LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-23-2004, 05:49 AM   #1
aikempshall
Member
 
Registered: Nov 2003
Location: Bristol, Britain
Distribution: Slackware
Posts: 900

Rep: Reputation: 153Reputation: 153
ClamAV found urlspoof in Knoppix


I've got a partition that holds a knoppix.iso that I rebuild now and again, also use it as a backup for my usb stick. Last night I ran clamav against my complete machine and it reported -

//spare2/knoppix/3.6/KNOPPIX/KNOPPIX: Trojan.URLspoof.gen FOUND
//spare2/knoppix/knoppix36.iso: Trojan.URLspoof.gen FOUND

This morning I ran clamav against -
my latest knoppix CD;
just the /spare2 directory
the complete machine

in none of the above did clamav find the URLspoof

I also ran Norton against the CD and again nothing!

Can anyone shed some light on this?

Thanks
 
Old 11-23-2004, 06:00 AM   #2
rjlee
Senior Member
 
Registered: Jul 2004
Distribution: Ubuntu 7.04
Posts: 1,994

Rep: Reputation: 76
Which version of ClamAV are you using?

According to Google (http://66.102.9.104/search?q=cache:J...poof.gen&hl=en) there was a fix on 2004-02-28 that fixed a false positive bug with Trojan.URLspoof.gen

Alternatively, you may have found a virus that's good at hiding itself.
 
Old 11-23-2004, 01:54 PM   #3
aikempshall
Member
 
Registered: Nov 2003
Location: Bristol, Britain
Distribution: Slackware
Posts: 900

Original Poster
Rep: Reputation: 153Reputation: 153
rjlee

Thanks for the quick response. Should have looked at the error logs first.

In clamav-update error log started to get the following some time between 15/10/2004 and 31/10/2004 -

ClamAV update process started at Tue Nov 23 11:45:01 2004
main.cvd is up to date (version: 28, sigs: 26630, f-level: 3, builder: tomek)
WARNING: Your ClamAV installation is OUTDATED - please update immediately !
WARNING: Current functionality level = 2, required = 3
daily.cvd is up to date (version: 601, sigs: 782, f-level: 3, builder: trog)
WARNING: Your ClamAV installation is OUTDATED - please update immediately !
WARNING: Current functionality level = 2, required = 3

Updated from 0.71 to 0.80 so that clamav-update is ok now. Will be running another scan this evening.

The clamav-update log looks like this now -

ClamAV update process started at Tue Nov 23 12:29:49 2004
main.cvd updated (version: 28, sigs: 26630, f-level: 3, builder: tomek)
daily.cvd updated (version: 601, sigs: 782, f-level: 3, builder: trog)
Database updated (27412 signatures) from database.clamav.net (147.229.3.16).

which looks ok to me. Still don't understand where URLspoof came from or went! One of life's mysteries I suppose. Until the next scan!

Thanks
 
Old 11-27-2004, 04:57 PM   #4
rjlee
Senior Member
 
Registered: Jul 2004
Distribution: Ubuntu 7.04
Posts: 1,994

Rep: Reputation: 76
Given the fact that a false-positive bug was found (i.e. a bug that reports a virus even though it isn't there), I suspect that you never had a urlspoof in the first place.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ClamAV depam Linux - Software 1 10-18-2005 07:33 PM
ClamAV dudeman41465 Linux - Software 3 10-11-2005 08:40 AM
knoppix 3.8.1 soundcard detected, but mixer cannot be found jfhawk06 Linux - Newbie 1 04-16-2005 09:24 PM
Knoppix filesystem not found rrfish72 Linux - General 9 03-23-2005 01:33 AM
help with clamAV Lleb_KCir Linux - Software 6 01-29-2005 03:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration