LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-22-2014, 12:34 PM   #1
winger9
Member
 
Registered: Jan 2014
Posts: 85

Rep: Reputation: 1
How can I determine if this unexpected disc activity is malware or not?


Hi fellas

Main question thanks:

I had unexpected hard disc (HD) activity recently, shortly after I booted. I'm
concerned that it might be caused by malware. Is there a program I can run which
monitors disc accessing, and that will tell me which processes are accessing the
disc?

Will that program tell me which program/file on the filesystem the process was
started from? Then if it IS malware I'll know which file to delete/quarantine.

Thanks, John.

--------------------------------------------------------------------------------
Full Details:

1. I got some unexpected disc activity* about 2 minutes after booting completed. (*Blue
disc light flashed for a few seconds). Don't think I've seen this before. You
know how you become familiar with patterns of things happening/not happening on
the laptop. The disc activity makes me suspicious that I MIGHT have malware (but
not sure).

2. You see I spend a lot of time on the Internet and haven't got a firewall
installed or an anti-virus program constantly running in the background. So this
is also why I'm concerned that my Knoppix system might have got malware.

3. Done so far: I booted the laptop using my Knoppix live DVD, to avoid running
my real system and letting any malware run amok. Ran clamtk which showed 154
threats. I believe 141 of them are false positives, but I don't know what to
make of the remaining 13.

These 13 are all in the directory
/home/knoppix/.cache/chromium/Default/Cache/ ,
and all the filenames have the same general appearance as the following one
from those 13: /home/knoppix/.cache/chromium/Default/Cache/f_00a67f .

clamtk gives the following threat "Status" to the 13 files:

Code:
Status			No. of files with this Status

PUA.Script.Packed-1:	3
PUA.Script.Packed-2:	1
PUA.Phishing.Bank:	1
PUA.JS.Obfus-2:		1
PUA.JS.Xored:		7
4. Got Knoppix live distro installed on hard disc, distro 7.0.2,
kernel release 3.3.7. Knoppix say that Knoppix installed on HD "basically
becomes Debian".

-- End of Full Details --

Last edited by unSpawn; 01-22-2014 at 01:20 PM. Reason: //Misplaced vBB code tags
 
Old 01-22-2014, 03:02 PM   #2
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
Quote:
Originally Posted by winger9 View Post

I had unexpected hard disc (HD) activity recently, shortly after I booted. I'm
concerned that it might be caused by malware. Is there a program I can run which
monitors disc accessing, and that will tell me which processes are accessing the
disc?
Well, it could be malware, but it could be a number of other things, too (updatedb plus all the file indexing stuff that could come with your desktop environment come to mind, as do any cron jobs, really).

Something like 'top' will tell you which programs are running. Anything suspicious there? I think you could use 'iotop' for what you are asking (not something I've much used), but you could also look at LMD (Linux Malware Detect), rkhunter, and similar programs to look for maleware on disk. The trouble with programs of this sort is that they tend to throw up a few false positives, so be prepared to search on-line to see whether what they find is likely to be a false positive before panicking. After panicking (...if...), ask here to see if anyone can help you further.
 
2 members found this post helpful.
Old 01-22-2014, 03:03 PM   #3
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,627

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
is indexing turned on ?

that indexes the drive and allows for searching

also it is normal for a OS to look for updates on boot

as above likely it is nothing
but if you are really paranoid
install "snort"
and look and see what is going on, network wise
and read the system logs

Last edited by John VV; 01-22-2014 at 03:06 PM.
 
1 members found this post helpful.
Old 01-22-2014, 03:10 PM   #4
jamison20000e
Senior Member
 
Registered: Nov 2005
Location: ...uncanny valley... infinity\1975; (randomly born:) Milwaukee, WI, US( + travel,) Earth&Mars (I wish,) END BORDER$!◣◢┌∩┐ Fe26-E,e...
Distribution: any GPL that work on freest-HW; has been KDE, CLI, Novena-SBC but open.. http://goo.gl/NqgqJx &c ;-)
Posts: 4,888
Blog Entries: 2

Rep: Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567Reputation: 1567
Hi. Can try others: http://www.makeuseof.com/tag/free-li...irus-programs/
and searching the "threats:" http://askubuntu.com/questions/26666...ossible-threat best wishes and have fun.

Last edited by jamison20000e; 01-22-2014 at 03:12 PM.
 
Old 01-22-2014, 10:39 PM   #5
Doug G
Member
 
Registered: Jul 2013
Posts: 749

Rep: Reputation: Disabled
you can use iotop to view disk read/write activity
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Bash/perl script to determine network activity mrjoe42 Programming 1 07-07-2009 07:03 PM
[SOLVED] May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 22 08-17-2008 01:05 PM
May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 1 06-12-2008 05:10 AM
Lots of unexpected network activity mdixon Linux - Security 2 11-23-2004 06:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:30 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration