LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-29-2004, 10:16 AM   #1
sh1ft
Member
 
Registered: Feb 2004
Location: Ottawa, Ontario, Can
Distribution: Slackware, ubuntu
Posts: 391

Rep: Reputation: 32
1st ClamAV scan.. 48 files infected... What??!!


So I did my first full virus scan in linux the other day with ClamAV. I figured hey, this is linux, I don't get viruses. But better safe than sorry right? Well I left it going overnight, and to my suprise, when I checked the output in the morning it reported 48 INFECTED FILES!

Luckily I made it log, so I went and checked the clamAV log and this is what I found:

Code:
//usr/share/xmms/Skins/XMMS-Green.zip: Oversized.Zip FOUND
//usr/share/xmms/Skins/Plume-XMMS-v1.zip: Oversized.Zip FOUND
//usr/share/xmms/Skins/cherry.zip: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/venice.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/SG_1945_final.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/warehouse_beta.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/temple_final.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/over_the_top.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/mp_beach.516d495c.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/mp_beach.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/2hide.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/UrbanTerritory.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/venice_b4.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/fun_beach_final.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/axislab_b2.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/stalingrad.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/xsb1.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/resurrection.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/bayraid_beta1.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/mml_helmsdeep_a2.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/ROP_River.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/mc_bergen_beta4.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/v2_factory_b2.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/steelplant2.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/berserk_te.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/ffr_final.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/denoflions_etdual.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/voilegarde_b2.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/northpole.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/SoT_b1.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/caen.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/mcassino.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/sector47_pubbeta.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/raiders.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/custom1icepack.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/eagles_b1.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/darji_a2.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/SG1945_V2_CatC.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/citadel_obj.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/voilegarde_b3.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/vara.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etmain/7map8.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/shrubet/et_ice.pk3: Oversized.Zip FOUND
//home/nolan/.etwolf/etpro/lp1_1.pk3: Oversized.Zip FOUND
//home/nolan/.q3a/InstaUnlagged/q3wpak0.pk3: Oversized.Zip FOUND
//home/nolan/.q3a/instaunlagged/q3wpak0.pk3: Oversized.Zip FOUND
//home/nolan/.q3a/instaunlagged/brok3npak.pk3: Oversized.Zip FOUND

-- summary --
Known viruses: 22168
Scanned directories: 39303
Scanned files: 382001
Infected files: 48
Data scanned: 16741.49 MB
I/O buffer size: 131072 bytes
Time: 24437.469 sec (407 m 17 s)

Whoa... wait a minute, it's reporting all my enemy territory and quake3 maps/pk3 as VIRUSES? What's up with that? And what about the xmms skins? Why does it say those are infected? I know the quake files are clean... This makes no sense.
 
Old 06-29-2004, 09:21 PM   #2
Diminished7th
Member
 
Registered: Apr 2004
Distribution: Gentoo, FreeBSD
Posts: 88

Rep: Reputation: 15
Trash that Brok3n pack
 
Old 06-29-2004, 10:06 PM   #3
sh1ft
Member
 
Registered: Feb 2004
Location: Ottawa, Ontario, Can
Distribution: Slackware, ubuntu
Posts: 391

Original Poster
Rep: Reputation: 32
Quote:
Originally posted by Diminished7th
Trash that Brok3n pack
lol abom. I don't even know why I have it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ClamAV scan with a LiveCD AvatarofVirgo Linux - Security 4 10-12-2007 05:08 PM
Why don't search ClamAV infected files dawidson Linux - Newbie 2 11-24-2005 12:03 PM
clamav: infected files provkitir Linux - Security 2 12-20-2004 01:19 AM
What is the best way to get clamav to scan emails? luca2005 Linux - Software 0 12-12-2004 04:52 AM
clamav infected file emetib Linux - Software 1 04-11-2004 03:43 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:36 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration