tl;dr: A linux anti-malware tool is intermittently flagging unityhub as evil and I don’t know what to do…
So last week I installed the linux version of unity for linux, and all was well. It goes a bit chunky, a couple setup problems, but it worked. Yesterday, however, I got annoyed because it was freezing the screen and becoming unresponsive, so I tried to find out why, went into the rabbit hole, and ended up running chkrootkit, and found a match: infected with a thing called linux.xor.ddos, which is apparently a sophisticated piece of malware that f**** you up.
I’m not an expert on linux, I know my way around a bit but not enough to solve this properly, so I went with the nuclear option, and reformatted the disk, did a fresh install from a usb, and the first thing I did was download chkrootkit again and check it, and It turned out clean.
A bit paranoid at this point, I started rebuilding the system, reinstalling apps one by one and scanning the system again, and all was well until I downloaded and reinstalled unityhub, and checked, and positive again. Same thing.
I did a second fresh install, but this time, I checked the router settings and scanned the local network, and nothing was wrong at first sight, and looked at the chkrootkit log (it pointed to some random /tmp/.org.chrome.Chromium.xxxxxxx files, but i use firefox??? I don’t have chromium installed?) but nothing came out of that.
After a bit of additional poking around, apparently, chkrootkit gives a positive match on unityhub, not on unity, and only while it is running. It looks like unityhub creates a virtual drive on /tmp/.mount_UnityRaNdOmLeTTeRs, and that also gives a positive. Now my computer might be infected for the third time. I’m definitely going to be forgetting which new passwords are the correct ones.
What do I do?
Do I have a serious problem?
Is it a false positive? Another tool (rkhunter) says everything’s fine.
Is this even the right place to ask?
Is this real life?
Does Unity have a serious problem?
Thank you all in advance.