LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Puppy (https://www.linuxquestions.org/questions/puppy-71/)
-   -   puppy linux tahr 64 bit non eufi russian virus (https://www.linuxquestions.org/questions/puppy-71/puppy-linux-tahr-64-bit-non-eufi-russian-virus-4175630929/)

mtdew3q 05-31-2018 07:04 PM

puppy linux tahr 64 bit non eufi russian virus
 
Hi-

Sorry... I made a typo UEFI.

The "russian" virus is back, and I found it in puppy linux. I downloaded puppylinux from the website. ClamAV turns up infected pscan, and there is no way to get it off my system.

I got a tip from the FBI via yahoo that I needed to reset my router. Upon resetting, I could not log back in with my default user and password when resetting with a paperclip.

Time warner couldn't get into my system too.

Who had the idea that every time you reset your router you wanted wifi blasting with an insecure password? I live in an apartment and don't trust anyone.

It is all very frustrating, and I'd like to hear where I can get puppy linux WITHOUT pnscan infected!

error:
cant remove file pnscan /initrd/pup_ro2/usr/local/bin/pnscan !

I tried joining puppy-linux forums the other day but didn't hear back after unable to register.

thx.-
J. McNamara
3rdshiftcoder

rokytnji 05-31-2018 08:17 PM

Ibiblio seemed to work OK for me. But that was then. I AM NOT a regular puppy user now.

https://distro.ibiblio.org/puppylinux/

rokytnji 05-31-2018 08:26 PM

I FORGOT to mention. I always md5sum check any linux isos I download. If one is not supplied at the download site. I do a internet search to find a md5sum checksum.

It keeps things like you just described from occurring. For me.

mtdew3q 05-31-2018 08:28 PM

Hi Rokytnji-

I will try to find out how to download from that mirror. I will fix this tomorrow. I am going to ditch this router. Timewarner said they aren't aware of any routers being infected. I talked to them last night. If I can get puppy linux hooked back up, I will let them know that it did get compromised.

thx.-
mtdew3q

mtdew3q 05-31-2018 08:29 PM

Yes, I did do md5sum. I use 2 other operating systems. I suspect it could be one of them. Maybe the router was compromised already when downloading puppy linux.

thx.

rokytnji 05-31-2018 08:31 PM

Here is a example of what I mean.

Code:

harry@biker:~
$ cd Isos
harry@biker:~/Isos
$ ls
antix_17  debian-chromebook  gallium  Hirens  PLOP  Pmagic_rar  Puppy
harry@biker:~/Isos
$ cd Puppy
harry@biker:~/Isos/Puppy
$ ls
Mac_Pen_630-Hu.iso  studio_4.iso
harry@biker:~/Isos/Puppy
$ md5sum studio_4.iso
bc3d1779798e20136e31107c5885c08b  studio_4.iso

See that long number that starts with letters bc3d1779

I internet search that number to make sure it matches the iso I downloaded.
That keeps me from getting a corrupted iso.

Edit: you type faster than I do. I see now you know what I mean.

mtdew3q 05-31-2018 08:43 PM

yes, i know. i do checksums always. i even do checksums on cygwin.

i use gpg etc.

i think maybe the router got hacked and they put that file on puppy.

i will find out when I get a new router.

I am not going to turn the other operating systems back on!

I guess I will format them.

thx.

mtdew3q 05-31-2018 08:44 PM

I will check back tomorrow later on. have to go on trip to buy new router in the big city close by.

then I will start over. i will report back.

thx.

removed001 05-12-2019 03:28 PM

Quote:

Originally Posted by mtdew3q (Post 5862000)
I will check back tomorrow later on. have to go on trip to buy new router in the big city close by.

then I will start over. i will report back.

thx.

Nothing reported yet. Probably solved without to mark?

If not solved, here's just a small hint:

Quote:

error:
cant remove file pnscan /initrd/pup_ro2/usr/local/bin/pnscan
If unable to remove that file could be caused by two different issues.

1. You can't remove anything from /initrd/pup_ro folders - since the 'ro' means 'read only'
2. The file isn't just existing.

Though, if you can see the file in /initrd/pup_ro2/usr/local/bin then definitely it IS inside the puppy_tahr_6.0.5.sfs. That would mean it was already there when creating the .sfs and the .iso before uploading.


All times are GMT -5. The time now is 02:33 AM.