LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Newbie (https://www.linuxquestions.org/questions/linux-newbie-8/)
-   -   Virus infested my laptops (dell 620 D820etc) 17. by doing a loopback on the cd rom cannot remove. (https://www.linuxquestions.org/questions/linux-newbie-8/virus-infested-my-laptops-dell-620-d820etc-17-by-doing-a-loopback-on-the-cd-rom-cannot-remove-4175587762/)

IsaacKuo 08-24-2016 02:03 PM

If you want to wipe the hard drive, just go back to gparted and delete the partitions from /dev/sda. It appears that this is the only hard drive in the laptop. The structure looks like a very conventional default Linux install:

/dev/sda1 = big main OS partition (ext4)
/dev/sda2 = small extended container partition (contains other partitions)
/dev/sda5 = small swap partition (within sda2)

In gparted, delete all three of these partitions and click on the check button to make it perform the requested actions.

This will wipe the drive with the exception of the main boot record. You can use various methods to truly erase everything on the drive, but start with this.

Afterward, you should see /dev/sda with no partitions, just unallocated space.

Do not concern yourself with /rofs or cloop. Those are associated with the Mint LiveCD. There is only one actual hard drive. It is the only thing you need to wipe. You can use similar procedures to wipe any USB drive.

yancek 08-24-2016 04:15 PM

If you want to use GParted to delete partitions, you must first unmount them or verify that they are not mounted whether you are using an installed system or a GParted
bootable iso on a CD/DVD or flash drive. When you open GParted, you see the main window with the various drives/partitions and you click on one to highlight it and then
right click to see if you have an unmount option. If you do, that means it is mounted so click unmount to unmount it. Verify all the partitions you want to delete are
not mounted and then click the Partition tab at the top and select Delete.

I booted a Mint 17 iso and shred is on it so either you used the wrong command or you need to prefix the command you want to run with sudo.

sundialsvcs 08-24-2016 05:41 PM

I agree with IsaacKuo in post #13 above ... I, too, do not smell a "virus" here ... and I strongly urge you to stop.

"ROFS" means "Read-Only File System." Most of the other "symptoms" that you describe here also appear to have benign(!) explanations.

Always remember: "a digital computer is not(!) a biological organism. You might be able to be struck with Ebola just by walking into the wrong elevator, but your computer can't. All that it can do is to execute software. Your computer, therefore, cannot "become infected," in the biological sense. This is the biggest fallacy that has ever been thrust upon the general public by snake-oil salesmen.

chrism01 08-26-2016 03:01 AM

As above, you could use a LiveCD to mount and clean HDDs or some distros eg RHEL/Centos come with a Rescue Mode option on the install media, which enables you to do the same ie mount offending HDDs as purely data disks and then format+mkfs etc.

zuegma 09-04-2016 06:22 PM

DBANNED Installed Clamtk here are results: 107 virus 1 trojan
 
5 Attachment(s)
Thank you all for all your help! I FINALLY have the data you need. It took quite awhile and a lot of DBAN to get here. I am using a dell latitude with 17.1 Mate 32 bit installed yesterday from a CD, after using it as a live user for 2 days, installing nothing, just changing all my passwords, and replacing old e-mail addresses with new as sign on and recovery. I changed my cell number. I talked to my ISP, if you recommend that I trade in my modem then we are ready. Whatever you need let me know.

I put 3 pkgs on. 2 from the software manager: Qbittorrent, Picasa (installed but NOT have opened it yet) and Clamtk from a Linux site

Clamtk took me a long time to get- I finally was able to install it but cannot retrieve one update. I was able to scan / I have 8 screen shots of all the info. 107 viruses, 1 trojan. The part citing the trojan I also saved as a copy and blew it up. I still have the original screen shot and will include that too. It will tell you way more than I can.

Here is my Problem at the moment: When I went to quarantine all of them, the results were gone and the results showed zero. If I had not taken the screen shots first, I would have nothing to show you.

Lastly, on the blown up image you will not see a date or time, if you look at the smaller images it will show this information.

My previous idiocy is what threw you off. The upshot to that mess was I was using an infected usb and giving myself the same virus again and again, is what I believe happened. Another possibility is that someone has my IP. Nothing has been compromised, my bank accounts etc.

Please advise?

zuegma 09-04-2016 06:43 PM

Additional Screen shot (resized)
 
The extension on my zoomed image wasn't supported. I changed the extension from xfc to png. It is a duplicate of an untouched screen shot but much easier to read.

Thanks.

Emerson 09-04-2016 06:51 PM

What virus? You have a bunch of WIN stuff there, is there a problem with some Windows install you have?

zuegma 09-04-2016 08:52 PM

1 Attachment(s)
Windows is not installed on this laptop. It has been completely wiped by Dban 2ce. Then I inserted a CD of 17.1 and installed it. I just went into the terminal to update Clamtk because I cannot do so in the menu. When I did the 'apt-get update Clamtk'
It stated that I had the latest version. Then it wanted to update quite a few more things. I copied the entire session; here is the link:

https://docs.google.com/document/d/1...it?usp=sharing

Yes, I used google docs so I could save it my drive. I have also sent you a snap of my partitions. If there is a way I can prove to you that windows is not on this machine, please tell me how.

I am sorry- I am still sending this to you in case it may help someone else. It is unnecessary to reply. I will cancel my account and just follow the postings if I need to.

Thank everyone who has tried to help. I wish you all well.

agillator 09-05-2016 05:39 AM

Note that if you are going to modify partitions with gparted they CANNOT be mounted.

As mentioned above you need to be running gparted from a live cd - linux install disk or the gparted live cd.

jefro 09-05-2016 03:05 PM

I too am wondering if you installed some things in wine where you'd get a C:\ drive or what??

Do you have another drive in the machine also? Use Gparted on top right for pull down to see if you have an extra drive or recovery drive in there. Even if the partition was marked hidden it should have shown up in gparted.

IsaacKuo 09-05-2016 10:56 PM

The "WIN" stuff in the screenshots are files which may affect Windows, not Linux - although it looks like a Windows application for Picasa is indeed installed via WINE.

The stuff in .cache/mozilla/firefox would have nothing to do with the USB drive. It's just garbage you may have picked up while web browsing.

But in any case, it's likely that nothing listed in the screenshot is a trojan or a virus. They start with "PUA" which simply means "Potentially Unwanted Application". But the stuff listed is all probably wanted or simply incidental false positives. The libreroffice templates, for example, are just sample template files which ship with libreoffice. They exist in the place you'd expect them to exist - in /usr/.../share/..., which is a directory only root would have access to anyway. The location of Picasa is also where I'd expect something you wanted to install it would go. The stuff in the firefox cache is probably just random junk you've picked up while web browsing.

I stand by my original assessment that the symptoms do not sound like any virus is involved. Just expected behavior from trying to use gparted on a read only cdrom filesystem.

Habitual 09-06-2016 05:16 AM

3 things.
Ignore warning on clamtk that GUI is "out of date."
Dont enable PUA scanning.
Don't scan / with clamtk.


All times are GMT -5. The time now is 01:26 AM.