Fedora 16/Linux virus?

asked 2011-12-23 10:47:15 -0500

bdicejr gravatar image

updated 2014-09-28 15:47:00 -0500

mether gravatar image

I was under the impression linux systems could not get a virus. Lucky me, I got one! First I noticed all the media apps on my machine, Only one of which i ever used were recently used. I went to the file tree and clicked on a few folders and noticed EVERY ONE of my folders and files had a "desktop" link in it.I tried to delete the link or send it to the trash can but that just made things worse because it would replicate two more. I also noticed my mail accounts had been set up and my entire file system was replicating, migrating to mail accouunt and beeing mailed somwhere. By the way, I use an on line mail service so I didnt set up any mail service on my machine. Somebody or something did. I think could not erase any of my browser history. I think it came from a rougue adobe pop up I clicked on. Most of the problems seemed to centered around my Adobe flash player. I opened the program file and it had a huge amount of my info in it. From every site I visited to were my pass words were used. (unless thats normal) to when i logged on and off my machine. I ended up formatting my hsrd drive and reinstalling fedora this morning. Even that was rough. It took me four tries till I finally got it to reinstall properly. Has anyone else had this type of plroblem or heard of anyone that has? I read up on this clickjack attack and insalled ghostery and no script. they seem to be the best tools for avoiding this in the future. Im new to the computer world and would be open to any other sugestions on how to steer clear of this hacker/virus bullsh**!

answered 2011-12-23 11:36:41 -0500

I understand you are furstrated, but ...

First, I do not know any credible source that claims Linux is immune to crackers. In Fedora selinux is used to help mitigate such things.

Second, forensics can be very complex and it comes down to who is more skilled, you or your intruder.

What services are you running ? ssh ? vnc ? ftp ?

See also

Third, your question is a "wall of text" without any actual information. What is in this Desktop file ?

I would file a bug report on this.

answered 2013-09-10 05:58:06 -0500

FranciscoD_ gravatar image

updated 2013-09-10 19:13:18 -0500

You did not have a virus, you got "hacked". No system is immune to hacking, specially if you leave your firewall down, ports open, and have stupid passwords like your own name. Also, the internet is strewn with pop ups that collect information on you, quite like the many many phishing mails that hit our mail boxes requesting your personal information. The system cannot do anything against these, it is the user that needs to be careful. Unfortunately, the data that you've lost cannot be gotten back.

  • Clean the drive, completely.
  • Install the latest available Fedora and all updates.
  • Keep SELinux and your firewall on
  • Only open ports in the firewall that you really need
  • Check your router, is the firewall there on?
  • Be careful what you click on the internet.

This is not a Fedora or Linux issue. You need to be more careful about what you do.

