Results 1 to 5 of 5

Thread: Virus scan with Knoppix?

  1. #1
    Member registered user
    Join Date
    Mar 2004
    Posts
    46

    Virus scan with Knoppix?

    With Knoppix, I understand that I can run a virus
    scan on a (potentially infected) Windows NTFS PC.

    How should I do this?
    Which application does this?
    How will it get the latest virus definitions?

  2. #2
    Senior Member registered user
    Join Date
    Aug 2004
    Location
    In a house... hopefully
    Posts
    554
    NOT RECOMENDED!! to what i know... it isnt recomended to edit any NTFS file system.... but if you want to risk it... i would sugggest

    f-prot or Av-clam (it could be called av-clan)...

    those two are good linux virus scanners....

  3. #3
    Administrator Site Admin-
    Join Date
    Apr 2003
    Location
    USA
    Posts
    5,441
    Chris, it was a valid question. No one said anything about editing files on a NTFS partitiion (which is a bad idea™), but scanning a Windows system with something other than that copy of Windows itself can be important. Once a nasty virus gets into a system (and this is true for any OS, not just Windows) it can gain enough control to hide itself from virus scanners. All virus scanners that run under Windows make API or System Calls to the operating system to request things like the disk sectors they want to scan. If a virus is clever enough (and this ain't rocket science), it can watch these calls and when the call that would return it's location on the disk and reveal it is made, it can just return emptry blocks or some other part of the disk. The scanner never knows it is being lied to. There are, of course, plenty of other ways to fool a scanning program once you have control of the system. Even most experienced users would never detect them. So scanning with software completely independent of the infected system is important. If you get a clean scan you have no need to write to the NTFS partition. If you detect a virus that conceals itself with a "root kit", this may be the only reasonable way that you could detect it. Only then do you need to decide what to do about it, which may well be salvage all of your data with Knoppix, reformat the disk, and completely reinstall.

  4. #4
    Senior Member registered user
    Join Date
    Aug 2004
    Location
    In a house... hopefully
    Posts
    554
    oh ok... me mistake...


    thanks.. i cant wait until we would be able to edit NTFS... then we can all be evil (especially me)

  5. #5
    Senior Member registered user
    Join Date
    Apr 2005
    Location
    italy
    Posts
    245

Similar Threads

  1. Virus Scan from LiveCD
    By patches1391 in forum General Support
    Replies: 8
    Last Post: 04-01-2009, 12:47 AM
  2. knoppix and virus scan
    By mid1700s in forum MS Windows & New to Linux
    Replies: 3
    Last Post: 04-09-2007, 04:32 PM
  3. Trying to virus scan a networked Windows PC from Knoppix
    By Synthpopalooza in forum Networking
    Replies: 2
    Last Post: 09-22-2005, 01:10 PM
  4. newbie - auto myconfig=scan home=scan
    By eentonig in forum General Support
    Replies: 0
    Last Post: 01-11-2005, 10:57 AM
  5. Using F-Prot to Virus Scan Windows Partitions
    By cascadefx in forum Tips and Tricks
    Replies: 1
    Last Post: 07-01-2003, 09:13 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


ProLabs 10GBase-TX SFP+ RJ-45 Copper Transceiver Module P/N: SFP-10GBASE-T-C NEW picture

ProLabs 10GBase-TX SFP+ RJ-45 Copper Transceiver Module P/N: SFP-10GBASE-T-C NEW

$34.99



NEW Sealed Cisco SFP-10G-LR 10GBASE-LR SFP+ 1310nm 10km *US Shipping* picture

NEW Sealed Cisco SFP-10G-LR 10GBASE-LR SFP+ 1310nm 10km *US Shipping*

$18.00



Lot (10) Dell 0N8TDR 850nm SFP-10G-SR-85C 10Gbs sfp+ FTLX8574D3BNL-FC N8TDR NEW picture

Lot (10) Dell 0N8TDR 850nm SFP-10G-SR-85C 10Gbs sfp+ FTLX8574D3BNL-FC N8TDR NEW

$68.00



New Sealed Cisco SFP-10G-LR 10GBASE-LR SFP Plug-in GBIC Transceiver module A picture

New Sealed Cisco SFP-10G-LR 10GBASE-LR SFP Plug-in GBIC Transceiver module A

$15.80



Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module 10-2415-03  picture

Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module 10-2415-03

$8.00



Authentic Cisco GLC-SX-MMD 1000BASE-SX SFP Module WITH Green Hologram picture

Authentic Cisco GLC-SX-MMD 1000BASE-SX SFP Module WITH Green Hologram

$29.99



Cisco SFP-10G-LR 10GBASE-LR SFP+ TRASNCEIVER picture

Cisco SFP-10G-LR 10GBASE-LR SFP+ TRASNCEIVER

$99.99



Lot of 10 - HP 10Gb SR SFP+ Transceiver 455883-B21 455885-001 456096-001 850nm picture

Lot of 10 - HP 10Gb SR SFP+ Transceiver 455883-B21 455885-001 456096-001 850nm

$25.99



New Sealed Cisco GLC-TE 1000BASE-T RJ45 SFP Transceiver module *US Shipping* picture

New Sealed Cisco GLC-TE 1000BASE-T RJ45 SFP Transceiver module *US Shipping*

$20.00



Lot of 20 Genuine CISCO GLC-TE 30-1475-03 GBIC 1000BASE-T RJ-45 SFP+ Transceiver picture

Lot of 20 Genuine CISCO GLC-TE 30-1475-03 GBIC 1000BASE-T RJ-45 SFP+ Transceiver

$180.99