LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-25-2006, 07:46 PM   #1
(TPM) Croaker
LQ Newbie
 
Registered: Jan 2005
Posts: 7

Rep: Reputation: 0
Security Question


I am constantly helping friends of mine, who use various flavors of Windows, to disinfect their PC's. This usually requires using Windows based tools to scan for Viruses, Spy/Mal/Ad Ware, Trojans, and so forth.

What I was thinking was "What if I could use a Live CD Linux distro that has Linux based tools to detect Windows security risks".

I did some searches on Google and did not find what I was looking for, so I was wondering if anyone here may have some experience/suggestions.

Here's what I am looking for:

A Linux distro that allows me to boot from CD and include other packages in the setup. The distro would need to be capable of mounting the Windows harddrives and, preferably, see the partitions and mount them automatically.

A Linux based package that could be added to the above distro which would allow me to scan the Windows partitions for security risks and give a report outlining the viruses, Spy/Mal/Ad ware, etc that it finds.

Actually removing these threats would be nice, but not required. As far as I know, many Linux distros still have problems doing anything but reading from NTFS based partitions.

Thanks in advance for any suggestions.
 
Old 01-25-2006, 08:28 PM   #2
kilgoretrout
Senior Member
 
Registered: Oct 2003
Posts: 2,989

Rep: Reputation: 388Reputation: 388Reputation: 388Reputation: 388
Clamav is a free linux based antivirus program that can scan a windows partition for viruses. I believe it's included in knoppix and kannotix and probably more.
 
Old 01-26-2006, 01:49 AM   #3
(TPM) Croaker
LQ Newbie
 
Registered: Jan 2005
Posts: 7

Original Poster
Rep: Reputation: 0
kilgoretrout,

Thanks for the reply, that's good to know. Believe it or not, Knoppix is one of the Distros that I have not yet tried. This sounds though as if it is just Viruses. Are there any *Ware scanner available for Linux that would scan the Windows partitions? I still haven't been able to find any through google. The closest I have come are some of the online scanners, but they all require ActiveX which, to the best of my knowledge, will not run under Linux. Is that correct?
 
Old 01-26-2006, 10:56 AM   #4
kilgoretrout
Senior Member
 
Registered: Oct 2003
Posts: 2,989

Rep: Reputation: 388Reputation: 388Reputation: 388Reputation: 388
That's correct. ActiveX is a windows abomination and the main reason people have so much spyware in the first place. It allows code to be installed on the user's system through IE without any intervention from the user. One of the worst security blunders that MS ever made IMHO.
I know of no spyware scanners for linux, i.e. a linux app that can scan windows for spyware. You might try running a windows spyware removal app in linux under wine but I doubt that would work.

Here's another nice livecd with clamav called Insert:

http://www.inside-security.de/insert_en.html

It's only about 50MB and has some very handy apps.
 
Old 01-26-2006, 09:46 PM   #5
(TPM) Croaker
LQ Newbie
 
Registered: Jan 2005
Posts: 7

Original Poster
Rep: Reputation: 0
Hey kilgoretrout,

Thanks again. I will try both of those distros and see which works. I came across an online scanner from Trend-Micro that uses Java rather than ActiveX to operate, so I'm going to see what happens if I try to run that from a Live CD distro.

Would you be interested in the results?
 
Old 01-26-2006, 10:02 PM   #6
kilgoretrout
Senior Member
 
Registered: Oct 2003
Posts: 2,989

Rep: Reputation: 388Reputation: 388Reputation: 388Reputation: 388
Sure. Good luck.
 
Old 01-27-2006, 05:58 PM   #7
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
maybe you could get windows-based anti-spyware programs to run on a linux live cd by using Wine?? anyways, it's just a thought...

Last edited by win32sux; 01-27-2006 at 06:00 PM.
 
Old 01-28-2006, 06:01 PM   #8
(TPM) Croaker
LQ Newbie
 
Registered: Jan 2005
Posts: 7

Original Poster
Rep: Reputation: 0
I'm still working on this. The Trend-Micro scanner has not worked yet because it says it does not yet work with Multi-Byte addresses. I'm still looking into what I can do about that.

As for using WINE, I know a lot of people have tried it and liked it, but I have never gotten it to work right for me.

I found some programs called Ultimate Boot CD that you can get for free and boot either Windows or DOS with programs embedded on the CD for recovery purposes. The DOS are complete, as they come with FreeDOS. For the Windows version you have to have your own copy of Windows to add into the CD with the Utils. I have tried them however, and they do work.

FYI...Knoppix DVD version comes with the ClamAV Anti-Virus, but the CD version does not. I'm still working with the Inside Security package to see what may work.

Later.
 
Old 01-29-2006, 04:08 AM   #9
Arles
Member
 
Registered: Oct 2005
Location: Venezia
Distribution: Ubuntu 10.10
Posts: 42

Rep: Reputation: 15
I'm not sure how to help you with scanning from linux but your friends should not have problems with this kind of stuff. Let's say that I personally had no spyware or virus for last one year on my win partition. The combination I use is winupdate,spybot search&destroy, nod32 and a firewall that came with SP2..So far so good..So give it a try
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Question brokenflea Slackware 1 02-16-2005 03:19 PM
Security Question? DeezNutz Linux - Newbie 11 12-30-2002 06:45 AM
Security Question oulevon Linux - Security 1 07-11-2002 01:55 PM
Security question {newbie question} Radio Linux - Security 3 05-17-2002 06:32 PM
Security Question mswebs Linux - Security 4 10-29-2001 08:43 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration