LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 10-25-2008, 01:43 PM   #1
mia_tech
Member
 
Registered: Dec 2007
Location: FL, USA
Distribution: CentOS 5.3, Ubuntu 9.04
Posts: 245

Rep: Reputation: 16
help removing virus/malware from ubuntu


guys I decided to port forward on my router to my ubuntu box, so I can access my files when I'm away, 5 min after that, my pc stop responding, it will not render control over the mouse or kayboard, first thing I did was to close the port at the router, now what live cd's you guys recommend I use to clean up my box?
 
Old 10-25-2008, 02:18 PM   #2
j.todd
Member
 
Registered: Feb 2008
Location: Michigan
Distribution: Debian GNU/Linux Unstable
Posts: 144

Rep: Reputation: 16
You probably don't have a virus/malware on your ubuntu box, did you try rebooting the box?

And why not just use ssh to access files remotely?
 
Old 10-25-2008, 03:40 PM   #3
jiml8
Senior Member
 
Registered: Sep 2003
Posts: 3,171

Rep: Reputation: 116Reputation: 116
What port(s) did you forward? 135 and 139? Those might have been attacked but it shouldn't hurt your box. If you have lost keyboard and mouse you probably had a driver crash. Try to ssh in from another computer and restart services on the box that is locked up. It probably isn't locked up, by the way, but merely keyboard and mouse are dead.

If you can't ssh in, then reboot it.

In the future, you'll find that using ssh -Y is the best way to go.
 
Old 10-25-2008, 04:27 PM   #4
mia_tech
Member
 
Registered: Dec 2007
Location: FL, USA
Distribution: CentOS 5.3, Ubuntu 9.04
Posts: 245

Original Poster
Rep: Reputation: 16
Quote:
Originally Posted by jiml8 View Post
What port(s) did you forward? 135 and 139? Those might have been attacked but it shouldn't hurt your box. If you have lost keyboard and mouse you probably had a driver crash. Try to ssh in from another computer and restart services on the box that is locked up. It probably isn't locked up, by the way, but merely keyboard and mouse are dead.

If you can't ssh in, then reboot it.

In the future, you'll find that using ssh -Y is the best way to go.
no, I'm in front of the computer, and yes I forwarded ssh, I opened 2222 on my router and forward it to 22 on my ubuntu machine, I just rebooted with sysrescuecd and ran clamav, chkrootkit, rkhunter, and came back negative...I've also rested the machine numerous time no help there either...running out of options here
 
Old 10-25-2008, 04:40 PM   #5
jiml8
Senior Member
 
Registered: Sep 2003
Posts: 3,171

Rep: Reputation: 116Reputation: 116
Can you ssh into the machine and have it work without problem?

What kind of mouse/keyboard? If they are both PS2 and they don't work after a reboot, potentially you have had a motherboard failure?
 
Old 10-25-2008, 05:05 PM   #6
mia_tech
Member
 
Registered: Dec 2007
Location: FL, USA
Distribution: CentOS 5.3, Ubuntu 9.04
Posts: 245

Original Poster
Rep: Reputation: 16
Quote:
Originally Posted by jiml8 View Post
Can you ssh into the machine and have it work without problem?

What kind of mouse/keyboard? If they are both PS2 and they don't work after a reboot, potentially you have had a motherboard failure?
no, not the case as I rebooted with a live cd and everything worked ok
 
Old 10-26-2008, 05:05 PM   #7
blackhole54
Senior Member
 
Registered: Mar 2006
Posts: 1,896

Rep: Reputation: 61
Do I understand correctly that you enabled SSH access to your computer from the Internet? If so, did you have strong passwords on all accounts? Did you disable root login via SSH? If not, it is possible that somebody (or something) logged in and did something malicious. (Although 5 minutes seems kind of quick to me for a non-standard port.)

If somebody did login I would think it likely they installed a root kit. You can run chkrootkit from KNOPPIX after mounting the partition:

Code:
chkrootkit -r /mnt/sda1 | less
(change /mnt/sda1 as appropriate)

Beware that chkrootkit can have both false positives and false negatives. Search the Internet for help with it. You can also checkout Rootkit Hunter.

If you decide a rootkit was installed, it is probably best to do a reinstallation since you can never be sure you have removed everything malicious.
 
Old 10-27-2008, 12:02 AM   #8
mia_tech
Member
 
Registered: Dec 2007
Location: FL, USA
Distribution: CentOS 5.3, Ubuntu 9.04
Posts: 245

Original Poster
Rep: Reputation: 16
first thing I checked was the auth.log, and no one logged in, as far as rootkit, I booted from sysrescd and ran chkrootkit, rkhunter, and for good measure ran also avscan after updating the virus definition, it seems a bit odd but after restarting the machine several times, it started to respond again, I suspect it might have been the kvm switch...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus/Spyware/Malware MS Network/Linux to the Rescue metallica1973 General 5 09-08-2008 02:24 PM
[SOLVED] May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 22 08-17-2008 01:05 PM
May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 1 06-12-2008 05:10 AM
Anti-virus and malware remover advertising Tomermory LQ Suggestions & Feedback 4 06-28-2007 11:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 01:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration