LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-01-2011, 01:52 PM   #1
secretlydead
Member
 
Registered: Sep 2003
Location: Qingdao, China
Distribution: mandriva, slack, red flag
Posts: 249

Rep: Reputation: 31
malware in firefox?


Hi,

Firefox slowed to a crawl on my computer. I searched using clamav and found a "SearchBar", but eliminating it did not speed it up. I eventually renamed ~/.mozilla and urpme'd then urpmi'd firefox - this brought it back to normal speed.

However, I'm guessing there is some malware in my old configuration files and that those signatures should be added to clamav, and also, that desktop systems have clamd installed and running on them by default.

What should I do now?
 
Old 06-01-2011, 02:10 PM   #2
ButterflyMelissa
Senior Member
 
Registered: Nov 2007
Location: Somewhere on my hard drive...
Distribution: Manjaro
Posts: 2,766
Blog Entries: 23

Rep: Reputation: 411Reputation: 411Reputation: 411Reputation: 411Reputation: 411
Possibly not...I had the same thing, but I had to clean out the downloads list. Does FF do this: slow down to a crawl, lotsa disk activity then "pick up" again? If so, try to clean up the download list.

FF uses slqite to access/build the download list (is is a database...) so you ma see this in the ps -A list too...

Luck

Thor
 
Old 06-01-2011, 02:10 PM   #3
Joe of Loath
Member
 
Registered: Dec 2009
Location: Bristol, UK
Distribution: Ubuntu, Debian, Arch.
Posts: 152

Rep: Reputation: 28
Any malware running on Firefox on Linux will have to be cross platform - EG a browser addon. Did you try running Firefox in safe mode?
 
Old 06-01-2011, 02:19 PM   #4
craigevil
Senior Member
 
Registered: Apr 2005
Location: OZ
Distribution: Debian Sid/RPIOS
Posts: 4,887
Blog Entries: 28

Rep: Reputation: 534Reputation: 534Reputation: 534Reputation: 534Reputation: 534Reputation: 534
Try installing and using Bleachbit.

BleachBit deletes unnecessary files to free valuable disk space, maintain
privacy, and remove junk. It removes cache, Internet history, temporary files,
cookies, and broken shortcuts.

It handles cleaning of Adobe Reader, Bash, Beagle, Epiphany, Firefox, Flash,
GIMP, Google Earth, Java, KDE, OpenOffice.org, Opera, RealPlayer, rpmbuild,
Second Life Viewer, VIM, XChat, and more.

Beyond simply erasing junk files, BleachBit wipes free disk space (to hide
previously deleted files for privacy and to improve compression of images),
vacuums Firefox databases (to improve performance without deleting data), and
securely shreds arbitrary files.
Homepage: http://bleachbit.sourceforge.net

or Nixory - Antispyware tool for Firefox, IE, Chrome - http://nixory.sourceforge.net/
Quote:
Nixory is a free and open source antispyware tool written in Python/PyGTK aimed at removing malicious tracking cookies from your browser. It currently supports Mozilla Firefox, Internet Explorer and Google Chrome. It runs on all OS, including Windows, Linux and MacOSX.
 
Old 06-01-2011, 10:33 PM   #5
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,627

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
that search bar might be from oracle's java install

if you are not using the one in your distros repo.

there is also a Apple mac virus that will run ( bu not install ) on linux .A reboot removes it.

Now "slowing to a crawl"
could be ff prefetchng links on whatever site you were on and one of the "prefetched" had a mess of advertising or a video ,or something
 
Old 06-01-2011, 11:57 PM   #6
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by Joe of Loath View Post
Any malware running on Firefox on Linux will have to be cross platform
This sounds kinda weird. Care to elaborate?
 
Old 06-02-2011, 01:14 AM   #7
ButterflyMelissa
Senior Member
 
Registered: Nov 2007
Location: Somewhere on my hard drive...
Distribution: Manjaro
Posts: 2,766
Blog Entries: 23

Rep: Reputation: 411Reputation: 411Reputation: 411Reputation: 411Reputation: 411
Quote:
could be ff prefetchng links on whatever site you were on and one of the "prefetched" had a mess of advertising or a video ,or something
That too, of course...it could be a clever idea to set the home page to something more static (www.linuxmanpages.com for example) to have a clean start up...eh, just me thinking out loud way too early in the morning...
 
Old 06-02-2011, 05:10 AM   #8
Joe of Loath
Member
 
Registered: Dec 2009
Location: Bristol, UK
Distribution: Ubuntu, Debian, Arch.
Posts: 152

Rep: Reputation: 28
Quote:
Originally Posted by win32sux View Post
This sounds kinda weird. Care to elaborate?
Sorry, I didn't explain fully. Since most malware is written for Windows, the only malware I know of that's out there which will run on Linux has to be cross platform, since there isn't much written for Linux itself. Especially in the realm of browser *sploits, since most Linux desktops are pretty well locked down, as well as being used by technical users and kept up to date. Not to mention the fact that everyone and their mother prefers a different browser. It's not like Windows
 
Old 06-02-2011, 04:57 PM   #9
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,627

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
Quote:
Care to elaborate
cross platform even on windows to get the same code to do the same thing in IE7,IE8,IE9 and in FF3.6 and ff4 AND opera
is hard but is being done

about 2 months ago a notice went out that a Windows/MAC virus for FF was by shear random chance was able to run ( but NOT install - ran in ram )
to uninstall it on linux -- reboot

personally I am more worried about a rootkit that a virus
but some of the javascript stuff ?? who knows . But rebooting will stop that stuff, seeing as to would be running in system ram and not installed .

Right now just doing the normal everyday basics will keep all but the most determined "cracker" off your system
run no-script
run add block pulse
link ~/.macromedia/Flash_Player/#SharedObjects to /dev/null
type in the web address from the advertising that pops up and DO NOT click on the advertising
stay updated
do not run the gui as root
-- and so no ---
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Mozilla says Microsoft browser malware can Firefox off LXer Syndicated Linux News 1 10-18-2009 02:12 PM
HELP!! I think some malware got on my machine (on firefox) =( darksmiley Linux - Security 6 11-19-2008 02:02 PM
[SOLVED] May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 22 08-17-2008 01:05 PM
May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 1 06-12-2008 05:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration