Announcement

Collapse
No announcement yet.

lynis, clamav, clamTK and two viruses

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    lynis, clamav, clamTK and two viruses

    I saw an article about lynis, which led to clamav, clamTK and two viruses.

    The 211 version of lynis is in the repository. One has to update from the lynis homepage to get the latest, version 250. Lynis was written by the same group that wrote rkhunter, and the results look similar, except that lynis checks more areas and offers suggestions for improving security weaknesses it discovers.

    That article led to clamav and its gui, clamTK. The latest version of both are in the repository. Here is the clamav gui:

    Click image for larger version

Name:	ClamTk_gui.png
Views:	1
Size:	31.3 KB
ID:	649209

    I scanned my home account and here are the results:

    Click image for larger version

Name:	Two_infected_files-2.png
Views:	1
Size:	46.4 KB
ID:	649208

    I don't know if those are real infections or false positives. That is something I plan to investigate later today. However, since I no longer run Minecraft 11.02 I deleted that entire directory. The Acer shipping report pdf I also deleted.

    More on this later.

    EDIT:
    The heuristic encrypted pdf is a false positive:
    https://community.sophos.com/kb/en-us/116206

    The java.malware.agent is a false positive.
    http://lists.clamav.net/pipermail/cl...er/003511.html
    Last edited by GreyGeek; Jul 09, 2017, 08:42 AM.
    "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
    – John F. Kennedy, February 26, 1962.

    #2
    he he ,,,yes false positives are always a possibility ,,,,,,,,, a linux-live .iso will get a positive/possible vulnerability when scanned in a windows systems AV

    VINNY
    i7 4core HT 8MB L3 2.9GHz
    16GB RAM
    Nvidia GTX 860M 4GB RAM 1152 cuda cores

    Comment

    Working...
    X