Clamav Begin - virus detected

General Discussion of atomic repo and development projects.

Ask for help here with anything else not covered by other forums.
mist_firefly
Forum User
Forum User
Posts: 60
Joined: Mon Jul 23, 2012 5:22 am
Location: Salisbury

Clamav Begin - virus detected

Unread post by mist_firefly »

Hi,

Had these for a couple of days on the logwatch on plesk and need to find out how to fix it.

--------------------- Clamav Begin ------------------------

Viruses detected:
Atomicorp.honeypot.hex.php.cmdshell.unclassed.344.UNOFFICIAL: 24 Time(s)
......................................................................................................................

Any ideas? (what it means, what type of virus, where to find the information, what to do next)

Thanks
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Re: Clamav Begin - virus detected

Unread post by scott »

That log is incomplete so there isnt really any information in it, did it actually write to syslog like that?
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Clamav Begin - virus detected

Unread post by mikeshinn »

I think thats the message from logwatch.

So ASL will display any clamav messages in the ASL gui, along with any details. Please log into asl, and search in the events window for any clamav events and let us know you see.
mist_firefly
Forum User
Forum User
Posts: 60
Joined: Mon Jul 23, 2012 5:22 am
Location: Salisbury

Re: Clamav Begin - virus detected

Unread post by mist_firefly »

Not exactly sure what to look for in the ASL events as clamav has many entries.

Could you advice me please?
This mention in logwatch has been going on for more then a month.
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Clamav Begin - virus detected

Unread post by mikeshinn »

Thanks for the question, so you can search for clamav events a couple of different ways:

1) search for the word "clam" in the ASL gui

2) You can search for the specific rule IDs that are used for malware, 52502 is the big one.\
shot.png
shot.png (191.34 KiB) Viewed 5662 times
Post Reply