Linux - SecurityThis forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
I had strange problems with 2 graphic browsers (Opera and Firefox) at the same time and I guess this problem is related to some sort of malware (virus, trojan, worm, rootkit) or something else.
1. When I start the browsers this morning, all my preferences setting (fonts, homepage, wand etc) are reset back to the default settings. It looks like the browsers are in similar condition as newly installed browser from rpm (I use mandriva).
2. The strange thing, the ".mozilla" and ".opera" directory are intact / still exist.
3. I had deleted both graphical browsers as prevention.
Is this some sort of malware?
If this is malware, what other programs are attacked?
Thank you.
Firefox user dirs are kept in .mozilla/firefox/randomstring.default and the active profile is specified in .mozilla/firefox/profiles.ini. Given that your profile is saved in .mozilla/firefox/yolzv1zl.default, make sure that you have something similar to the below in your profiles.ini:
I am of the opinion that viruses don't actually really exist (on Linux) and that it was likely an inadvertant configuration change that lead to your woes.
I had strange problems with 2 graphic browsers (Opera and Firefox) at the same time and I guess this problem is related to some sort of malware (virus, trojan, worm, rootkit) or something else.
...<SNIP>...
Is this some sort of malware?
If this is malware, what other programs are attacked?
Thank you.
Possible but highly, highly unlikely. More likely a system update or a corrupted file or a drive that has some bad sectors. To be safe follow normal procedures to see if your system has been compromised (cert checklist is a good start), check your logs, etc.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.