31 stycznia 2019

Antywirus

Diagnose antivirus avquery statistics

Firmware – FortiOS: 5.0 5.2 5.4

Syntax
diagnose antivirus avquery statistics [flush|list]

Options
flush
Used to flush the daemon and cache statistics.
list
Displays the cache and daemon statistics.



Diagnose antivirus avquery statistics flush

Firmware – FortiOS: 5.0 5.2 5.4

This command is used to flush daemon and cache statistics.

Syntax
diagnose antivirus avquery statistics flush < Enter >


Diagnose antivirus avquery statistics list

Firmware – FortiOS: 5.0 5.2
Syntax
diagnose antivirus avquery statistics list < Enter > — Display cache and daemon statistics. {5.0}
Example
diagnose antivirus avquery statistics list

Output
DNS failures : 0
DNS lookups : 0
Data send failures : 0
Data read failures : 0
Incorrect CRCs in responses : 0
Proxy request failures : 0
Requests timed out : 0
Total Requests : 0
Requests to rating servers : 0
Server error responses : 0
Relayed requests : 0
Jobs passed on daemon shutdown : 0
Server error, files passed : 0
Bad license, files passed : 0
Request queue full, files passed : 0
Daemon not started; files passed : 0
No server, files passed : 0
No resources, files passed : 0
Bad query format, files passed : 0
Cache mem allowed : 0
Cache mem used : 0
Number of cache entries : 0
Cache queries : 0
Cache hits : 0



Diagnose antivirus avquery status

Firmware – FortiOS: 5.0 5.2
Syntax
diagnose antivirus avquery status < Enter > — FortiGuard – AV Query service status {5.0}

Example
Command
diagnose antivirus avquery status

Output
FortiGuard – AV Query service is disabled.
Server available on UDP port 53


Diagnose antivirus bypass

Firmware – FortiOS: 5.0 5.2 5.4 5.6 6.0
Use this command to turn on or off the antivirus check bypass. Omitting the on or off command will display the current status of the antivirus bypass.

Syntax
diagnose antivirus bypass < on|off - On for bypassing AV checking> — bypass

Example
Command
diagnose antivirus bypass

Output
off


Diagnose antivirus database-info

Firmware – FortiOS: 5.4 5.6 6.0
This command displays antivirus database information.
For previous firmware versions of this command, please see diagnose antivirus virus list.

Syntax
diagnose antivirus database-info

Example
diagnose antivirus database-info
version:
atdb found 0 loaded 0
virus ID count 0
grayware ID count 0
signature ID count 0
etdb found 0 loaded 0
virus ID count 0
grayware ID count 0
signature ID count 0
exdb found 0 loaded 0
virus ID count 0
grayware ID count 0
signature ID count 0
mmdb found 0 loaded 0
virus ID count 0
grayware ID count 0
signature ID count 0
fsadb found 0 loaded 0
virus ID count 0
grayware ID count 0
signature ID count 0


Diagnose antivirus heuristic showrules

Firmware – FortiOS: 5.0 5.2

Syntax
diagnose antivirus heuristic showrules < Enter > — Display heuristic rule overrides


Diagnose antivirus heuristic showthreshold

Firmware – FortiOS: 5.0 5.2
Syntax
diagnose antivirus heuristic showthreshold < Enter > — Display heuristic threshold. {5.0}
Example
diagnose antivirus heuristic showthreshold
Threshold: 0


Diagnose antivirus outbreak-prevention statistics

Firmware – FortiOS: 5.6 6.0
Use this command to display the statistics of the antivirus cache and daemon

Syntax
diagnose antivirus outbreak-prevention statistics {list|flush}
Options
Option Discription
list displays the available statistics
flush clears the statistics cache

Example(s)
List
diagnose antivirus outbreak-prevention statistics list

DNS failures : 0
DNS lookups : 0
Data send failures : 0
Data read failures : 0
Incorrect CRCs in responses : 0
Proxy request failures : 0
Requests timed out : 0
Total Requests : 0
Requests to rating servers : 0
Server error responses : 0
Relayed requests : 0
Jobs passed on daemon shutdown : 0
Server error, files passed : 0
Bad license, files passed : 0
Request queue full, files passed : 0
Daemon not started; files passed : 0
No server, files passed : 0
No resources, files passed : 0
Bad query format, files passed : 0
Cache mem allowed : 0
Cache mem used : 0
Number of cache entries : 0
Cache queries : 0
Cache hits : 0


Diagnose antivirus quarantine delete

Firmware – FortiOS: 5.0 5.2 5.4 5.6 6.0
This command is used to delete a file in quarantine.

Syntax
diagnose antivirus quarantine delete < checksum of the file to delete >


Diagnose antivirus quarantine purge

Firmware – FortiOS: 5.0 5.2 5.4 5.6 6.0
This command is used to delete all quarantined files.

Syntax
diagnose antivirus quarantine purge < Enter >


Diagnose antivirus test

Firmware – FortiOS: 5.6
This command is used to display information from within the AV engine for the purposes of aiding troubleshooting and diagnostics if the AV engine crashes or times out. The command is defined and interpreted by the AV engine. FortiOS just passes the CLI command into the AV engine and outputs the strings returned by AV engine.

In AV engine 5.4.239, the following command are supported.

  • get scantypes
  • set scantypes
  • debug
  • Syntax
    diagnose antivirus test

    Its syntax can be one of the following:

    diagnose antivirus test
    or
    diagnose antivirus test ; ;…


    Diagnose antivirus virus list

    Firmware – FortiOS: 5.0 5.2
    This command is used to display the list of detected viruses.
    This command has been removed in 5.4 and was replaced with diagnose antivirus database-info.

    Syntax
    diagnose antivirus virus list < Enter >

    Example
    Command
    diagnose antivirus virus list

    Output

    Virus List
    ==========
    ACM/Bursted.AN
    ACM/Medre.A@mm
    ACM/Pasdoc.A
    Akuku.889.A
    ALS/Medre.A!tr
    Android/Agent.BY!tr
    Android/Agent.FS!tr
    Android/Basebridge.B!tr
    Android/DrdDream.A!exploit.CVE2010EASY
    Android/DroidRooter.A
    Android/DroidRooter.C
    Android/DroidRt.B
    Android/DrSheep.A
    Android/FakeInst.C!tr
    Android/Fakelash.A!tr.spy