[clamav-users] Php.Trojan.MSShellcode-81 FOUND on MS IIS log file?

Michael Wang mwang at unixlabplus.com
Mon Jul 12 14:41:40 UTC 2021


Clamscan detested a virus in Microsoft Internet Information Services 8.5
log file:

*C:\inetpub\logs\LogFiles\W3SVC1\u_exNNNNNN.log: Php.Trojan.MSShellcode-81
> FOUND*
>

I looked at the file manually, it consists of comments and GET and POST
messages. How do I determine if  this is a real or false positive? The
files are dynamic and new files will be generated, how are my options?
Thanks.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.clamav.net/pipermail/clamav-users/attachments/20210712/54ab60e8/attachment.htm>


More information about the clamav-users mailing list