Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 14th December 2004, 02:50 AM
carlos Offline
Registered User
 
Join Date: Nov 2004
Posts: 28
F-prot anti-virus - do I delete the files?

I ran an f-prot anti0virus scan
f-prot -auto -disinf -report=blah /
and got the following message as part of it.
I update the viruses every few hours so i don't see how I could have unknown viruses - should I delete these files or are they benign? Thanks for any pointers.

/usr/lib/mailman/tests/msgs/nimda.txt->readme.exe could be infected with an unknown virus
Virus-infected files in archives cannot be disinfected.
/usr/lib/debug/sbin/ip.debug could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
/usr/lib/debug/sbin/rtmon.debug could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
/usr/lib/debug/sbin/tc.debug could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
/usr/lib/debug/usr/sbin/rtacct.debug could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
/usr/lib/debug/usr/sbin/rtstat.debug could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
/usr/lib/debug/usr/sbin/nstat.debug could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
/usr/lib/debug/usr/sbin/ss.debug could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
Reply With Quote
  #2  
Old 14th December 2004, 04:36 AM
crackers's Avatar
crackers Offline
Retired Community Manager
 
Join Date: Feb 2004
Location: Seattle, WA, USA
Age: 56
Posts: 3,423
You can find out if the file is part of an installed package:
Code:
$ rpm -qif /usr/lib/debug/sbin/ip.debug
Name        : iproute                      Relocations: (not relocatable)
Version     : 2.6.9                             Vendor: Red Hat, Inc.
Release     : 3                             Build Date: Mon 20 Sep 2004 04:21:34 AM CDT
...
As far as I can tell, these are special files used to debug the specific processes they're named after. I do not know what just deleting them would do - you could always move (mv) them elsewhere (make sure to keep track of them and keep the owner/permissions correct) and see what happens.

I actually kind of doubt they're infected - F-Prot is apparently seeing something ambiguous in them and flagging them as possibly being infected. I'd almost bet they're not...
__________________
Linux User #28251 (April '93)
Professional Java Geek :cool:
Reply With Quote
  #3  
Old 14th December 2004, 05:36 AM
carlos Offline
Registered User
 
Join Date: Nov 2004
Posts: 28
Thanks. I checked them all out as you said and they all seem kosher.
Reply With Quote
Reply

Tags
antivirus, delete, files, fprot

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Anti-virus dozix Security and Privacy 20 1st March 2009 02:44 AM
f-prot; anti-virus removal blkwell Using Fedora 1 4th September 2008 01:16 AM
Any need for Anti-Virus / Anti-Spyware apps. ? teishu Security and Privacy 4 8th August 2006 08:10 PM
Anti-virus, Firewall, and anti-spyware jsabarese Using Fedora 17 8th June 2006 03:20 PM
anti virus ieuuk Security and Privacy 24 30th December 2004 10:44 PM


Current GMT-time: 03:12 (Thursday, 20-06-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat