LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 04-29-2018, 09:05 AM   #1
theKbStockpiler
Member
 
Registered: Sep 2009
Location: Central New York
Distribution: RPM Distros,Mostly Mandrake Forks;Drake Tools/Utilities all the way!GO MAGEIA!!!
Posts: 986

Rep: Reputation: 53
system windows /malware question


Hi, I have/had malware that was opening a system window and asking to "active" a link to "live Science" when I used the Network Manager to connect to the internet. I don't have it set to automatic. It would pop up after the Network Managers window of 'network is up' appeared.

I ran clamav and it did not find anything. Intuitively I wanted to remove and reinstall Firefox and there was a new version so I did this. The windows do not appear now.

My question is what program opens up System Windows (dialog boxes) so I can better track down the malware if clam misses it?

Thanks for your expertise!
 
Old 04-29-2018, 09:27 AM   #2
jsbjsb001
Senior Member
 
Registered: Mar 2009
Location: Earth, unfortunately...
Distribution: Currently: OpenMandriva. Previously: openSUSE, PCLinuxOS, CentOS, among others over the years.
Posts: 3,881

Rep: Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063
Quote:
Originally Posted by theKbStockpiler View Post
Hi, I have/had malware that was opening a system window and asking to "active" a link to "live Science" when I used the Network Manager to connect to the internet. I don't have it set to automatic. It would pop up after the Network Managers window of 'network is up' appeared.

I ran clamav and it did not find anything. Intuitively I wanted to remove and reinstall Firefox and there was a new version so I did this. The windows do not appear now.

My question is what program opens up System Windows (dialog boxes) so I can better track down the malware if clam misses it?
...
It sounds like it might have been a Firefox add-on or similar that caused the dialog to pop up.

To my understanding it's either your desktop environment/window manager or X itself, that can bring up dialog boxes. And of course, applications themselves may have different dialog boxes they bring up depending on what's going on with it.

You could look at using a different antivirus program - but I would not recommend using more than one though. You can also use https://www.virustotal.com/#/home/upload to scan any suspect files.
 
Old 04-29-2018, 09:30 AM   #3
Keruskerfuerst
Senior Member
 
Registered: Oct 2005
Location: Horgau, Germany
Distribution: Manjaro KDE, Win 10
Posts: 2,199

Rep: Reputation: 164Reputation: 164
There are several free antivirus programs available.
 
Old 04-29-2018, 02:02 PM   #4
Keruskerfuerst
Senior Member
 
Registered: Oct 2005
Location: Horgau, Germany
Distribution: Manjaro KDE, Win 10
Posts: 2,199

Rep: Reputation: 164Reputation: 164
And: also in the browser cache can virus/malware be installed.

Last edited by Keruskerfuerst; 04-30-2018 at 11:11 AM.
 
Old 04-30-2018, 11:19 AM   #5
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
https://msdn.microsoft.com/en-us/lib...(v=vs.85).aspx

Use
Code:
msconfig
as debug tool

https://www.makeuseof.com/tag/how-to...onfig-utility/
 
Old 04-30-2018, 04:37 PM   #6
theKbStockpiler
Member
 
Registered: Sep 2009
Location: Central New York
Distribution: RPM Distros,Mostly Mandrake Forks;Drake Tools/Utilities all the way!GO MAGEIA!!!
Posts: 986

Original Poster
Rep: Reputation: 53
This issue is with Mageia.
 
Old 05-01-2018, 09:48 AM   #7
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
was the browser running when the popups came?
 
Old 05-01-2018, 04:04 PM   #8
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,982

Rep: Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626
I too think it is a browser popup.

Install hosts file from http://winhelp2002.mvps.org/hosts.htm maybe or other that slows down the internet creeps.

I kind of doubt your system is in any danger as long as you are not running as root.

Might run wireshark to see what ip addresses or domain names show up on this.

There ways to increase firewall or iptables or white/black lists too.
 
Old 05-02-2018, 02:34 PM   #9
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by theKbStockpiler View Post
This issue is with Mageia.
Sorry, I took "windows" in subject literally.
Version?

Code:
Mageia 6 will be supported until January 16th, 2019.
Mageia 5 was supported until December 31st, 2017. More details and advice are available on our wiki page and from our blog.
Mageia 4 was supported until September 19th, 2015.
Mageia 3 was supported until November 26th, 2014.
Mageia 2 was supported until November 22nd, 2013.
Mageia 1 was supported until December 1st, 2012.
1
 
Old 05-02-2018, 08:29 PM   #10
theKbStockpiler
Member
 
Registered: Sep 2009
Location: Central New York
Distribution: RPM Distros,Mostly Mandrake Forks;Drake Tools/Utilities all the way!GO MAGEIA!!!
Posts: 986

Original Poster
Rep: Reputation: 53
Quote:
was the browser running when the popups came?
Opera and Firefox were open.

I opened one of these links after Firefox warned that it was infecting computers and did the "I know the risks" routine. I really wanted to look at the material and I'm using linux so what the hell.
http://www.mytreelessons.com/Drawing...20Thoughts.htm

It could also be consequential and not have anything to do with MyTreeLessons.

I'm quite sure it was a system window and asked if I wanted to 'activate the link' after giving the headline of the webpage and it was always "live Science". It's a nice website by the way.

I'm actually running Mageia 4. I intalled 6 on a laptop and it was the worst mandrake fork I had ever used so updating got put on the back burner for my usual desktop computer. I thought I had a 32 bit system etcetera, but I'm going to try to see if Mageia 6 64bit is okay on this desktop before I bite the bullet and switch over to Fedora or Centos again.

I know I need to get more involved with computer security but I have some other pressing needs to take care of first. Right now I can only react and not be proactive like I should be. I have clam ,wireshark and a few others on this install but I really don't know enough about them to be of intentional use. I would be relying on mostly luck in other words.
 
Old 05-03-2018, 11:43 AM   #11
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by theKbStockpiler View Post
I'm quite sure it was a system window
yes, the spammers/mal/spywarehackers do their best to make it look "genuine".
from your description, i think it's safe to assume it's a bad browser addon or some such.
just create a new profile, and dlete the old one, and be more careful in the future.
don't allow javascript by default, clean out local files after closing the browser, and of course don't install fishy addons.
 
Old 05-03-2018, 01:09 PM   #12
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,982

Rep: Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626
"I opened one of these links after Firefox warned that it was infecting computers" '


Sometimes firefox and others may legitimately warn users of a compromised web site. You should heed that warning and not proceed .....ever.....!

Many times the popups are as fake as the news.
 
Old 05-03-2018, 01:31 PM   #13
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by jefro View Post
....ever....
i wouldn't go that far.

it is well possible to safely traverse the web without depending on yet another google product (the lists of "potentially harmful" sites).

and not every site with an outdated security cert is even potentially harmful.
 
Old 05-04-2018, 08:39 AM   #14
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by theKbStockpiler View Post
Hi, I have/had malware that was opening a system window and asking to "active" a link to "live Science" when I used the Network Manager to connect to the internet. I don't have it set to automatic. It would pop up after the Network Managers window of 'network is up' appeared.

I ran clamav and it did not find anything. Intuitively I wanted to remove and reinstall Firefox and there was a new version so I did this. The windows do not appear now.

My question is what program opens up System Windows (dialog boxes) so I can better track down the malware if clam misses it?

Thanks for your expertise!
The browser "let this happen" so clearing/cleaning the cache and/or profile now and then is pretty common.
Tested backups are suggested as recovery methodology

The "malware" is whatever you were doing at the time, plus Internet.
If you believe the system infected, here's a basic diagnostic technique:
Create a new (unprivilged first...) user on the system.
Log in as the new user. Passive monitoring of the new user... meaning, just use it for a few...no scan, no diagnostics, just use it. Waiting for confirmation via a (dialog boxes)?
Do NOT go back to the site or sites that instigated this.

and tell us how you "ran clamav" exactly.
ClamTK. c-line....?
Change any options before you scanned? PUA? Scan / ?
Yeah, don't as the new user.
 
Old 05-07-2018, 11:38 AM   #15
theKbStockpiler
Member
 
Registered: Sep 2009
Location: Central New York
Distribution: RPM Distros,Mostly Mandrake Forks;Drake Tools/Utilities all the way!GO MAGEIA!!!
Posts: 986

Original Poster
Rep: Reputation: 53
I ran 'clamscan -i -e'.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
More windows malware revealed!! cousinlucky General 37 04-24-2017 02:36 PM
LXer: How Windows 10 became malware LXer Syndicated Linux News 0 06-09-2016 07:51 AM
LXer: Are Windows and OS X malware? LXer Syndicated Linux News 0 05-26-2015 09:24 PM
LXer: Details of the first-ever control system malware LXer Syndicated Linux News 0 07-21-2010 09:01 PM
May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 1 06-12-2008 05:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 10:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration