LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-20-2010, 11:24 AM   #1
Mr. Alex
Senior Member
 
Registered: May 2010
Distribution: No more Linux. Done with it.
Posts: 1,238

Rep: Reputation: Disabled
Question Is there any antivirus to delete GNU/Linux'es viruses?


I read some articles about viruses in Linux and about some antiviruses which work in Linux and delete Windows viruses but I still don't understand: is there any antivirus which specializes in Linux viruses? Even though there are very little of Linux viruses, I know.
 
Old 09-20-2010, 11:38 AM   #2
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 681Reputation: 681Reputation: 681Reputation: 681Reputation: 681Reputation: 681
You can use tools like rkhunter or chkrootkit to identify root kits. It works better if you plan on this during installation, and create a database which you copy to read-only off-line media, and run your test from a live disc while the system is off line.


Prevention is more important than reaction. Make sure you use strong passwords. Use pub key authentication if you use ssh, and use a strong passphrase to protect the private key. Keep software up to date. Only use software you distro supplies. The source is open and should be vetted before being compiled and packaged. Being open the original author would get into trouble if they included spyware or a trojan. If you have a high speed Internet connection, using a Cable/DSL modem would be a good idea. An extra firewall (which NAT provides) will provide an extra layer of protection. Lock down your system. E.G. AllowUsers in sshd_config; providing a password for the mysql root user if that is installed; checking your computer's firewall settings, etc.

The Linux scanners for Windows viruses is intended to detect malware infected files on Samba shares, not to remove malware that already has infected a windows machine. Once a host is infected, re-installation is needed.
 
1 members found this post helpful.
Old 09-20-2010, 11:40 AM   #3
MS3FGX
LQ Guru
 
Registered: Jan 2004
Location: NJ, USA
Distribution: Slackware, Debian
Posts: 5,852

Rep: Reputation: 361Reputation: 361Reputation: 361Reputation: 361
Linux-specific AV exists (AVG and BitDefender have Linux versions, at the very least), but I can't vouch for how useful they are in practice.
 
Old 09-20-2010, 12:09 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599
Quote:
Originally Posted by MS3FGX View Post
Linux-specific AV exists (..), but I can't vouch for how useful they are in practice.
I can as I have tested BitDefender, ClamAV and F-prot in this web log post of mine in 2009.
 
Old 09-20-2010, 12:17 PM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599
Quote:
Originally Posted by Mr. Alex View Post
Even though there are very little of Linux viruses, I know.
If you don't try to execute unknown binaries from unknown origins then chances you'll come across one are rare. The only one I come across often are RST-B variants.
 
1 members found this post helpful.
Old 09-20-2010, 12:20 PM   #6
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
I've actually used CA's AV solution for Linux. Sophos for Linux too. This was back in 2004-2005...those solutions left much to be desired, but things have probably changed since then.

The biggest turn-off with CA's solution was that each install included a locally-run webserver. That was a deal-breaker for the shop I was working for. The biggest turn-off with Sophos' AV solution was the fact that you had to create scripts around it for it to even work satisfactorily. We felt that we shouldn't have to create hacks to make a paid-for enterprise solution work.
 
Old 09-20-2010, 01:27 PM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599
Your post reminded me NOD32 has a Beta out for Linux (see http://beta.eset.com/linux). I tried Beta 4 on F13, it worked quite OK, and the feature set is quite similar to what users know from running it on The Other OS. YMMV(VM) as it's still beta and I haven't checked under the hood as I've used a VMware disposable.
 
Old 09-21-2010, 11:19 AM   #8
Mr. Alex
Senior Member
 
Registered: May 2010
Distribution: No more Linux. Done with it.
Posts: 1,238

Original Poster
Rep: Reputation: Disabled
Exclamation

rkhunter:
Code:
[20:11:23]   Checking for directory '/var/log/ssh'           [ Not found ]
[20:11:23]   Checking for directory '/usr/doc/.spool'        [ Not found ]
[20:11:23]   Checking for directory '/usr/lib/kterm'         [ Not found ]
[20:11:23] Warning: Adore Rootkit                            [ Warning ]
[20:11:23]          File '/usr/sbin/kfd' found
Same problem here: https://bbs.archlinux.org/viewtopic.php?id=86539 . So this utility has false warnings.
 
Old 09-21-2010, 11:25 AM   #9
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Well, they're all going to have false warnings at some point, IMO. I once had an issue with an enterprise AV solution triggering falses on RAdmin. The issue was fixed the same day, but it created operational challenges until they (CA) fixed the issue. This happens with other vendors also. It's a part of using AV, I guess.

Last edited by unixfool; 11-12-2010 at 09:01 AM.
 
1 members found this post helpful.
Old 09-21-2010, 01:24 PM   #10
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599
Let's establish once and for all that rootkits (may be infected with but) are not equal to viruses and that RKH does not equal AV.
 
Old 09-21-2010, 01:30 PM   #11
nomb
Member
 
Registered: Jan 2006
Distribution: Debian Testing
Posts: 675

Rep: Reputation: 58
McAfee and Semantec both have AVs for Linux which remove and quarantine. The both also have command line versions and GUIs available. They both also have on-demand, scheduled, and real time scanning. The McAfee version can also be hooked up to and pushed out via an ePo server where it can pull its updates from.

Kaspersky has a Linux version also but I've never used it before.

nomb

Last edited by nomb; 09-21-2010 at 01:31 PM.
 
Old 09-21-2010, 02:18 PM   #12
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,612

Rep: Reputation: 2649Reputation: 2649Reputation: 2649Reputation: 2649Reputation: 2649Reputation: 2649Reputation: 2649Reputation: 2649Reputation: 2649Reputation: 2649Reputation: 2649
as to removing ??
in 8 or so years i have never needed that option .Clam has never shown that there was one installed ( except on my MS Xp disk that norton missed )

and even then i did a manual removal and replace of the files ( from fedora )
 
  


Reply

Tags
virus antivirus


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Does linux antivirus scan for windows viruses? nkoplm Linux - Security 6 11-22-2009 03:46 PM
how can I delete the viruses rob33n Ubuntu 2 11-12-2008 02:50 PM
how can one search for viruses without an antivirus wisdomvk Linux - Software 2 04-24-2007 11:41 AM
F-prot antivirus not scanning attachments for viruses rhea Linux - Newbie 1 01-23-2006 11:30 AM
antivirus with windows viruses? hobylinux Linux - Security 5 08-15-2003 12:47 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:00 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration