I have installed CLAM AV and it is running on a schedule. Today a pop-up said infected file found. They are probably very old files from the mass of files I imported from windows. I still would like to know which files they are. The problem is when I look at View-results it says no threats found, but then under Logs I see the notice of 8 infected files. Worse, in the details is lists the malware name preceded by the string [REDACTED_PATH].
What in tarnation does this mean? Whose side is this app on?
if your using the terminal to scan and it finds something in the terminal type
sudo clamscan -r --remove /home/your home name
it will look like a scan but its looking for what it taged and will remove it
replace your home name with whatever you named your home file
there is a better way in software store look up clamUI its way better and quarintines automaticly
Thank you for your response.
In am indeed using ClamUI.
Having seen it before I turned on "quarantine automatically" and ran a "full scan" and like before it says no threats.
So
-
I have no idea how these two searches are different and how the one running in the background is different?
-
Why is the path redacted?
-
I have not ran Clam on the CLI. If you think running it in the terminal will help I'd appreciate if you say what is the command. But I prefer to answer to the first two questions for my understanding.
Thank you again, for your time
When You click on ClamAV Daemon at the top right what do You get there to see?
Thanks for your reply.
I have scrolled down to the bottom of the window where malware is reported.
The exported-log is available but seems I cannot attach it here.
Ok to best of my knowledge they are redacted as linux puts those in a sandbox it keeps them from getting to Root area as well as Home directorys also im assumeing you are duel booting windows/linux? as those look like windows trojans that attack storage area in windows basicly erasing some windows files that it needs effectively killing windows
They likely are, as I mentioned. I'll be sure, once I know which files they are.
But what I really need to know is how can I find out which files they are?
Hopefully they will be quarantined the next time a scheduled scan runs and I'll see.
BUT, if you know of any other way to id them, please let me know.
Thanks!
NP i think the stuff sandboxed is in a hidden folder that isnt excessable in linux....and for good reason
Hmm ... I would like to try something but this would need Time. So, this is nothing what You could present in a couple Minutes.
Open the Terminal and type sudo apt install clamtk for installing the ClamAV graphical Frontend ClamTK. It is an old Project but for Double-Check it is fine. When installed, open it and open the Settings. There activate everything.
Then open the Update Assistant and set it to manual Updates. Then click on Updates and update it.
When You have set everything up, choose the Option to scan a Folder and there choose Your Drive and let it make a whole Scan. This can take a lot of Time. But when it is finished, You get and List Output where You see the Files and the Threats.
Thanks!
I'll try that in the next few days.
Between regular work and surviving Zorin from complete scratch, I am past buried.
Meantime I found this:
If you find anything actionable in it, do let me know.
Well, that reads like the Answer relates to the Fact that ClamUI is a Flatpak and have limited Permissions. Also the False Positive Point is a Possibility, too. But this all falls back to ClamAV directly. So, when You use ClamAV (or clamd) directly to scan something.
But You used ClamUI as Interface for scanning. Now is this pretty new Software and only a 0.1.X Version. So, that could be a Factor, too depending how it is set up internally.
I would suggest to try ClamTK like I wrote before to Double-Check that. Yes, it takes Time for the Scan and that isn't optimal but You get a better Output. One Thing to add: When You use ClamTK and You don't have ClamAV installed as .deb, too You need that to install, too.
So, then use the Command sudo apt install clamav clamtk to install both.
There is also a .deb package for ClamUI on github:
I posted a tutorial in the post that brought ClamUI to the forum's attention and I posted the commands on what to run without the need to go to the GitHub page with the one exception of acquiring the .deb package.
It requires that you uninstall ClamAV and the Flatpak and start from scratch.
Having searched Brave A.I. with the trojan name claims to be a false positive with ClamAV but there are Killwin family of malware but not with that name:
is Win.Trojan.Killwin-24 a false positive in ClamAV?
Quick Answer
There is no specific information in the provided search context confirming whether Win.Trojan.Killwin-24 is a false positive.
The search results discuss ClamAV's general tendency to produce false positives for Windows applications and files that do not exist on Linux systems, noting that if only ClamAV reports a virus while other engines (like those on VirusTotal) do not, it is almost certainly a false positive . However, the specific detection name Win.Trojan.Killwin-24 is not mentioned in any of the provided snippets, which instead cite detections like Win.Trojan.Katusha , Win.Trojan.Ramnit , or Win.Trojan.Agent . To verify this specific signature, you would need to upload the affected file to VirusTotal to see if other antivirus engines flag it.
Are there known cases of Win.Trojan.Killwin-24 in malware samples?
Finished
Yes, Win.Trojan.Killwin-24 is associated with known malware samples, although the detection name might be a variation or misreporting of similar threats.
Analysis of a file named Trojan.KillWin.exe on ANY.RUN confirms it as malicious , categorizing it as a stealer designed to gain unauthorized access to user information such as files, passwords, and cryptocurrency. The malware is capable of keylogging, taking screenshots, and is often distributed via phishing campaigns.
Furthermore, Microsoft Defender detects variants like Trojan:MSIL/KillWin.MA!MTB and Trojan:BAT/Killwin.T , confirming that the KillWin family is recognized as a genuine threat by reputable antivirus engines. These variants can perform arbitrary malicious actions on an infected device.
While ClamAV may sometimes generate false positives for Windows-specific trojans on Linux systems, the existence of confirmed malware samples under the KillWin name suggests that Win.Trojan.Killwin-24 is likely not a false positive when detected on a Windows system or a file intended for Windows execution."
Thank you all.
I will go through each suggestion step by step, and report back.
For now I am rather suspicious that this is real, because the files from the windows history were thoroughly checked every day by several av-tools with non-overlapping methods. It could be files that were in deep storage from more than a decade ago. Over at least the past 11 years no virus infection of any kind ever occurred.
update: After having turned on quarantining, today's scan shows the path/filename; it was not anywhere exotic: a subfolder under /Documents.
The identification is surely a false positive since these are zip files of installation package of software I myself wrote way back in yr 2002.
I had missed the Quarantine switch, because it is half-hidden away in the menu in the title-bar and why are there effectively two menus in this program?? (rhetorical question)
This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.





