LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-03-2010, 09:33 AM   #16
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301

If you really think you have a rootkit, try using rkhunter and chkrootkit.

As for a BIOS kit ... they are quite rare, and AFAIK you can only get one by flashing a hacked BIOS ...

Quote:
Originally Posted by compuslave View Post
As for the bios it would only keep some changes, others would revert even if I didn't let the os boot. Some features that were there a year ago, like the acpi stuff, were totally gone. Also while poking around with Hiren's boot cd and Ultimate boot cd one of the bios utilities said I had an active virus in cmos, this happened with both cds. As for the video rom, I just have strong suspicion based on my untrained eye that the video rom was involved somehow. Once I read more about the subject I was convinced. It's in there.

So, how do I save my files?
Which utility said this ? Did it have an option to remove it ? If not, try flashing a new BIOS, a good one.

Video ROM ? what is that ?
 
Click here to see the post LQ members have rated as the most helpful post in this thread.
Old 02-03-2010, 12:16 PM   #17
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
Quote:
Originally Posted by compuslave
Anyway, what kinds of things did you want to see?
Take a look at post #2 in this thread. unSpawn asked a couple of basic questions that really need to be answered in detail. The way this forum works is with evidence, not speculation or vague descriptions. What tends to work best is posting records, logs, traffic logs, that sort of stuff. Normally the CERT checklist is a good place to start, but given the amount of time that has elapsed, I suspect it will be of minimal use. H_TexMex_H's suggestions are worth a go as well.

Basically, you need to have some evidence about why this system is different from what a normal system would be.

By the way, did you get your copy of Backtrack3 from a reputable dealer? To be honest, that would be my first investigation. If your copy of Backtrack was cracked, that could explain a fair bit.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
97 Bios, needs acpi=force... how? philip.aston@ntlworl Linux - Newbie 2 10-03-2007 04:04 AM
Linux ACPI and BIOS ACPI - problem to understand and giving out bugs marisdembovskis Linux - Software 3 09-20-2007 10:22 PM
ACPI disabled because bios is from 99 and too old laurahlane Linux - Newbie 2 06-04-2005 09:32 PM
ACPI Bios Problem GoRinNoSho Linux - Newbie 1 06-27-2003 08:30 AM
big BIG javascript & loading time luigi Programming 3 09-10-2001 03:53 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:50 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration