LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-24-2021, 03:23 PM   #1
whois1230
Member
 
Registered: Sep 2018
Posts: 214

Rep: Reputation: Disabled
Ubuntu Remote Access Trojan


Hello, my laptop is misbehaving and I suspect that I am dealing with a Remote Access Trojan. For example I am browsing in Google Chrome and the browser closes itself without me clicking anything. A symbol appears, which shows my touchpad is disabled, without me clicking anything. I was deleting some files on my USB flash drive and all of a sudden my mouse cursor slows down and starts moving randomly. I have Ubuntu 18.04 Desktop. I installed ClamAV, updated to the latest version and scanned and it found nothing. I changed my router's password, as well as the Wi-Fi network's password. I am using KeePassX as a password manager, where I store all of my passwords. I would appreciate some help with this issue, as I have no experience in removing malware from Linux.
 
Old 03-24-2021, 04:16 PM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,745

Rep: Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982
Quote:
Originally Posted by whois1230 View Post
Hello, my laptop is misbehaving and I suspect that I am dealing with a Remote Access Trojan. For example I am browsing in Google Chrome and the browser closes itself without me clicking anything. A symbol appears, which shows my touchpad is disabled, without me clicking anything. I was deleting some files on my USB flash drive and all of a sudden my mouse cursor slows down and starts moving randomly. I have Ubuntu 18.04 Desktop. I installed ClamAV, updated to the latest version and scanned and it found nothing. I changed my router's password, as well as the Wi-Fi network's password. I am using KeePassX as a password manager, where I store all of my passwords. I would appreciate some help with this issue, as I have no experience in removing malware from Linux.
So what makes you think you've got some 'trojan' program, as opposed to (what sounds like) a flaky touchpad?

Beyond that, you claim to have little knowledge of systems and Linux...yet have a system booting FOUR operating systems, one of which being Kali, from just a month ago?
https://www.linuxquestions.org/quest...ut-4175690541/

We'll be happy to try to help you, but based on what you posted what do you think we can tell you? You provide no logs, messages, and tell us anti-virus came back clean. ClamAV is probably the 'standard' solution..and if you want to scan for rootkits, rkhunter is available in your software repository, and has ample documentation.
 
2 members found this post helpful.
Old 03-24-2021, 06:44 PM   #3
OlgaM
Member
 
Registered: Mar 2019
Distribution: Debian Bullseye
Posts: 65

Rep: Reputation: Disabled
Check if you have remote login session and close it. More info here
 
1 members found this post helpful.
Old 03-25-2021, 12:29 AM   #4
Linux_Kidd
Member
 
Registered: Jan 2006
Location: USA
Posts: 737

Rep: Reputation: 78
suspected C2?
this happens only when connected to internet? does the random weird stuff stop when you down the iface that uses internet?

does tcpdump show odd traffic?

why do say 'trojan' ? did you install something shady/questionable? how would a trojan get onto your system?
 
1 members found this post helpful.
Old 03-25-2021, 05:30 AM   #5
whois1230
Member
 
Registered: Sep 2018
Posts: 214

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by TB0ne View Post
So what makes you think you've got some 'trojan' program, as opposed to (what sounds like) a flaky touchpad?

Beyond that, you claim to have little knowledge of systems and Linux...yet have a system booting FOUR operating systems, one of which being Kali, from just a month ago?
https://www.linuxquestions.org/quest...ut-4175690541/

We'll be happy to try to help you, but based on what you posted what do you think we can tell you? You provide no logs, messages, and tell us anti-virus came back clean. ClamAV is probably the 'standard' solution..and if you want to scan for rootkits, rkhunter is available in your software repository, and has ample documentation.
I am trying to install rkhunter using this guide https://kifarunix.com/how-to-install...-ubuntu-18-04/ but I am running into an error, when I try to modify MIRRORS_MODE
Attached Thumbnails
Click image for larger version

Name:	rkhunter error.png
Views:	26
Size:	190.7 KB
ID:	35915  
 
Old 03-25-2021, 07:29 AM   #6
leclerc78
Member
 
Registered: Dec 2020
Posts: 169

Rep: Reputation: Disabled
I also have problem with Chrome recently.
I use an Acer C720 Chromebook, have to do a factory reset a few times the last two weeks.
 
1 members found this post helpful.
Old 03-25-2021, 07:50 AM   #7
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,745

Rep: Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982
Quote:
Originally Posted by whois1230 View Post
I am trying to install rkhunter using this guide https://kifarunix.com/how-to-install...-ubuntu-18-04/ but I am running into an error, when I try to modify MIRRORS_MODE
Please go back and read/think about what you posted. You're trying to edit a file...the editor is telling you there's already a .swp file. Typically meaning the editor was closed badly last time. And you also don't show us what you're typing in to get that error. Instead of posting screen-shots, copy and past the text.

And AGAIN, as myself and linux_kidd asked...what makes you think it's a trojan, rather than a flaky touchpad, which seems much more likely??
 
1 members found this post helpful.
Old 03-25-2021, 02:17 PM   #8
whois1230
Member
 
Registered: Sep 2018
Posts: 214

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by OlgaM View Post
Check if you have remote login session and close it. More info here
Code:
user@Lenovo-ideapad-110-17IKB:~$ tty
/dev/pts/0
user@Lenovo-ideapad-110-17IKB:~$ ps -fu user
UID        PID  PPID  C STIME TTY          TIME CMD
user      1682     1  0 19:51 ?        00:00:00 /lib/systemd/systemd --user
user      1683  1682  0 19:51 ?        00:00:00 (sd-pam)
user      1696     1  0 19:51 ?        00:00:00 /usr/bin/gnome-keyring-daemon --
user      1700  1678  0 19:51 tty2     00:00:00 /usr/lib/gdm3/gdm-x-session --ru
user      1702  1700  4 19:51 tty2     00:01:05 /usr/lib/xorg/Xorg vt2 -displayf
user      1727  1682  0 19:52 ?        00:00:00 /usr/bin/dbus-daemon --session -
user      1730  1700  0 19:52 tty2     00:00:00 /usr/lib/gnome-session/gnome-ses
user      1807  1730  0 19:52 ?        00:00:00 /usr/bin/ssh-agent /usr/bin/im-l
user      1813  1682  0 19:52 ?        00:00:00 /usr/lib/at-spi2-core/at-spi-bus
user      1818  1813  0 19:52 ?        00:00:00 /usr/bin/dbus-daemon --config-fi
user      1821  1682  0 19:52 ?        00:00:00 /usr/lib/at-spi2-core/at-spi2-re
user      1841  1730  5 19:52 tty2     00:01:19 /usr/bin/gnome-shell
user      1851  1682  0 19:52 ?        00:00:00 /usr/lib/gvfs/gvfsd
user      1856  1682  0 19:52 ?        00:00:00 /usr/lib/gvfs/gvfsd-fuse /run/us
user      1860     1  7 19:52 ?        00:01:40 /usr/bin/pulseaudio --start --lo
user      1884  1841  0 19:52 tty2     00:00:00 ibus-daemon --xim --panel disabl
user      1888  1884  0 19:52 tty2     00:00:00 /usr/lib/ibus/ibus-dconf
user      1890     1  0 19:52 tty2     00:00:00 /usr/lib/ibus/ibus-x11 --kill-da
user      1892  1682  0 19:52 ?        00:00:00 /usr/lib/ibus/ibus-portal
user      1903  1682  0 19:52 ?        00:00:00 /usr/libexec/xdg-permission-stor
user      1908  1682  0 19:52 ?        00:00:00 /usr/lib/gnome-shell/gnome-shell
user      1917  1682  0 19:52 ?        00:00:00 /usr/lib/dconf/dconf-service
user      1921  1682  0 19:52 ?        00:00:00 /usr/lib/gvfs/gvfs-udisks2-volum
user      1925  1682  0 19:52 ?        00:00:00 /usr/lib/gvfs/gvfs-goa-volume-mo
user      1929  1682  0 19:52 ?        00:00:00 /usr/lib/gnome-online-accounts/g
user      1933  1682  0 19:52 ?        00:00:00 /usr/lib/evolution/evolution-sou
user      1946  1682  0 19:52 ?        00:00:00 /usr/lib/gnome-online-accounts/g
user      1951  1682  0 19:52 ?        00:00:00 /usr/lib/gvfs/gvfs-gphoto2-volum
user      1955  1682  0 19:52 ?        00:00:00 /usr/lib/gvfs/gvfs-mtp-volume-mo
user      1959  1682  0 19:52 ?        00:00:00 /usr/lib/gvfs/gvfs-afc-volume-mo
user      1964  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      1965  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      1968  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      1972  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      1975  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      1978  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      1980  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      1986  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      1989  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      1995  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      1996  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      2002  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      2007  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      2009  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      2011  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      2014  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      2018  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      2047     1  0 19:52 tty2     00:00:00 /usr/lib/gnome-settings-daemon/g
user      2064  1730  0 19:52 tty2     00:00:00 /usr/bin/python3 /usr/bin/redshi
user      2074  1730  0 19:52 tty2     00:00:03 nautilus-desktop
user      2082  1730  0 19:52 tty2     00:00:00 /usr/lib/gnome-disk-utility/gsd-
user      2093  1682  0 19:52 ?        00:00:00 /usr/lib/evolution/evolution-cal
user      2094  2064  0 19:52 tty2     00:00:00 /usr/bin/redshift -v
user      2107  1884  0 19:52 tty2     00:00:00 /usr/lib/ibus/ibus-engine-simple
user      2116  1851  0 19:52 ?        00:00:00 /usr/lib/gvfs/gvfsd-trash --spaw
user      2135  2093  0 19:52 ?        00:00:00 /usr/lib/evolution/evolution-cal
user      2149  1682  0 19:52 ?        00:00:00 /usr/lib/evolution/evolution-add
user      2160  2149  0 19:52 ?        00:00:00 /usr/lib/evolution/evolution-add
user      2186  1682  0 19:52 ?        00:00:00 /usr/lib/gvfs/gvfsd-metadata
user      2254  1730  0 19:53 tty2     00:00:05 /usr/bin/gnome-software --gappli
user      2256  1730  0 19:53 tty2     00:00:00 update-notifier
user      2444  1730  0 19:54 tty2     00:00:00 /usr/lib/deja-dup/deja-dup-monit
user      2526     1  6 20:03 tty2     00:00:47 /opt/google/chrome/chrome
user      2532  2526  0 20:03 tty2     00:00:00 cat
user      2533  2526  0 20:03 tty2     00:00:00 cat
user      2536  2526  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2537  2526  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2538  2537  0 20:03 tty2     00:00:00 /opt/google/chrome/nacl_helper
user      2541  2537  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2562  2536  3 20:03 tty2     00:00:22 /opt/google/chrome/chrome --type
user      2567  2526  0 20:03 tty2     00:00:04 /opt/google/chrome/chrome --type
user      2589  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2606  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2608  2541  1 20:03 tty2     00:00:10 /opt/google/chrome/chrome --type
user      2621  2541  0 20:03 tty2     00:00:03 /opt/google/chrome/chrome --type
user      2631  2541  1 20:03 tty2     00:00:07 /opt/google/chrome/chrome --type
user      2632  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2754  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2773  2541  0 20:03 tty2     00:00:01 /opt/google/chrome/chrome --type
user      2793  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2798  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2800  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2811  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2815  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2819  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2831  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2834  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      2843  2541  0 20:03 tty2     00:00:00 /opt/google/chrome/chrome --type
user      3121  1682  0 20:10 ?        00:00:00 /usr/bin/zeitgeist-daemon
user      3133  1682  0 20:10 ?        00:00:00 /usr/lib/zeitgeist/zeitgeist/zei
user      3372  2526  0 20:12 tty2     00:00:00 /opt/google/chrome/chrome --type
user      3546  2541  4 20:13 tty2     00:00:06 /opt/google/chrome/chrome --type
user      3585  2541  4 20:13 tty2     00:00:05 /opt/google/chrome/chrome --type
user      3601  2541  0 20:14 tty2     00:00:00 /opt/google/chrome/chrome --type
user      3647  1682  2 20:15 ?        00:00:00 /usr/lib/gnome-terminal/gnome-te
user      3657  3647  0 20:15 pts/0    00:00:00 bash
user      3669  3657  0 20:15 pts/0    00:00:00 ps -fu user
user@Lenovo-ideapad-110-17IKB:~$
 
Old 03-25-2021, 02:29 PM   #9
whois1230
Member
 
Registered: Sep 2018
Posts: 214

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by Linux_Kidd View Post
suspected C2?
this happens only when connected to internet? does the random weird stuff stop when you down the iface that uses internet?

does tcpdump show odd traffic?

why do say 'trojan' ? did you install something shady/questionable? how would a trojan get onto your system?
It happened when I was connected to the internet and shortly after I disconnected, the cursor was still moving randomly. I use an external mouse and keyboard, so I find this behaviour strange. I'm not using the laptop's own keyboard and touchpad. I had only installed Proton VPN recently. I believe it's reputable.
Code:
user@Lenovo-ideapad-110-17IKB:~$ sudo tcpdump -i any -c5 -nn
[sudo] password for user: 
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on any, link-type LINUX_SLL (Linux cooked), capture size 262144 bytes
20:27:46.287518 IP6 fe80::7254:25ff:fe74:740e > ff02::1: ICMP6, router advertisement, length 104
20:27:46.299575 IP6 fe80::dc21:c6db:9ebc:a59c > ff02::16: HBH ICMP6, multicast listener report v2, 5 group record(s), length 108
20:27:46.403876 ARP, Request who-has 192.168.0.1 tell 192.168.0.5, length 28
20:27:46.407571 ARP, Reply 192.168.0.1 is-at 70:54:25:74:74:0e, length 28
20:27:46.486757 IP6 fe80::7254:25ff:fe74:740e > 2a02:908:1a5:e9a0::da55: ICMP6, neighbor solicitation, who has 2a02:908:1a5:e9a0::da55, length 32
5 packets captured
6 packets received by filter
0 packets dropped by kernel
 
Old 03-25-2021, 02:30 PM   #10
whois1230
Member
 
Registered: Sep 2018
Posts: 214

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by leclerc78 View Post
I also have problem with Chrome recently.
I use an Acer C720 Chromebook, have to do a factory reset a few times the last two weeks.
Chromebook means it's running Chrome OS? From what I know it's similar to Android, could be wrong though.
 
Old 03-25-2021, 02:38 PM   #11
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,745

Rep: Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982
Quote:
Originally Posted by whois1230 View Post
It happened when I was connected to the internet and shortly after I disconnected, the cursor was still moving randomly. I use an external mouse and keyboard, so I find this behaviour strange. I'm not using the laptop's own keyboard and touchpad. I had only installed Proton VPN recently. I believe it's reputable.
Code:
user@Lenovo-ideapad-110-17IKB:~$ sudo tcpdump -i any -c5 -nn
[sudo] password for user: 
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on any, link-type LINUX_SLL (Linux cooked), capture size 262144 bytes
20:27:46.287518 IP6 fe80::7254:25ff:fe74:740e > ff02::1: ICMP6, router advertisement, length 104
20:27:46.299575 IP6 fe80::dc21:c6db:9ebc:a59c > ff02::16: HBH ICMP6, multicast listener report v2, 5 group record(s), length 108
20:27:46.403876 ARP, Request who-has 192.168.0.1 tell 192.168.0.5, length 28
20:27:46.407571 ARP, Reply 192.168.0.1 is-at 70:54:25:74:74:0e, length 28
20:27:46.486757 IP6 fe80::7254:25ff:fe74:740e > 2a02:908:1a5:e9a0::da55: ICMP6, neighbor solicitation, who has 2a02:908:1a5:e9a0::da55, length 32
5 packets captured
6 packets received by filter
0 packets dropped by kernel
Again: the only 'symptom' points to a flaky touchpad. Whether you're using it or not doesn't mean its not ACTIVE and doing something....if you pressed a key on your laptop keyboard, letters will come up on the screen right?? Same with the touchpad.

Sorry, nothing you're describing or providing will let anyone offer anything. You still haven't addressed the messages for rkhunter. The only thing that I'd disable is the zeitgeist system in Ubuntu, but even that won't do what you're claiming.
 
1 members found this post helpful.
Old 03-25-2021, 02:40 PM   #12
whois1230
Member
 
Registered: Sep 2018
Posts: 214

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by TB0ne View Post
Please go back and read/think about what you posted. You're trying to edit a file...the editor is telling you there's already a .swp file. Typically meaning the editor was closed badly last time. And you also don't show us what you're typing in to get that error. Instead of posting screen-shots, copy and past the text.

And AGAIN, as myself and linux_kidd asked...what makes you think it's a trojan, rather than a flaky touchpad, which seems much more likely??
https://success.trendmicro.com/solut...based-products

So I ran
Code:
sudo apt install rkhunter -y
and that went well. I then ran
Code:
vim /etc/rkhunter.conf
and I pressed "/" like in the guide above. Then I searched for UPDATE_MIRRORS and the value is set to 1, how the guide said it should be. After that I searched for MIRRORS_MODE in order to set the value to 0 and I got this:
Code:
-- INSERT -- W10: Warning: Changing a readonly file
E325: ATTENTION
Found a swap file by the name "/etc/.rkhunter.conf.swp"
          owned by: root   dated: Mon Mar  8 12:53:50 2021
         file name: /etc/rkhunter.conf
          modified: YES
         user name: root   host name: Lenovo-ideapad-110-17IKB
        process ID: 30094
While opening file "/etc/rkhunter.conf"
             dated: Mon Mar  8 12:48:04 2021

(1) Another program may be editing the same file.  If this is the case,
    be careful not to end up with two different instances of the same
    file when making changes.  Quit, or continue with caution.
(2) An edit session for this file crashed.
    If this is the case, use ":recover" or "vim -r /etc/rkhunter.conf"
    to recover the changes (see ":help recovery").
    to recover the changes (see ":help recovery").
    If you did this already, delete the swap file "/etc/.rkhunter.conf.swp"
    to avoid this message.

E325: ATTENTION
Found a swap file by the name "/var/tmp/rkhunter.conf.swp"
-- More --
 
Old 03-25-2021, 03:16 PM   #13
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,745

Rep: Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982Reputation: 7982
Quote:
Originally Posted by whois1230 View Post
https://success.trendmicro.com/solut...based-products

So I ran
Code:
sudo apt install rkhunter -y
and that went well. I then ran
Code:
vim /etc/rkhunter.conf
and I pressed "/" like in the guide above. Then I searched for UPDATE_MIRRORS and the value is set to 1, how the guide said it should be. After that I searched for MIRRORS_MODE in order to set the value to 0 and I got this:
Code:
-- INSERT -- W10: Warning: Changing a readonly file
E325: ATTENTION
Found a swap file by the name "/etc/.rkhunter.conf.swp"
          owned by: root   dated: Mon Mar  8 12:53:50 2021
         file name: /etc/rkhunter.conf
          modified: YES
         user name: root   host name: Lenovo-ideapad-110-17IKB
        process ID: 30094
While opening file "/etc/rkhunter.conf"
             dated: Mon Mar  8 12:48:04 2021

