LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 07-12-2018, 08:32 AM   #1
johnny23
Member
 
Registered: Aug 2009
Location: Lapu-Lapu City, Philippines
Distribution: Slackware
Posts: 62

Rep: Reputation: 44
clamav detection on cups


If I run a clamscan on a Slackware 14.2 machine I have I get this:

Quote:
/... usb stick with installer .../SLACKDVD/slackware64/ap/cups-2.1.4-x86_64-1.txz: Unix.Trojan.Vali-6606621-0 FOUND
/usr/bin/lprm-cups: Unix.Trojan.Vali-6606621-0 FOUND
re-installing the cups package from pkgs.org doesn't help.

Is this a concern or is it a false positive? Does anyone else see this?
 
Old 07-12-2018, 09:04 AM   #2
RadicalDreamer
Senior Member
 
Registered: Jul 2016
Location: USA
Distribution: Slackware64-Current
Posts: 1,816

Rep: Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981
Where did you get it originally?

Upload lprm-cups to here and find out:
https://www.virustotal.com

Edit: Nice official Slackware mirror: http://mirrors.xmission.com/slackware/

Last edited by RadicalDreamer; 07-12-2018 at 09:06 AM.
 
Old 07-12-2018, 09:05 AM   #3
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,097

Rep: Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174
Quote:
Originally Posted by johnny23 View Post
re-installing the cups package from pkgs.org doesn't help.
don't use the shitty pkgs.org (not related to Slackware and full of ads), use an official Slackware mirror!

Quote:
Is this a concern or is it a false positive? Does anyone else see this?
I see that too and I think it's a false positive.

Last edited by ponce; 07-12-2018 at 09:06 AM.
 
Old 07-12-2018, 09:59 AM   #4
johnny23
Member
 
Registered: Aug 2009
Location: Lapu-Lapu City, Philippines
Distribution: Slackware
Posts: 62

Original Poster
Rep: Reputation: 44
Quote:
Originally Posted by ponce View Post
I see that too and I think it's a false positive.
That's my feeling. I can't see any other evidence of anything amiss with the machine.
 
Old 07-14-2018, 11:02 PM   #5
bamunds
Member
 
Registered: Sep 2013
Location: Mounds View MN
Distribution: Slackware64-14.2-Multilib XDM/FVWM3
Posts: 780

Rep: Reputation: 260Reputation: 260Reputation: 260
Have you thought of submitting it to virustotal? See if it still shows there, if not this is probably a false positive.
 
1 members found this post helpful.
Old 07-15-2018, 05:58 AM   #6
RadicalDreamer
Senior Member
 
Registered: Jul 2016
Location: USA
Distribution: Slackware64-Current
Posts: 1,816

Rep: Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981Reputation: 981
Code:
/usr/lib64/cups/cgi-bin/jobs.cgi: Unix.Trojan.Vali-6606621-0 FOUND

----------- SCAN SUMMARY -----------
Known viruses: 6574044
Engine version: 0.100.0
Scanned directories: 62809
Scanned files: 631261
Infected files: 1
Data scanned: 28049.14 MB
Data read: 534662.63 MB (ratio 0.05:1)
Time: 3388.527 sec (56 m 28 s)
~
Results:
https://www.virustotal.com/#/file/e7...c37b/detection
 
Old 07-15-2018, 03:29 PM   #7
bamunds
Member
 
Registered: Sep 2013
Location: Mounds View MN
Distribution: Slackware64-14.2-Multilib XDM/FVWM3
Posts: 780

Rep: Reputation: 260Reputation: 260Reputation: 260
I see that it is only ClamAV still detecting this as a virus. I'd send it to the folks at ClamAV and ask them if it is a false positive. Then I'd follow the other instructions, download only from a valid Slackware repository the needed file and install it. If you hear back from ClamAV please post back here their comments, especially if they still think it is a valid trojan, maybe you've found a new one.
 
Old 07-15-2018, 05:03 PM   #8
mralk3
Slackware Contributor
 
Registered: May 2015
Distribution: Slackware
Posts: 1,900

Rep: Reputation: 1050Reputation: 1050Reputation: 1050Reputation: 1050Reputation: 1050Reputation: 1050Reputation: 1050Reputation: 1050
I sent a report using the clamtk interface so that the clamav people can correct the false positive.
 
2 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
CUPS printing a test page or document over multiple pages - CUPS 1.5.4 Asjas SUSE / openSUSE 3 08-14-2015 02:17 AM
[SOLVED] configure: error: Could not find CUPS. Install libcups2-dev or cups-devel GameCodingNinja Linux From Scratch 6 07-14-2015 11:16 AM
Ethernet bonding -- link layer detection failover isn't enough, smarter detection? pwn Linux - Networking 1 07-10-2011 10:42 PM
Mimedefang clamav vs clamav-milter digitolx Linux - Server 0 10-20-2010 03:45 PM
file-scan-clamav-1.8 or clamav-0.93.1 invader44 Linux - Newbie 1 12-29-2009 08:49 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 03:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration