Results 1 to 5 of 5

Thread: Virus scan with Knoppix?

  1. #1
    Member registered user
    Join Date
    Mar 2004
    Posts
    46

    Virus scan with Knoppix?

    With Knoppix, I understand that I can run a virus
    scan on a (potentially infected) Windows NTFS PC.

    How should I do this?
    Which application does this?
    How will it get the latest virus definitions?

  2. #2
    Senior Member registered user
    Join Date
    Aug 2004
    Location
    In a house... hopefully
    Posts
    554
    NOT RECOMENDED!! to what i know... it isnt recomended to edit any NTFS file system.... but if you want to risk it... i would sugggest

    f-prot or Av-clam (it could be called av-clan)...

    those two are good linux virus scanners....

  3. #3
    Administrator Site Admin-
    Join Date
    Apr 2003
    Location
    USA
    Posts
    5,392
    Chris, it was a valid question. No one said anything about editing files on a NTFS partitiion (which is a bad idea), but scanning a Windows system with something other than that copy of Windows itself can be important. Once a nasty virus gets into a system (and this is true for any OS, not just Windows) it can gain enough control to hide itself from virus scanners. All virus scanners that run under Windows make API or System Calls to the operating system to request things like the disk sectors they want to scan. If a virus is clever enough (and this ain't rocket science), it can watch these calls and when the call that would return it's location on the disk and reveal it is made, it can just return emptry blocks or some other part of the disk. The scanner never knows it is being lied to. There are, of course, plenty of other ways to fool a scanning program once you have control of the system. Even most experienced users would never detect them. So scanning with software completely independent of the infected system is important. If you get a clean scan you have no need to write to the NTFS partition. If you detect a virus that conceals itself with a "root kit", this may be the only reasonable way that you could detect it. Only then do you need to decide what to do about it, which may well be salvage all of your data with Knoppix, reformat the disk, and completely reinstall.

  4. #4
    Senior Member registered user
    Join Date
    Aug 2004
    Location
    In a house... hopefully
    Posts
    554
    oh ok... me mistake...


    thanks.. i cant wait until we would be able to edit NTFS... then we can all be evil (especially me)

  5. #5
    Senior Member registered user
    Join Date
    Apr 2005
    Location
    italy
    Posts
    245

Similar Threads

  1. Virus Scan from LiveCD
    By patches1391 in forum General Support
    Replies: 8
    Last Post: 04-01-2009, 12:47 AM
  2. knoppix and virus scan
    By mid1700s in forum MS Windows & New to Linux
    Replies: 3
    Last Post: 04-09-2007, 04:32 PM
  3. Trying to virus scan a networked Windows PC from Knoppix
    By Synthpopalooza in forum Networking
    Replies: 2
    Last Post: 09-22-2005, 01:10 PM
  4. newbie - auto myconfig=scan home=scan
    By eentonig in forum General Support
    Replies: 0
    Last Post: 01-11-2005, 09:57 AM
  5. Using F-Prot to Virus Scan Windows Partitions
    By cascadefx in forum Tips and Tricks
    Replies: 1
    Last Post: 07-01-2003, 09:13 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
" IBM " Computer Server Memory Ram 4 X 2GB PC2 - 5300 CL5 DDR2-667
$16.99
Samsung PC2-5300P 8GB (2x4GB) 2Rx4 Server Memory M393T5166AZA-CE6 Dell HP IBM
$25.14
Samsung PC2-5300P 8GB (2x4GB) 2Rx4 Server Memory M393T5166AZA-CE6 Dell HP IBM pictureHynix PC2-5300P 8GB (2x4GB) 2Rx4 Server Memory HYMP151P72CP4-Y5 Dell, HP IBM
$25.14
Hynix PC2-5300P 8GB (2x4GB) 2Rx4 Server Memory HYMP151P72CP4-Y5 Dell, HP IBM picture(1) IBM eServer Rio-2 Server Loop Adapter Module ( 97P3896 28E7 )
$29.99
(1) IBM eServer Rio-2 Server Loop Adapter Module ( 97P3896 28E7 ) pictureSamsung PC2-5300P 8GB (2x4GB) 2Rx4 Server Memory M393T5160QZA-CE6 Dell HP IBM
$25.14
Samsung PC2-5300P 8GB (2x4GB) 2Rx4 Server Memory M393T5160QZA-CE6 Dell HP IBM picture