LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-11-2020, 06:20 PM   #1
derezion
Member
 
Registered: Aug 2018
Distribution: Anything Debian-based
Posts: 84

Rep: Reputation: Disabled
Question ClamAV found many threats; What do I do now?


ClamTK/ClamAV found so many threats… What should I do now?
So I did a full scan with ClamTK. I scanned for everything including PUAs using my standard account on Ubuntu. ClamTK found a lot of threats. It could have been a little over a hundred. It showed me a list of results and gave me three options at the bottom: Quarantine, Delete, and Analysis and the it had three columns: File, Status, and Action Taken. The thing is the Quarantine option didn’t seem to do anything most of the time. When I deleted a file it would be marked as deleted in the results window under Action Taken. Anyway, the first half the threats it reported were in

/usr/lib/libreoffice/share/basi…

I didn’t want LibreOffice to stop working so these are the files I tried to quaratine. They had things like PUA.Tool.LibreOffice… in the status

The threats were from three primary sources: LibreOffice system files (I assume), files including js files from webpages I saved on this machine, and old Windows programs I backed up on this computer.

Some of the stuff found:
# In Saved pages:
PUA.Doc.Tool.LibreOfficeMa…
PUA.Html.Trojan.Agent-3707...
PUA.Pdf.Trojan.EmbeddedJavascript…

# In Downloaded Windows apps
PUA.Win.Adware.Slugin-680…
PUA.Win.Downloader.Aiis-68...
PUA.Win.Malware.Speeding…
PUA.Win.Packer.InnoInstaller...

I could go on.

With the LibreOffice files I tried to quarantine all of them but everything else (the files from saved web pages and Windows programs) I deleted.

Where do I go from here? FYI: I was going to set up a dual boot soon and wipe out this hard drive soon with my brother anyway but I don’t know when that will be.
 
Old 03-12-2020, 12:06 AM   #2
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,627

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
i would hazard a guess with the LibreOffice files
you have "macros" in the Calc ( excel) documents


as to the "old microsoft files" those are likely NOT a false positives

as to " js files from webpages I saved " those ?? Might ?? have malware in them
the web is full of nasty things

ClamAV is also known for false positives , even on a NEW install of a OS there will be some
 
Old 03-12-2020, 04:22 PM   #3
derezion
Member
 
Registered: Aug 2018
Distribution: Anything Debian-based
Posts: 84

Original Poster
Rep: Reputation: Disabled
My calc documents are very simple. I don't even know how to make "Macros." I have one spreadsheet from the web and it doesn't seem too complicated. It's a calculator for how long it would take to finish writing a book. It's from Michael Hyatt and Co and I don't think it's harmful.

I agree with you on those Microsoft programs. They gave me trouble on the XP machine I downloaded them for. One or another compromised that PC running XP in like 2015.

I didn't know ClamAV was known for false positives.
I should add that it marked these files from LibreOffice, saved web pages, and Windows programs as possible threats.
 
  


Reply

Tags
clamav, libreoffice, security, threat, ubuntu



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] No package 'x11' found No package 'xext' found No package 'xdamage' found No package 'xfixes' found No package 'x11-xcb' found Jigsaw Linux From Scratch 14 02-23-2021 08:35 PM
Clamav upgrade telling me clamav is newest version, but running 'sudo freshclam' tells me it is outdated! hddfsck Linux - Newbie 16 09-13-2019 09:43 PM
Mimedefang clamav vs clamav-milter digitolx Linux - Server 0 10-20-2010 03:45 PM
file-scan-clamav-1.8 or clamav-0.93.1 invader44 Linux - Newbie 1 12-29-2009 08:49 AM
Multi Booting many, many, many, OS's mac_man25 Linux - General 10 10-26-2003 09:13 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration