Page 2 of 2 FirstFirst 12
Results 11 to 18 of 18

Thread: Knoppix for Virus Scanning

  1. #11
    Member registered user
    Join Date
    Feb 2004
    Posts
    72
    Cuddles,

    you're not out of date. 3.4 only came out a few days ago.

  2. #12
    Junior Member registered user
    Join Date
    May 2004
    Posts
    11
    The f-prot live-install on Knoppix 3.4 downloads f-prot and its complete, up-to-date virus definitions each time it is run. It works beautifully with a high-speed internet connection, but I haven't tried installing it over a dialup connection.

    It has to download all the virus definitions, not just the new ones, each time you boot up and run the live-install. There just isn't room on the Knoppix cd for the f-prot program and a basic set of virus definitions, and apparently Klaus Knopper has concerns about it not being Free-as-in-freedom.

    If anyone knows of a good way to carry f-prot and a basic set of virus definitions around on a USB thumbdrive, with incremental updates downloaded quickly over the 'net, please post it here.

    The BitDefender cd, LinuxDefender_Live!_v1.5.6_CeBIT.iso, was based on the c't Knoppix 3.4 iso. It had a built-in Windows virus scanner with the definition database updated over the net, and support for Captive ntfs read-write access. I haven't actually tried it, though, and it doesn't seem to be available on the BitDefender site anymore. Try http://gddistrowatch.tuwien.ac.at/?newsid=01481#0

    For "native" MS-Windows antivirus, PCWorld.com has a review ( http://www.pcworld.com/howto/article...,113462,00.asp ) of four free-as-in-beer programs that are quite good, with scheduled scans and definition updates. They recommend Alwil's Avast ( http://www.asw.cz/i_idt_1016.html ) as the best of the bunch. Make sure all your MS-Windows using friends are running it, and you'll have less work to do helping them recover from virus infections.

  3. #13
    Member registered user
    Join Date
    Feb 2004
    Posts
    72
    >>Thanks especially to softwaretester, I

    You're welcome.

  4. #14
    Junior Member
    Join Date
    May 2004
    Posts
    1
    I now have knoppix v3.4 too, and I've used f-prot, but I wonder, is it really only capable of scanning and reporting by showing a logfile, or can you order it to disinfect/delete too? Because else this is useless to me...

    ?

  5. #15
    Member registered user
    Join Date
    Nov 2003
    Posts
    66
    You can also (if you have the time to read documentation) use BartPE (a bootable windowsXP system), but it is sort of a pain to get it to work properly. I have used f-prot before, but I have never gotten to see how well it works since I haven't gotten a virus on my box for a while, not to mention that my brother has to use my Windows XP box to get his palm to sinc up (he won't even look at any of the damnable configuration files, or ask for help, so "it doesn't work". He won't even dual boot his computer, so he has to inconvience me).

  6. #16
    Member registered user
    Join Date
    Apr 2004
    Posts
    34

    lol

    hi all

    some add infos

    overcloacking :
    hide a file from windows file listing
    can hide a process from windows taskmon

    injection :
    there are several ways to " inject a process into another " spoofing the real process commander

    autostart keys
    several ways to load a process on windows start up (some are not detected by av (antivirus)

    the virus last generation join theese technologies :
    you can delete the file, but often the virii has already messed up the win system and often will download and execute a new one

    free av won't protect you neither norton av
    new critical security whole on outlook express allow the mail html code content to simulate a browser breaking all the web security features (script blocking & iframe blocking)

    for me the best av is kaspersky av, but the best to do with an infected win os is
    take an image (norton ghost)
    format the hd
    reinstall win os
    backup your important files from the image
    take a new image

    btw : the av have not all the signatures from all the existing malware
    it's easy to discover which strings they use to detect it
    by changing one bit or by addicting a space inside the string, the malware become undetected

    sorry for the bad news

  7. #17
    Junior Member registered user
    Join Date
    May 2004
    Posts
    11
    Hmmm. I've tried f-prot again, on an NTFS partition I know has infected files, and I'm less impressed. It scans it all, lists the full pathnames of all 26273 files, and then says how many are infected (finding a couple more than AVG under WinXP). But it won't disinfect them (no surprise), and it won't even seem to list the infected files so I can delete or replace them manually with captive-ntfs (big surprise). So that's not much use, really.

    I'm sympathetic to the recommendation to run a "native" MS-Windows virus scanner, or just backup user files and reinstall everything, but there are times when it would be helpful to find and fix a minor infection without worrying that a running virus will prevent a Windows virus-scanner from doing its job.

    If anyone has any suggestions as to what I'm missing here, please post them.
    ________________________________________
    Results of virus scanning:
    Files: 26273
    MBRs: 0
    Boot sectors: 0
    Objects scanned: 60691
    Infected: 29
    Suspicious: 2
    Disinfected: 0
    Deleted: 0
    Renamed: 0

    Time: 21:18

  8. #18
    Junior Member registered user
    Join Date
    May 2004
    Posts
    11
    Apparently f-prot liveinstall will disinfect automatically if you run it from the command line with the right options; the GUI just scans, and doesn't even report properly for me. I haven't tested it yet, but see http://www.oreillynet.com/pub/wlg/5118 for an article on virus scanning with f-prot under Knoppix.

Page 2 of 2 FirstFirst 12

Similar Threads

  1. virus scanning in knoppix?
    By Coco in forum MS Windows & New to Linux
    Replies: 8
    Last Post: 11-30-2004, 11:39 PM
  2. Scanning for Spyware in Knoppix
    By MaldiGola in forum General Support
    Replies: 1
    Last Post: 11-28-2004, 03:37 AM
  3. scanning university's with x-scan
    By illcuban in forum General Support
    Replies: 0
    Last Post: 12-21-2003, 07:42 PM
  4. Virus Scanner / minimal knoppix version
    By freeballer in forum Ideas
    Replies: 5
    Last Post: 07-11-2003, 03:58 PM
  5. Use Knoppix for Windows anti-virus?
    By Loper in forum Ideas
    Replies: 26
    Last Post: 07-01-2003, 09:18 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


Lot of 50 Mixed Manufacturer 4GB DDR3L SO-DIMM laptop RAM picture

Lot of 50 Mixed Manufacturer 4GB DDR3L SO-DIMM laptop RAM

$89.99



A-Tech 8GB DDR3 1600 PC3-12800 Laptop SODIMM 204-Pin Memory RAM PC3L DDR3L 1x 8G picture

A-Tech 8GB DDR3 1600 PC3-12800 Laptop SODIMM 204-Pin Memory RAM PC3L DDR3L 1x 8G

$13.99



HyperX FURY DDR3 8GB 16GB 32GB 1600 MHz PC3-12800 Desktop RAM Memory DIMM 240pin picture

HyperX FURY DDR3 8GB 16GB 32GB 1600 MHz PC3-12800 Desktop RAM Memory DIMM 240pin

$15.90



8GB PC3L-12800S 1600MHz SODIMM DDR3 RAM | Grade A picture

8GB PC3L-12800S 1600MHz SODIMM DDR3 RAM | Grade A

$12.00



Corsair Vengeance 16GB (2x8GB) DDR3 RAM 1866MHz (CMZ16GX3M2A1866C9) picture

Corsair Vengeance 16GB (2x8GB) DDR3 RAM 1866MHz (CMZ16GX3M2A1866C9)

$15.99



Team T-FORCE VULCAN Z 32GB (2 x 16GB) PC RAM DDR4 3200 (PC4 25600) Memory picture

Team T-FORCE VULCAN Z 32GB (2 x 16GB) PC RAM DDR4 3200 (PC4 25600) Memory

$54.99



16GB (2X8GB) DDR3 PC3-12800R 1600MHz ECC Reg Server Memory RAM DIMM Upgrade Kit picture

16GB (2X8GB) DDR3 PC3-12800R 1600MHz ECC Reg Server Memory RAM DIMM Upgrade Kit

$8.98



G.SKILL Trident Z5 RGB 64GB (2 x 32GB) 288-Pin PC RAM DDR5 6400 (PC5 51200) M... picture

G.SKILL Trident Z5 RGB 64GB (2 x 32GB) 288-Pin PC RAM DDR5 6400 (PC5 51200) M...

$229.99



🔥Acer Chromebase All-In-One 24

🔥Acer Chromebase All-In-One 24"Intel Celeron 1.8 GHz |4GB RAM| 128GB SSD|Webcam

$99.00



Kingston HyperX FURY DDR3 8GB 16GB 32G 1600 1866 1333 Desktop Memory RAM DIMM picture

Kingston HyperX FURY DDR3 8GB 16GB 32G 1600 1866 1333 Desktop Memory RAM DIMM

$38.95