The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Disabling "Trojan Horses Detected" daily e-mail

Discussion in 'Security' started by PlasmaAu, Nov 5, 2011.

  1. PlasmaAu

    PlasmaAu Registered

    Joined:
    Nov 5, 2011
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Root Administrator
    Hi,

    I am receiving daily "Trojan Horses Detected" e-mails from WHM.

    The results are false positives, and other people on this forum indicate that the scanner is useless.

    How do I disable this daily false positive check from being done by WHM?

    Others say to disable it, but I don't see an option in WHM, or a suitable entry in cron to comment out.

    Thanks,
    Andrew
     
  2. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,447
    Likes Received:
    195
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Could you please post the contents of that email to peek at?
     
  3. PlasmaAu

    PlasmaAu Registered

    Joined:
    Nov 5, 2011
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Root Administrator
    Sure.

    Subject:
    Body:
    Thank you
     
  4. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,447
    Likes Received:
    195
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    WHM does not by default send out this email that I'm aware of although it does have a tool for checking. You might ask your server provider if they've added this to alert you.
    You might also check here:
    /var/spool/cron/root
     
  5. storminternet

    storminternet Well-Known Member

    Joined:
    Nov 2, 2011
    Messages:
    462
    Likes Received:
    0
    Trophy Points:
    16
    cPanel Access Level:
    Root Administrator
    Hello Andrew ,

    You might have been hacked. Please scan your server with chkrootkit and if scan report shows infected binaries then it is recommended to take the backup of your data.

    You can also reinstall your server with fresh operating system.

    Regards

    Mohammed
     
  6. PlasmaAu

    PlasmaAu Registered

    Joined:
    Nov 5, 2011
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Root Administrator
    Hi Infopro,

    I tracked down the instigator of this e-mail to this command:
    /usr/local/cpanel/bin/dcpumon --killproc

    This (wrongly) detects mysqld and other standard services as trojans, and fires off an e-mail to me every day.

    It's instantiated because its listed in /scripts/maintenance:
    I have now commented this call out. This maintenance script file was executed by /scripts/upcp --cron which is run via cron once daily (root's crontab):
    storminternet,

    Thanks for the concern, but I am positive I have not been hacked -- the VPS was locked away from the internet, and the services it complains about are all valid and not at all dangerous.

    Additionally, others on this and other forums suggest that this trojan detector is very broken (http://forums.cpanel.net/f5/disable-limit-trojan-detection-54249.html and Trojan Horses Detected by (WHM) on server.domain.com - Web Hosting Talk and Trojan Horses Detected by WHM - Web Hosting Talk)

    Regards,
    Andrew
     
  7. storminternet

    storminternet Well-Known Member

    Joined:
    Nov 2, 2011
    Messages:
    462
    Likes Received:
    0
    Trophy Points:
    16
    cPanel Access Level:
    Root Administrator
    Hello Andrew,

    Thank you for sharing this valuable information.
     
Loading...

Share This Page