freshclam
10 0  * * *        /usr/local/clamav/bin/clamscan  --infected  -r /  --remove -l /usr/local/clamav/logs/clamscan.log




说明没有病毒库
可能会报错:
No supported database files found in /usr/local/clamav/share/clamav


手动下载病毒库

手动下载病毒目录库:
wget http://database.clamav.net/main.cvd
wget http://database.clamav.net/daily.cvd
wget http://database.clamav.net/bytecode.cvd

手动创建病毒目了:
将下载后的病毒cp到目录库中

[root@qhd13 clamav]# cd /usr/local/clamav/share/clamav
[root@qhd13 clamav]# ll
total 229460
-rw-r--r-- 1 root root    289733 Oct 22 10:02 bytecode.cvd
-rw-r--r-- 1 root root  64181892 Oct 22 10:03 daily.cvd
-rw-r--r-- 1 root root 170479789 Oct 22 10:02 main.cvd

病毒扫描
[root@qhd13 bin]# cd  /usr/local/clamav/bin
[root@qhd13 bin]#  ./clamscan -r /var

[root@qhd13 bin]# ./clamscan -r /var
LibClamAV Warning: ***********************************************************
LibClamAV Warning: ***  This version of the ClamAV engine is outdated.     ***
LibClamAV Warning: ***   Read http://www.clamav.net/doc/install.html       ***
LibClamAV Warning: ***********************************************************
LibClamAV Warning: cli_loadldb: logical signature for Img.Exploit.CVE_2017_2902-6355547-1-6355547-2 uses PCREs but support is disabled, skipping
LibClamAV Warning: cli_loadldb: logical signature for Email.Phishing.VOF2-6231767-3 uses PCREs but support is disabled, skipping
LibClamAV Warning: cli_loadldb: logical signature for Email.Phishing.VOF2-6231772-2 uses PCREs but support is disabled, skipping
LibClamAV Warning: cli_loadldb: logical signature for Email.Phishing.VOF2-6231773-2 uses PCREs but support is disabled, skipping
...........................(省略)
...........................
...........................
/var/lib/yum/repos/x86_64/6Server/management-agent/gpgdir-ro/gpg.conf: OK
/var/lib/yum/repos/x86_64/6Server/management-agent/gpgdir-ro/trustdb.gpg: OK
/var/lib/yum/repos/x86_64/6Server/management-agent/gpgdir-ro/pubring.gpg~: Empty file
/var/lib/yum/rpmdb-indexes/file-requires: OK
/var/lib/yum/rpmdb-indexes/pkgtups-checksums: OK
/var/lib/yum/rpmdb-indexes/conflicts: OK
/var/lib/yum/rpmdb-indexes/version: OK
/var/lib/dbus/machine-id: OK
/var/lib/postfix/master.lock: OK
/var/lib/polkit-1/localauthority/10-vendor.d/10-desktop-policy.pkla: OK

----------- SCAN SUMMARY -----------
Known viruses: 8623506
Engine version: 0.99.4
Scanned directories: 1790
Scanned files: 12262
Infected files: 0
Data scanned: 226.60 MB
Data read: 1166.49 MB (ratio 0.19:1)
Time: 48.339 sec (0 m 48 s)


参考: https://www.hotxf.com/article/41

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值