Skip to main content

infected files detected in /tmp - how to find actual file name and path

Comments

5 comments

  • 24x7server
    Hi, Go through the maldet session files to check for this report: /tmp/20171106-153532-WgAz6@gWpWvvRn0QlYP2pwAAAGA-file-Rt8qKW If nothing is found, then you can restore this particular session and then when it goes back to the original place, you can check the ownership of this file to get to know what user actually uploaded it.
    0
  • KV Karia
    1) How to find actual file name after restore? 2) It is infected file hence not recommended to restore it. any other way?
    0
  • cPanelMichael
    Hello, You may find the following thread helpful: Log Checking Thank you.
    0
  • KV Karia
    Hello, Log Checking

    It is more about configure maldet / clamav with modsec (facing challenge in that also but I will raise separate topic for that) Still I unable to find way of my query : How to find from which website or path url it is uploaded or trying to upload ?
    0
  • cPanelMichael
    Hello, This is generally a task you should seek out help from a system administrator for if the log checking thread is unhelpful. We provide a list of system admin services at: System Administration Services | cPanel Forums Thank you.
    0

Please sign in to leave a comment.