LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-26-2017, 12:02 PM   #1
rhandwor
Member
 
Registered: Oct 2005
Posts: 130
Blog Entries: 1

Rep: Reputation: 16
Clam Anti Virus


My Fedora 25 color went on most of my Activities panel. I ran a virus scan and found 28 different malware. Do you think I can click on the items and delete without shutting of the system? I have another hard drive and know this is the problem.
 
Old 06-26-2017, 12:53 PM   #2
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Where were they found?
Were they PUAs?

Advice: Don't enable PUA and don't scan /
There are False Positives having mono installed, for example.
Have a good one!

I wouldn't delete anything.

Last edited by Habitual; 06-26-2017 at 03:24 PM. Reason: Added mono INFO
 
Old 06-26-2017, 04:17 PM   #3
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
If you are not an administrative user with access to "root," then the odds IMHO are nearly 100% that every single one of these reports is false.

Don't bother with anti-virus (sic) software.
 
1 members found this post helpful.
Old 06-27-2017, 07:00 AM   #4
rhandwor
Member
 
Registered: Oct 2005
Posts: 130

Original Poster
Blog Entries: 1

Rep: Reputation: 16
Quote:
Originally Posted by Habitual View Post
Where were they found?
Were they PUAs?

Advice: Don't enable PUA and don't scan /
There are False Positives having mono installed, for example.
Have a good one!

I wouldn't delete anything.
How do you enable PUA
The are in the boot section and changed ISP numbers. Every thing worked fine until I had a problem with a download.Basically I have to fix the problem or wipe the drive and reinstall.
 
Old 06-27-2017, 08:14 AM   #5
hydrurga
LQ Guru
 
Registered: Nov 2008
Location: Pictland
Distribution: Linux Mint 21 MATE
Posts: 8,048
Blog Entries: 5

Rep: Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925
Please paste a list of the files that were found by your anti-virus program.

To disable searching for PUAs, you don't say if you are running ClamAV through the command line (clamscan) or through the GUI (ClamTK). If the former, use --detect-pua=no (it's in man clamscan). If the latter, uncheck Configuration->Settings->Scan for PUAs.

What was the download that caused the problem? Can you describe that problem in more detail?

Did you make any system backups or images before the problem arose? If you did, then revert to the last one before the problem rather than having to reinstall.
 
Old 06-27-2017, 08:31 AM   #6
rhandwor
Member
 
Registered: Oct 2005
Posts: 130

Original Poster
Blog Entries: 1

Rep: Reputation: 16
Quote:
Originally Posted by hydrurga View Post
Please paste a list of the files that were found by your anti-virus program.

To disable searching for PUAs, you don't say if you are running ClamAV through the command line (clamscan) or through the GUI (ClamTK). If the former, use --detect-pua=no (it's in man clamscan). If the latter, uncheck Configuration->Settings->Scan for PUAs.

What was the download that caused the problem? Can you describe that problem in more detail?

Did you make any system backups or images before the problem arose? If you did, then revert to the last one before the problem rather than having to reinstall.
I have another hard drive I'm using at the present time I'm presently getting ideas for when I switch hard drives. I can just shut down and unplug this one and plug into the other one. The other one boots up fine but not every thing works.I'm waiting until a new update is released. I'm planning to check if this is good before going further.I'm also waiting on fedora 26 being released so I can make a new cd-rom. I also have a linux drive wiper cd-rom. I've had more problems with Fedora 25 than the last few issues. Thanks for your help.
 
Old 06-27-2017, 09:40 AM   #7
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
Remember that a digital computer cannot "get 'infected.'" You could catch the flu just by walking into the wrong elevator, if your immune system did not destroy the virus first. But a digital computer has no corollary to a virus. The files that comprise the core of the system should not be modifiable by any ordinary user ... and your regular login account should not be capable of gaining elevated privileges. You should be running backups to safely preserve copies of anything that a piece of rogue software could modify, and you should also be exercising due diligence.

For instance – run an "ad blocker." Those advertisements are actually computer programs, from a completely unknown source, and they could do anything while flashing pretty pictures at you.
 
Old 06-30-2017, 03:36 PM   #8
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by hydrurga View Post
Please paste a list of the files that were found by your anti-virus program.

To disable searching for PUAs, you don't say if you are running ClamAV through the command line (clamscan) or through the GUI (ClamTK).
Either method, PUA is disabled by default.
My point was most folks enable it thinking "extra" will result, and then clicky-clicky on /
Hence, My personal suggestion is always
Don't enable PUA and don't scan /

Code:
clamscan -ri $HOME
will report infected files it finds recursively.

And as a consolation prize for the OP, <wait for it>
...
clamscan doesn't actually clean.
Delete yes, clean no.
But it is still a good first step in analyzing the system for potential threats.
It's a Great Reporting tool.

I absolutely rely on it for servers.

Just sayin'

Peace.

Last edited by Habitual; 06-30-2017 at 03:43 PM. Reason: thanks for --detect-pua=no
 
Old 06-30-2017, 05:31 PM   #9
rhandwor
Member
 
Registered: Oct 2005
Posts: 130

Original Poster
Blog Entries: 1

Rep: Reputation: 16
I plan on trying this weekend. A new Kernel is available I plan on installing.
Thanks for the info I have to plug into this hard drive to complete this.
 
Old 07-01-2017, 02:12 PM   #10
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
What does a new kernel have to do with anything?
 
Old 07-01-2017, 06:22 PM   #11
rhandwor
Member
 
Registered: Oct 2005
Posts: 130

Original Poster
Blog Entries: 1

Rep: Reputation: 16
I ran by the command line and didn't pick up anything.Some of the problems were in the kernal. Using the normal clam from the interface showed it still in the new kernel.
I downloaded comodo fr4ee linux anti virus and it didn't pick up anything. The problem appears to be related to perlgtk.
I will look further tomorrow. When I used dnf update --enablerepo=updates-testing I think it changes web sites causing multiple ip addresses.
 
Old 07-02-2017, 07:40 AM   #12
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
done here.

Quote:
Originally Posted by rhandwor View Post
Some of the problems were in the kernal.
I've advised you not to scan / to avoid false positives.
but it's your host, have at it.

Have a Great Day!
 
Old 07-03-2017, 01:15 PM   #13
Crippled
Member
 
Registered: Sep 2015
Distribution: MX Linux 21.3 Xfce
Posts: 595

Rep: Reputation: Disabled
Quote:
Originally Posted by rhandwor View Post
My Fedora 25 color went on most of my Activities panel. I ran a virus scan and found 28 different malware. Do you think I can click on the items and delete without shutting of the system? I have another hard drive and know this is the problem.
Quarantine them incase there are false positive which is highly likely. This way you can restore them when you find out that they are not a virus.
 
Old 07-03-2017, 06:02 PM   #14
rhandwor
Member
 
Registered: Oct 2005
Posts: 130

Original Poster
Blog Entries: 1

Rep: Reputation: 16
I tried to do this but clam says I don't have permission or the hard drive isn't large enough. I have a 2T drive with more than 1/2 left available to use.
 
Old 07-03-2017, 06:05 PM   #15
Crippled
Member
 
Registered: Sep 2015
Distribution: MX Linux 21.3 Xfce
Posts: 595

Rep: Reputation: Disabled
Quote:
Originally Posted by rhandwor View Post
I tried to do this but clam says I don't have permission or the hard drive isn't large enough. I have a 2T drive with more than 1/2 left available to use.
Are you using ClamTK or ClamAV?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Clam Anti Virus database Updates ravikiran189 Linux - General 2 06-14-2012 03:12 AM
Clam Anti Virus and vmlinuz adymcc Linux - Software 3 02-28-2008 04:53 AM
Is clam anti-virus a decent product HGeneAnthony Linux - Software 8 04-29-2006 05:01 PM
Clam Anti-Virus jspaceman Slackware 3 03-28-2005 10:57 AM
Clam Anti-Virus database down? jspaceman Linux - Software 3 03-23-2004 02:53 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:49 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration