Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Weird Virus showing with Kaspersky but not ClamAV

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    6 Posts 4 Posters 563 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee
      last edited by JonathanLee

      Has anyone else seen this virus before? This is showing up on a fact check website a student shared at the university.

      Screenshot 2024-04-20 at 09.38.51.png

      Please yet me know I think it is a real item however my Squid ClamAV does not see this one. I am running SSL Intercept so it does detect https viruses as seen here.

      Screenshot 2024-04-21 at 12.42.40.png

      On the 2100 the only way for it to work with how much memory ClamAV uses was to adapt the concurrent reload and set it to no for updates.

      Long story short what is HEUR:Trojan-PSW

      I thought Cisco's ClamAV would spot it long before my host machine's antivirus software. Weird normally Cisco's ClamAV stops it all before it gets to my machines.

      Make sure to upvote

      johnpozJ Dobby_D 2 Replies Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @JonathanLee
        last edited by

        @JonathanLee totalvirus shows it as clean

        https://www.virustotal.com/gui/url/d2dd9546c1dddaf34268933648d6fc514eb547602c2fc456bbf9176f150657be

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 1
        • Dobby_D
          Dobby_ @JonathanLee
          last edited by

          @JonathanLee said in Weird Virus showing with Kaspersky but not ClamAV:

          I thought Cisco's ClamAV would spot it long before my host machine's antivirus software. Weird normally Cisco's ClamAV stops it all before it gets to my machines.

          ClamAV is nearly to 60 % effective in virus hunt then others you must pay for.

          #~. @Dobby

          Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
          PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
          PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

          1 Reply Last reply Reply Quote 1
          • L
            lolip
            last edited by

            If Kaspersky detects a weird virus that ClamAV doesn't, it may be due to differences in their virus databases.

            1 Reply Last reply Reply Quote 1
            • Dobby_D
              Dobby_
              last edited by

              @JonathanLee

              But you can set up your own virus databases, such as a french company
              is offering free private and paid for business customers. You will be able
              to reach then somethings about 4.000.000 viruses ClamAV can be find.

              There are also on github projects or else where in the internet you can
              search for, and they may let you also for free use their databases to
              gain security more.

              #~. @Dobby

              Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
              PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
              PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

              JonathanLeeJ 1 Reply Last reply Reply Quote 0
              • JonathanLeeJ
                JonathanLee @Dobby_
                last edited by

                @Dobby_ That website no longer gives out a free version after so many days they disable it and expect you to pay now.

                Make sure to upvote

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.