<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="fr">
	<id>https://wiki.livois.com/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Protection_contre_les_virus</id>
	<title>Protection contre les virus - Historique des versions</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.livois.com/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Protection_contre_les_virus"/>
	<link rel="alternate" type="text/html" href="https://wiki.livois.com/mediawiki/index.php?title=Protection_contre_les_virus&amp;action=history"/>
	<updated>2026-05-25T04:48:11Z</updated>
	<subtitle>Historique des versions pour cette page sur le wiki</subtitle>
	<generator>MediaWiki 1.39.3</generator>
	<entry>
		<id>https://wiki.livois.com/mediawiki/index.php?title=Protection_contre_les_virus&amp;diff=49&amp;oldid=prev</id>
		<title>Christophe : 1 version</title>
		<link rel="alternate" type="text/html" href="https://wiki.livois.com/mediawiki/index.php?title=Protection_contre_les_virus&amp;diff=49&amp;oldid=prev"/>
		<updated>2012-05-28T20:31:46Z</updated>

		<summary type="html">&lt;p&gt;1 version&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Nouvelle page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;__TOC__&lt;br /&gt;
[[Category:Messagerie]]&lt;br /&gt;
&lt;br /&gt;
http://fr.wikipedia.org/wiki/Antivirus&lt;br /&gt;
&lt;br /&gt;
=F-prot=&lt;br /&gt;
http://www.f-prot.com/&lt;br /&gt;
&lt;br /&gt;
http://www.f-prot.com/products/corporate_users/unix/linux/mailserver.html&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;F-PROT Antivirus for Linux x86 Mail Servers:&lt;br /&gt;
* &amp;#039;&amp;#039;Scans for over 1310835 known viruses and their variants&amp;#039;&amp;#039;&lt;br /&gt;
* &amp;#039;&amp;#039;Removes viruses safely without damaging the original file&amp;#039;&amp;#039;&lt;br /&gt;
* &amp;#039;&amp;#039;Scans all mounted filesystems, directories or specific files&amp;#039;&amp;#039;&lt;br /&gt;
* &amp;#039;&amp;#039;Scans archives and compressed files&amp;#039;&amp;#039;&lt;br /&gt;
* &amp;#039;&amp;#039;Includes automated updates to the virus signature database&amp;#039;&amp;#039;&lt;br /&gt;
* &amp;#039;&amp;#039;Can be configured to perform scheduled scans when used with the cron utility&amp;#039;&amp;#039;&lt;br /&gt;
* &amp;#039;&amp;#039;Scans e-mail in transit with the three most widely used e-mail systems: Sendmail, Postfix, and Qmail.&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote class=&amp;quot;gentoo&amp;quot;&amp;gt;&lt;br /&gt;
Package Gentoo: f-prot&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mises à jour de f-prot tous les jours + mail qui prévient lors de mise à jour.&lt;br /&gt;
&amp;lt;licode file=/etc/crontab&amp;gt;&lt;br /&gt;
0     *     *     *     *   root    /opt/f-prot/fpupdate&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Avec gentoo, seul fpscan est installé, le démon fpscand est payant (130€ pour 10 personnes au 24/05/2009).&lt;br /&gt;
&lt;br /&gt;
F-prot est donc configuré en antivirus de backup avec amavisd-new.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;licode file=/etc/amavis.conf&amp;gt;&lt;br /&gt;
  ### http://www.f-prot.com/   - backs up F-Prot Daemon, V6&lt;br /&gt;
  [&amp;#039;F-PROT Antivirus for UNIX&amp;#039;, [&amp;#039;fpscan&amp;#039;],&lt;br /&gt;
    &amp;#039;--report --mount --adware {}&amp;#039;,  # consider: --applications -s 4 -u 3 -z 10&lt;br /&gt;
    [0,8,64],  [1,2,3, 4+1,4+2,4+3, 8+1,8+2,8+3, 12+1,12+2,12+3],&lt;br /&gt;
    qr/^\[Found\s+[^\]]*\]\s+&amp;lt;([^ \t(&amp;gt;]*)/ ],&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Clamav=&lt;br /&gt;
http://www.clamav.net/&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote class=&amp;quot;gentoo&amp;quot;&amp;gt;&lt;br /&gt;
Package Gentoo: clamav&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;licode file=/etc/clamd.conf&amp;gt;&lt;br /&gt;
#(Verbose logging with syslog)&lt;br /&gt;
LogSyslog&lt;br /&gt;
LogVerbose&lt;br /&gt;
LogFacility LOG_MAIL&lt;br /&gt;
#(Change pid file location) &lt;br /&gt;
PidFile /var/run/amavis/clamd.pid&lt;br /&gt;
#(Set the clamav socket) &lt;br /&gt;
LocalSocket /var/amavis/clamd&lt;br /&gt;
#(Close the connection when this limit is exceeded)&lt;br /&gt;
StreamMaxLength 10M&lt;br /&gt;
#(Don&amp;#039;t run clamd as root)&lt;br /&gt;
User amavis&lt;br /&gt;
#(Newer versions require you to uncomment this)&lt;br /&gt;
ScanMail&lt;br /&gt;
ScanArchive&lt;br /&gt;
Mises à jour (changer le proxy)&lt;br /&gt;
/etc/freshclam.conf &lt;br /&gt;
(Syslog logging)&lt;br /&gt;
LogSyslog&lt;br /&gt;
(Verbose logging)&lt;br /&gt;
LogVerbose&lt;br /&gt;
(Explicitly drop root privileges)&lt;br /&gt;
DatabaseOwner clamav&lt;br /&gt;
(Check for updates every two hours. That is the official recommendation)&lt;br /&gt;
Checks 12&lt;br /&gt;
(Use the mirror closest to you. Replace XY with your country code&lt;br /&gt;
DatabaseMirror db.fr.clamav.net&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;licode file=/etc/conf.d/clamd&amp;gt;&lt;br /&gt;
START_CLAMD=yes&lt;br /&gt;
FRESHCLAM_OPTS=&amp;quot;-d&amp;quot;&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Dans amavisd.conf, les deux variables qui indiquent les antivirus à utilisers sont:&lt;br /&gt;
*@av_scanners&lt;br /&gt;
*@av_scanners_backup&lt;br /&gt;
&lt;br /&gt;
av_scanners correspond aux antivirus qui sont lancés en permanence en mémoire&lt;br /&gt;
&lt;br /&gt;
av_scanners_backup sont à relancer pour chaque message (plus lent)&lt;br /&gt;
&lt;br /&gt;
Fixme: les scanners backup sont t&amp;#039;ils utilisés qd un scanner ppl est activé ?&lt;br /&gt;
&lt;br /&gt;
&amp;lt;licode file=/etc/amavisd.conf&amp;gt;&lt;br /&gt;
(Uncomment the clamav scanner and modify socket location)&lt;br /&gt;
[&amp;#039;ClamAV-clamd&amp;#039;,&lt;br /&gt;
\&amp;amp;ask_daemon, [&amp;quot;CONTSCAN {}\n&amp;quot;, &amp;quot;/var/amavis/clamd&amp;quot;],&lt;br /&gt;
  qr/\bOK$/, qr/\bFOUND$/,&lt;br /&gt;
  qr/^.*?: (?!Infected Archive)(.*) FOUND$/ ],&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 #rc-update add clamd default&lt;br /&gt;
&lt;br /&gt;
==Signatures externes==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Securite Info&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
http://www.securiteinfo.com/services/clamav_unofficial_malwares_signatures.shtml&lt;br /&gt;
&lt;br /&gt;
&amp;lt;licode file=/etc/cron.daily/antivirus.cron&amp;gt;&lt;br /&gt;
cd /var/lib/clamav&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
wget http://clamav.securiteinfo.com/vx.hdb.gz&lt;br /&gt;
wget http://clamav.securiteinfo.com/securiteinfo.hdb.gz&lt;br /&gt;
wget http://clamav.securiteinfo.com/honeynet.hdb.gz&lt;br /&gt;
wget http://clamav.securiteinfo.com/antispam.ndb.gz&lt;br /&gt;
gunzip vx.hdb.gz securiteinfo.hdb.gz honeynet.hdb.gz antispam.ndb.gz&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Avast=&lt;br /&gt;
http://www.avast.com/&lt;br /&gt;
&lt;br /&gt;
Récupérer une licence sur http://www.avast.com/i_kat_340.php?lang=ENG&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#cp  /root/License.dat /var/lib/avast4/License.dat&lt;br /&gt;
#tar zxvf libavastengine-4.6.0-i586.tar.gz&lt;br /&gt;
#cd libavastengine-4.6.0&lt;br /&gt;
#./mkinstall.sh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;licode file=/etc/crontab&amp;gt;&lt;br /&gt;
0 */6 * * * /usr/bin/avastvpsupdate.pl&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#cd avast4server-2.0.0-i586&lt;br /&gt;
#./mkinstall.sh&lt;br /&gt;
#avastcmd -h&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Editer /etc/init.d/avastd (bug indique ne trouve pas fichier de conf)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#man avastd.conf  &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Lire patches/HOWTO.amavisd-new&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 3) Create a new avastd scanner section in your avastd.conf configuration&lt;br /&gt;
    file designed for mail scanning (see avastd.conf(5) manual page):&lt;br /&gt;
&lt;br /&gt;
    [mailscanner]&lt;br /&gt;
        listen=/var/run/avast4/mailscanner.sock&lt;br /&gt;
        ....&lt;br /&gt;
&lt;br /&gt;
4)Restart avastd and amavisd-new daemons.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Editer amavisd.conf&lt;br /&gt;
&amp;lt;licode file=/etc/amavisd.conf&amp;gt;&lt;br /&gt;
@av_scanners = (&lt;br /&gt;
+  ### http://www.avast.com/&lt;br /&gt;
+  [&amp;#039;avast! Antivirus daemon&amp;#039;,&lt;br /&gt;
+    \&amp;amp;ask_daemon,      # greets with 220, terminates with QUIT&lt;br /&gt;
+    [&amp;quot;SCAN {}\r\nQUIT\r\n&amp;quot;, &amp;#039;/var/run/avast4/mailscanner.sock&amp;#039;],&lt;br /&gt;
+    qr/[\t]\[+\]/, qr/[\t]\[L\][\t]/, qr/[\t]\[L\][\t](.+)[^\r\n]/ ],&lt;br /&gt;
@av_scanners_backup = (&lt;br /&gt;
+  ### http://www.avast.com/&lt;br /&gt;
+  [&amp;#039;avast! Antivirus&amp;#039;, &amp;#039;avastcmd&amp;#039;,&lt;br /&gt;
+    &amp;#039;-ai -n -tA {}&amp;#039;, [0], [1], qr/infected by: (.*)/ ],&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=AVG (grisoft)=&lt;br /&gt;
&lt;br /&gt;
http://www.grisoft.com&lt;br /&gt;
&lt;br /&gt;
AVG Linux Server Edition&lt;br /&gt;
&lt;br /&gt;
195€ pour 15 adresses e-mail sur 2ans&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote class=&amp;quot;gentoo&amp;quot;&amp;gt;&lt;br /&gt;
Package Gentoo: sys-libs/lib-compat&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#cd avg7-linux/&lt;br /&gt;
#./install.sh&lt;br /&gt;
# avgscan -register &amp;lt;your license number&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Le n° de licence d&amp;#039;essai suivant peut être utilisé: 70LINUX-TTS05-PZ-C01-S1-J18-IHAR&lt;br /&gt;
&lt;br /&gt;
&amp;lt;licode file=/etc/avg.conf&amp;gt;&lt;br /&gt;
unixSocketName = /tmp/avg.sock&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#avgscan -d&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote class=&amp;quot;gentoo&amp;quot;&amp;gt;&lt;br /&gt;
Remarque Gentoo: Créer le script /etc/init.d/avgscan suivant:&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;licode file=/etc/init.d/avgscan&amp;gt;&lt;br /&gt;
#!/sbin/runscript&lt;br /&gt;
&lt;br /&gt;
depend() {&lt;br /&gt;
        need net&lt;br /&gt;
        use logger&lt;br /&gt;
        #provide antivirus&lt;br /&gt;
        before amavisd-new&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
checkconfig() {&lt;br /&gt;
        if [ ! -e /etc/avg.conf ] ; then&lt;br /&gt;
                eerror &amp;quot;You need an /etc/avg.conf to AVG7 Anti-Vir Daemon&amp;quot;&lt;br /&gt;
                return 1&lt;br /&gt;
        fi&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
start() {&lt;br /&gt;
        ebegin &amp;quot;Starting AVG7 Anti-Vir Daemon&amp;quot;&lt;br /&gt;
        start-stop-daemon --start --quiet --chuid amavis --exec  /usr/bin/avgscan -- -d&lt;br /&gt;
        eend $?&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
stop() {&lt;br /&gt;
        ebegin &amp;quot;Stopping AVG7 Anti-Vir Daemon&amp;quot;&lt;br /&gt;
        start-stop-daemon --stop --quiet --name avgscan&lt;br /&gt;
        eend $?&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The AVG section in the configuration file for amavid-new should contain&lt;br /&gt;
&lt;br /&gt;
&amp;lt;licode file=/etc/amavisd.conf&amp;gt;&lt;br /&gt;
[&amp;#039;AVG Anti-Virus&amp;#039;,&lt;br /&gt;
        \&amp;amp;ask_daemon, [&amp;quot;SCAN {}\n&amp;quot;, &amp;#039;/tmp/avg.sock&amp;#039;],&lt;br /&gt;
        qr/^200/, qr/^403/, qr/^403 .*?: (.+)/ ],&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;AVG Update&amp;lt;/u&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#avgupdate -o &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;licode file=/etc/crontab&amp;gt;&lt;br /&gt;
0 *   * * * root   avgupdate --online --no-progress –no-daemons 1&amp;gt;/dev/null&lt;br /&gt;
&amp;lt;/licode&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Copy|2006-2010|Christophe de Livois|FDL}}&lt;/div&gt;</summary>
		<author><name>Christophe</name></author>
	</entry>
</feed>