GeneralThis forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
Can a windows virus that is on the hd cache be put on a ubuntu hd cache. The fallowing has my story.
My wife received a nasty virus on her laptop. The symptom is she was unable to get it out of safe mode. She had to restart the laptop, and when it booted up it said win did not shut down properly. Well it has gotten to the point that the only way to get it past boot. Is to have it shut down for a period amount of time. When I restart the laptop it either can not go past boot, but if it can it just hangs their.
Well I wondered what will happen if I plug the Ethernet cable in. Well that is when it infected my win desktop. Then my desktop started to do the same thing. I scanned for virus and mail ware, and nothing came up. So I zeroed out the hard drive with seatools, took out the cmos battery, and reset my cmos. I did the ecaxt same thing to my ubuntu machine. Well it looks like I did not get rid of it. So I am thinking the bug must of attached itself to the hard drive cache. I am wondering if my Ubuntu machine has the same thing? I hate to replace the hard drive, and when I connect it to my net work it would effect my win desktop. The ubuntu machine is acting fine.
No Windows virus can run on Linux, two completely different systems. The runtime DLLs that it would need are not there. If it's in the MBR it may mean a new hard drive, zeroing it out won't work. A low-level format might. Hard to offer more without know what virus it is.
If it's in the MBR it may mean a new hard drive, zeroing it out won't work.
You can wipe the Master Boot Record partition table using a tool such as gparted (or the command-line equivalent parted). This won't require a new hard drive, but it will erase all content on the drive.
No Windows virus can run on Linux, two completely different systems. The runtime DLLs that it would need are not there. If it's in the MBR it may mean a new hard drive, zeroing it out won't work. A low-level format might. Hard to offer more without know what virus it is.
...
Could the virus be stored on it, and when my windows access the samba share? Could it re-get the virus?
You can wipe the Master Boot Record partition table using a tool such as gparted (or the command-line equivalent parted). This won't require a new hard drive, but it will erase all content on the drive.
I will try it when I get home. Some one hear at work said it may be a bad hard drive. I know that their is a tool on Ubuntu that can check the S.M.A.R.T. to see if their is any bad sectors. Can't remember what it is called.
Routers have interfaces you can reach.
Cable modems are less "friendly", so I'm saying "no" here. I could be wrong.
If nothing boots, then I suspect the MBR got scrambled.
I ran out of time while I was writing this originally, and could not proofread what I put down. I forgot to mention. I re installed windows. It acted fine until I started to do the updates. Then it started to do the same symptoms. When I ran IE to get chrome and my other software. The pc just froze. Earlier I did re set my router by putting a paperclip in the reset button hole. I did run a program to supposedly fix the MBR from the installation cd. So if gparted does not fix the issue. I am guessing it may be hanging around my cable modem. Hopefully the cable modem has a reset option like the router. Well two more hours until I get home. Hopefully my wife does not need mt to do something. I will keep you all posted.
I ran out of time while I was writing this originally, and could not proofread what I put down. I forgot to mention. I re installed windows. It acted fine until I started to do the updates. Then it started to do the same symptoms. When I ran IE to get chrome and my other software. The pc just froze. Earlier I did re set my router by putting a paperclip in the reset button hole. I did run a program to supposedly fix the MBR from the installation cd. So if gparted does not fix the issue. I am guessing it may be hanging around my cable modem. Hopefully the cable modem has a reset option like the router. Well two more hours until I get home. Hopefully my wife does not need mt to do something. I will keep you all posted.
Unless your modem runs Windows, what you're describing is impossible. I've never heard of a virus that can target Windows that also targets embedded systems like a router. Since routers and modems don't have hard drives, replicating a virus to one would be difficult, to say the least. It's more likely that a compromised system would change DNS settings on a router that was not secured properly to something malicious. Does your router/modem have a hard password set? It would also be unlikely you would get a virus off a Samba share unless it was already embedded in a program or file of some kind, or an e-mail attachment that could be executed. As far as your hard drive, it's possible you have or had a rootkit in the MBR. This will load before the OS and can do all kinds of things. They can range from hard to very hard to remove without specialized software, and can be impossible to detect with the system running without knowing what to look for. I'm not aware of any Linux rootkits in the wild, but anything is possible these days, it seems.
Last edited by guyonearth; 05-09-2013 at 06:57 PM.
Get hiren's boot cd it has plenty of AV tools that run from cd, also if you refomat hdd from live-cd any virus is already eliminated so there would be no reason to run Av from live-cd all though if paranoid you can. I just had a wins computer with the Alura virus which is quite difficult to get rid of.
I had to run bit defender from live-cd to cure it.
I believe it is the hard drive. I ran a handful of updates at a time, and it was fine. Then when I continued to do the updates. I ran into my situation. When I checked the SMART from ubuntu boot cd. It said it was not activated. However it was activated in the BIOS. So I believe that it is trying to write something to a bad sector causing my issue.
I just found out that my wife's laptop was dropped a couple of times. So it was coincidence that both of them crapped out about the same time. Making me think that it was a virus.
ok folks. I thought I had this nipped in the butt. However I do not. A person at work lent me a hard drive until I can get mine replaced. I installed the windows updates just fine, and it ran fine. Until shortly after I put the window machine on my Lan. Then shortly after it started to act up. I went to change the screen saver, and my mouse went really slow. Then the pc locked up.
I have a fresh install of Ubuntu on my server. I ran rkhunter, and it said it was ok. However it had a warning. The warning was Hidden directory found: '/dev/.udev' and 'dev/.initramfs' I did remove both of the directories. Then continued to reboot. Ran rkhunter again and it came up with the found directories. Ummm before the reboot it also found some files that I was successful of getting rid of.
If your saying that your security software running on a Unix filesystem found rootkits, I find that highly suspect. I'm not aware of any rootkits running in the wild that affect Linux. Most of the ones that have been shown are proof-of-concept more than anything. The only way you could be infected would be if your install media was infected, or your software sources were infected. I also fail to see how it would affect Windows, unless you in fact have multiple infections for both systems. There are rootkits that affect firmware and BIOS chips, that can actually survive hard drive replacements and system reinstalls.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.