LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   linux virus "aMuler" ? (https://www.linuxquestions.org/questions/linux-security-4/linux-virus-amuler-272058/)

dryajov 12-30-2004 05:06 PM

linux virus "aMuler" ?
 
Hi All,

I just found out that my Linux box might be infected with a virus, it all started when I tried to do an “ls” on my terminal, instead listing the files in the “dir” it logged me out, I reinstalled the terminal emulator which is “rxvt” still the same thing. A couple of hours later all of my terminals where having the same behavior. Then I tried shutting down X and doing “ls” from the console same thing it would log me out. The strangest thing that happened, that convinced me of “IT” being a virus was that it started rebuting on its own, whit messages like “message from root aMuleR – EO”. Does anybody have a clue of what it is and how to remove it.


Thanks in advance.

P.S: Yes I do have “aMule” installed and I probably cached the virus while downloading stuff whit it.

Tuttle 12-30-2004 05:30 PM

are you able to install and run f-prot or other av software?

dryajov 12-30-2004 05:39 PM

Yes I'm using bitDefender.Just finished the scan and it didn't find anything. Maybe it is not a virus maybe someone made some sort of an attack, which I doubt because i checked the log files and did not find anything strange.

TruckStuff 12-30-2004 08:12 PM

Quote:

Originally posted by dryajov
Maybe it is not a virus maybe someone made some sort of an attack, which I doubt because i checked the log files and did not find anything strange.
That doesn't mean anything these days. A careful hacker (or for that matter a skiddie attacking a system with the usual "default" settings) will erase any traces of their entrance into your system. I think you've been had... time to reinstall and patch software. :)

slackMeUp 12-30-2004 10:43 PM

Well I would check for root kits... but in the end you will need to do a full reinstall just to be safe.

Boot off a Live CD, backup your important data to another drive or CDs, and then nuke your partition.

Reinstall and you're good to go.

Remember to keep up-to-date with your distro.


All times are GMT -5. The time now is 11:38 PM.