一,安装clamav
1.yum install clamav -y
如果找不到包的话,只有下载源码自己编译安装了。
tar zxf clamav-0.97.4.tar.gz
cd clamav-0.97.4
groupadd clamav
useradd -g clamav -s /bin/false clamav
./configure --prefix=/usr/local/clamav && make && make install
首先创建一个目录.
mkdir /home/clamav/logs (clanav 日志目录)
mkdir /usr/local/clamav/update (clanav 病毒库目录)
修改配置文件/usr/local/clamav/etc/clamd.conf
sed -i 's/Example/#Example/' /usr/local/clamav/etc/clamd.conf
sed -i '14 a\LogFile \/home\/clamav\/logs\/clamd.log' /usr/local/clamav/etc/clamd.conf
sed -i '57 a\PidFile \/usr\/local\/clamav\/update\/clamd.pid' /usr/local/clamav/etc/clamd.conf
sed -i '65 a\DatabaseDirectory \/usr\/local\/clamav\/update ' /usr/local/clamav/etc/clamd.conf
修改配置文件/usr/local/clamav/etc/freshclam.conf
sed -i 's/Example/#Example/' /usr/local/clamav/etc/freshclam.conf
sed -i '13 a\DatabaseDirectory \/usr\/local\/clamav\/update' /usr/local/clamav/etc/freshclam.conf
sed -i '18 a\UpdateLogFile \/home\/clamav\/logs\/freshclam.log' /usr/local/clamav/etc/freshclam.conf
sed -i '49 a\PidFile \/usr\/local\/clamav\/update\/freshclam.pid' /usr/local/clamav/etc/freshclam.conf
sed -i '103 a\Checks 4' /usr/local/clamav/etc/freshclam.conf
sed -i '78 a\DatabaseMirror clamav.inet6.fr' /usr/local/clamav/etc/freshclam.conf
sed -i '78 a\DatabaseMirror clamav.netopia.pt' /usr/local/clamav/etc/freshclam.conf
sed -i '78 a\DatabaseMirror clamav.sonic.net' /usr/local/clamav/etc/freshclam.conf
下面创建日志文件
touch /home/clamav/logs/freshclam.log
chown clamav:clamav /home/clamav/logs/freshclam.log
touch /home/clamav/logs/clamd.log
chown clamav:clamav /home/clamav/logs/clamd.log
chown clamav:clamav /usr/local/clamav/update
创建软连接:
ln -s /usr/local/clamav/bin/clamscan /usr/bin/clamscan
ln -s /usr/local/clamav/bin/freshclam /usr/bin/freshclam
二,下载病毒库
1.freshclam --verbose
freshclam上面这个命令是更新病毒库,如果没有,会自动下载,不过比较慢。你也可以手动下载,http://www.clamav.net/lang/en/,下二个就可以main.cvd、daily.cvd、bytecode.cvd。把下载的病毒库文件放到/usr/local/clamav/update目录下面,就行了。
2.手工下载病毒库文件:
cd /usr/local/clamav/update
wget wget http://db.local.clamav.net/daily.cvd
wget http://db.local.clamav.net/main.cvd
wget http://db.local.clamav.net/bytecode.cvd
三,查看一下clamav进程
[root@Test208 update]# ps ax |grep clam
4858 ? Ss 0:00 /usr/bin/freshclam -d --quiet
5401 pts/0 S+ 0:00 grep --color=auto clam
[root@Test208 update]# ps ax |grep clam
4858 ? Ss 0:00 /usr/bin/freshclam -d --quiet
5401 pts/0 S+ 0:00 grep --color=auto clam
四,一些常规用法举例
1,扫描某个目录,clamscan -r /home/
2,将扫描结果存放到log中,clamscan -r /home/ -l /usr/local/clamav/logs/clamd.log
3,扫描过程中,只显示有问题的文件并且发出警报声音,clamscan -r --bell -i /home/
4,扫描到有问题的文件,直接删除,clamscan -r --remove /home/ > /home/clamscan.log,这一步要小心,最好不要这样操作,如果删除了系统文件就麻烦了,可能导致系统崩溃。
五,扫描结果
[root@Test208 update]# clamscan -r /home/
/home/xhprof/xhprof_html/callgraph.php: OK
/home/xhprof/xhprof_html/css/xhprof.css: OK
....................................................
/home/xhprof/xhprof_lib/utils/callgraph_utils.php: OK
/home/xhprof/xhprof_lib/utils/xhprof_runs.php: OK
/home/xhprof/xhprof_lib/utils/xhprof_lib.php: OK
/home/xhprof/xhprof_lib/display/typeahead_common.php: OK
/home/xhprof/xhprof_lib/display/xhprof.php: OK
----------- SCAN SUMMARY -----------
Known viruses: 1210664
Engine version: 0.97.4
Scanned directories: 145
Scanned files: 1096
Infected files: 0
Data scanned: 54.04 MB
Data read: 45.68 MB (ratio 1.18:1)
Time: 7.834 sec (0 m 7 s)
六、定期扫描
crontab -e
添加如下两行:
30 5 * * * clamscan -ri --remove /tmp /home >> /home/clamav/logs/clamd.log --每天5:30运行
10 2 * * 7 clamscan -ri --remove /home >> /home/clamav/logs/clamd.log --每周日2:10运行
转载于:https://blog.51cto.com/shoring/857052