Como usar o ClamAV ?

133. Re: Como usar o ClamAV ?

aguamole
aguamole

(usa KUbuntu)

Enviado em 04/04/2024 - 10:30h

Henrique-RJ escreveu:
Mas eu li em um post que era antigo sim e que só agora foi descoberto por acaso senão continuaria desconhecido.

Uai mas toda vulnerabilidade é descoberta por acaso, se não fosse assim não seria descoberta se foi descoberta então foi o acaso. A única forma de não ser descoberta(acaso) seria quem fez o backdoor se arrepender e ele mesmo denunciar o seu ato de desonestidade, nesse caso não seria mesmo uma descoberta já que o próprio autor é quem denuncio a ele mesmo.

Moral da historia, praticamente não existe vulnerabilidade que não seja descoberta por acaso.


  


134. Re: Como usar o ClamAV ?

Random
Rand0m

(usa Arch Linux)

Enviado em 04/04/2024 - 12:21h

@Henrique-RJ
O backdoor foi implantado em fevereiro de 2024, e foi descoberto em março. Era algo extremamente recente e foi descoberto bem rápido


135. Re: Como usar o ClamAV ?

Random
Rand0m

(usa Arch Linux)

Enviado em 04/04/2024 - 12:22h

@aguamole
Se fosse código fechado ele ia ficar circulando por uns 10 anos antes de finalmente ser descoberto


136. Re: Como usar o ClamAV ?

Henrique
Henrique-RJ

(usa Outra)

Enviado em 08/04/2024 - 04:18h

Acabei de fazer um escaneamento com o clamscan e com alguns parâmetros adicionados e encontrou muita coisa na pasta sys com acesso negado inclusive módulos e drivers.

É nisso que podem esconder os códigos maliciosos a meu ver para não serem detectados.

Achou alguns também criptografados.

root@Henrique-Bodhi-5:~# clamscan --alert-broken --alert-broken-media --alert-encrypted --alert-encrypted-archive --alert-encrypted-doc --alert-macros --alert-phishing-ssl --alert-phishing-cloak --alert-partition-intersection --infected --bell --recursive / | tee clamscan.log

_______________________________________________________
E viu-se um grande sinal no céu: uma mulher vestida do sol, tendo a lua debaixo dos seus pés, e uma coroa de doze estrelas sobre a sua cabeça. Apocalipse 12:1 Nsa Sra de Fátima, Nsa Sra de Lourdes, Nsa Sra das Graças ...
_______________________________________________________
São Padre Pio de Pietrelcina, Santa Faustina Kowalska, São Francisco de Assis e Santa Gema Galgani foram alguns dos que tiveram os milagres dos Estigmas de Cristo em seus corpos, Feridas que sangravam
_______________________________________________________
Milagre Eucarístico que ocorreu em uma Igreja de Lanciano na Itália no ano de 750 em que o vinho se tornou sangue e o pão carne humana estão até hoje intactos. https://pt.wikipedia.org/wiki/Milagre_eucar%C3%ADstico_de_Lanciano


137. Re: Como usar o ClamAV ?

Henrique
Henrique-RJ

(usa Outra)

Enviado em 11/04/2024 - 01:51h

Como navego quase todos os dias, passei a fazer escaneamento completo só com o ClamAV após o uso do PC e deixei de lado, ainda que instalado, o Comodo, pois confio mais na sensibilidade do primeiro principalmente na detecção de coisas do cache dos navegadores. E quase deixei de usar o Kaspersky Rescue Disk também para escanear todo o sistema a cada mês pelo mesmo motivo.


_______________________________________________________
E viu-se um grande sinal no céu: uma mulher vestida do sol, tendo a lua debaixo dos seus pés, e uma coroa de doze estrelas sobre a sua cabeça. Apocalipse 12:1 Nsa Sra de Fátima, Nsa Sra de Lourdes, Nsa Sra das Graças ...
_______________________________________________________
São Padre Pio de Pietrelcina, Santa Faustina Kowalska, São Francisco de Assis e Santa Gema Galgani foram alguns dos que tiveram os milagres dos Estigmas de Cristo em seus corpos, Feridas que sangravam
_______________________________________________________
Milagre Eucarístico que ocorreu em uma Igreja de Lanciano na Itália no ano de 750 em que o vinho se tornou sangue e o pão carne humana estão até hoje intactos. https://pt.wikipedia.org/wiki/Milagre_eucar%C3%ADstico_de_Lanciano


138. Re: Como usar o ClamAV ?

Buckminster
Buckminster

(usa Debian)

Enviado em 11/04/2024 - 14:05h

Também uso o ClamAV, mas não sou um entusiasta como tu.
A pasta sys deixo de fora do escaneamento na maioria das vezes porque dá muito falso positivo.
Escaneio ela pouquíssimas vezes.


_________________________________________________________
Always listen the Buck!
Enquanto o cursor estiver pulsando, há vida!


139. Re: Como usar o ClamAV ?

Henrique
Henrique-RJ

(usa Outra)

Enviado em 13/04/2024 - 01:53h

Buckminster escreveu:

Também uso o ClamAV, mas não sou um entusiasta como tu.
A pasta sys deixo de fora do escaneamento na maioria das vezes porque dá muito falso positivo.
Escaneio ela pouquíssimas vezes.


_________________________________________________________
Always listen the Buck!
Enquanto o cursor estiver pulsando, há vida!



Pois é, aqui tem pasta dentro da sys que o ClamAV diz ter acesso negado. São as subpastas uevent, ubind e bind ( esse bind talvez tenha a ver com o navegador Bind da Microsoft que pode ter vindo no Win ). Estas no diretório " /sys/bus/i2c/drivers/* ".

Também como acesso negado para LibClamAV do próprio ClamAV e algumas heurísticas de encrypted e broken como de alguns arquivos de boot EFI que não são usados em minhas máquinas velhas.

É esse tipo de avaliação que eu procurava nos antivírus que consegui com o ClamAV pelo terminal com os comandos:

root@Henrique-Bodhi-5:~# clamscan --detect-pua --alert-broken --alert-broken-media --alert-encrypted --alert-encrypted-archive --alert-encrypted-doc --alert-macros --alert-phishing-ssl --alert-phishing-cloak --alert-partition-intersection --infected --bell --recursive / | tee clamscan.log


Resumo de escaneamento:


/home/henrique/.thunderbird/q4gm5rny.default-release/ImapMail/imap.mail.yahoo.com/Sent-1: Heuristics.Encrypted.Zip FOUND
/home/henrique/.thunderbird/q4gm5rny.default-release/ImapMail/imap.mail.yahoo-1.com/Sent-1: Heuristics.Encrypted.Zip FOUND
/home/henrique/.config/libreoffice/4/user/basic/Standard/Module1.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/home/henrique/Novo(a)/Configurar Horário de Verão 3.1/ConfHV.exe: PUA.Win.Adware.Popuper-6888135-0 FOUND
/home/henrique/Novo(a)/YUMI-2.0.4.9.exe: PUA.Win.Packer.BorlandDelphi-5 FOUND
/home/henrique/Downloads/Configurar Horário de Verão 3.1/ConfHV.exe: PUA.Win.Adware.Popuper-6888135-0 FOUND
/home/henrique/Downloads/eicar.com: Eicar-Test-Signature FOUND
/home/henrique/Downloads/rainlendar2.deb: Heuristics.Broken.Media.PNG.EOFReadingChunk FOUND
/home/henrique/Downloads/YUMI-2.0.4.9.exe: PUA.Win.Packer.BorlandDelphi-5 FOUND
/home/henrique/Downloads/Hirens Boot CD 15.1/DefaultKeyboardPatch.zip: PUA.Win.Packer.Mingwin32Gcc-2 FOUND
/home/henrique/Downloads/Hirens Boot CD 15.1/HBCDCustomizer.exe: PUA.Win.Packer.Upack-29 FOUND
/home/henrique/Downloads/BIOS ECS 945GZT-M GZ071107/AFUDOS.EXE: PUA.Win.Packer.PmodeW-4 FOUND
/home/henrique/Downloads/BIOS ECS 945GZT-M GZ070724/AFUDOS.EXE: PUA.Win.Packer.PmodeW-4 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/05F7534A965663A9882FD9193B55984E8EB78084: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/11911B9F906FD15F7A57CC3F7083E21557EA9429: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/FC9660E0C0599773668E47F37EC1045A70FEB8B3: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/AEDADB3AD7FFC3853F51CD80D7D28491183E2A59: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/AA7B0BF93B5F8FD8FC3D7C0761F0A3688AB2D38D: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/3DDE42697CEEAF11959A68FD6C5AA0E66B9A513C: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/C71C04D1B5755C8D9025C5946BAE3203BF004C04: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/C9F9CE2AEB9E4993D5369D0E70B9EAE0FAED161E: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/829E8D5375C72059A633E791E3EBC54FE279BE44: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/4E12118BBD0D911FA93097E8DC355CE47C67DB3F: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/36185673BB18C85B0222EF248F17674417451CCB: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/7C354ED79A96DD941ACA45971E8CAD3A29D2F840: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/DC4F7105C13B4C0EDB696108CFB0FFE7AB225B11: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/E6F22C7E40ED621655E0719E96989CF69518E570: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/E06AFE60F39E94938A82F3456F6AEDC0FC0401EB: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/FF4C39CE830331C3E299ECFD9A3FCDE4CA00142D: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/13AFE392F45597D6A5D323F8426AB7B694825DED: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/907D4CC3A2CE634DDBC2FFC465A17B652C1A9605: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/AFE1DE8E6A0ECC8223EBDA8A0872341735812024: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/A7563DDC0FE996C66B300030CB7525F534696680: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/E67F48BD8D5F213F601CEFB7DD8716F534AB959D: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/5C50EFA698AD5EB92FCE7DF9B9E58798EA4A25C9: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/4987BB826003A9A5ACBC44965E66CC1187B9A850: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/F863CEDF89C8E6D21A3C83CE957D1DA2BED7F55F: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/CBC449BBE2A5374384BC23FE6C73021AC749669D: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/B574192E1841DADB73C7F990B64895D7AD5A2AC3: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/DB5E64F34A0981BE581FB6BBF4B6FBDB6951F70F: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/3F6A9B33414FED873746403359A38E3A3B0C3E2E: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/7BD85952452C1634B2315D4C2EB483586D5F3D83: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/34DCA82C4A9AF12F22AE1A48A00F3EE10CD00F08: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/703C6D6B8242EAC815C0DC0748335DDB4CED9827: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/6A91FCAF25C488E3E7F273A9A5CEDF4AAB987DBB: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/B60CCE72FED67EE10BD068C31170265DE63D6F35: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/CE9309E05812F0EF5263CC3D53C8773265D120AE: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/E557C3294C1938386F8409E41F175B84788A2667: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/22639E09CCB91A516DFBD4058DF51DC3CC96DE4D: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/F8FC7FBC4390684DD0260B1ED3AA1333CEC64E31: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/2A617394079E824C1D1C63A13CD8897A2269769A: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/17FDED4735EBE88B417A0240934C28D939B76374: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/C6DDEAFCE9F790D8F12ED1B06A385698555C45E9: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/A15917C7238EE543153EA48C9039BAE6CAE3BFFC: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/1F474680422C0FBA22F0C4A94A0C27F6BCD91523: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/EB55F3DD3FEB08811D8FBF2ACBBCF67F42C9276C: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/3B275D04B869E98A0BE0A27E91992B6DF7D05405: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/1ED3D275D3E825F4DE303EC3AF7F7743EF3ADA6B: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/A7539ECD400DAD23DCCA5C3A7B9AB66322B3314B: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/3A9EB68F99BCB51B2CC41B3802897DC70ED0040E: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/0A8BA9AF0B96CCEE1D4960586E6FD4B314F51F5E: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/5D8EFFE9CB7EECACC987749019F9824EA002F8C3: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/A5638DCDFBFAC95F4D366173C72F4CEB9A71DCF2: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/FD7A0695231DCE10C1350F4D0C887E82E7E2F4DB: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/5B04760D1CB33EDBF964154219E19953C40B5AC9: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/6BCFF8D38A02FAA6340D05B0284058F7272DC945: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/B8A360B0DC7A6E79B87EF11F81351BE3873A928C: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/22431386D86B83833D54BDBD5F474C85A0673998: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/8F70425EBCD8290EB4A42F8F0CF663BDBAE7C287: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/6934ADAD91BCB286C7EE846CEA13FED84CB115A6: Heuristics.Broken.Media.JPEG.SpuriousBytesBeforeSegment FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/A3FC20ED7D839F94208433C9D26BE96E9B5EAF1B: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/root/.config/libreoffice/4/user/basic/Standard/Module1.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/root/.local/share/Trash/files/60F8610C72FF1C0B692508F3196DA04FA0EB5315: PUA.Win.Trojan.Xored-1 FOUND
/boot/vmlinuz-4.15.0-20-generic: Heuristics.Broken.Executable FOUND
/boot/vmlinuz-4.15.0-20-generic.efi.signed: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/venus-1.8/venus.b00: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/venus-1.8/venus.mdt: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/a530_zap.mdt: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/a530_zap.b00: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/venus-4.2/venus.b00: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/venus-4.2/venus.mdt: Heuristics.Broken.Executable FOUND
/lib/firmware/vxge/X3fw-pxe.ncf: Heuristics.Encrypted.Zip FOUND
/lib/firmware/vxge/X3fw.ncf: Heuristics.Encrypted.Zip FOUND
/etc/bodhibuilder/uefi/EFI/BOOT/grubx64.efi: Heuristics.Broken.Executable FOUND
/etc/bodhibuilder/uefi/EFI/BOOT/BOOTx64.EFI: Heuristics.Broken.Executable FOUND
/usr/lib/systemd/boot/efi/systemd-bootx64.efi: Heuristics.Broken.Executable FOUND
/usr/lib/systemd/boot/efi/linuxx64.efi.stub: Heuristics.Broken.Executable FOUND
/usr/lib/libreoffice/share/extensions/wiki-publisher/WikiEditor/Module1.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Depot.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_de.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/tools.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/CommonLang.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_ko.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Internet.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_en.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_ja.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_sv.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Currency.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_it.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_zh.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_es.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_fr.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_tw.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/ShowInfoDialog.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/TutorialClose.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/TutorialCreator.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/Functions.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/TutorialOpen.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/RoadMap.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/Listbox.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/Misc.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/ModuleControls.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/UCB.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/Debug.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/Strings.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/ImportWizard/API.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/ImportWizard/FilesModul.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/ImportWizard/DialogModul.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/ImportWizard/Language.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/ImportWizard/Main.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Gimmicks/ReadDir.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Gimmicks/GetTexts.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Gimmicks/Userfields.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Gimmicks/ChangeAllChars.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Gimmicks/AutoText.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/PropertiesSet.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/acConstants.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Property.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Collect.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Form.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Utils.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Field.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Application.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/UtilProperty.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Methods.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Trace.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Dialog.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Module.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Root_.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/_License.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Compatible.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/SubForm.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/L10N.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Control.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/PropertiesGet.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/CommandBar.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Event.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/DoCmd.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Database.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Test.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/OptionGroup.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/CommandBarControl.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/DataDef.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Recordset.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/TempVar.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Template/Autotext.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Template/Samples.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Template/ModuleAgenda.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Template/Correspondence.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/DBMeta.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/Layouter.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/tools.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/develop.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/Language.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/FormWizard.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Common.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/AutoPilotRun.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Protect.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Soft.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Writer.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Hard.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Init.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/ConvertRun.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/presets/basic/Standard/Module1.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND

----------- SCAN SUMMARY -----------
Known viruses: 8705958
Engine version: 0.103.8
Scanned directories: 31222
Scanned files: 180351
Infected files: 174
Total errors: 15268
Data scanned: 16216.78 MB
Data read: 24631.44 MB (ratio 0.66:1)
Time: 6768.189 sec (112 m 48 s)
Start Date: 2024:04:13 04:06:31
End Date: 2024:04:13 05:59:19


Nenhuma dessas ocorrências as considero falsos positivos pelas suas nomenclaturas.


_______________________________
__________________
E viu-se um grande sinal no céu: uma mulher vestida do sol, tendo a lua debaixo dos seus pés, e uma coroa de doze estrelas sobre a sua cabeça. Apocalipse 12:1 Nsa Sra de Fátima, Nsa Sra de Lourdes, Nsa Sra das Graças ...
_______________________________________________________
São Padre Pio de Pietrelcina, Santa Faustina Kowalska, São Francisco de Assis e Santa Gema Galgani foram alguns dos que tiveram os milagres dos Estigmas de Cristo em seus corpos, Feridas que sangravam
_______________________________________________________
Milagre Eucarístico que ocorreu em uma Igreja de Lanciano na Itália no ano de 750 em que o vinho se tornou sangue e o pão carne humana estão até hoje intactos. https://pt.wikipedia.org/wiki/Milagre_eucar%C3%ADstico_de_Lanciano


140. Re: Como usar o ClamAV ?

aguamole
aguamole

(usa KUbuntu)

Enviado em 13/04/2024 - 09:19h

Uai, passa no parâmetro para o clamscan deletar tudo, o parâmetro para remoção é "--remove". Ou você pode escrever um comando de shell para o shell deletar todos os arquivos descritos no log que vc crio com o "tee".


141. Re: Como usar o ClamAV ?

Henrique
Henrique-RJ

(usa Outra)

Enviado em 13/04/2024 - 12:34h


aguamole escreveu:

Uai, passa no parâmetro para o clamscan deletar tudo, o parâmetro para remoção é "--remove". Ou você pode escrever um comando de shell para o shell deletar todos os arquivos descritos no log que vc crio com o "tee".


Calma chefe !!

O que o ClamAV detectou não são exatamente vírus mas arquivos ou programas com alguma característica deles como os broken que poderiam ser vírus quebrados ou corrompidos mas também programas comuns nessa condição ou então criptografados que só podem ser acessados com alguma chave também usado por programas legítimos e ainda os de acesso negado como o tal libclamav que imagino serem bibliotecas do próprio ClamAV que não deixam ser verificados por proteção.

Todas essas características ( broken, criptografia, acesso negado, PUA, heurística ) podem ser portanto indícios de softwares mal intencionados que com um exame mais cuidadoso se pode descobrir por meio de seu hash ( algoritmo de soma ) e de sua localização ( diretório ) e ainda de um escaneamento no site VirusTotal. No caso, parecem ser benignos, mas teria que pesquisar alguns poucos deles como os de boot por exemplo lembrando que o Kaspersky nada detectou no sistema.

Essa sensibilidade do ClamAV é que me agrada.

_______________________________________________________
E viu-se um grande sinal no céu: uma mulher vestida do sol, tendo a lua debaixo dos seus pés, e uma coroa de doze estrelas sobre a sua cabeça. Apocalipse 12:1 Nsa Sra de Fátima, Nsa Sra de Lourdes, Nsa Sra das Graças ...
_______________________________________________________
São Padre Pio de Pietrelcina, Santa Faustina Kowalska, São Francisco de Assis e Santa Gema Galgani foram alguns dos que tiveram os milagres dos Estigmas de Cristo em seus corpos, Feridas que sangravam
_______________________________________________________
Milagre Eucarístico que ocorreu em uma Igreja de Lanciano na Itália no ano de 750 em que o vinho se tornou sangue e o pão carne humana estão até hoje intactos. https://pt.wikipedia.org/wiki/Milagre_eucar%C3%ADstico_de_Lanciano


142. Re: Como usar o ClamAV ?

Jose Mario
zezaocapoeira

(usa Slackware)

Enviado em 13/04/2024 - 13:49h


Salve galera.

Depois de ter acompanhado acompanhado 12 páginas + .

Sugiro que @Henrique-RJ teste outro sistema operacional, lá existe diversas ferramentas para o que procura de fato.
- anti-virus, anti-malware, etc... ( free, pago)

Talvez consiga encontrar algo que lhe deixe mais sossegado em relação ao monitoramento do pc e de suas atividades.

Obrigado pela atenção, salve!!!


143. Re: Como usar o ClamAV ?

Henrique
Henrique-RJ

(usa Outra)

Enviado em 13/04/2024 - 16:27h


zezaocapoeira escreveu:


Salve galera.

Depois de ter acompanhado acompanhado 12 páginas + .

Sugiro que @Henrique-RJ teste outro sistema operacional, lá existe diversas ferramentas para o que procura de fato.
- anti-virus, anti-malware, etc... ( free, pago)

Talvez consiga encontrar algo que lhe deixe mais sossegado em relação ao monitoramento do pc e de suas atividades.

Obrigado pela atenção, salve!!!



Não largo o Bodhi Linux em minhas velhas máquinas de mais de 10 anos ...

A próxima distro que deverei vir a usar deverá ser o mesmo Bodhi Linux.


_______________________________________________________
E viu-se um grande sinal no céu: uma mulher vestida do sol, tendo a lua debaixo dos seus pés, e uma coroa de doze estrelas sobre a sua cabeça. Apocalipse 12:1 Nsa Sra de Fátima, Nsa Sra de Lourdes, Nsa Sra das Graças ...
_______________________________________________________
São Padre Pio de Pietrelcina, Santa Faustina Kowalska, São Francisco de Assis e Santa Gema Galgani foram alguns dos que tiveram os milagres dos Estigmas de Cristo em seus corpos, Feridas que sangravam
_______________________________________________________
Milagre Eucarístico que ocorreu em uma Igreja de Lanciano na Itália no ano de 750 em que o vinho se tornou sangue e o pão carne humana estão até hoje intactos. https://pt.wikipedia.org/wiki/Milagre_eucar%C3%ADstico_de_Lanciano


144. Re: Como usar o ClamAV ?

Henrique
Henrique-RJ

(usa Outra)

Enviado em 17/04/2024 - 07:23h

Criei um novo frashclam.conf com o script da dica abaixo do @Buckminster aqui do fórum e o ClamAV detectou mais coisas suspeitas como foxhole ( buraco da raposa ) como mostra o clamav.log:

https://www.vivaolinux.com.br/etc/freshclamconf/

O novo script do frashclam.conf na pasta /etc/clamav ( o original renomiei para frashclam.conf.standard ):



# Automatically created by the clamav-freshclam postinst
# Comments will get lost when you reconfigure the clamav-freshclam package

DatabaseOwner clamav
UpdateLogFile /var/log/clamav/freshclam.log
LogVerbose false
LogSyslog false
LogFacility LOG_LOCAL6
LogFileMaxSize 0
LogRotate true
LogTime true
Foreground false
Debug false
MaxAttempts 5
DatabaseDirectory /var/lib/clamav
DNSDatabaseInfo current.cvd.clamav.net
ConnectTimeout 30
ReceiveTimeout 0
TestDatabases yes
ScriptedUpdates yes
CompressLocalDatabase no
Bytecode true
NotifyClamd /etc/clamav/clamd.conf
# Check for new database 2 times a day
Checks 2
DatabaseMirror db.local.clamav.net
DatabaseMirror database.clamav.net
#
DatabaseMirror db.br.clamav.net
DatabaseMirror db.ar.clamav.net
DatabaseMirror db.at.clamav.net
DatabaseMirror db.au.clamav.net
DatabaseMirror db.be.clamav.net
DatabaseMirror db.bg.clamav.net
DatabaseMirror db.ca.clamav.net
DatabaseMirror db.ch.clamav.net
DatabaseMirror db.cn.clamav.net
DatabaseMirror db.cz.clamav.net
DatabaseMirror db.de.clamav.net
DatabaseMirror db.dk.clamav.net
DatabaseMirror db.ec.clamav.net
DatabaseMirror db.ee.clamav.net
DatabaseMirror db.es.clamav.net
DatabaseMirror db.fr.clamav.net
DatabaseMirror db.gr.clamav.net
DatabaseMirror db.hk.clamav.net
DatabaseMirror db.hu.clamav.net
DatabaseMirror db.id.clamav.net
DatabaseMirror db.ie.clamav.net
DatabaseMirror db.it.clamav.net
DatabaseMirror db.jp.clamav.net
DatabaseMirror db.kr.clamav.net
DatabaseMirror db.lt.clamav.net
DatabaseMirror db.mx.clamav.net
DatabaseMirror db.nl.clamav.net
DatabaseMirror db.pl.clamav.net
DatabaseMirror db.pt.clamav.net
DatabaseMirror db.ro.clamav.net
DatabaseMirror db.ru.clamav.net
DatabaseMirror db.se.clamav.net
DatabaseMirror db.sg.clamav.net
DatabaseMirror db.sk.clamav.net
DatabaseMirror db.tr.clamav.net
DatabaseMirror db.tw.clamav.net
DatabaseMirror db.ua.clamav.net
DatabaseMirror db.uk.clamav.net
DatabaseMirror db.us.clamav.net

# Argentina
DatabaseMirror clamav.md5.com.ar

# Australia
DatabaseMirror clamav.island.net.au
DatabaseMirror clamav.mirror.pacific.net.au
DatabaseMirror clamavdb.planetmirror.com

# Austria
DatabaseMirror clamav.inode.at
DatabaseMirror xarch.clamav.net

# Belgium
DatabaseMirror clamav.edpnet.net

# Bulgaria
DatabaseMirror clamav.host.bg
DatabaseMirror clamav.paralax.org

# Canada
DatabaseMirror clamav.mirror.rafal.ca
DatabaseMirror clamav.gossamer-threads.com

# China
DatabaseMirror clamav.ialfa.net

# Czech Rrepublic
DatabaseMirror clamav.iol.cz
DatabaseMirror clamav.skynet.cz
DatabaseMirror clamav.mirror.vutbr.cz

# Denmark
DatabaseMirror clamav.dif.dk
DatabaseMirror clamav.mirrors.webpartner.dk

# Ecuador
DatabaseMirror clamav.ecualinux.com

# Estonia
DatabaseMirror clamav.infonet.ee

# France
DatabaseMirror clamav.easynet.fr
DatabaseMirror clamav.inet6.fr
DatabaseMirror clamav.univ-nantes.fr
DatabaseMirror clamav.ovh.net
DatabaseMirror clamav.mirror.waycom.net

# Germany
DatabaseMirror clamav.mirror.fizzelpark.com
DatabaseMirror clamav.informatik.fh-furtwangen.de
DatabaseMirror clamav.lug-norderstedt.de
DatabaseMirror clamav.mcs.de
DatabaseMirror clamav.mirror.myebs.de
DatabaseMirror clamav.pcn.de
DatabaseMirror clamav.power-netz.de
DatabaseMirror clamav.savework.de
DatabaseMirror fuxhausen.tiscali.de
DatabaseMirror clamav.ftpproxy.org
DatabaseMirror clamav.kgt.org

# Greece
DatabaseMirror clamav.forthnet.gr
DatabaseMirror clamav.uoc.gr

# Hong Kong
DatabaseMirror clamav.meiwing.com
DatabaseMirror clamavdb.hostlink.com.hk
DatabaseMirror clamav.cpss.edu.hk

# Hungary
DatabaseMirror clamav.crysys.hu
DatabaseMirror clamav.dc.hu
DatabaseMirror clamav.fisher.hu
DatabaseMirror clamavdb.ikk.sztaki.hu

# Indonesia
DatabaseMirror clamav.cbn.net.id
DatabaseMirror db.clamav.or.id

# Ireland
DatabaseMirror clamavdb.heanet.ie

# Italy
DatabaseMirror clamav.oltrelinux.com
DatabaseMirror clamav.mirror.garr.it
DatabaseMirror clamav.linux.it
DatabaseMirror idea.sec.dico.unimi.it

# Japan
DatabaseMirror clamav.nara.wide.ad.jp
DatabaseMirror clamav-mirror.wiseknot.co.jp
DatabaseMirror clamavdb.ml-club.jp
DatabaseMirror clamav.mtcnet.jp
DatabaseMirror clamav.begi.net
DatabaseMirror clamavdb.osj.net
DatabaseMirror clamav.s-lines.net
DatabaseMirror clamav.yukiguni.net
DatabaseMirror clamavdb.mithril-linux.org

# Republic of Korea
DatabaseMirror clamav.hanbiro.com

# Lithuania
DatabaseMirror clamav.vtu.lt

# Mexico
DatabaseMirror clamav.mpsnet.com.mx

# Netherlands
DatabaseMirror clamav.essentkabel.com
DatabaseMirror clamav.fx-services.com
DatabaseMirror clamav.prolocation.net
DatabaseMirror clamav.mirror.transip.nl
DatabaseMirror clamav.unnet.nl
DatabaseMirror clamav.xs4all.nl
DatabaseMirror clamav.packetstorm.nu

# Poland
DatabaseMirror database.clamav.ps.pl

# Portugal
DatabaseMirror clamav.linux.pt

# Romania
DatabaseMirror clamav.iasi.roedu.net

# Russian Federation
DatabaseMirror clamav.citrin.ru
DatabaseMirror clamav.eastweb.ru
DatabaseMirror clamav.unix.su

# Singapore
DatabaseMirror clamav.acnova.com

# Slovakia
DatabaseMirror clamav.hq.alert.sk

# Spain
DatabaseMirror clamav.talika.eii.us.es

# Sweden
DatabaseMirror clamav.kratern.se
DatabaseMirror clamav.df.lth.se
DatabaseMirror clamav.mainloop.se

# Switzerland
DatabaseMirror switch.clamav.net

# Taiwan
DatabaseMirror clamav.cs.pu.edu.tw
DatabaseMirror clamav.stu.edu.tw

# Turkey
DatabaseMirror clamav.enderunix.org
DatabaseMirror clamav.ubak.gov.tr

# Ukraine
DatabaseMirror clamav.intercom.net.ua

# United Kingdom
DatabaseMirror clamav.mirror.camelnetwork.com
DatabaseMirror clamav.dbplc.com
DatabaseMirror clamav.spod.org
DatabaseMirror clamav.public-internet.co.uk

# United States
DatabaseMirror clamav.catt.com
DatabaseMirror clamav.clearfield.com
DatabaseMirror clamav.devolution.com
DatabaseMirror clamav.edebris.com
DatabaseMirror clamav.edgescape.com
DatabaseMirror clamav.infotex.com
DatabaseMirror clamav.irontec.com
DatabaseMirror clamav.liquidweb.com
DatabaseMirror clamav.pathlink.com
DatabaseMirror avmirror2.prod.rxgsys.com
DatabaseMirror clamav.theshell.com
DatabaseMirror clamav-du.viaverio.com
DatabaseMirror clamav-sj.viaverio.com
DatabaseMirror clamav.walkertek.com
DatabaseMirror clamav.westlinks.com
DatabaseMirror clamav.xyxx.com
DatabaseMirror clamav.pinna.cx
DatabaseMirror clamav.unet.brandeis.edu
DatabaseMirror clamav.bridgeband.net
DatabaseMirror clamav.inoc.net
DatabaseMirror clamav-000.mirrors.nks.net
DatabaseMirror clamav-001.mirrors.nks.net
DatabaseMirror clamav-002.mirrors.nks.net
DatabaseMirror clamav-003.mirrors.nks.net
DatabaseMirror clamav-004.mirrors.nks.net
DatabaseMirror clamav-005.mirrors.nks.net
DatabaseMirror clamav.oc1.mirrors.redwire.net
DatabaseMirror clamav.securityminded.net
DatabaseMirror clamav.securitywonks.net
DatabaseMirror clamav.sonic.net
#
# Malware
DatabaseCustomURL https://cdn.malware.expert/malware.expert.ndb
DatabaseCustomURL https://cdn.malware.expert/malware.expert.hdb
DatabaseCustomURL https://cdn.malware.expert/malware.expert.ldb
DatabaseCustomURL https://cdn.malware.expert/malware.expert.fp
#
# Sanesecurity: malware, spam, phishing, lottery, etc
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/sigwhitelist.ign2
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/sanesecurity.ftm
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/MiscreantPunch099-INFO-Low.ldb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/MiscreantPunch099-Low.ldb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/Sanesecurity_BlackEnergy.yara
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/Sanesecurity_sigtest.yara
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/Sanesecurity_spam.yara
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/badmacro.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/blurl.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/hackingteam.hsb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/junk.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/jurlbl.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/jurlbla.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/lott.ndb
# Bofhland
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/bofhland_cracked_URL.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/bofhland_malware_URL.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/bofhland_malware_attach.hdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/bofhland_phishing_URL.ndb
# Foxhole
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/foxhole_all.cdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/foxhole_all.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/foxhole_filename.cdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/foxhole_generic.cdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/foxhole_js.cdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/foxhole_js.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/foxhole_links.ldb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/foxhole_mail.cdb
# Malware.expert
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/malware.expert.fp
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/malware.expert.hdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/malware.expert.ldb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/malware.expert.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/malwarehash.hsb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/phish.ndb
# Porcupine
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/phishtank.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/porcupine.hsb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/porcupine.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/rogue.hdb
# Spam
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/scam.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/scamnailer.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/shelter.ldb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/spam.ldb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/spamattach.hdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/spamimg.hdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/spear.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/spearl.ndb
# Winnow
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/winnow.attachments.hdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/winnow.complex.patterns.ldb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/winnow_bad_cw.hdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/winnow_extended_malware.hdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/winnow_extended_malware_links.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/winnow_malware.hdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/winnow_malware_links.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/winnow_phish_complete.ndb
# DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/winnow_phish_complete_url.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/winnow_spam_complete.ndb
# Maldet
DatabaseCustomURL https://www.rfxn.com/downloads/rfxn.ndb
DatabaseCustomURL https://www.rfxn.com/downloads/rfxn.hdb
# Phishing, scams and other junk, hashes of spam documents and images
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/crdfam.clamav.hdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/doppelstern-phishtank.ndb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/doppelstern.hdb
DatabaseCustomURL https://ftp.swin.edu.au/sanesecurity/doppelstern.ndb


O clamav.log do escaneamento de hoje que levou 2 horas e meia para escanear todo o sistema:



/home/henrique/.thunderbird/q4gm5rny.default-release/ImapMail/imap.mail.yahoo.com/Sent-1: Heuristics.Encrypted.Zip FOUND
/home/henrique/.thunderbird/q4gm5rny.default-release/ImapMail/imap.mail.yahoo-1.com/Sent-1: Heuristics.Encrypted.Zip FOUND
/home/henrique/.thunderbird/q4gm5rny.default-release/ImapMail/imap.gmail.com/[Gmail].sbd/Spam: Porcupine.Phishing.57765.UNOFFICIAL FOUND
/home/henrique/.config/libreoffice/4/user/basic/Standard/Module1.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/home/henrique/.mozilla/firefox/7p142xn6.default-release/features/{1d0bcb01-0511-4b9c-8cc4-a8dc7660885a}/addons-restricted-domains@mozilla.com.xpi: Sanesecurity.Foxhole.JS_Zip_1.UNOFFICIAL FOUND
/home/henrique/.mozilla/firefox/7p142xn6.default-release/extensions/uBlock0@raymondhill.net.xpi: Sanesecurity.Foxhole.JS_Zip_22.UNOFFICIAL FOUND
/home/henrique/.mozilla/firefox/7p142xn6.default-release/extensions/forecastfox@s3_fix_version.xpi: Sanesecurity.Foxhole.JS_Zip_16.UNOFFICIAL FOUND
/home/henrique/Novo(a)/Configurar Horário de Verão 3.1/ConfHV.exe: PUA.Win.Adware.Popuper-6888135-0 FOUND
/home/henrique/Novo(a)/Gold Memory 7.85 Pro/Win32DiskImager-0.9.5-binary.zip: Sanesecurity.Foxhole.Zip_exe.UNOFFICIAL FOUND
/home/henrique/Novo(a)/YUMI-2.0.4.9.exe: PUA.Win.Packer.BorlandDelphi-5 FOUND
/home/henrique/Novo(a)/BIOSTAR K8M800 Micro AM2/T_BIOS_Update_1948.zip: Sanesecurity.Foxhole.Zip_exe.UNOFFICIAL FOUND
/home/henrique/.qmmp/skins/KGP_Win98.zip: Sanesecurity.Foxhole.Zip_exe.UNOFFICIAL FOUND
/home/henrique/.qmmp/skins/SkinnersAtlas1.wsz: Sanesecurity.Foxhole.Zip_com.UNOFFICIAL FOUND
/home/henrique/Downloads/Configurar Horário de Verão 3.1/ConfHV.exe: PUA.Win.Adware.Popuper-6888135-0 FOUND
/home/henrique/Downloads/eicar.com: {HEX}EICAR.TEST.3.UNOFFICIAL FOUND
/home/henrique/Downloads/rainlendar2.deb: Heuristics.Broken.Media.PNG.EOFReadingChunk FOUND
/home/henrique/Downloads/YUMI-2.0.4.9.exe: PUA.Win.Packer.BorlandDelphi-5 FOUND
/home/henrique/Downloads/Hirens Boot CD 15.1/DefaultKeyboardPatch.zip: Sanesecurity.Foxhole.Zip_cmd.UNOFFICIAL FOUND
/home/henrique/Downloads/Hirens Boot CD 15.1/HBCDCustomizer.exe: PUA.Win.Packer.Upack-29 FOUND
/home/henrique/Downloads/rainlendar2/skins/Shadow4.r2skin: Sanesecurity.Foxhole.Zip_bat.UNOFFICIAL FOUND
/home/henrique/Downloads/rainlendar2/skins/Chromophore.r2skin: Sanesecurity.Foxhole.Zip_bat.UNOFFICIAL FOUND
/home/henrique/Downloads/rainlendar2/skins/Savannah.r2skin: Sanesecurity.Foxhole.Zip_bat.UNOFFICIAL FOUND
/home/henrique/Downloads/BIOS ECS 945GZT-M GZ071107/AFUDOS.EXE: PUA.Win.Packer.PmodeW-4 FOUND
/home/henrique/Downloads/BIOSTAR K8M800 Micro AM2/T_BIOS_Update_1948.zip: Sanesecurity.Foxhole.Zip_exe.UNOFFICIAL FOUND
/home/henrique/Downloads/BIOS ECS 945GZT-M GZ070724/AFUDOS.EXE: PUA.Win.Packer.PmodeW-4 FOUND
/home/henrique/Downloads/Skins do qmmp/Skins_All_in_One.zip: Sanesecurity.Foxhole.Zip_com.UNOFFICIAL FOUND
/home/henrique/Downloads/Skins do qmmp/Skins_All_in_One/KGP_Win98.zip: Sanesecurity.Foxhole.Zip_exe.UNOFFICIAL FOUND
/home/henrique/Downloads/Skins do qmmp/Skins_All_in_One/SkinnersAtlas1.wsz: Sanesecurity.Foxhole.Zip_com.UNOFFICIAL FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/BA43F0A5E7B556660EBB0ACFF3F989309CDFB3E1: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/11911B9F906FD15F7A57CC3F7083E21557EA9429: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/FC9660E0C0599773668E47F37EC1045A70FEB8B3: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/AEDADB3AD7FFC3853F51CD80D7D28491183E2A59: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/AA7B0BF93B5F8FD8FC3D7C0761F0A3688AB2D38D: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/C71C04D1B5755C8D9025C5946BAE3203BF004C04: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/829E8D5375C72059A633E791E3EBC54FE279BE44: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/4E12118BBD0D911FA93097E8DC355CE47C67DB3F: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/0C6F4F1EF7F20600867F79E110EFD039D070576B: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/DC4F7105C13B4C0EDB696108CFB0FFE7AB225B11: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/E06AFE60F39E94938A82F3456F6AEDC0FC0401EB: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/FF4C39CE830331C3E299ECFD9A3FCDE4CA00142D: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/13AFE392F45597D6A5D323F8426AB7B694825DED: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/907D4CC3A2CE634DDBC2FFC465A17B652C1A9605: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/AFE1DE8E6A0ECC8223EBDA8A0872341735812024: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/B47D02378034169317704B99E4CA58F1A9718895: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/E67F48BD8D5F213F601CEFB7DD8716F534AB959D: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/5C50EFA698AD5EB92FCE7DF9B9E58798EA4A25C9: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/CBC449BBE2A5374384BC23FE6C73021AC749669D: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/B574192E1841DADB73C7F990B64895D7AD5A2AC3: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/0D24481BFD658D587860B88F7795D561B109DB61: Sanesecurity.Foxhole.GZip_js.UNOFFICIAL FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/8D4AA1DC816327382AC9A3DEE79383BC7E7CA05F: Sanesecurity.Foxhole.GZip_js.UNOFFICIAL FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/34DCA82C4A9AF12F22AE1A48A00F3EE10CD00F08: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/703C6D6B8242EAC815C0DC0748335DDB4CED9827: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/B60CCE72FED67EE10BD068C31170265DE63D6F35: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/E557C3294C1938386F8409E41F175B84788A2667: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/F9D4407C441F22DFA007700AF0617FEE09B66D1B: Sanesecurity.Foxhole.GZip_js.UNOFFICIAL FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/15D7B0BE49555D651C526D4A940C37C0C0CE74BE: Sanesecurity.Foxhole.JS_Zip_22.UNOFFICIAL FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/F8FC7FBC4390684DD0260B1ED3AA1333CEC64E31: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/2A617394079E824C1D1C63A13CD8897A2269769A: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/17FDED4735EBE88B417A0240934C28D939B76374: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/C6DDEAFCE9F790D8F12ED1B06A385698555C45E9: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/37F185E88ED47836319559B319C3BE441DCEDA01: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/A15917C7238EE543153EA48C9039BAE6CAE3BFFC: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/1F474680422C0FBA22F0C4A94A0C27F6BCD91523: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/E2400524F90A2CE21E72AD941C409459FDB269DA: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/1E43ABAD62090362BEAEFAED5A18C62E6383C507: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/EB55F3DD3FEB08811D8FBF2ACBBCF67F42C9276C: PUA.Win.Trojan.Xored-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/3B275D04B869E98A0BE0A27E91992B6DF7D05405: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/ACC61B00A1D4E3B5E83927B30F1C1FE45FF3A1DC: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/7B49D11D6BFA6FE40B16747072C412629F90D540: Sanesecurity.Foxhole.GZip_js.UNOFFICIAL FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/A7539ECD400DAD23DCCA5C3A7B9AB66322B3314B: Heuristics.Broken.Media.GIF.TruncatedImageDataBlock FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/0A8BA9AF0B96CCEE1D4960586E6FD4B314F51F5E: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/5D8EFFE9CB7EECACC987749019F9824EA002F8C3: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/5B04760D1CB33EDBF964154219E19953C40B5AC9: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/22431386D86B83833D54BDBD5F474C85A0673998: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/8F70425EBCD8290EB4A42F8F0CF663BDBAE7C287: Heuristics.Broken.Media.GIF.UnknownBlockLabel FOUND
/home/henrique/.cache/mozilla/firefox/7p142xn6.default-release/cache2/entries/A3FC20ED7D839F94208433C9D26BE96E9B5EAF1B: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/henrique/.cache/thunderbird/q4gm5rny.default-release/startupCache/startupCache.8.little: Sanesecurity.Foxhole.JS_Zip_1.UNOFFICIAL FOUND
/var/lib/clamav/Sanesecurity_spam.yara: YARA.Sanesecurity_Spam_test.UNOFFICIAL FOUND
/var/lib/clamav/Sanesecurity_BlackEnergy.yara: YARA.Sanesecurity_BlackEnergy3.UNOFFICIAL FOUND
/var/lib/clamav/MiscreantPunch099-Low.ldb: MiscreantPunch.EvilPDpdEgg.1.UNOFFICIAL FOUND
/root/.config/libreoffice/4/user/basic/Standard/Module1.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/root/.local/share/Trash/files/60F8610C72FF1C0B692508F3196DA04FA0EB5315: PUA.Win.Trojan.Xored-1 FOUND
/boot/vmlinuz-4.15.0-20-generic: Heuristics.Broken.Executable FOUND
/boot/vmlinuz-4.15.0-20-generic.efi.signed: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/venus-1.8/venus.b00: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/venus-1.8/venus.mdt: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/a530_zap.mdt: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/a530_zap.b00: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/venus-4.2/venus.b00: Heuristics.Broken.Executable FOUND
/lib/firmware/qcom/venus-4.2/venus.mdt: Heuristics.Broken.Executable FOUND
/lib/firmware/vxge/X3fw-pxe.ncf: Heuristics.Encrypted.Zip FOUND
/lib/firmware/vxge/X3fw.ncf: Heuristics.Encrypted.Zip FOUND
/etc/bodhibuilder/uefi/EFI/BOOT/grubx64.efi: Heuristics.Broken.Executable FOUND
/etc/bodhibuilder/uefi/EFI/BOOT/BOOTx64.EFI: Heuristics.Broken.Executable FOUND
/usr/share/live-usb-install/presets/Grml/2010.12 - small - amd64/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Grml/2010.12 - medium - amd64/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Grml/2010.12 - small - i386/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Grml/2010.12 - amd64/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Grml/2010.12 - i386/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Grml/2010.12 - medium - i386/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Xen Livecd/3.2-0.8.2 - i386/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Xen Livecd/3.2-0.8.2 - amd64/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Hirens Boot CD/10/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Hirens Boot CD/14/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Hirens Boot CD/11.1/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Hirens Boot CD/13.1/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Hirens Boot CD/10.2/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Parted Magic/5.2 - i386/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/share/live-usb-install/presets/Parted Magic/4.7 - i386/other.7z: Sanesecurity.Foxhole.7z_exe.UNOFFICIAL FOUND
/usr/lib/rainlendar2/skins/Shadow4.r2skin: Sanesecurity.Foxhole.Zip_bat.UNOFFICIAL FOUND
/usr/lib/rainlendar2/skins/Chromophore.r2skin: Sanesecurity.Foxhole.Zip_bat.UNOFFICIAL FOUND
/usr/lib/rainlendar2/skins/Savannah.r2skin: Sanesecurity.Foxhole.Zip_bat.UNOFFICIAL FOUND
/usr/lib/systemd/boot/efi/systemd-bootx64.efi: Heuristics.Broken.Executable FOUND
/usr/lib/systemd/boot/efi/linuxx64.efi.stub: Heuristics.Broken.Executable FOUND
/usr/lib/libreoffice/share/extensions/wiki-publisher/WikiEditor/Module1.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Depot.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_de.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/tools.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/CommonLang.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_ko.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Internet.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_en.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_ja.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_sv.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Currency.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_it.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_zh.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_es.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_fr.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Depot/Lang_tw.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/ShowInfoDialog.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/TutorialClose.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/TutorialCreator.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/Functions.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/TutorialOpen.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tutorials/RoadMap.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/Listbox.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/Misc.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/ModuleControls.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/UCB.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/Debug.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Tools/Strings.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/ImportWizard/API.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/ImportWizard/FilesModul.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/ImportWizard/DialogModul.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/ImportWizard/Language.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/ImportWizard/Main.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Gimmicks/ReadDir.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Gimmicks/GetTexts.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Gimmicks/Userfields.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Gimmicks/ChangeAllChars.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Gimmicks/AutoText.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/PropertiesSet.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/acConstants.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Property.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Collect.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Form.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Utils.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Field.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Application.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/UtilProperty.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Methods.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Trace.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Dialog.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Module.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Root_.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/_License.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Compatible.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/SubForm.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/L10N.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Control.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/PropertiesGet.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/CommandBar.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Event.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/DoCmd.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Database.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Test.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/OptionGroup.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/CommandBarControl.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/DataDef.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/Recordset.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Access2Base/TempVar.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Template/Autotext.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Template/Samples.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Template/ModuleAgenda.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Template/Correspondence.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/DBMeta.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/Layouter.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/tools.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/develop.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/Language.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/FormWizard/FormWizard.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Common.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/AutoPilotRun.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Protect.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Soft.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Writer.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Hard.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/Init.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/share/basic/Euro/ConvertRun.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/libreoffice/presets/basic/Standard/Module1.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/usr/lib/firefox/browser/features/webcompat-reporter@mozilla.org.xpi: Sanesecurity.Foxhole.JS_Zip_1.UNOFFICIAL FOUND
/usr/lib/firefox/browser/features/screenshots@mozilla.org.xpi: Sanesecurity.Foxhole.JS_Zip_1.UNOFFICIAL FOUND
/usr/lib/firefox/browser/features/formautofill@mozilla.org.xpi: Sanesecurity.Foxhole.JS_Zip_1.UNOFFICIAL FOUND
/usr/lib/firefox/browser/features/webcompat@mozilla.org.xpi: Sanesecurity.Foxhole.JS_Zip_19.UNOFFICIAL FOUND
/usr/lib/firefox/browser/features/pictureinpicture@mozilla.org.xpi: Sanesecurity.Foxhole.JS_Zip_1.UNOFFICIAL FOUND

----------- SCAN SUMMARY -----------
Known viruses: 8874243
Engine version: 0.103.8
Scanned directories: 31209
Scanned files: 177253
Infected files: 206
Total errors: 15362
Data scanned: 15988.32 MB
Data read: 24665.04 MB (ratio 0.65:1)
Time: 8756.243 sec (145 m 56 s)
Start Date: 2024:04:17 02:05:54
End Date: 2024:04:17 04:31:51


Os acessos negados não aparecem no log acima mas eles ocorreram durante o escaneamento no diretório da pasta sys em drivers e inclusive tentei enviar para o Virustotal mas não os aceitou por serem muito pequenos ( 4kB ).

A novidade que me chamou a atenção é ter detectado agora os foxhole em js e zip e gzip no cache da navegação além dos que já detectava. Também ocorreram foxholes em algumas extensões que tenho no Firefox ( .xpi ) como o uBlock Origin e o Forecastfox da previsão do tempo ou seja, os considerou inseguros.

Isso que venho fazendo com o passar dos dias é tipo uma auditoria, principalmente da navegação diária, á procura de suspeitos e também para avaliar o ClamAV.

O escaneamento foi feito pelo terminal com o clamscan com aquela longa linha de comandos que já citei antes.


_______________________________________________________
E viu-se um grande sinal no céu: uma mulher vestida do sol, tendo a lua debaixo dos seus pés, e uma coroa de doze estrelas sobre a sua cabeça. Apocalipse 12:1 Nsa Sra de Fátima, Nsa Sra de Lourdes, Nsa Sra das Graças ...
_______________________________________________________
São Padre Pio de Pietrelcina, Santa Faustina Kowalska, São Francisco de Assis e Santa Gema Galgani foram alguns dos que tiveram os milagres dos Estigmas de Cristo em seus corpos, Feridas que sangravam
_______________________________________________________
Milagre Eucarístico que ocorreu em uma Igreja de Lanciano na Itália no ano de 750 em que o vinho se tornou sangue e o pão carne humana estão até hoje intactos. https://pt.wikipedia.org/wiki/Milagre_eucar%C3%ADstico_de_Lanciano



  



Patrocínio

Site hospedado pelo provedor RedeHost.
Linux banner

Destaques

Artigos

Dicas

Tópicos

Top 10 do mês

Scripts