安裝ClamAV
1.安裝epel源
yum install epel-release
在安裝了EPEL源后,運行下面的命令安裝ClamAV
# yum install clamav-server clamav-data clamav-update clamav-filesystem clamav clamav-scanner-systemd clamav-devel clamav-lib clamav-server-systemd -y
2.在兩個配置文件/etc/freshclam.conf和/etc/scan.conf中移除“Example”字符
# sed -i -e “s/^Example/#Example/” /etc/freshclam.conf
# sed -i -e “s/^Example/#Example/” /etc/clamd.d/scan.conf
3.手動更新病毒庫
# freshclam
病毒庫更新時總是鏈接失敗,無法訪問到 默認的鏡像地址,遂再次進入freshclam.conf 配置文件,在將DatabaseDirectory /var/lib/clamav這一行將之前的注釋#刪除,然后在系統中創建此文件目錄,在 官網下載最新的三個
main.cvd :http://database.clamav.net/main.cvd
daily.cvd :http://database.clamav.net/daily.cvd
bytecode.cvd :http://database.clamav.net/bytecode.cvd
直接將這三個文件使用迅雷下載,基本上幾分鍾能下載完(不行就使用旋風),之后將這三個文件保存到/var/lib/clamav路徑下,這是再次運行跟新病毒庫命令freshclam 會提示病毒庫已更新到最近,接下來就可以執行掃描了
4.對/root目錄進行掃描,-r選項表示包含子目錄
# clamscan -r /root
/root/elasticsearch-servicewrapper-master.zip: OK
/root/tomcat.cap: OK
/root/test.sh: OK
/root/1.txt.bak: OK
/root/apache-tomcat-7.0.73.tar.gz: OK
/root/request.txt: OK
/root/jenkins.io.key: OK
/root/.bash_profile: OK
/root/.viminfo: OK
/root/.cshrc: OK
/root/配置免密碼訪問.txt: OK
/root/.tcshrc: OK
/root/.bash_history: OK
/root/bigdesk-master.zip: OK
/root/read.sh: OK
/root/.mysql_history: OK
/root/fun.sh: OK
/root/.my.cnf: OK
/root/case.sh: OK
/root/.bash_logout: OK
/root/elasticsearch-1.4.4.tar.gz: OK
/root/testfile: OK
/root/zabbix-sender-3.0.4-1.el6.x86_64.rpm: OK
/root/install.sh: OK
/root/zabbix.sh: OK
/root/zabbix-get-3.0.1-2.el6.x86_64.rpm: OK
/root/zookeeper-3.4.5.tar.gz: OK
/root/anaconda-ks.cfg: OK
/root/.bashrc: OK
/root/ping.sh: OK
/root/.mysql_secret: OK
/root/192.168.3.13: OK
/root/startzk.sh: OK
/root/zabbix-agent-3.0.4-1.el6.x86_64.rpm: OK
/root/p1.py: OK
/root/if.sh: OK
/root/jdk-7u80-linux-x64.gz: OK
/root/zookeeper.out: OK
/root/pingtest.sh: OK
----------- SCAN SUMMARY -----------
Known viruses: 5943094
Engine version: 0.99.1
Scanned directories: 1
Scanned files: 39
Infected files: 0
Data scanned: 92.54 MB
Data read: 210.36 MB (ratio 0.44:1)
Time: 94.219 sec (1 m 34 s)