ClamAV安装使用教程

环境:Centos 7.9/ClamAV0.104.1

1、ClamAV介绍

ClamAV(Clam AntiVirus)是Linux平台上的开源病毒扫描程序,主要应用于邮件服务器,采用多线程后台操作,可以自动升级病毒库。

2、安装epel软件源

#安装
yum install -y epel-release

#缓存
yum clean all && yum makecache

3、安装依赖环境

yum install -y openssl openssl-devel libcurl-devel zlib-devel libpng-devel libxml2-devel json-c-devel bzip2-devel pcre2-devel ncurses-devel

4、下载软件安装包

ClamAV官方下载地址:http://www.clamav.net/downloads

5、创建clamav用户和存放病毒库目录

groupadd clamav && useradd -g clamav clamav && id clamav

mkdir -p /usr/local/clamav/logs
touch /usr/local/clamav/logs/clamd.log
touch /usr/local/clamav/logs/freshclam.log
chown clamav:clamav /usr/local/calmav/logs/clamd.log
chown clamav:clamav /usr/local/clamav/logs/freshclam.log

mkdir -p /usr/local/clamav/updata
chown -R root:clamav /usr/local/clamav/
chown -R clamav:clamav /usr/local/clamav/updata/

6、解压软件安装包

tar xf clamav-0.104.1.tar.gz

7、编译安装

cd clamav-0.104.1/
./configure --prefix=/usr/local/clamav --disable-clamav --with-pcre
make && make install
echo $?

8、配置ClamAV

cd /usr/local/clamav/etc
cp clamd.conf.sample clamd.conf
cp freshclam.conf.sample freshclam.conf

vim clamd.conf
#Example    注释掉这一行.
添加下面三行:
LogFile /usr/local/clamav/logs/clamd.log    
PidFile /usr/local/clamav/updata/clamd.pid     
DatabaseDirectory /usr/local/clamav/updata

vim freshclam.conf
#Example    注释掉这一行. 
添加下面三行 
DatabaseDirectory /usr/local/clamav/updata
UpdateLogFile /usr/local/clamav/logs/freshclam.log
PidFile /usr/local/clamav/updata/freshclam.pid

9、启动ClamAV

chown -R clamav.clamav /usr/local/clamav/
systemctl start clamav-freshclam.service
systemctl enable clamav-freshclam.service 
systemctl status clamav-freshclam.service

10、跟新病毒库

#先停止freshclam
systemctl stop clamav-freshclam.service
#再更新
/usr/local/clamav/bin/freshclam  (根据网络质量确定更新时长)
#或者
cd /usr/local/clamav/share/clamav
wget http://database.clamav.net/main.cvd
wget http://database.clamav.net/daily.cvd
wget http://database.clamav.net/bytecode.cvd
#更新完成启动
systemctl start clamav-freshclam.service
systemctl status clamav-freshclam.service

11、创建软链接

ln -s /usr/local/clamav/bin/clamscan /usr/local/sbin/clamscan
#说明:如果在手动更新病毒库的时候遇到错误,此时就要删除掉旧的镜像地址文件
#rm -f /var/lib/clamav/mirrors.dat,再手动更新一次病毒库。

12、扫描病毒

clamscan /
扫描参数:
-r/--recursive[=yes/no]             所有文件
--log=FILE/-l FILE        增加扫描报告
--move [路径]          移动病毒文件至..
--remove [路径]              删除病毒文件
--quiet                  只输出错误消息
--infected/-i                       只输出感染文件
--suppress-ok-results/-o                   跳过扫描OK的文件
--bell                         扫描到病毒文件发出警报声音
--unzip(unrar)                 解压压缩文件扫描

13、定时扫描

#让服务器每天晚上定时更新和杀毒,保存杀毒日志,crontab文件如下:
1  3  * * *  /usr/local/clamav/bin/freshclam --quiet
20 3  * * *  /usr/local/clamav/bin/clamscan  -r /home  --remove -l /var/log/clamscan.log
Logo

为开发者提供学习成长、分享交流、生态实践、资源工具等服务,帮助开发者快速成长。

更多推荐