(1) Another program may be editing the same file.  If this is the case,
    be careful not to end up with two different instances of the same
    file when making changes.  Quit, or continue with caution.
(2) An edit session for this file crashed.
    If this is the case, use ":recover" or "vim -r /etc/rkhunter.conf"
    to recover the changes (see ":help recovery").
    to recover the changes (see ":help recovery").
    If you did this already, delete the swap file "/etc/.rkhunter.conf.swp"
    to avoid this message.

E325: ATTENTION
Found a swap file by the name "/var/tmp/rkhunter.conf.swp"
-- More --
AGAIN: this is because you either closed the file incorrectly the first time, or don't have permissions to edit it. Did you read/understand the message??? There is ABSOLUTELY NOTHING nefarious with what you posted, at all. Unless you edit the file with root/sudo rights, you can't....unless you save the file correctly, the .swp file for vim will be there...and it even TELLS YOU how to fix that message...did you read/understand those lines??
 
1 members found this post helpful.
Old 03-25-2021, 03:24 PM   #14
Emerson
LQ Sage
 
Registered: Nov 2004
Location: Saint Amant, Acadiana
Distribution: Gentoo ~amd64
Posts: 7,665

Rep: Reputation: Disabled
And, if you are not using the touchpad disable it with 'xinput', see if "trojan" goes away.
 
1 members found this post helpful.
Old 03-25-2021, 03:37 PM   #15
Linux_Kidd
Member
 
Registered: Jan 2006
Location: USA
Posts: 737

Rep: Reputation: 78
Quote:
Originally Posted by whois1230 View Post
It happened when I was connected to the internet and shortly after I disconnected, the cursor was still moving randomly. I use an external mouse and keyboard, so I find this behaviour strange. I'm not using the laptop's own keyboard and touchpad. I had only installed Proton VPN recently. I believe it's reputable.
Code:
user@Lenovo-ideapad-110-17IKB:~$ sudo tcpdump -i any -c5 -nn
[sudo] password for user: 
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on any, link-type LINUX_SLL (Linux cooked), capture size 262144 bytes
20:27:46.287518 IP6 fe80::7254:25ff:fe74:740e > ff02::1: ICMP6, router advertisement, length 104
20:27:46.299575 IP6 fe80::dc21:c6db:9ebc:a59c > ff02::16: HBH ICMP6, multicast listener report v2, 5 group record(s), length 108
20:27:46.403876 ARP, Request who-has 192.168.0.1 tell 192.168.0.5, length 28
20:27:46.407571 ARP, Reply 192.168.0.1 is-at 70:54:25:74:74:0e, length 28
20:27:46.486757 IP6 fe80::7254:25ff:fe74:740e > 2a02:908:1a5:e9a0::da55: ICMP6, neighbor solicitation, who has 2a02:908:1a5:e9a0::da55, length 32
5 packets captured
6 packets received by filter
0 packets dropped by kernel
Probably have a stuck key either on laptop or your ext stuff. Is the ext stuff wireless or wired?
Boot it with a Slax liveCD, does the random crap still happen (w/ and w/o your ext stuff)? <-- there you will have your answer as to where to look next.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Where to look for trojan file in ubuntu infected server? Ketmen Linux - Newbie 21 10-15-2020 01:04 PM
RAT infected files (remote access tool - remote access trojan) - corrupt? jettjett Linux - Newbie 16 03-20-2018 10:07 PM
Ubuntu 8.04 and the UPS Trojan AllanB Linux - Security 2 03-27-2009 08:57 PM
Help..... !! a Trojan horse raz Linux - Security 1 04-27-2001 04:19 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration