Announcement

Collapse
No announcement yet.

Virus warning by Klamav and 'warnings' from rkhunter. What's wrong? ANSWERED

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Virus warning by Klamav and 'warnings' from rkhunter. What's wrong? ANSWERED

    Chasing very erratic boot problems again. Virus check with Klamav produces 14 viruses/problems. As shown in the attached screenshot. Since almost all follow the same pattern, I presume that Klamav identifies 'zip files ( and xxx.so) as 'problems'. Is that correct?
    Here is the pattern:
    /usr/lib/xulrunner-1.9.1.5/libxul.so
    /usr/lib/libwx_baseu-2.8.so.0.6.0 and so on.

    rkhunter produced the following warnings:

    [18:42:36] Warning: The file '/usr/sbin/unhide-linux26' exists on the system, but it is not present in the rkhunter.dat file.

    [18:42:36] /usr/sbin/unhide-linux26 [ Warning ]
    [18:42:36] Warning: The file '/usr/sbin/unhide-linux26' exists on the system, but it is not present in the rkhunter.dat file.


    Info: Test 'hidden_procs' disabled at users request.
    [18:44:36]
    [18:44:36] Info: Test 'suspscan' disabled at users request.



    [18:45:03] Checking /dev for suspicious file types [ Warning ]

    [18:45:03] Warning: Suspicious file types found in /dev:
    [18:45:04] /dev/shm/pulse-shm-3974406540: data

    [18:45:04] Checking for hidden files and directories [ Warning ]
    [18:45:05] Warning: Hidden directory found: /dev/.udev
    [18:45:05] Warning: Hidden directory found: /dev/.initramfs

    The hidden directories are apparently harmless and required.

    Fourteen files of the ".so" type that are identified as 'virus/problem' may also just be leftover from updated or system installation.

    But I am suspicious because of the erratic nature of the boot problems.
    Checksum error
    Drive A found when there is none installed and blank screens on startup galore.
    Some of it may still be an OS problem.
    I know my Cmos battery is brand new. I reset the Cmos. My Bios setup is correct, but resets itself on startup at times.

    Is I can make a DOS startup diskette, I will update the Bios. If that does not help, then I suspect MoBo or virus.

    Can anyone please comment on the strange files flagged by Klamav and rkhunter?

    Attached Files

    #2
    Re: Virus warning by Klamav and 'warnings' from rkhunter. What's wrong?

    Related thread: ClamTK vs KlamAV gui virus scanner

    Welcome newbies!
    Verify the ISO
    Kubuntu's documentation

    Comment


      #3
      Re: Virus warning by Klamav and 'warnings' from rkhunter. What's wrong?

      your Warning's from rkhunter (root kit hunter) are ok I get the same and are just reports of hiden files in /dev DIR's
      and unhide-linux26 is for unhiding hiden proseses.

      the clamav is reporting compresed and or encripted files and PROBABLEY nothing to worey about.
      read Telengard's links!!

      do you have windows on the box?

      your startup problems are probable a seprete ishue.

      however thare are windows viruses that infect or try to infect the bootsecter of the drive.

      VINNY
      i7 4core HT 8MB L3 2.9GHz
      16GB RAM
      Nvidia GTX 860M 4GB RAM 1152 cuda cores

      Comment


        #4
        Re: Virus warning by Klamav and 'warnings' from rkhunter. What's wrong?

        It is possible for a virus to infect any part of the computer which is writable through software. That includes operating system boot sectors, the hard disk main boot record, and even the BIOS itself. The thing is that most viruses don't use these vectors anymore AFAIK. If we assume that it did happen in this case, then the virus might cause problems for Linux even though the original infection came in through Windows.

        I don't mean to imply that the computer is infected, because I definitely don't know. What I do know is that it is more likely for your computer to be struck by lightning than to become infected with a virus while using Linux. (Don't laugh, it has happened to me.)

        Virus scanners frequently produce false positives. In the case of Windows, I would be inclined to trust the scanner when it finds a virus. In the case of Linux, I would start doing research and try to prove that the result was correct. Otherwise it is probably safe to assume your Linux system is not infected.

        The warnings produced by most virus scanners are usually not infections. Most of the time it is just the scanner notifying you of something that it thinks is suspicious. Remember that virus scanners are automated systems, so they rely upon the human operator to discern whether or not the warning is something worth worrying about. The only way to know for sure is for you to do the research and discover for yourself whether or not the condition is worth worrying about.

        Lastly, if an actual virus is found by signature match then the virus scanner should positively identify the virus by name. The name used by the virus scanner to identify the virus can be looked up in the many online virus databases. After you find the virus in the online database then you can compare symptoms described online with what you find on your own system. I used to do this a lot with Windows, but not so much with Linux.
        Welcome newbies!
        Verify the ISO
        Kubuntu's documentation

        Comment


          #5
          Virus warning by Klamav and 'warnings' from rkhunter. What's wrong? ANSWERED

          Telengard and Vinny, thank you for your input.
          You are certainly correct. I have come to the same conclusion especially after reading Telengard's link.
          The Klamav setup defaults to 'warn about' encrypted files, zip and .so, I guess).

          The hide/ubhide warning was sort of put to rest in a previous post I made. It refers to directories that are part of the installation process.

          No, I do not have Windows on the machine at all.

          And yes, the startup problems are most likely not related. Just eliminating all possibilities.
          I gave the computer a thorough cleaning (dusting) today. You won't believe how much dust accumulated on the memory and other chips. I can just picture the shorts on the MoBo. . .

          I also ran chkrootkit. Did come up clean.

          So, I consider my question as answered. Thanks you all.,


          Originally posted by vinnywright
          your Warning's from rkhunter (root kit hunter) are ok I get the same and are just reports of hiden files in /dev DIR's
          and unhide-linux26 is for unhiding hiden proseses.

          the clamav is reporting compresed and or encripted files and PROBABLEY nothing to worey about.
          read Telengard's links!!

          do you have windows on the box?

          your startup problems are probable a seprete ishue.

          however thare are windows viruses that infect or try to infect the bootsecter of the drive.

          VINNY

          Comment

          Working...
          X