Welcome to Linux Forums!

With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.

Linux Forum ArticlesLinux ForumsLinux Forum DownloadsLinux HostsFree MagazinesJobs
Home|Register|FAQ|Member List|Calendar|Unanswered Posts|Forum Rules|Today's Posts|Advanced Search|
SEARCH FOR IN
Go Back   Linux Forums > GNU Linux Zone > Linux Security
Reload this Page Win32/PolyCrypt Virus on my box...help?
Linux Forums
Linux Forums
Welcome To The Linux Forums!
Welcome to Linux Forums. We pride ourselves in being one of the largest Linux communities on the web, we encourage you to REGISTER on our forums and participate in the community. There are over 150,000 members ready to answer your questions. JOINING US today will allow you to make new posts, get support, send messages to other members and submit downloads to our downloads directory and many other great features!

Linux Security Discussion about keeping your machines secure, and the crackers out.

Reply
 
Thread Tools Display Modes
Old 08-09-2007   #1 (permalink)
Just Joined!
 
WebThingy's Avatar
 
Join Date: May 2006
Location: Bellingham, WA
Posts: 69
Win32/PolyCrypt Virus on my box...help?

Ok, been running Ubuntu for about two years now quite happily, and even though it's not really thought of as necessary I still scan for viruses every single day...give me a break, Windows conditioned me to do it for years

So anyway, I've never had a virus of any kind for any system on a Linux box before, so my question is:

How do I remove a Windows virus from a Linux (Ubuntu) machine?

I did a scan with AVG (for some reason Clam has never been able to run on my computer) and to my surprise it showed me that I have Win32/PolyCrypt in multiple locations on my computer.

I know I can't just delete the files as many are needed files. Some listed I don't know what they are, but many I recognize.

Anyone know what I should do? I don't want to pass this on to Windows users.

Here's the infected files output...

Code:
etc/alternatives/x-session-manager
usr/bin/as
usr/bin/evolution
usr/bin/evolution-2.10
usr/bin/evolution-2.2
usr/bin/gdbserver
usr/bin/gencat
usr/bin/gnome-session
usr/bin/gnome-system-monitor
usr/bin/mawk
usr/bin/msgunfmt
usr/bin/vmnet-dhcpd
usr/bin/x-session-manager
usr/lib/libgettextsrc-0.16.1.so
usr/lib/libgettextsrc.so
usr/lib/libneon.so.25
usr/lib/libneon.so.25.0.5
usr/lib/libportaudio.so.0
usr/lib/libportaudio.so.0.0.18
usr/lib/libuniquewm-0.9.so.25
usr/lib/libuniquewm-0.9.so.25.0.0
usr/lib/gnome-applets/cpufreq-applet
usr/lib/gnome-pilot/conduits/libmal_conduit.so
usr/lib/gnome-vfs-2.0/modules/libhttp.so
usr/lib/gstreamer-0.10/libpitfdll.so
usr/lib/gtk-2.0/2.10.0/engines/libsmooth.so
usr/lib/jvm/java-6-sun-1.6.0.00/jre/lib/i386/libjdwp.s0
usr/lib/openoffice/program/configimport.bin
usr/lib/openoffice/program/dlgprov680li.uno.so
usr/lib/openoffice/program/libdbpool2.so
usr/lib/openoffice/program/libgcc3_uno.so
usr/lib/openoffice/program/libjava_uno
usr/lib/openoffice/program/libjava_uno.so
usr/lib/openoffice/program/liburp_uno.so
usr/lib/openoffice/program/libxsltfilter680li.so
usr/lib/openoffice/program/proxyfac.uno.so
usr/lib/openoffice/program/servicemgr.uno.so
usr/lib/openoffice/program/uno.bin
usr/lib/openoffice/program/vbaevents680li.uno.so
usr/lib/sane/libsane-pixma.so.1
usr/lib/sane/libsane-pixma.so.1.0.18
usr/lib/vmware-player/libconf/lib/gtk-2.0/2.4.0/loaders/libpixbufloader-ico.so
usr/lib/xorg/modules/libddc.so
usr/sbin/pam_tally
For a virus that's supposed to be just for Windows, it sure does know how to spread itself around a Linux operating system.

I can't find any info on how to remove Windows viruses from a Linux machine, maybe I'm searching for the wrong thing?
WebThingy is offline   Reply With Quote
Old 08-09-2007   #2 (permalink)
Bigtomrodinator
 
bigtomrodney's Avatar
 
Join Date: Nov 2004
Location: Sunny South-East of Ireland
Posts: 5,194
It's a false positive. Even if it was the real thing it would not be able to do anything on your system as it was written for Windows. It wouldn't even execute. The problem is that virus detection is based on certain signatures. There really is nothing to worry about.
__________________
Registered Linux user #378740
New members read here / Forum Rules
#linuxforums on irc.freenode.net
bigtomrodney is offline   Reply With Quote
Old 08-09-2007   #3 (permalink)
Just Joined!
 
WebThingy's Avatar
 
Join Date: May 2006
Location: Bellingham, WA
Posts: 69
Ok thanks, the folks over at the Ubuntu forums just said the same thing you did. I appreciate the reply
WebThingy is offline   Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
 

Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft Windows is NOT a virus. chadders The Coffee Lounge 1 03-05-2007 01:02 PM
Virus Software For Linux n3wo Linux Security 20 11-04-2006 11:03 PM
Virus scanners... chris-harry Debian Linux Help 10 07-20-2005 04:35 PM
Desperate in search of the best SMTP gateway virus scanner!! jmschuur Servers 3 03-02-2004 02:51 PM
Mail relay with virus scanner. What's the best to do? jmschuur Servers 0 02-26-2004 01:15 PM

Free Magazines
Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe
Systems Management News, the newspaper for IT systems administration and data center managers!
Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe
The Enterprise Newsweekly
eWeek is the essential technology information source for builders of e-business.
subscribe
Oracle Magazine
Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe
Total Telecom
Total Telecom is "The Economist of the communications industry".
subscribe
More free magazines »



All times are GMT. The time now is 02:42 AM.




© 2000 - 2008 - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.2.0