Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Using Fedora
FedoraForum Search

Forgot Password? Join Us!

Using Fedora General support for current versions. Ask questions about Fedora and it's software that do not belong in any other forum.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 12th December 2004, 06:26 PM
dontcare Offline
Registered User
 
Join Date: Sep 2004
Posts: 24
spyware? please help

I have no idea what's going on and I seem to be the only problrm with this so here it is....

It seems like a cannot get the 404 error when I put in an invaled internet address in firefox and mozilla. For example when I type the address linux.he i get this add for freeservers.com. It says "Site available.
The subdomain linux.he is available. Use the link on the right to sign up for your FREE Web site." WTH?

I can't even get to google.com, a page for "ray's corvett page" shows up.

I get ads for freeservers.com and 20m. Sometimes before these pages show up after the address will look like this "fedoraforum.org/cgi-bin/" What is this cgi-bin business?

It has been like this since the beggening of the installation of FC3.

I'm sorry if this is a dumb question and all but how can I fix this? If I can fix it i'll jsut go back to windows were I can actuallty surf the internet.
Reply With Quote
  #2  
Old 12th December 2004, 08:53 PM
james_in_denver Offline
Registered User
 
Join Date: Oct 2004
Posts: 1,227
Where did you get your mozilla/firefox from?

I have NEVER heard of that in linux....(10 year user)

Are you using a windows box somewhere as a router/firewall??? (if so, then it's likely that the windows box is the one actually re-writing the URL's you are trying to use)

Unless you are trying to pull an "April fools day" type of prank?
__________________
Only dead fish go with the flow....

Hmmm, what did I miss?
Reply With Quote
  #3  
Old 12th December 2004, 08:57 PM
h4d's Avatar
h4d Offline
Registered User
 
Join Date: Feb 2004
Location: Boston
Posts: 239
This is the wierdest thing I've heard of. On most windows machines on my network, I actually installed Firefox because it solved this issue which happens with crappy IE! Keep us posted on what's going on here!
Reply With Quote
  #4  
Old 12th December 2004, 10:27 PM
Uhlix's Avatar
Uhlix Offline
Registered User
 
Join Date: Oct 2004
Location: /us/tn/nashville
Posts: 142
i have to agree with james in denver. Sounds very wierd to say the least
Reply With Quote
  #5  
Old 12th December 2004, 10:58 PM
Jman Offline
Registered User
 
Join Date: Mar 2004
Location: Minnesota, USA
Age: 27
Posts: 7,909
I'm guessing it has something to do with the browser or DNS.

Have you installed any browser extensions? I don't know of any malicious ones for Firefox and Mozilla but they may exist. Perhaps a reinstall of the browser is in order. Or you may want to test other browsers like the text based lynx.

Attach the contents of /etc/hosts and /etc/resolv.conf. These contain DNS servers and hostname information. They may have been modified to redirect you.

I doubt there is anything wrong with your ISP's DNS servers or any proxying if you can connect fine with Windows.

If you suspect your machine has compromised try chkrootkit to search for signs of tampering.
Reply With Quote
  #6  
Old 13th December 2004, 12:43 AM
imdeemvp's Avatar
imdeemvp Offline
Registered User
 
Join Date: Feb 2004
Age: 44
Posts: 8,256
About 2 weeks ago some reported similiar issue with firefox. I was shocked to see it too. It makes me wonder if there could now be spyware for linux and we are not aware yet.
__________________
HELP with JAVA, MP3's, Wireless, Repo's, YUM, Partitions, System Monitors, Nvidia, ATI drivers, LIMEWIRE PRO & MORE!.

Easiest and most friendly desktop ever is PCLinuxOS! Includes all this apps. Just try it.

"The greater the struggle THE greater the achievment."

Do you know HIM?

If you are an idiot click here. NThis will test you linux skills :D
Reply With Quote
  #7  
Old 13th December 2004, 01:32 AM
dontcare Offline
Registered User
 
Join Date: Sep 2004
Posts: 24
back

Glad to see that you guys are so eager to help...

Anyways, as I said this happens with Firefox and Mozilla (Epiphany). I have installed extensions but I had this problem when I first installed FC3. Could you please explain this DNS server thing a bit more? I don't know if this will help but I am dual booting with windows and internet there works fine.

This is no prank and I really want to fix it.
Reply With Quote
  #8  
Old 13th December 2004, 01:45 AM
dontcare Offline
Registered User
 
Join Date: Sep 2004
Posts: 24
I just tried Elinks, text base browser, and I still get this "Rays Corvette Page" when I try to go to google.

Did a download a messed up version of FC3? I downloaded it from one of the mirrors from the site.

Please save me.
Reply With Quote
  #9  
Old 13th December 2004, 02:57 AM
h4d's Avatar
h4d Offline
Registered User
 
Join Date: Feb 2004
Location: Boston
Posts: 239
How about your /etc/hosts file? Anything wierd there redirecting google.com to the corvette page?
Reply With Quote
  #10  
Old 13th December 2004, 03:00 AM
dontcare Offline
Registered User
 
Join Date: Sep 2004
Posts: 24
There's nothing realy in that file except "order hosts,bind". Is this what should be there?
Reply With Quote
  #11  
Old 13th December 2004, 03:04 AM
dontcare Offline
Registered User
 
Join Date: Sep 2004
Posts: 24
Something I just noticed...
In "ray's corvette page" when I right click on one of the pictures and click view image, it comes from here "http://www.google.com/fs_img/builder/builder51/sportscar2.jpg"

....yeah I have no idea.../

update: I was looking through xbox-scene anyways that BS thing came up out of the blue (it's kind of random).

One of the picutres came from here "http://forums.xbox-scene.com/cgi-bin/image/logo_small.gif"

Can you guys see these images? If no then they must be comming from my computer or something....

Last edited by dontcare; 13th December 2004 at 03:08 AM.
Reply With Quote
  #12  
Old 13th December 2004, 03:26 AM
bob's Avatar
bob Online
Administrator (yeah, back again)
 
Join Date: Jul 2004
Location: Colton, NY; Junction of Heaven & Earth (also Routes 56 & 68).
Age: 67
Posts: 21,214
Dontcare, I'd seriously think about checking your computer with a free anti-virus program. If this was Windows, I'd be telling you to download 'hijack this' (not available for Linux, I see). Here's a link to some: http://linux.tucows.com/antivirus_default.html
__________________
Linux & Beer - That TOTALLY Computes!
Registered Linux User #362651


Don't use any of my solutions on working computers or near small children.
Reply With Quote
  #13  
Old 13th December 2004, 03:31 AM
h4d's Avatar
h4d Offline
Registered User
 
Join Date: Feb 2004
Location: Boston
Posts: 239
Quote:
Originally Posted by dontcare
There's nothing realy in that file except "order hosts,bind". Is this what should be there?
I'm not getting it...you should have something like this:
Code:
# Do not remove the following line, or various programs
# that require network functionality will fail.
127.0.0.1       localhost.localdomain       localhost
Unless you have added more aliases to your localhost...
What exactly do you see when you cat /etc/hosts?
Reply With Quote
  #14  
Old 13th December 2004, 03:47 AM
dontcare Offline
Registered User
 
Join Date: Sep 2004
Posts: 24
I'm sorry I was looking at hosts.conf. Yes my hosts file look like that. That's not the problem.

Any idea about the image thing?
Reply With Quote
  #15  
Old 13th December 2004, 03:49 AM
h4d's Avatar
h4d Offline
Registered User
 
Join Date: Feb 2004
Location: Boston
Posts: 239
Quote:
Originally Posted by dontcare
Any idea about the image thing?
I get a 404 on both those images. wierd...I think I'm looking at the first infected linux box since I started using *nix! Did you run an antivirus program? I use clamav on the mail servers and it works great. Give it a try and tell us what happens...
Reply With Quote
Reply

Tags
spyware

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux for spyware removel squirtmph Using Fedora 0 2nd October 2009 06:01 AM
Spyware Problem jazzer386 Using Fedora 6 4th February 2009 06:04 PM
Spyware on my linux computer??? ian.rogers Using Fedora 8 12th May 2007 11:41 PM
fedora spyware? nshack31 Security and Privacy 35 22nd February 2006 09:45 PM


Current GMT-time: 17:19 (Wednesday, 22-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat