LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-04-2014, 11:40 AM   #1
kcredden
Member
 
Registered: Jul 2006
Posts: 38

Rep: Reputation: 0
Malware?


Folks: For the last few days I've been receiving a spat of rejected e-mails; ones I did not send. So I installed ClamAV, and ClamTK and did a complete system-wide scan and came up with these two:

/usr/lib/mono/4.0/mscorelib.dll - UA win32 packerprivateexeprote-7

and

/home/kcredden/.mozaillafirefox/yhm UA win32p packerprivateexeprote-7

Now, I told it to quarantine these files, it did the Mozilla one, but the one in mono was not. I assume I need to be in / to do that since it's /USR

But let me ask; firstly are they malware? I cannot find this on goggle.

#2: Would it be safe to rip this out? For that matter, do I even NEED mono? I did not install mono when I reinstalled the system.

I'll do an image before I do anything risky of course but I wanted your opinion first.

I'm very new to malware on linux. I feel a bit honored. 12 years on linux, first one.
 
Old 05-04-2014, 12:15 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by kcredden View Post
are they malware?
First of all you didn't copy the name right, please be careful what you post, it's "PUA.Win32.Packer.PrivateExeProte-7".
- PUA stands for Potentially Unwanted Applications so it's not a virus but a definition of what some would call "unwanted".
- If you don't trust a package or its contents then verify it against a clean copy from a known trustworthy repo.
- (upload and) scan with another antivirus tool.
*While I shouldn't speculate you'll likely find it's not a virus. That doesn't matter as it's knowing how to verify things that matters.


Quote:
Originally Posted by kcredden View Post
Would it be safe to rip this out? For that matter, do I even NEED mono?
You didn't tell us what you run and I'm not clairvoyant so only you know if you need Mono.
If unsure just try uninstalling Mono and see what b0rks ;-p


Quote:
Originally Posted by kcredden View Post
I did not install mono when I reinstalled the system.
That's like saying "I didn't install /sbin/init" ;-p
It may have been a dependency of Something Completely Different.
 
Old 05-04-2014, 12:19 PM   #3
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,623

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
the microsoft emulators can get Windows viruses
wine and the "dot net " mono

and this is odd
Quote:
/home/kcredden/.mozaillafirefox/yhm UA win32p packerprivateexeprote-7
it should be very different

that is NOT!!! the firefox folder
that would look something like this
Quote:
/home/kcredden/.mozilla/firefox/????????.default/
replace the 8 ???????? with a random string

Last edited by John VV; 05-04-2014 at 12:29 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LQ Has Malware? dudeman41465 LQ Suggestions & Feedback 11 02-04-2013 09:22 AM
Why the lack of malware? eveningsky339 Linux - Security 7 09-23-2010 04:47 AM
[SOLVED] May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 22 08-17-2008 01:05 PM
May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 1 06-12-2008 05:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:01 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration