Announcement

Collapse
No announcement yet.

Just Got Hit by Malware?

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Just Got Hit by Malware?

    How do I get that crap out of Kubuntu? Basically it said there was an issue with Linux / Chrome and that it had disable me from quitting Chrome for computer safety reasons. I couldn't get away from it's popup window or change tabs. I finally managed to get away from it however I feel I'm now infected with this garbage. I got hit when I clicked on a lawnmower belt replacement link in google search. Adbloc Plus failed me. Perhaps it didn't consider it an ad. Here's a screen shot of the garbage from my history:

    Last edited by logan01; Jun 13, 2016, 09:02 PM.
    Kubuntu 14.04 / KDE 4.13.3 / GRUB Version: 0.97-29ubuntu66
    HP15 -
    -f033wm Laptop / CPU: Intel / GPU: Intel Corporation Atom Processor / RAM: 8GB / Hard Drive: 1 each / Seagate / Optical Drive: HP DVDRW GUB0N / Windows 10


    #2
    I heard about this chrome vulnerability recently and it seems pretty bad and it likely was not the ad that triggered it... sorry I don't have an answer to help clean up the mess.
    Resort to a system backup maybe? Maybe reinstall... but act quickly they will potentially still have access to your system.

    Chrome is not the be all end all like many are choosing to believe.
    Kubuntu 18.04 on AMD

    Comment


      #3
      Depending on the attack you may, and i stress may, be able to get away with removing the Chrome configuration directory (~/.chrome or ~/.chromium perhaps) but if you do suspect a full breech then a re-install or restore if you have an image prior to the breech is the best way to go. I don't know which vulnerability @otisklt is referring so so it is difficult to be more precise.

      In either case, I would recommend installing firejail (sudo apt install firejail) and using it to lock down at least all of your web facing software.
      If you're sitting wondering,
      Which Batman is the best,
      There's only one true answer my friend,
      It's Adam Bloody West!

      Comment


        #4
        You Kubuntu installation is NOT infected and neither is Chrome. What happened is that you encountered a web page that did not follow HTML coding convention. It presented HTML frames that were missing the usual back buttons and tabs, and re-programmed the "X" to do nothing, making it next to impossible for the average user to move off of the page or close the browser. Meanwhile, it displays a bogus claim about your browser or OS being infected, displays a phone number which it claims to be a Google (or Microsoft) support number. It's not, of course, and if you call them they'll lead you into downloading and installing a back door, then ask for your CC# to bill you. Then they'll peruse your PC for financial gain.

        To close the browser press the Ctl + Alt + ESC keys at the same time. A skull and crossbones will appear in place of the mouse pointer. Move it to hover over the browser, if it is not already over the browser, and press the Left Mouse key. That will close the browser. When you open the browser it should be on your home page. If it returns to the bad web page you may have set the browser to do that. If not, delete the browser config file and then open the browser and reconfigure it.
        Last edited by GreyGeek; Jun 14, 2016, 07:02 AM.
        "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
        – John F. Kennedy, February 26, 1962.

        Comment


          #5
          Originally posted by GreyGeek View Post
          You Kubuntu installation is NOT infected and neither is Chrome. What happened is that you encountered a web page that did not follow HTML coding convention. It presented HTML frames that were missing the usual back buttons and tabs, and re-programmed the "X" to do nothing, making it next to impossible for the average user to move off of the page or close the browser. Meanwhile, it displays a bogus claim about your browser or OS being infected, displays a phone number which it claims to be a Google (or Microsoft) support number. It's not, of course, and if you call them they'll lead you into downloading and installing a back door, then ask for your CC# to bill you. Then they'll peruse your PC for financial gain.

          To close the browser press the Ctl + Alt + ESC keys at the same time. A skull and crossbones will appear in place of the mouse pointer. Move it to hover over the browser, if it is not already over the browser, and press the Left Mouse key. That will close the browser. When you open the browser it should be on your home page. If it returns to the bad web page you may have set the browser to do that. If not, delete the browser config file and then open the browser and reconfigure it.
          Oh I like that. Greatly appreciate it. Thank you all for your replies.
          Kubuntu 14.04 / KDE 4.13.3 / GRUB Version: 0.97-29ubuntu66
          HP15 -
          -f033wm Laptop / CPU: Intel / GPU: Intel Corporation Atom Processor / RAM: 8GB / Hard Drive: 1 each / Seagate / Optical Drive: HP DVDRW GUB0N / Windows 10

          Comment


            #6
            Originally posted by GreyGeek View Post
            press the Ctl + Alt + ESC keys at the same time. A skull and crossbones will appear in place of the mouse pointer.
            That is so much easier than opening a terminal and running a killall command.
            If you're sitting wondering,
            Which Batman is the best,
            There's only one true answer my friend,
            It's Adam Bloody West!

            Comment


              #7
              To close the browser press the Ctl + Alt + ESC keys at the same time. A skull and crossbones will appear in place of the mouse pointer. Move it to hover over the browser, if it is not already over the browser, and press the Left Mouse key. That will close the browser.
              Neat! Many thanks, GreyGeek.
              Lenovo T460s

              Comment


                #8
                Yep, pretty much as GreyGeek stated. The page I landed on had huge red warning letters saying something about a conflict between Linux and Chrome. A small popup appeared speaking to I need to call their help line and standing by were trained Microsoft technicians, etc. Chrome has been disabled from closing for computer safety reasons, blah, blah, blah. I later read that when you call and give them 200.00 w/ your credit card that perhaps the issue goes away or maybe not. GreyGeek nailed it.
                Kubuntu 14.04 / KDE 4.13.3 / GRUB Version: 0.97-29ubuntu66
                HP15 -
                -f033wm Laptop / CPU: Intel / GPU: Intel Corporation Atom Processor / RAM: 8GB / Hard Drive: 1 each / Seagate / Optical Drive: HP DVDRW GUB0N / Windows 10

                Comment


                  #9
                  Originally posted by logan01 View Post
                  Yep, pretty much as GreyGeek stated. The page I landed on had huge red warning letters saying something about a conflict between Linux and Chrome. A small popup appeared speaking to I need to call their help line and standing by were trained Microsoft technicians, etc. Chrome has been disabled from closing for computer safety reasons, blah, blah, blah. I later read that when you call and give them 200.00 w/ your credit card that perhaps the issue goes away or maybe not. GreyGeek nailed it.
                  Do you run plugins such as noscript? At the cost of having to allow javascripts you need to run, it helps protect from things like that. I recommend firejail. A default setup is as easy as modifying you menu item to say "firejail chrome" instead of just chrome. I'm in the process of learning to lock down all my internet facing applications so they don't even know the rest of my disk exists. It's in the 16.04 repository and available on the website as a couple of deb files.

                  I keep getting phone calls from the Microsoft Monitoring Center and I consider it my civic duty to keep them entertained for as long as possible.

                  Multi layer security is the only way to go these days and firejail seems so much easier to set up than the brain melter that is selinux.
                  If you're sitting wondering,
                  Which Batman is the best,
                  There's only one true answer my friend,
                  It's Adam Bloody West!

                  Comment


                    #10
                    These are my Chrome plugins if that's what you're asking. How do I do the firejail deal?

                    Kubuntu 14.04 / KDE 4.13.3 / GRUB Version: 0.97-29ubuntu66
                    HP15 -
                    -f033wm Laptop / CPU: Intel / GPU: Intel Corporation Atom Processor / RAM: 8GB / Hard Drive: 1 each / Seagate / Optical Drive: HP DVDRW GUB0N / Windows 10

                    Comment


                      #11
                      http://blog.talosintel.com/2016/06/pdfium.html
                      Chrome on linux is not immune.

                      I may have overestimated what OP experienced but I want others to not be too overconfident in supposed safe software.
                      Last edited by otisklt; Jun 14, 2016, 08:15 PM.
                      Kubuntu 18.04 on AMD

                      Comment


                        #12
                        Originally posted by otisklt View Post
                        http://blog.talosintel.com/2016/06/pdfium.html
                        Chrome on linux is not immune.

                        I may have overestimated what OP experienced but I want others to not be too overconfident in supposed safe software.
                        Thanks for that though it's Greek to me. Another one of my dumb questions. Being that it is known, is there not a blocker / detector / remover of that?
                        Kubuntu 14.04 / KDE 4.13.3 / GRUB Version: 0.97-29ubuntu66
                        HP15 -
                        -f033wm Laptop / CPU: Intel / GPU: Intel Corporation Atom Processor / RAM: 8GB / Hard Drive: 1 each / Seagate / Optical Drive: HP DVDRW GUB0N / Windows 10

                        Comment


                          #13
                          It's not as good as noscript on Firefoxbut it nearly is: script safe also add ublock origin. If it's as good as the Firefox version then it's gonna be brilliant.

                          As for firejail, you install it by on 16.04 by running sudo apt install firejail If you're running an older version of Kubuntu then you'll have to grab the deb file from their web site here. Basic usage is to run firejail program-name from the command line or to edit the program's menu entry to be firejail program-name.
                          If you're sitting wondering,
                          Which Batman is the best,
                          There's only one true answer my friend,
                          It's Adam Bloody West!

                          Comment


                            #14
                            Originally posted by logan01 View Post
                            Thanks for that though it's Greek to me. Another one of my dumb questions. Being that it is known, is there not a blocker / detector / remover of that?
                            Yeah, if you are running Chrome Stable 51.0.2704.63 or later then it has been fixed.
                            If you're sitting wondering,
                            Which Batman is the best,
                            There's only one true answer my friend,
                            It's Adam Bloody West!

                            Comment


                              #15
                              Originally posted by elijathegold View Post
                              Yeah, if you are running Chrome Stable 51.0.2704.63 or later then it has been fixed.
                              Had another issue (Firefox) https://www.kubuntuforums.net/showth...irefox-Anomaly

                              Qqmike suggested your remedy post #48 in https://www.kubuntuforums.net/showth...535#post387535 It worked. Thanks.
                              Last edited by logan01; Jun 15, 2016, 08:16 AM.
                              Kubuntu 14.04 / KDE 4.13.3 / GRUB Version: 0.97-29ubuntu66
                              HP15 -
                              -f033wm Laptop / CPU: Intel / GPU: Intel Corporation Atom Processor / RAM: 8GB / Hard Drive: 1 each / Seagate / Optical Drive: HP DVDRW GUB0N / Windows 10

                              Comment

                              Working...
                              X