I am wondering if logging like this could be moved to mysql, as cxs picks up entries in the file and quarantines it.
eg
'/home/xxxxxxxx/public_html/logs/admintools_breaches.log'
(quarantined to /home/quarantine/xxxxxxx/xxxxxxx/admintools_breaches.log.1455206637_1) ClamAV detected virus = [{HEX}base64.inject.unclassed.7.UNOFFICIAL] (md5sum:355ae0630a7b24ad125b02611a2c39a6)
ie sees the record, says "that's a virus" (when it's actually just a record of what admin tools saw dodgy brothers tried to do, and was logged), and removes the file from the user account
Ian