store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Mon May 20, 2013 9:39 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 
Author Message
 Post subject: Clamav Begin - virus detected
Unread postPosted: Mon Sep 10, 2012 4:53 am 
Offline
Forum User
Forum User

Joined: Mon Jul 23, 2012 5:22 am
Posts: 60
Location: Salisbury
Hi,

Had these for a couple of days on the logwatch on plesk and need to find out how to fix it.

--------------------- Clamav Begin ------------------------

Viruses detected:
Atomicorp.honeypot.hex.php.cmdshell.unclassed.344.UNOFFICIAL: 24 Time(s)
......................................................................................................................

Any ideas? (what it means, what type of virus, where to find the information, what to do next)

Thanks


Top
 Profile  
 
 Post subject: Re: Clamav Begin - virus detected
Unread postPosted: Mon Sep 10, 2012 1:20 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7420
Location: earth
That log is incomplete so there isnt really any information in it, did it actually write to syslog like that?


Top
 Profile  
 
 Post subject: Re: Clamav Begin - virus detected
Unread postPosted: Mon Sep 10, 2012 5:00 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3243
Location: Chantilly, VA
I think thats the message from logwatch.

So ASL will display any clamav messages in the ASL gui, along with any details. Please log into asl, and search in the events window for any clamav events and let us know you see.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Clamav Begin - virus detected
Unread postPosted: Tue Sep 11, 2012 10:40 am 
Offline
Forum User
Forum User

Joined: Mon Jul 23, 2012 5:22 am
Posts: 60
Location: Salisbury
Not exactly sure what to look for in the ASL events as clamav has many entries.

Could you advice me please?
This mention in logwatch has been going on for more then a month.


Top
 Profile  
 
 Post subject: Re: Clamav Begin - virus detected
Unread postPosted: Tue Sep 11, 2012 2:50 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3243
Location: Chantilly, VA
Thanks for the question, so you can search for clamav events a couple of different ways:

1) search for the word "clam" in the ASL gui

2) You can search for the specific rule IDs that are used for malware, 52502 is the big one.\

Attachment:
shot.png
shot.png [ 191.34 KiB | Viewed 689 times ]

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group