LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-25-2017, 12:16 PM   #1
winger9
Member
 
Registered: Jan 2014
Posts: 85

Rep: Reputation: 1
Will mounting sda6 to run rkhunter allow the malware to become active?


I think I've got malware on my laptop. You see, I got suspicious disc activity
after accessing a dodgey website.

So I'm going to run rkhunter on the laptop from a live knoppix USB stick.

My linux system is on partition /dev/sda6. Presumably I need to actually MOUNT
sda6 in order to run rkhunter on it (or am I wrong). But if I mount it, does
this allow the malware to become active and do nasty things?


I'm only just starting to learn about malware scanners, and was proposing to run
the following on the laptop: rkhunter, chkrootkit, and clamtk or clamav. Will
running all 3 programs be sufficient in searching for malware?


I acquired the malware while running linux on sda6, but do I need to check for
this malware on the other partitions too
(sda1, sda2, and sda3 are for Windows,
and sda5 is linux swap)?

Is rkhunter better than chkrootkit or vice versa?

Many thanks.
 
Old 07-25-2017, 12:58 PM   #2
lazydog
Senior Member
 
Registered: Dec 2003
Location: The Key Stone State
Distribution: CentOS Sabayon and now Gentoo
Posts: 1,249
Blog Entries: 3

Rep: Reputation: 194Reputation: 194
Best way is to use a CD not a usb stick as usb can be written to unless it has a write protect switch.
I would check the entire disk to be on the safe side.
 
Old 07-25-2017, 03:58 PM   #3
Trihexagonal
Member
 
Registered: Jul 2017
Posts: 362
Blog Entries: 1

Rep: Reputation: 334Reputation: 334Reputation: 334Reputation: 334
Quote:
Originally Posted by winger9 View Post
Is rkhunter better than chkrootkit or vice versa?
Personally, I prefer rkhunter and is what I use on my FreeBSD boxen.

Running both on a Debian box, chkrootkit seemed to give a lot of false positives.
 
Old 07-25-2017, 06:30 PM   #4
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Try malwarebytes, for Windows.
 
Old 07-25-2017, 07:39 PM   #5
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,974

Rep: Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623
I agree with the live cd or a usb without persistance sort of boot. Have no other drive connected.

The problem with trying to fix a problem is that you can't always be sure you have it fixed. I'd consider the data's value versus the systems or lans value.

If this is an OS drive then just reload from known good sources.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Active malware campaign uses thousands of WordPress sites to infect visitors LXer Syndicated Linux News 0 09-21-2015 03:12 AM
rkhunter hangs on malware test replica9000 Linux - Security 6 09-16-2015 01:02 AM
LXer: Fake EFF site serving espionage malware was likely active for 3+ weeks LXer Syndicated Linux News 0 08-31-2015 09:51 PM
LXer: Detect rootkits and malware on Linux Servers using rkhunter LXer Syndicated Linux News 0 06-26-2013 07:01 PM
Do you need STP enabled to run active active bonding one CentOS4? ch19251 Linux - Networking 1 06-17-2009 09:30 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:51 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration