Bay 12 Games Forum

Please login or register.

Login with username, password and session length
Advanced search  
Pages: [1] 2

Author Topic: Rootkit on Ubuntu  (Read 3072 times)

Dave1004

  • Bay Watcher
  • This is getting personal.
    • View Profile
Rootkit on Ubuntu
« on: December 23, 2011, 07:10:33 pm »

Hey, Bay12'ers. I come to you with an urgent plea for help. If you don't know anything about Linux, specifically Ubuntu, please don't bother. I do appreciate any, an all help, but your time would just be wasted.

I'll keep it short and simple. I downloaded a small (3mb) exe a while back, it was for something called OmegleSpy (A friend recommended it to me, I can't get in-contact with him now.) After that, I started getting banned on websites and forums for spamming "Quickprize.net", and I just figure out that I have a root-kit. I tried to use Avast, and I managed to install it, but after (attempting) to update it, I get this error:

Deleted stale lock file '/home/(me)/.avast/lockfile-(me).'
An error occurred in the Avast! engine: Invalid argument

I can't launch Avast! now. Please help me! Are there any good Rootkit scanners, and preferably removers out there? Anything that I can do to fix this? Thank you! I'll be eternally in your debt.

I'm also a Linux newbie, so I don't know much. I also can't get the Terminal to work, it says that I'm not an Administrator, and then asks if I'm root, but I can't activate any commands. Please recommend any decent programs to clean my computer!

One final time, - Thank you!!
Logged


Hardcap of 200 MB/24 hours.

Nirur Torir

  • Bay Watcher
    • View Profile
Re: Rootkit on Ubuntu
« Reply #1 on: December 23, 2011, 07:37:01 pm »

I'm also a Linux newbie, so I don't know much. I also can't get the Terminal to work, it says that I'm not an Administrator, and then asks if I'm root, but I can't activate any commands.
Preface your terminal commands with Sudo to run them as an administrator.

I'd boot from the installation CD and then try to run whatever scanners you can find. I expect it would prevent the rootkit from disabling them. (This is almost as obvious as "Is it plugged in?" and I hate to say anything, but for the sake of completion, make sure you downloaded the Linux version of Avast! [I make no claims that these installation instructions work. This was the first page I found with a quick search.])

Actually, I'd probably format and reinstall in a paranoid frenzy.
Logged

Dave1004

  • Bay Watcher
  • This is getting personal.
    • View Profile
Re: Rootkit on Ubuntu
« Reply #2 on: December 23, 2011, 07:45:10 pm »

I'm also a Linux newbie, so I don't know much. I also can't get the Terminal to work, it says that I'm not an Administrator, and then asks if I'm root, but I can't activate any commands.
Preface your terminal commands with Sudo to run them as an administrator.

I'd boot from the installation CD and then try to run whatever scanners you can find. I expect it would prevent the rootkit from disabling them. (This is almost as obvious as "Is it plugged in?" and I hate to say anything, but for the sake of completion, make sure you downloaded the Linux version of Avast! [I make no claims that these installation instructions work. This was the first page I found with a quick search.])

Actually, I'd probably format and reinstall in a paranoid frenzy.

No worries, I had gotten the Linux avast. I'm a newbie, but not that bad lol. I lost my installation CD ages ago, and the chances of finding it are...Slim at best.

The major problem is, I can't find any scanners. I tried ClamTK, but it found nothing...Ugh. So worried...

Thanks for the post, Nirur!
Logged


Hardcap of 200 MB/24 hours.

ChairmanPoo

  • Bay Watcher
  • Send in the clowns
    • View Profile
Re: Rootkit on Ubuntu
« Reply #3 on: December 23, 2011, 07:52:10 pm »

have you tried chkrootkit?
Logged
Everyone sucks at everything. Until they don't. Not sucking is a product of time invested.

Dave1004

  • Bay Watcher
  • This is getting personal.
    • View Profile
Re: Rootkit on Ubuntu
« Reply #4 on: December 23, 2011, 07:58:02 pm »

have you tried chkrootkit?

I think I had looked it up, but the last update was late 2009, so...Unless I misse something, it probably won't help...Thanks, though!
Logged


Hardcap of 200 MB/24 hours.

Dave1004

  • Bay Watcher
  • This is getting personal.
    • View Profile
Re: Rootkit on Ubuntu
« Reply #5 on: December 23, 2011, 08:14:39 pm »

I just installed Rootkit Hunter, but I can't find out how to run it. I had installed it from the Software center. I tried sudo chkrootkit -c, but it just says that the command isn't found...

Anybody know why? Thanks!
Logged


Hardcap of 200 MB/24 hours.

ChairmanPoo

  • Bay Watcher
  • Send in the clowns
    • View Profile
Re: Rootkit on Ubuntu
« Reply #6 on: December 23, 2011, 08:33:05 pm »

the command for that one is rkhunter

(I've never used any of these programs, mind you. I'm just translating from here: http://www.noticiasubuntu.com/como-buscar-rootkits-en-ubuntu/ )
Logged
Everyone sucks at everything. Until they don't. Not sucking is a product of time invested.

Dave1004

  • Bay Watcher
  • This is getting personal.
    • View Profile
Re: Rootkit on Ubuntu
« Reply #7 on: December 23, 2011, 09:25:48 pm »

the command for that one is rkhunter

(I've never used any of these programs, mind you. I'm just translating from here: http://www.noticiasubuntu.com/como-buscar-rootkits-en-ubuntu/ )

Thanks! That actually worked, so...Let's see if it does anything D:

Ty mate!
Logged


Hardcap of 200 MB/24 hours.

DrKillPatient

  • Bay Watcher
  • The yak falls infinitely
    • View Profile
Re: Rootkit on Ubuntu
« Reply #8 on: December 23, 2011, 11:06:58 pm »

I suppose you ran the exe file with Wine. If so, it most likely installed stuff into your ~/.wine folder (which is basically like Windows' C: drive). Be sure to back up any applications you have in Wine's "program files" folder (if you have no idea what I'm talking about, you most likely have nothing to back up) and then remove ~/.wine with this command:
Code: [Select]
rm -rf ~/.wine
On the next time you try to run a Windows program with Wine, a fresh copy of the ~/.wine folder will be recreated for you.
Logged
"Frankly, if you're hanging out with people who tell you to use v.begin() instead of &v[0], you need to rethink your social circle."
    Scott Meyers, Effective STL

I've written bash scripts to make using DF easier under Linux!

Dave1004

  • Bay Watcher
  • This is getting personal.
    • View Profile
Re: Rootkit on Ubuntu
« Reply #9 on: December 23, 2011, 11:22:32 pm »

I suppose you ran the exe file with Wine. If so, it most likely installed stuff into your ~/.wine folder (which is basically like Windows' C: drive). Be sure to back up any applications you have in Wine's "program files" folder (if you have no idea what I'm talking about, you most likely have nothing to back up) and then remove ~/.wine with this command:
Code: [Select]
rm -rf ~/.wine
On the next time you try to run a Windows program with Wine, a fresh copy of the ~/.wine folder will be recreated for you.

Right, I did that, thanks. It probably worked, I dunno...I'll keep an eye on my system. Is it possible for them to hijack my webcam? It's integrated into my laptop or somesuch...

Thanks for the help!
Logged


Hardcap of 200 MB/24 hours.

Fenrir

  • Bay Watcher
  • The Monstrous Wolf
    • View Profile
Re: Rootkit on Ubuntu
« Reply #10 on: December 23, 2011, 11:36:51 pm »

Is it possible for them to hijack my webcam? It's integrated into my laptop or somesuch...

Yes.
Logged

Hitty40

  • Bay Watcher
  • Poker face, motherfucker.
    • View Profile
Re: Rootkit on Ubuntu
« Reply #11 on: December 23, 2011, 11:42:14 pm »

Is it possible for them to hijack my webcam? It's integrated into my laptop or somesuch...

Yes.

But I believe it will only work when your laptop is on. Could put duct tape on it for now so then they can't see through.

But don't take what I said completely, I don't know much how webcams on laptops.
Logged
Ho Ho Ho! I'm going to be sticking economic stone so far up your stockings, you'll be coughing up gemstone windows!
Quote
You see, when the devil comes on to your forums and begins dropping F bombs and shouts 'GIVE ALL YOUR WOMEN!', he's in a happy mood.
Quote
if there's lots of g's and z's, it's gobbo. If you don't really recognize it, it's human. if it's called Urist, it's dwarf.

Fenrir

  • Bay Watcher
  • The Monstrous Wolf
    • View Profile
Re: Rootkit on Ubuntu
« Reply #12 on: December 23, 2011, 11:53:53 pm »

Is it possible for them to hijack my webcam? It's integrated into my laptop or somesuch...

Yes.

But I believe it will only work when your laptop is on.

Naturally. The camera does need power, and network connectivity is a prerequisite for remote hacking.

Of course, it is not very important unless you place something in front of the camera that could be used against you. I can not find the article right now, but one hacker blackmailed hundreds of teenage girls who happened to leave their computers running while they were undressing — so refrain from being nude in front of it, and you should be safe.
Logged

DrKillPatient

  • Bay Watcher
  • The yak falls infinitely
    • View Profile
Re: Rootkit on Ubuntu
« Reply #13 on: December 24, 2011, 12:02:57 am »

Looking around the 'net, it appears Omeglespy is a cross-platform java application (if their site is to be trusted, anyway). If it is indeed such, you might want to try a scan with ClamAV. That picks up on trojans/rootkits/etc quite well, even if they're for a different OS (mainly Windows).

EDIT: Also, it's more likely a trojan (lies low and monitors activity) than a rootkit (hides malicious applications' processes and enables heightened privileges for them). Compared to, say, MSDOS-based operating systems, UNIX variants make it incredibly hard to gain root access unless the user has no idea what he's doing and enters his root password where he shouldn't, or uses a generic password/no password at all. If you've got a silly root password like "root" or something, change it now-- preferably to one you don't use elsewhere.
« Last Edit: December 24, 2011, 12:08:25 am by DrKillPatient »
Logged
"Frankly, if you're hanging out with people who tell you to use v.begin() instead of &v[0], you need to rethink your social circle."
    Scott Meyers, Effective STL

I've written bash scripts to make using DF easier under Linux!

Dave1004

  • Bay Watcher
  • This is getting personal.
    • View Profile
Re: Rootkit on Ubuntu
« Reply #14 on: December 24, 2011, 12:43:58 pm »

Looking around the 'net, it appears Omeglespy is a cross-platform java application (if their site is to be trusted, anyway). If it is indeed such, you might want to try a scan with ClamAV. That picks up on trojans/rootkits/etc quite well, even if they're for a different OS (mainly Windows).

EDIT: Also, it's more likely a trojan (lies low and monitors activity) than a rootkit (hides malicious applications' processes and enables heightened privileges for them). Compared to, say, MSDOS-based operating systems, UNIX variants make it incredibly hard to gain root access unless the user has no idea what he's doing and enters his root password where he shouldn't, or uses a generic password/no password at all. If you've got a silly root password like "root" or something, change it now-- preferably to one you don't use elsewhere.

Right...My root password is a combination of letters and numbers, for 10 in total. Should be decent. You're right, this may be a trojan...I scanned with both RKhunter and Chkrootkit, and they found nothing. I just did a scan with ClamAV, but...It found nothing as well? I don't understand. Thanks for all the help, mate!

Is it possible for them to hijack my webcam? It's integrated into my laptop or somesuch...

Yes.

But I believe it will only work when your laptop is on.

Naturally. The camera does need power, and network connectivity is a prerequisite for remote hacking.

Of course, it is not very important unless you place something in front of the camera that could be used against you. I can not find the article right now, but one hacker blackmailed hundreds of teenage girls who happened to leave their computers running while they were undressing — so refrain from being nude in front of it, and you should be safe.

Eeurgh. I've put some electrical tape over it, so...I should be fine. Luckily, I don't dress in-front on my laptop, so...Aye. Man, technology is bloody scary! Ugh. Then again, it is my fault that I got the...Whatever it is. Sigh...
Logged


Hardcap of 200 MB/24 hours.
Pages: [1] 2