Contenu | Rechercher | Menus

Annonce

Si vous avez des soucis pour rester connecté, déconnectez-vous puis reconnectez-vous depuis ce lien en cochant la case
Me connecter automatiquement lors de mes prochaines visites.

À propos de l'équipe du forum.

#1 Le 03/10/2016, à 12:27

imost

[Résolu] fichier suspect détecté via rkhunter

Bonjour, j ai mon compte wow battlenet qui a été piraté et j ai donc installé clamav pour voir si je trouve quelque chose. Cependant lorque j essaie de faire la mise a jour de clamav ca ne marche pas
Voici ce qu il se passe:

 sudo freshclam
ERROR: /var/log/clamav/freshclam.log is locked by another process
ERROR: Problem with internal logger (UpdateLogFile = /var/log/clamav/freshclam.log).

J ai fais mise a jour via clamtk mais ca me dit toujours que mes signatures ont plus de 7 jours

Dernière modification par imost (Le 24/05/2020, à 13:45)


Ubuntu 22.04 LTS

Hors ligne

#2 Le 03/10/2016, à 13:13

koshieIsYourDaddy

Re : [Résolu] fichier suspect détecté via rkhunter

Salut,

Tu te perd un peu. Si ton compte WOW a été piraté par un virus, ClamAV ne peut rien pour toi. Il vérifie les virus Windows, qui ne risquent pas de faire grand chose sur ton Ubuntu.

De plus, sans te demander ton mot de passe, de quel genre était-il? Par exemple, prénom + chiffre du département etc... Tu aurais pu aussi te faire pisher. Bref, y'a pleins de pistes. Ça peut aussi être ta boîte mail qui dans un premier temps à été piraté (logué sur un ordinateur de l'université/un cyber café sans bien fermer ta session etc).

À ta place je m'amuserai à recréer tout mes mots de passes et à les changer (boîte mail, compte blizzard et autres jeux etc), en s'assurant qu'ils sont d'au moins 8 caractères, avec chiffres, lettres (minuscule et majuscule) et des caractères accentués. Et surtout, le mot de passe de la boîte mail doit être à usage unique, parce que si je trouve le mot de passe associé à ton compte X, et que je me rend compte que c'est le même sur ta boîte mail, c'est la fête.

Et blizzard n'a pas des outils qui empêche les connexions via un poste où on a pas autorisé l'accès une première fois (par e-mail, SMS)? Si c'est en place, ça pourrait confirmer que quelqu'un a un accès directe ou distant à ton ordinateur / ton téléphone...

Quand à ClamAV, il dit qu'un autre processus est en cours d'exécution:

ERROR: /var/log/clamav/freshclam.log is locked by another process

koshicalement

Dernière modification par koshieIsYourDaddy (Le 03/10/2016, à 13:14)

Hors ligne

#3 Le 03/10/2016, à 14:16

imost

Re : [Résolu] fichier suspect détecté via rkhunter

ca veut dire qquoi concernant l'autre processus?
je fais quoi?
de plus tu me dis que quelqu'un a un acces distant a mon pc??

Dernière modification par imost (Le 03/10/2016, à 14:23)


Ubuntu 22.04 LTS

Hors ligne

#4 Le 03/10/2016, à 16:13

guitbass

Re : [Résolu] fichier suspect détecté via rkhunter

Bonjour,

Eventuellement  installe la dernière version de clamav 0.99.2 disponible depuis peu dans les paquets..





Cordialement

Hors ligne

#5 Le 03/10/2016, à 16:39

imost

Re : [Résolu] fichier suspect détecté via rkhunter

justement je l'ai installé j 'ai fais une analyse et ca m'a dit qu'il y avait un fichier infesté, mais je n ai su que faire suite au scan


Ubuntu 22.04 LTS

Hors ligne

#6 Le 03/10/2016, à 16:48

cqfd93

Re : [Résolu] fichier suspect détecté via rkhunter

Modération

Bonjour,

Deux discussions pour traiter le même problème, c'est trop ! Je ferme l'autre et on continue ici.


cqfd93

Hors ligne

#7 Le 03/10/2016, à 16:55

pires57

Re : [Résolu] fichier suspect détecté via rkhunter

ca veut dire qquoi concernant l'autre processus?

Cela veut dire que quelque chose d'autre est en train d'utiliser la ressource clamav et donc que tu ne peut pas l'utiliser.

je fais quoi?

Changes tes mots de passes ! le soucis ne viens probablement pas de ton ubuntu.

de plus tu me dis que quelqu'un a un acces distant a mon pc??

non t'as rien compris, relis sa phrase.


Utilisateur d'Archlinux, Ubuntu et Kali Linux
Administrateur système et réseau spécialisé Linux.
LinkedIn

Hors ligne

#8 Le 03/10/2016, à 18:15

imost

Re : [Résolu] fichier suspect détecté via rkhunter

ok j'ai du lire trop vite. Non je n avais pas les outils en place, par contre je viens de les mettre en place.
Cela dit j ai changé tous mes mots de passe depuis que je me suis apercu que je me suis fais cracker. Je les change encore?

Dernière modification par imost (Le 03/10/2016, à 18:16)


Ubuntu 22.04 LTS

Hors ligne

#9 Le 03/10/2016, à 18:47

imost

Re : [Résolu] fichier suspect détecté via rkhunter

je viens de changer encore mes mots de passe et le message d'erreur persiste.


Ubuntu 22.04 LTS

Hors ligne

#10 Le 03/10/2016, à 19:05

imost

Re : [Résolu] fichier suspect détecté via rkhunter

Je ne dois rien faire d 'autre?


Ubuntu 22.04 LTS

Hors ligne

#11 Le 04/10/2016, à 12:18

koshieIsYourDaddy

Re : [Résolu] fichier suspect détecté via rkhunter

Calme toi imost. Je vais te ré-expliquer quelques points concernant ton problème:

Si ton compte Blizzard a été piraté, c'est sûrement parce que quelqu'un a eu soit accès à ton mot de passe (tu l'aurais noté quelque part, on t'aurais trahis, tu aurais un keylogger* sur ton ordinateur, ou un petit frère plus malin que tu ne le crois etc), soit à ton adresse e-mail (sur le même principe). Sachant qu'en général les adresses mails sont très visés par d'éventuel pirates (c'est là où on a un accès à presque tout ses comptes) c'est elle qu'il faut protéger en priorité.

Tu avais déjà changé tes mots de passes une première fois, c'est bien, tu l'as refais, c'est très bien aussi mais ça suffira tongue. L'important; avoir autant de mot de passe unique que possible, et à défaut au moins pour l'adresse e-mail! Qu'il soit suffisamment sûr (+ de 8 caractères, chiffres, lettre minuscule + majuscule et un ou plusieurs caractères de ponctuation). Comme: J&Ms2cvm. (ne t'en sers pas de celui-là, et non ce n'est pas un de mes mots de passes tongue)

Concernant ClamAV, cette interface pourra t'aider: ClamTK. Et l'erreur en début de topic veut simplement dire qu'un processus (une instance si tu préfère) est en cours et que tu ne peux lui demander d'être là deux fois. Il faudrait voir si tu ne l'avais pas lancé auparavant, s'il ne se lance pas au démarrage...

Mais je le rappel, ClamAV cherche des virus Windows, pour Linux il faudrait se tourner vers les rootkit, qui eux sont un danger pour Linux.

Ton jeu, tu le lance via Playonlinux/WINE ou sur ton Windows (que tu aurais en dual boot dans ce cas)?

koshicalement

* les keylogger sont des logiciels malveillants qui enregistrent et envoie à distance toute la frappe au clavier de ton ordinateur, ça permet de récupérer des mots de passes, identifiants de carte bleu etc.

PS: Pour ajouter des détails, ne fait pas 3 ou 4 messages à la suite dans la même journée... Modifie le dernier. Ça flood un peu wink.

Dernière modification par koshieIsYourDaddy (Le 04/10/2016, à 12:18)

Hors ligne

#12 Le 04/10/2016, à 13:14

imost

Re : [Résolu] fichier suspect détecté via rkhunter

tout d abord merci, smile, j 'utilise wine. je n ai que ubuntu sur l'ordi en question. hier j ai fais un scan complet avec clamav en ligne de commande. il m'a dit que j avais un fichier infesté mais je n'ai su que faire en suite et sur clamtk ca ne disait rien.
et si j ai bien compris tu me dis d'installer un anti rookit.
et en ce moment si c'est un keylogger il continue a enregistrer mes frappes?

sudo rkhunter --checkall --report-warnings-only
Warning: The command '/usr/bin/lwp-request' has been replaced by a script: /usr/bin/lwp-request: a /usr/bin/perl -w script, ASCII text executable
Warning: The SSH and rkhunter configuration options should be the same:
         SSH configuration option 'PermitRootLogin': prohibit-password
         Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no
Warning: Suspicious file types found in /dev:
         /dev/shm/pulse-shm-1673721254: data
         /dev/shm/pulse-shm-4052801653: data
         /dev/shm/pulse-shm-132324202: data
         /dev/shm/pulse-shm-3975175099: data
         /dev/shm/pulse-shm-3441172232: data
         /dev/shm/pulse-shm-21482027: data
         /dev/shm/pulse-shm-1190472284: data
         /dev/shm/pulse-shm-1059657955: data
         /dev/shm/pulse-shm-930879024: data
         /dev/shm/pulse-shm-1651184676: data
 sudo cat rkhunter.log
[16:56:04] Running Rootkit Hunter version 1.4.2 on
[16:56:04]
[16:56:04] Info: Start date is mardi 4 octobre 2016, 16:56:04 (UTC+0200)
[16:56:04]
[16:56:04] Checking configuration file and command-line options...
[16:56:04] Info: Detected operating system is 'Linux'
[16:56:04] Info: Found O/S name: Ubuntu 16.04.1 LTS
[16:56:04] Info: Command line is /usr/bin/rkhunter -c --rwo
[16:56:04] Info: Environment shell is /bin/bash; rkhunter is using dash
[16:56:04] Info: Using configuration file '/etc/rkhunter.conf'
[16:56:04] Info: Installation directory is '/usr'
[16:56:04] Info: Using language 'en'
[16:56:04] Info: Using '/var/lib/rkhunter/db' as the database directory
[16:56:04] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[16:56:04] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin' as the command directories
[16:56:04] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[16:56:04] Info: No mail-on-warning address configured
[16:56:04] Info: X will be automatically detected
[16:56:04] Info: Using second color set
[16:56:04] Info: Found the 'basename' command: /usr/bin/basename
[16:56:05] Info: Found the 'diff' command: /usr/bin/diff
[16:56:05] Info: Found the 'dirname' command: /usr/bin/dirname
[16:56:05] Info: Found the 'file' command: /usr/bin/file
[16:56:05] Info: Found the 'find' command: /usr/bin/find
[16:56:05] Info: Found the 'ifconfig' command: /sbin/ifconfig
[16:56:05] Info: Found the 'ip' command: /sbin/ip
[16:56:05] Info: Found the 'ipcs' command: /usr/bin/ipcs
[16:56:05] Info: Found the 'ldd' command: /usr/bin/ldd
[16:56:05] Info: Found the 'lsattr' command: /usr/bin/lsattr
[16:56:05] Info: Found the 'lsmod' command: /sbin/lsmod
[16:56:05] Info: Found the 'lsof' command: /usr/bin/lsof
[16:56:05] Info: Found the 'mktemp' command: /bin/mktemp
[16:56:05] Info: Found the 'netstat' command: /bin/netstat
[16:56:05] Info: Found the 'perl' command: /usr/bin/perl
[16:56:05] Info: Found the 'pgrep' command: /usr/bin/pgrep
[16:56:05] Info: Found the 'ps' command: /bin/ps
[16:56:05] Info: Found the 'pwd' command: /bin/pwd
[16:56:05] Info: Found the 'readlink' command: /bin/readlink
[16:56:05] Info: Found the 'stat' command: /usr/bin/stat
[16:56:05] Info: Found the 'strings' command: /usr/bin/strings
[16:56:05] Info: System is not using prelinking
[16:56:05] Info: Using the '/usr/bin/sha256sum' command for the file hash checks
[16:56:05] Info: Stored hash values used hash function '/usr/bin/sha256sum'
[16:56:05] Info: Stored hash values did not use a package manager
[16:56:05] Info: The hash function field index is set to 1
[16:56:05] Info: No package manager specified: using hash function '/usr/bin/sha256sum'
[16:56:05] Info: Previous file attributes were stored
[16:56:05] Info: Enabled tests are: all
[16:56:05] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps apps
[16:56:05] Info: Found ksym file '/proc/kallsyms'
[16:56:05] Info: Using syslog for some logging - facility/priority level is 'authpriv.warning'.
[16:56:05] Info: Using 'date' to process epoch second times
[16:56:05]
[16:56:05] Checking if the O/S has changed since last time...
[16:56:05] Info: Nothing seems to have changed.
[16:56:05] Info: Locking is not being used
[16:56:05]
[16:56:05] Starting system checks...
[16:56:05]
[16:56:05] Info: Starting test name 'system_commands'
[16:56:05] Checking system commands...
[16:56:05]
[16:56:05] Info: Starting test name 'strings'
[16:56:05] Performing 'strings' command checks
[16:56:05]   Scanning for string /usr/sbin/ntpsx             [ OK ]
[16:56:05]   Scanning for string /usr/sbin/.../bkit-ava      [ OK ]
[16:56:05]   Scanning for string /usr/sbin/.../bkit-d        [ OK ]
[16:56:05]   Scanning for string /usr/sbin/.../bkit-shd      [ OK ]
[16:56:05]   Scanning for string /usr/sbin/.../bkit-f        [ OK ]
[16:56:05]   Scanning for string /usr/include/.../proc.h     [ OK ]
[16:56:05]   Scanning for string /usr/include/.../.bash_history [ OK ]
[16:56:05]   Scanning for string /usr/include/.../bkit-get   [ OK ]
[16:56:06]   Scanning for string /usr/include/.../bkit-dl    [ OK ]
[16:56:06]   Scanning for string /usr/include/.../bkit-screen [ OK ]
[16:56:06]   Scanning for string /usr/include/.../bkit-sleep [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../bkit-adore.o   [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../ls             [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../netstat        [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../lsof           [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../bkit-ssh/bkit-mots [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../uconf.inv      [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../psr            [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../find           [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../pstree         [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../slocate        [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../du             [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../top            [ OK ]
[16:56:06]   Scanning for string /usr/sbin/...               [ OK ]
[16:56:06]   Scanning for string /usr/include/...            [ OK ]
[16:56:06]   Scanning for string /usr/include/.../.tmp       [ OK ]
[16:56:06]   Scanning for string /usr/lib/...                [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../.ssh           [ OK ]
[16:56:06]   Scanning for string /usr/lib/.../bkit-ssh       [ OK ]
[16:56:06]   Scanning for string /usr/lib/.bkit-             [ OK ]
[16:56:06]   Scanning for string /tmp/.bkp                   [ OK ]
[16:56:07]   Scanning for string /tmp/.cinik                 [ OK ]
[16:56:07]   Scanning for string /tmp/.font-unix/.cinik      [ OK ]
[16:56:07]   Scanning for string /lib/.sso                   [ OK ]
[16:56:07]   Scanning for string /lib/.so                    [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/clean      [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/dxr        [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/read       [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/write      [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/lf         [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/xl         [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/xdr        [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/psg        [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/secure     [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/rdx        [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/va         [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/cl.sh      [ OK ]
[16:56:07]   Scanning for string /var/run/...dica/last.log   [ OK ]
[16:56:07]   Scanning for string /usr/bin/.etc               [ OK ]
[16:56:07]   Scanning for string /etc/sshd_config            [ OK ]
[16:56:07]   Scanning for string /etc/ssh_host_key           [ OK ]
[16:56:07]   Scanning for string /etc/ssh_random_seed        [ OK ]
[16:56:07]   Scanning for string /dev/ptyp                   [ OK ]
[16:56:07]   Scanning for string /dev/ptyq                   [ OK ]
[16:56:07]   Scanning for string /dev/ptyr                   [ OK ]
[16:56:07]   Scanning for string /dev/ptys                   [ OK ]
[16:56:07]   Scanning for string /dev/ptyt                   [ OK ]
[16:56:07]   Scanning for string /dev/fd/.88/freshb-bsd      [ OK ]
[16:56:08]   Scanning for string /dev/fd/.88/fresht          [ OK ]
[16:56:08]   Scanning for string /dev/fd/.88/zxsniff         [ OK ]
[16:56:08]   Scanning for string /dev/fd/.88/zxsniff.log     [ OK ]
[16:56:08]   Scanning for string /dev/fd/.99/.ttyf00         [ OK ]
[16:56:08]   Scanning for string /dev/fd/.99/.ttyp00         [ OK ]
[16:56:08]   Scanning for string /dev/fd/.99/.ttyq00         [ OK ]
[16:56:08]   Scanning for string /dev/fd/.99/.ttys00         [ OK ]
[16:56:08]   Scanning for string /dev/fd/.99/.pwsx00         [ OK ]
[16:56:08]   Scanning for string /etc/.acid                  [ OK ]
[16:56:08]   Scanning for string /usr/lib/.fx/sched_host.2   [ OK ]
[16:56:08]   Scanning for string /usr/lib/.fx/random_d.2     [ OK ]
[16:56:08]   Scanning for string /usr/lib/.fx/set_pid.2      [ OK ]
[16:56:08]   Scanning for string /usr/lib/.fx/setrgrp.2      [ OK ]
[16:56:08]   Scanning for string /usr/lib/.fx/TOHIDE         [ OK ]
[16:56:08]   Scanning for string /usr/lib/.fx/cons.saver     [ OK ]
[16:56:08]   Scanning for string /usr/lib/.fx/adore/ava/ava  [ OK ]
[16:56:08]   Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[16:56:08]   Scanning for string /bin/sysback                [ OK ]
[16:56:08]   Scanning for string /usr/local/bin/sysback      [ OK ]
[16:56:08]   Scanning for string /usr/lib/.tbd               [ OK ]
[16:56:08]   Scanning for string /dev/.lib/lib/lib/t0rns     [ OK ]
[16:56:08]   Scanning for string /dev/.lib/lib/lib/du        [ OK ]
[16:56:08]   Scanning for string /dev/.lib/lib/lib/ls        [ OK ]
[16:56:08]   Scanning for string /dev/.lib/lib/lib/t0rnsb    [ OK ]
[16:56:08]   Scanning for string /dev/.lib/lib/lib/ps        [ OK ]
[16:56:08]   Scanning for string /dev/.lib/lib/lib/t0rnp     [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/find      [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/ifconfig  [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/pg        [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/ssh.tgz   [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/top       [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/sz        [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/login     [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/1i0n.sh   [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/pstree    [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/mjy       [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/sush      [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/tfn       [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/name      [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/getip.sh  [ OK ]
[16:56:09]   Scanning for string /usr/info/.torn/sh*         [ OK ]
[16:56:09]   Scanning for string /usr/src/.puta/.1addr       [ OK ]
[16:56:09]   Scanning for string /usr/src/.puta/.1file       [ OK ]
[16:56:09]   Scanning for string /usr/src/.puta/.1proc       [ OK ]
[16:56:09]   Scanning for string /usr/src/.puta/.1logz       [ OK ]
[16:56:09]   Scanning for string /usr/info/.t0rn             [ OK ]
[16:56:09]   Scanning for string /dev/.lib                   [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib               [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib           [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/lib/dev       [ OK ]
[16:56:09]   Scanning for string /dev/.lib/lib/scan          [ OK ]
[16:56:10]   Scanning for string /usr/src/.puta              [ OK ]
[16:56:10]   Scanning for string /usr/man/man1/man1          [ OK ]
[16:56:10]   Scanning for string /usr/man/man1/man1/lib      [ OK ]
[16:56:10]   Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[16:56:10]   Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[16:56:10]
[16:56:10] Info: Starting test name 'shared_libs'
[16:56:10] Performing 'shared libraries' checks
[16:56:10]   Checking for preloading variables               [ None found ]
[16:56:10]   Checking for preloaded libraries                [ None found ]
[16:56:10]
[16:56:10] Info: Starting test name 'shared_libs_path'
[16:56:10]   Checking LD_LIBRARY_PATH variable               [ Not found ]
[16:56:10]
[16:56:10] Info: Starting test name 'properties'
[16:56:10] Performing file properties checks
[16:56:10]   Checking for prerequisites                      [ OK ]
[16:56:16]   /usr/sbin/adduser                               [ OK ]
[16:56:16] Info: Found file '/usr/sbin/adduser': it is whitelisted for the 'script replacement' check.
[16:56:16]   /usr/sbin/chroot                                [ OK ]
[16:56:16]   /usr/sbin/cron                                  [ OK ]
[16:56:17]   /usr/sbin/groupadd                              [ OK ]
[16:56:17]   /usr/sbin/groupdel                              [ OK ]
[16:56:17]   /usr/sbin/groupmod                              [ OK ]
[16:56:17]   /usr/sbin/grpck                                 [ OK ]
[16:56:18]   /usr/sbin/nologin                               [ OK ]
[16:56:18]   /usr/sbin/pwck                                  [ OK ]
[16:56:18]   /usr/sbin/rsyslogd                              [ OK ]
[16:56:19]   /usr/sbin/tcpd                                  [ OK ]
[16:56:19]   /usr/sbin/useradd                               [ OK ]
[16:56:19]   /usr/sbin/userdel                               [ OK ]
[16:56:20]   /usr/sbin/usermod                               [ OK ]
[16:56:20]   /usr/sbin/vipw                                  [ OK ]
[16:56:20]   /usr/sbin/unhide                                [ OK ]
[16:56:20]   /usr/sbin/unhide-linux                          [ OK ]
[16:56:20]   /usr/sbin/unhide-posix                          [ OK ]
[16:56:20]   /usr/sbin/unhide-tcp                            [ OK ]
[16:56:21]   /usr/bin/awk                                    [ OK ]
[16:56:21]   /usr/bin/basename                               [ OK ]
[16:56:21]   /usr/bin/chattr                                 [ OK ]
[16:56:22]   /usr/bin/curl                                   [ OK ]
[16:56:22]   /usr/bin/cut                                    [ OK ]
[16:56:22]   /usr/bin/diff                                   [ OK ]
[16:56:22]   /usr/bin/dirname                                [ OK ]
[16:56:22]   /usr/bin/dpkg                                   [ OK ]
[16:56:22]   /usr/bin/dpkg-query                             [ OK ]
[16:56:23]   /usr/bin/du                                     [ OK ]
[16:56:23]   /usr/bin/env                                    [ OK ]
[16:56:23]   /usr/bin/file                                   [ OK ]
[16:56:23]   /usr/bin/find                                   [ OK ]
[16:56:24]   /usr/bin/GET                                    [ OK ]
[16:56:24]   /usr/bin/groups                                 [ OK ]
[16:56:24]   /usr/bin/head                                   [ OK ]
[16:56:24]   /usr/bin/id                                     [ OK ]
[16:56:25]   /usr/bin/killall                                [ OK ]
[16:56:25]   /usr/bin/last                                   [ OK ]
[16:56:25]   /usr/bin/lastlog                                [ OK ]
[16:56:25]   /usr/bin/ldd                                    [ OK ]
[16:56:25] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
[16:56:26]   /usr/bin/less                                   [ OK ]
[16:56:26]   /usr/bin/locate                                 [ OK ]
[16:56:26]   /usr/bin/logger                                 [ OK ]
[16:56:26]   /usr/bin/lsattr                                 [ OK ]
[16:56:26]   /usr/bin/lsof                                   [ OK ]
[16:56:27]   /usr/bin/mail                                   [ OK ]
[16:56:27]   /usr/bin/md5sum                                 [ OK ]
[16:56:27]   /usr/bin/mlocate                                [ OK ]
[16:56:27]   /usr/bin/newgrp                                 [ OK ]
[16:56:27]   /usr/bin/passwd                                 [ OK ]
[16:56:28]   /usr/bin/perl                                   [ OK ]
[16:56:28]   /usr/bin/pgrep                                  [ OK ]
[16:56:28]   /usr/bin/pkill                                  [ OK ]
[16:56:28]   /usr/bin/pstree                                 [ OK ]
[16:56:28]   /usr/bin/rkhunter                               [ OK ]
[16:56:29]   /usr/bin/rpm                                    [ OK ]
[16:56:29]   /usr/bin/runcon                                 [ OK ]
[16:56:29]   /usr/bin/sha1sum                                [ OK ]
[16:56:29]   /usr/bin/sha224sum                              [ OK ]
[16:56:29]   /usr/bin/sha256sum                              [ OK ]
[16:56:29]   /usr/bin/sha384sum                              [ OK ]
[16:56:29]   /usr/bin/sha512sum                              [ OK ]
[16:56:30]   /usr/bin/size                                   [ OK ]
[16:56:30]   /usr/bin/sort                                   [ OK ]
[16:56:30]   /usr/bin/ssh                                    [ OK ]
[16:56:30]   /usr/bin/stat                                   [ OK ]
[16:56:30]   /usr/bin/strace                                 [ OK ]
[16:56:30]   /usr/bin/strings                                [ OK ]
[16:56:31]   /usr/bin/sudo                                   [ OK ]
[16:56:31]   /usr/bin/tail                                   [ OK ]
[16:56:31]   /usr/bin/telnet                                 [ OK ]
[16:56:31]   /usr/bin/test                                   [ OK ]
[16:56:31]   /usr/bin/top                                    [ OK ]
[16:56:31]   /usr/bin/touch                                  [ OK ]
[16:56:31]   /usr/bin/tr                                     [ OK ]
[16:56:32]   /usr/bin/uniq                                   [ OK ]
[16:56:32]   /usr/bin/users                                  [ OK ]
[16:56:32]   /usr/bin/vmstat                                 [ OK ]
[16:56:32]   /usr/bin/w                                      [ OK ]
[16:56:32]   /usr/bin/watch                                  [ OK ]
[16:56:32]   /usr/bin/wc                                     [ OK ]
[16:56:32]   /usr/bin/wget                                   [ OK ]
[16:56:33]   /usr/bin/whatis                                 [ OK ]
[16:56:33]   /usr/bin/whereis                                [ OK ]
[16:56:33]   /usr/bin/which                                  [ OK ]
[16:56:33]   /usr/bin/who                                    [ OK ]
[16:56:33]   /usr/bin/whoami                                 [ OK ]
[16:56:33]   /usr/bin/mawk                                   [ OK ]
[16:56:33]   /usr/bin/lwp-request                            [ Warning ]
[16:56:33] Warning: The command '/usr/bin/lwp-request' has been replaced by a script: /usr/bin/lwp-request: a /usr/bin/perl -w script, ASCII text executable
[16:56:34]   /usr/bin/s-nail                                 [ OK ]
[16:56:34]   /usr/bin/x86_64-linux-gnu-size                  [ OK ]
[16:56:34]   /usr/bin/x86_64-linux-gnu-strings               [ OK ]
[16:56:34]   /usr/bin/telnet.netkit                          [ OK ]
[16:56:34]   /usr/bin/w.procps                               [ OK ]
[16:56:35]   /sbin/depmod                                    [ OK ]
[16:56:35]   /sbin/fsck                                      [ OK ]
[16:56:35]   /sbin/ifconfig                                  [ OK ]
[16:56:36]   /sbin/ifdown                                    [ OK ]
[16:56:36]   /sbin/ifup                                      [ OK ]
[16:56:36]   /sbin/init                                      [ OK ]
[16:56:36]   /sbin/insmod                                    [ OK ]
[16:56:36]   /sbin/ip                                        [ OK ]
[16:56:37]   /sbin/lsmod                                     [ OK ]
[16:56:37]   /sbin/modinfo                                   [ OK ]
[16:56:37]   /sbin/modprobe                                  [ OK ]
[16:56:38]   /sbin/rmmod                                     [ OK ]
[16:56:38]   /sbin/route                                     [ OK ]
[16:56:38]   /sbin/runlevel                                  [ OK ]
[16:56:39]   /sbin/sulogin                                   [ OK ]
[16:56:39]   /sbin/sysctl                                    [ OK ]
[16:56:40]   /bin/bash                                       [ OK ]
[16:56:40]   /bin/cat                                        [ OK ]
[16:56:40]   /bin/chmod                                      [ OK ]
[16:56:40]   /bin/chown                                      [ OK ]
[16:56:40]   /bin/cp                                         [ OK ]
[16:56:41]   /bin/date                                       [ OK ]
[16:56:41]   /bin/df                                         [ OK ]
[16:56:41]   /bin/dmesg                                      [ OK ]
[16:56:41]   /bin/echo                                       [ OK ]
[16:56:42]   /bin/ed                                         [ OK ]
[16:56:42]   /bin/egrep                                      [ OK ]
[16:56:42] Info: Found file '/bin/egrep': it is whitelisted for the 'script replacement' check.
[16:56:42]   /bin/fgrep                                      [ OK ]
[16:56:42] Info: Found file '/bin/fgrep': it is whitelisted for the 'script replacement' check.
[16:56:42]   /bin/fuser                                      [ OK ]
[16:56:42]   /bin/grep                                       [ OK ]
[16:56:43]   /bin/ip                                         [ OK ]
[16:56:43]   /bin/kill                                       [ OK ]
[16:56:43]   /bin/less                                       [ OK ]
[16:56:43]   /bin/login                                      [ OK ]
[16:56:44]   /bin/ls                                         [ OK ]
[16:56:44]   /bin/lsmod                                      [ OK ]
[16:56:44]   /bin/mktemp                                     [ OK ]
[16:56:44]   /bin/more                                       [ OK ]
[16:56:44]   /bin/mount                                      [ OK ]
[16:56:45]   /bin/mv                                         [ OK ]
[16:56:45]   /bin/netstat                                    [ OK ]
[16:56:45]   /bin/ping                                       [ OK ]
[16:56:45]   /bin/ps                                         [ OK ]
[16:56:45]   /bin/pwd                                        [ OK ]
[16:56:45]   /bin/readlink                                   [ OK ]
[16:56:46]   /bin/sed                                        [ OK ]
[16:56:46]   /bin/sh                                         [ OK ]
[16:56:46]   /bin/su                                         [ OK ]
[16:56:47]   /bin/touch                                      [ OK ]
[16:56:47]   /bin/uname                                      [ OK ]
[16:56:47]   /bin/which                                      [ OK ]
[16:56:47] Info: Found file '/bin/which': it is whitelisted for the 'script replacement' check.
[16:56:48]   /bin/kmod                                       [ OK ]
[16:56:48]   /bin/systemd                                    [ OK ]
[16:56:48]   /bin/systemctl                                  [ OK ]
[16:56:48]   /bin/dash                                       [ OK ]
[16:56:51]   /lib/systemd/systemd                            [ OK ]
[16:56:52]
[16:56:52] Info: Starting test name 'rootkits'
[16:56:52] Checking for rootkits...
[16:56:53]
[16:56:53] Info: Starting test name 'known_rkts'
[16:56:53] Performing check of known rootkit files and directories
[16:56:53]
[16:56:53] Checking for 55808 Trojan - Variant A...
[16:56:53]   Checking for file '/tmp/.../r'                  [ Not found ]
[16:56:53]   Checking for file '/tmp/.../a'                  [ Not found ]
[16:56:53] 55808 Trojan - Variant A                          [ Not found ]
[16:56:53]
[16:56:53] Checking for ADM Worm...
[16:56:53]   Checking for string 'w0rm'                      [ Not found ]
[16:56:53] ADM Worm                                          [ Not found ]
[16:56:53]
[16:56:53] Checking for AjaKit Rootkit...
[16:56:53]   Checking for file '/dev/tux/.addr'              [ Not found ]
[16:56:53]   Checking for file '/dev/tux/.proc'              [ Not found ]
[16:56:53]   Checking for file '/dev/tux/.file'              [ Not found ]
[16:56:53]   Checking for file '/lib/.libgh-gh/cleaner'      [ Not found ]
[16:56:53]   Checking for file '/lib/.libgh-gh/Patch/patch'  [ Not found ]
[16:56:53]   Checking for file '/lib/.libgh-gh/sb0k'         [ Not found ]
[16:56:53]   Checking for directory '/dev/tux'               [ Not found ]
[16:56:53]   Checking for directory '/lib/.libgh-gh'         [ Not found ]
[16:56:53] AjaKit Rootkit                                    [ Not found ]
[16:56:53]
[16:56:53] Checking for Adore Rootkit...
[16:56:53]   Checking for file '/usr/secure'                 [ Not found ]
[16:56:53]   Checking for file '/usr/doc/sys/qrt'            [ Not found ]
[16:56:53]   Checking for file '/usr/doc/sys/run'            [ Not found ]
[16:56:53]   Checking for file '/usr/doc/sys/crond'          [ Not found ]
[16:56:53]   Checking for file '/usr/sbin/kfd'               [ Not found ]
[16:56:53]   Checking for file '/usr/doc/kern/var'           [ Not found ]
[16:56:53]   Checking for file '/usr/doc/kern/string.o'      [ Not found ]
[16:56:53]   Checking for file '/usr/doc/kern/ava'           [ Not found ]
[16:56:53]   Checking for file '/usr/doc/kern/adore.o'       [ Not found ]
[16:56:53]   Checking for file '/var/log/ssh/old'            [ Not found ]
[16:56:54]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[16:56:54]   Checking for directory '/usr/doc/kern'          [ Not found ]
[16:56:54]   Checking for directory '/usr/doc/backup'        [ Not found ]
[16:56:54]   Checking for directory '/usr/doc/backup/txt'    [ Not found ]
[16:56:54]   Checking for directory '/lib/backup'            [ Not found ]
[16:56:54]   Checking for directory '/lib/backup/txt'        [ Not found ]
[16:56:54]   Checking for directory '/usr/doc/work'          [ Not found ]
[16:56:54]   Checking for directory '/usr/doc/sys'           [ Not found ]
[16:56:54]   Checking for directory '/var/log/ssh'           [ Not found ]
[16:56:54]   Checking for directory '/usr/doc/.spool'        [ Not found ]
[16:56:54]   Checking for directory '/usr/lib/kterm'         [ Not found ]
[16:56:54] Adore Rootkit                                     [ Not found ]
[16:56:54]
[16:56:54] Checking for aPa Kit...
[16:56:54]   Checking for file '/usr/share/.aPa'             [ Not found ]
[16:56:54] aPa Kit                                           [ Not found ]
[16:56:54]
[16:56:54] Checking for Apache Worm...
[16:56:54]   Checking for file '/bin/.log'                   [ Not found ]
[16:56:54] Apache Worm                                       [ Not found ]
[16:56:54]
[16:56:54] Checking for Ambient (ark) Rootkit...
[16:56:54]   Checking for file '/usr/lib/.ark?'              [ Not found ]
[16:56:54]   Checking for file '/dev/ptyxx/.log'             [ Not found ]
[16:56:54]   Checking for file '/dev/ptyxx/.file'            [ Not found ]
[16:56:54]   Checking for file '/dev/ptyxx/.proc'            [ Not found ]
[16:56:55]   Checking for file '/dev/ptyxx/.addr'            [ Not found ]
[16:56:55]   Checking for directory '/dev/ptyxx'             [ Not found ]
[16:56:55] Ambient (ark) Rootkit                             [ Not found ]
[16:56:55]
[16:56:55] Checking for Balaur Rootkit...
[16:56:55]   Checking for file '/usr/lib/liblog.o'           [ Not found ]
[16:56:55]   Checking for directory '/usr/lib/.kinetic'      [ Not found ]
[16:56:55]   Checking for directory '/usr/lib/.egcs'         [ Not found ]
[16:56:55]   Checking for directory '/usr/lib/.wormie'       [ Not found ]
[16:56:55] Balaur Rootkit                                    [ Not found ]
[16:56:55]
[16:56:55] Checking for BeastKit Rootkit...
[16:56:55]   Checking for file '/usr/sbin/arobia'            [ Not found ]
[16:56:55]   Checking for file '/usr/sbin/idrun'             [ Not found ]
[16:56:55]   Checking for file '/usr/lib/elm/arobia/elm'     [ Not found ]
[16:56:55]   Checking for file '/usr/lib/elm/arobia/elm/hk'  [ Not found ]
[16:56:55]   Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
[16:56:55]   Checking for file '/usr/lib/elm/arobia/elm/sc'  [ Not found ]
[16:56:55]   Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
[16:56:55]   Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
[16:56:55]   Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
[16:56:55]   Checking for directory '/lib/ldd.so/bktools'    [ Not found ]
[16:56:55] BeastKit Rootkit                                  [ Not found ]
[16:56:55]
[16:56:55] Checking for beX2 Rootkit...
[16:56:55]   Checking for file '/usr/info/termcap.info-5.gz' [ Not found ]
[16:56:55]   Checking for file '/usr/bin/sshd2'              [ Not found ]
[16:56:55]   Checking for directory '/usr/include/bex'       [ Not found ]
[16:56:55] beX2 Rootkit                                      [ Not found ]
[16:56:55]
[16:56:55] Checking for BOBKit Rootkit...
[16:56:55]   Checking for file '/usr/sbin/ntpsx'             [ Not found ]
[16:56:55]   Checking for file '/usr/sbin/.../bkit-ava'      [ Not found ]
[16:56:55]   Checking for file '/usr/sbin/.../bkit-d'        [ Not found ]
[16:56:56]   Checking for file '/usr/sbin/.../bkit-shd'      [ Not found ]
[16:56:56]   Checking for file '/usr/sbin/.../bkit-f'        [ Not found ]
[16:56:56]   Checking for file '/usr/include/.../proc.h'     [ Not found ]
[16:56:56]   Checking for file '/usr/include/.../.bash_history' [ Not found ]
[16:56:56]   Checking for file '/usr/include/.../bkit-get'   [ Not found ]
[16:56:56]   Checking for file '/usr/include/.../bkit-dl'    [ Not found ]
[16:56:56]   Checking for file '/usr/include/.../bkit-screen' [ Not found ]
[16:56:56]   Checking for file '/usr/include/.../bkit-sleep' [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../bkit-adore.o'   [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../ls'             [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../netstat'        [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../lsof'           [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../bkit-ssh/bkit-mots' [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../uconf.inv'      [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../psr'            [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../find'           [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../pstree'         [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../slocate'        [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../du'             [ Not found ]
[16:56:56]   Checking for file '/usr/lib/.../top'            [ Not found ]
[16:56:56]   Checking for directory '/usr/sbin/...'          [ Not found ]
[16:56:56]   Checking for directory '/usr/include/...'       [ Not found ]
[16:56:56]   Checking for directory '/usr/include/.../.tmp'  [ Not found ]
[16:56:57]   Checking for directory '/usr/lib/...'           [ Not found ]
[16:56:57]   Checking for directory '/usr/lib/.../.ssh'      [ Not found ]
[16:56:57]   Checking for directory '/usr/lib/.../bkit-ssh'  [ Not found ]
[16:56:57]   Checking for directory '/usr/lib/.bkit-'        [ Not found ]
[16:56:57]   Checking for directory '/tmp/.bkp'              [ Not found ]
[16:56:57] BOBKit Rootkit                                    [ Not found ]
[16:56:57]
[16:56:57] Checking for cb Rootkit...
[16:56:57]   Checking for file '/dev/srd0'                   [ Not found ]
[16:56:57]   Checking for file '/lib/libproc.so.2.0.6'       [ Not found ]
[16:56:57]   Checking for file '/dev/mounnt'                 [ Not found ]
[16:56:57]   Checking for file '/etc/rc.d/init.d/init'       [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/cl'    [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/.x.tgz' [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/statdx' [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/wted'  [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/write' [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/scan'  [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/sc'    [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/sl2'   [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/wroot' [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/wscan' [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/wu'    [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/v'     [ Not found ]
[16:56:57]   Checking for file '/usr/bin/.zeen/..<SP>/read'  [ Not found ]
[16:56:57]   Checking for file '/usr/lib/sshrc'              [ Not found ]
[16:56:57]   Checking for file '/usr/lib/ssh_host_key'       [ Not found ]
[16:56:57]   Checking for file '/usr/lib/ssh_host_key.pub'   [ Not found ]
[16:56:58]   Checking for file '/usr/lib/ssh_random_seed'    [ Not found ]
[16:56:58]   Checking for file '/usr/lib/sshd_config'        [ Not found ]
[16:56:58]   Checking for file '/usr/lib/shosts.equiv'       [ Not found ]
[16:56:58]   Checking for file '/usr/lib/ssh_known_hosts'    [ Not found ]
[16:56:58]   Checking for file '/u/zappa/.ssh/pid'           [ Not found ]
[16:56:58]   Checking for file '/usr/bin/.system/..<SP>/tcp.log' [ Not found ]
[16:56:58]   Checking for file '/usr/bin/.zeen/..<SP>/curatare/attrib' [ Not found ]
[16:56:58]   Checking for file '/usr/bin/.zeen/..<SP>/curatare/chattr' [ Not found ]
[16:56:58]   Checking for file '/usr/bin/.zeen/..<SP>/curatare/ps' [ Not found ]
[16:56:58]   Checking for file '/usr/bin/.zeen/..<SP>/curatare/pstree' [ Not found ]
[16:56:58]   Checking for file '/usr/bin/.system/..<SP>/.x/xC.o' [ Not found ]
[16:56:58]   Checking for directory '/usr/bin/.zeen'         [ Not found ]
[16:56:58]   Checking for directory '/usr/bin/.zeen/..<SP>/curatare' [ Not found ]
[16:56:58]   Checking for directory '/usr/bin/.zeen/..<SP>/scan' [ Not found ]
[16:56:58]   Checking for directory '/usr/bin/.system/..<SP>' [ Not found ]
[16:56:58] cb Rootkit                                        [ Not found ]
[16:56:58]
[16:56:58] Checking for CiNIK Worm (Slapper.B variant)...
[16:56:58]   Checking for file '/tmp/.cinik'                 [ Not found ]
[16:56:58]   Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
[16:56:58] CiNIK Worm (Slapper.B variant)                    [ Not found ]
[16:56:58]
[16:56:58] Checking for Danny-Boy's Abuse Kit...
[16:56:58]   Checking for file '/dev/mdev'                   [ Not found ]
[16:56:58]   Checking for file '/usr/lib/libX.a'             [ Not found ]
[16:56:58] Danny-Boy's Abuse Kit                             [ Not found ]
[16:56:58]
[16:56:58] Checking for Devil RootKit...
[16:56:58]   Checking for file '/var/lib/games/.src'         [ Not found ]
[16:56:58]   Checking for file '/dev/dsx'                    [ Not found ]
[16:56:58]   Checking for file '/dev/caca'                   [ Not found ]
[16:56:58]   Checking for file '/dev/pro'                    [ Not found ]
[16:56:58]   Checking for file '/bin/bye'                    [ Not found ]
[16:56:59]   Checking for file '/bin/homedir'                [ Not found ]
[16:56:59]   Checking for file '/usr/bin/xfss'               [ Not found ]
[16:56:59]   Checking for file '/usr/sbin/tzava'             [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/holber' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/sense' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/clear' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/tzava' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/citeste' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/killrk' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/searchlog' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/gaoaza' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/cleaner' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/shk' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/srs' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/utile.tgz' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/webpage' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/getpsy' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/getbnc' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/getemech' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/localroot.sh' [ Not found ]
[16:56:59]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/old/sense' [ Not found ]
[16:56:59]   Checking for directory '/usr/doc/tar/.../.dracusor' [ Not found ]
[16:56:59] Devil RootKit                                     [ Not found ]
[16:56:59]
[16:56:59] Checking for Dica-Kit Rootkit...
[16:56:59]   Checking for file '/lib/.sso'                   [ Not found ]
[16:56:59]   Checking for file '/lib/.so'                    [ Not found ]
[16:56:59]   Checking for file '/var/run/...dica/clean'      [ Not found ]
[16:56:59]   Checking for file '/var/run/...dica/dxr'        [ Not found ]
[16:56:59]   Checking for file '/var/run/...dica/read'       [ Not found ]
[16:57:00]   Checking for file '/var/run/...dica/write'      [ Not found ]
[16:57:00]   Checking for file '/var/run/...dica/lf'         [ Not found ]
[16:57:00]   Checking for file '/var/run/...dica/xl'         [ Not found ]
[16:57:00]   Checking for file '/var/run/...dica/xdr'        [ Not found ]
[16:57:00]   Checking for file '/var/run/...dica/psg'        [ Not found ]
[16:57:00]   Checking for file '/var/run/...dica/secure'     [ Not found ]
[16:57:00]   Checking for file '/var/run/...dica/rdx'        [ Not found ]
[16:57:00]   Checking for file '/var/run/...dica/va'         [ Not found ]
[16:57:00]   Checking for file '/var/run/...dica/cl.sh'      [ Not found ]
[16:57:00]   Checking for file '/var/run/...dica/last.log'   [ Not found ]
[16:57:00]   Checking for file '/usr/bin/.etc'               [ Not found ]
[16:57:00]   Checking for file '/etc/sshd_config'            [ Not found ]
[16:57:00]   Checking for file '/etc/ssh_host_key'           [ Not found ]
[16:57:00]   Checking for file '/etc/ssh_random_seed'        [ Not found ]
[16:57:00]   Checking for directory '/var/run/...dica'       [ Not found ]
[16:57:00]   Checking for directory '/var/run/...dica/mh'    [ Not found ]
[16:57:00]   Checking for directory '/var/run/...dica/scan'  [ Not found ]
[16:57:00] Dica-Kit Rootkit                                  [ Not found ]
[16:57:00]
[16:57:00] Checking for Dreams Rootkit...
[16:57:00]   Checking for file '/dev/ttyoa'                  [ Not found ]
[16:57:00]   Checking for file '/dev/ttyof'                  [ Not found ]
[16:57:00]   Checking for file '/dev/ttyop'                  [ Not found ]
[16:57:00]   Checking for file '/usr/bin/sense'              [ Not found ]
[16:57:00]   Checking for file '/usr/bin/sl2'                [ Not found ]
[16:57:00]   Checking for file '/usr/bin/logclear'           [ Not found ]
[16:57:00]   Checking for file '/usr/bin/(swapd)'            [ Not found ]
[16:57:00]   Checking for file '/usr/bin/initrd'             [ Not found ]
[16:57:00]   Checking for file '/usr/bin/crontabs'           [ Not found ]
[16:57:00]   Checking for file '/usr/bin/snfs'               [ Not found ]
[16:57:01]   Checking for file '/usr/lib/libsss'             [ Not found ]
[16:57:01]   Checking for file '/usr/lib/libsnf.log'         [ Not found ]
[16:57:01]   Checking for file '/usr/lib/libshtift/top'      [ Not found ]
[16:57:01]   Checking for file '/usr/lib/libshtift/ps'       [ Not found ]
[16:57:01]   Checking for file '/usr/lib/libshtift/netstat'  [ Not found ]
[16:57:01]   Checking for file '/usr/lib/libshtift/ls'       [ Not found ]
[16:57:01]   Checking for file '/usr/lib/libshtift/ifconfig' [ Not found ]
[16:57:01]   Checking for file '/usr/include/linseed.h'      [ Not found ]
[16:57:01]   Checking for file '/usr/include/linpid.h'       [ Not found ]
[16:57:01]   Checking for file '/usr/include/linkey.h'       [ Not found ]
[16:57:01]   Checking for file '/usr/include/linconf.h'      [ Not found ]
[16:57:01]   Checking for file '/usr/include/iceseed.h'      [ Not found ]
[16:57:01]   Checking for file '/usr/include/icepid.h'       [ Not found ]
[16:57:01]   Checking for file '/usr/include/icekey.h'       [ Not found ]
[16:57:01]   Checking for file '/usr/include/iceconf.h'      [ Not found ]
[16:57:01]   Checking for directory '/dev/ida/.hpd'          [ Not found ]
[16:57:01]   Checking for directory '/usr/lib/libshtift'     [ Not found ]
[16:57:01] Dreams Rootkit                                    [ Not found ]
[16:57:01]
[16:57:01] Checking for Duarawkz Rootkit...
[16:57:01]   Checking for file '/usr/bin/duarawkz/loginpass' [ Not found ]
[16:57:01]   Checking for directory '/usr/bin/duarawkz'      [ Not found ]
[16:57:01] Duarawkz Rootkit                                  [ Not found ]
[16:57:01]
[16:57:01] Checking for Enye LKM...
[16:57:01]   Checking for file '/etc/.enyelkmHIDE^IT.ko'     [ Not found ]
[16:57:01]   Checking for file '/etc/.enyelkmOCULTAR.ko'     [ Not found ]
[16:57:01] Enye LKM                                          [ Not found ]
[16:57:01]
[16:57:01] Checking for Flea Linux Rootkit...
[16:57:01]   Checking for file '/etc/ld.so.hash'             [ Not found ]
[16:57:01]   Checking for file '/lib/security/.config/ssh/sshd_config' [ Not found ]
[16:57:01]   Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[16:57:01]   Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[16:57:02]   Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[16:57:02]   Checking for file '/usr/bin/ssh2d'              [ Not found ]
[16:57:02]   Checking for file '/usr/lib/ldlibns.so'         [ Not found ]
[16:57:02]   Checking for file '/usr/lib/ldlibps.so'         [ Not found ]
[16:57:02]   Checking for file '/usr/lib/ldlibpst.so'        [ Not found ]
[16:57:02]   Checking for file '/usr/lib/ldlibdu.so'         [ Not found ]
[16:57:02]   Checking for file '/usr/lib/ldlibct.so'         [ Not found ]
[16:57:02]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[16:57:02]   Checking for directory '/dev/..0'               [ Not found ]
[16:57:02]   Checking for directory '/dev/..0/backup'        [ Not found ]
[16:57:02] Flea Linux Rootkit                                [ Not found ]
[16:57:02]
[16:57:02] Checking for Fu Rootkit...
[16:57:02]   Checking for file '/sbin/xc'                    [ Not found ]
[16:57:02]   Checking for file '/usr/include/ivtype.h'       [ Not found ]
[16:57:02]   Checking for file '/bin/.lib'                   [ Not found ]
[16:57:02] Fu Rootkit                                        [ Not found ]
[16:57:02]
[16:57:02] Checking for Fuck`it Rootkit...
[16:57:02]   Checking for file '/lib/libproc.so.2.0.7'       [ Not found ]
[16:57:02]   Checking for file '/dev/proc/.bash_profile'     [ Not found ]
[16:57:02]   Checking for file '/dev/proc/.bashrc'           [ Not found ]
[16:57:02]   Checking for file '/dev/proc/.cshrc'            [ Not found ]
[16:57:02]   Checking for file '/dev/proc/fuckit/hax0r'      [ Not found ]
[16:57:02]   Checking for file '/dev/proc/fuckit/hax0rshell' [ Not found ]
[16:57:02]   Checking for file '/dev/proc/fuckit/config/lports' [ Not found ]
[16:57:02]   Checking for file '/dev/proc/fuckit/config/rports' [ Not found ]
[16:57:02]   Checking for file '/dev/proc/fuckit/config/rkconf' [ Not found ]
[16:57:02]   Checking for file '/dev/proc/fuckit/config/password' [ Not found ]
[16:57:02]   Checking for file '/dev/proc/fuckit/config/progs' [ Not found ]
[16:57:02]   Checking for file '/dev/proc/fuckit/system-bins/init' [ Not found ]
[16:57:02]   Checking for file '/usr/lib/libcps.a'           [ Not found ]
[16:57:02]   Checking for file '/usr/lib/libtty.a'           [ Not found ]
[16:57:03]   Checking for directory '/dev/proc'              [ Not found ]
[16:57:03]   Checking for directory '/dev/proc/fuckit'       [ Not found ]
[16:57:03]   Checking for directory '/dev/proc/fuckit/system-bins' [ Not found ]
[16:57:03]   Checking for directory '/dev/proc/toolz'        [ Not found ]
[16:57:03] Fuck`it Rootkit                                   [ Not found ]
[16:57:03]
[16:57:03] Checking for GasKit Rootkit...
[16:57:03]   Checking for file '/dev/dev/gaskit/sshd/sshdd'  [ Not found ]
[16:57:03]   Checking for directory '/dev/dev'               [ Not found ]
[16:57:03]   Checking for directory '/dev/dev/gaskit'        [ Not found ]
[16:57:03]   Checking for directory '/dev/dev/gaskit/sshd'   [ Not found ]
[16:57:03] GasKit Rootkit                                    [ Not found ]
[16:57:03]
[16:57:03] Checking for Heroin LKM...
[16:57:03]   Checking for kernel symbol 'heroin'             [ Not found ]
[16:57:03] Heroin LKM                                        [ Not found ]
[16:57:03]
[16:57:03] Checking for HjC Kit...
[16:57:03]   Checking for directory '/dev/.hijackerz'        [ Not found ]
[16:57:03] HjC Kit                                           [ Not found ]
[16:57:03]
[16:57:03] Checking for ignoKit Rootkit...
[16:57:03]   Checking for file '/lib/defs/p'                 [ Not found ]
[16:57:03]   Checking for file '/lib/defs/q'                 [ Not found ]
[16:57:03]   Checking for file '/lib/defs/r'                 [ Not found ]
[16:57:03]   Checking for file '/lib/defs/s'                 [ Not found ]
[16:57:03]   Checking for file '/lib/defs/t'                 [ Not found ]
[16:57:03]   Checking for file '/usr/lib/defs/p'             [ Not found ]
[16:57:03]   Checking for file '/usr/lib/defs/q'             [ Not found ]
[16:57:03]   Checking for file '/usr/lib/defs/r'             [ Not found ]
[16:57:03]   Checking for file '/usr/lib/defs/s'             [ Not found ]
[16:57:03]   Checking for file '/usr/lib/defs/t'             [ Not found ]
[16:57:03]   Checking for file '/usr/lib/.libigno/pkunsec'   [ Not found ]
[16:57:03]   Checking for file '/usr/lib/.libigno/.igno/psybnc/psybnc' [ Not found ]
[16:57:04]   Checking for directory '/usr/lib/.libigno'      [ Not found ]
[16:57:04]   Checking for directory '/usr/lib/.libigno/.igno' [ Not found ]
[16:57:04] ignoKit Rootkit                                   [ Not found ]
[16:57:04]
[16:57:04] Checking for IntoXonia-NG Rootkit...
[16:57:04]   Checking for kernel symbol 'funces'             [ Not found ]
[16:57:04]   Checking for kernel symbol 'ixinit'             [ Not found ]
[16:57:04]   Checking for kernel symbol 'tricks'             [ Not found ]
[16:57:04]   Checking for kernel symbol 'kernel_unlink'      [ Not found ]
[16:57:04]   Checking for kernel symbol 'rootme'             [ Not found ]
[16:57:04]   Checking for kernel symbol 'hide_module'        [ Not found ]
[16:57:05]   Checking for kernel symbol 'find_sys_call_tbl'  [ Not found ]
[16:57:05] IntoXonia-NG Rootkit                              [ Not found ]
[16:57:05]
[16:57:05] Checking for Irix Rootkit...
[16:57:05]   Checking for directory '/dev/pts/01'            [ Not found ]
[16:57:05]   Checking for directory '/dev/pts/01/backup'     [ Not found ]
[16:57:05]   Checking for directory '/dev/pts/01/etc'        [ Not found ]
[16:57:05]   Checking for directory '/dev/pts/01/tmp'        [ Not found ]
[16:57:05] Irix Rootkit                                      [ Not found ]
[16:57:05]
[16:57:05] Checking for Jynx Rootkit...
[16:57:05]   Checking for file '/xochikit/bc'                [ Not found ]
[16:57:05]   Checking for file '/xochikit/ld_poison.so'      [ Not found ]
[16:57:05]   Checking for file '/omgxochi/bc'                [ Not found ]
[16:57:05]   Checking for file '/omgxochi/ld_poison.so'      [ Not found ]
[16:57:05]   Checking for file '/var/local/^^/bc'            [ Not found ]
[16:57:05]   Checking for file '/var/local/^^/ld_poison.so'  [ Not found ]
[16:57:05]   Checking for directory '/xochikit'              [ Not found ]
[16:57:05]   Checking for directory '/omgxochi'              [ Not found ]
[16:57:05]   Checking for directory '/var/local/^^'          [ Not found ]
[16:57:05] Jynx Rootkit                                      [ Not found ]
[16:57:05]
[16:57:05] Checking for KBeast Rootkit...
[16:57:05]   Checking for file '/usr/_h4x_/ipsecs-kbeast-v1.ko' [ Not found ]
[16:57:05]   Checking for file '/usr/_h4x_/_h4x_bd'          [ Not found ]
[16:57:05]   Checking for file '/usr/_h4x_/acctlog'          [ Not found ]
[16:57:05]   Checking for directory '/usr/_h4x_'             [ Not found ]
[16:57:06]   Checking for kernel symbol 'h4x_delete_module'  [ Not found ]
[16:57:06]   Checking for kernel symbol 'h4x_getdents64'     [ Not found ]
[16:57:06]   Checking for kernel symbol 'h4x_kill'           [ Not found ]
[16:57:06]   Checking for kernel symbol 'h4x_open'           [ Not found ]
[16:57:06]   Checking for kernel symbol 'h4x_read'           [ Not found ]
[16:57:06]   Checking for kernel symbol 'h4x_rename'         [ Not found ]
[16:57:06]   Checking for kernel symbol 'h4x_rmdir'          [ Not found ]
[16:57:07]   Checking for kernel symbol 'h4x_tcp4_seq_show'  [ Not found ]
[16:57:07]   Checking for kernel symbol 'h4x_write'          [ Not found ]
[16:57:07] KBeast Rootkit                                    [ Not found ]
[16:57:07]
[16:57:07] Checking for Kitko Rootkit...
[16:57:07]   Checking for directory '/usr/src/redhat/SRPMS/...' [ Not found ]
[16:57:07] Kitko Rootkit                                     [ Not found ]
[16:57:07]
[16:57:07] Checking for Knark Rootkit...
[16:57:07]   Checking for file '/proc/knark/pids'            [ Not found ]
[16:57:07]   Checking for directory '/proc/knark'            [ Not found ]
[16:57:07] Knark Rootkit                                     [ Not found ]
[16:57:07]
[16:57:07] Checking for ld-linuxv.so Rootkit...
[16:57:07]   Checking for file '/lib/ld-linuxv.so.1'         [ Not found ]
[16:57:07]   Checking for directory '/var/opt/_so_cache'     [ Not found ]
[16:57:07]   Checking for directory '/var/opt/_so_cache/ld'  [ Not found ]
[16:57:07]   Checking for directory '/var/opt/_so_cache/lc'  [ Not found ]
[16:57:07] ld-linuxv.so Rootkit                              [ Not found ]
[16:57:07]
[16:57:07] Checking for Li0n Worm...
[16:57:07]   Checking for file '/bin/in.telnetd'             [ Not found ]
[16:57:07]   Checking for file '/bin/mjy'                    [ Not found ]
[16:57:07]   Checking for file '/usr/man/man1/man1/lib/.lib/mjy' [ Not found ]
[16:57:07]   Checking for file '/usr/man/man1/man1/lib/.lib/in.telnetd' [ Not found ]
[16:57:07]   Checking for file '/usr/man/man1/man1/lib/.lib/.x' [ Not found ]
[16:57:07]   Checking for file '/dev/.lib/lib/scan/1i0n.sh'  [ Not found ]
[16:57:07]   Checking for file '/dev/.lib/lib/scan/hack.sh'  [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/scan/bind'     [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/scan/randb'    [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/scan/scan.sh'  [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/scan/pscan'    [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/scan/star.sh'  [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/scan/bindx.sh' [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/scan/bindname.log' [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/1i0n.sh'       [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/lib/netstat'   [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/lib/dev/.1addr' [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/lib/dev/.1logz' [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/lib/dev/.1proc' [ Not found ]
[16:57:08]   Checking for file '/dev/.lib/lib/lib/dev/.1file' [ Not found ]
[16:57:08] Li0n Worm                                         [ Not found ]
[16:57:08]
[16:57:08] Checking for Lockit / LJK2 Rootkit...
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_config' [ Not found ]
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key' [ Not found ]
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub' [ Not found ]
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_random_seed*' [ Not found ]
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/sshd_config' [ Not found ]
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd' [ Not found ]
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/du' [ Not found ]
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ifconfig' [ Not found ]
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/inetd.conf' [ Not found ]
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/locate' [ Not found ]
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/login' [ Not found ]
[16:57:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ls' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/netstat' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ps' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/pstree' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/syslogd' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/tcpd' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/top' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1sauber' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1wted' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1parse' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1sniff' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1addr' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1dir' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1log' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1proc' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/README.modules' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1phide' [ Not found ]
[16:57:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh' [ Not found ]
[16:57:09]   Checking for directory '/usr/lib/libmen.oo/.LJK2' [ Not found ]
[16:57:09] Lockit / LJK2 Rootkit                             [ Not found ]
[16:57:09]
[16:57:09] Checking for Mood-NT Rootkit...
[16:57:09]   Checking for file '/sbin/init__mood-nt-_-_cthulhu' [ Not found ]
[16:57:09]   Checking for file '/_cthulhu/mood-nt.init'      [ Not found ]
[16:57:09]   Checking for file '/_cthulhu/mood-nt.conf'      [ Not found ]
[16:57:09]   Checking for file '/_cthulhu/mood-nt.sniff'     [ Not found ]
[16:57:09]   Checking for directory '/_cthulhu'              [ Not found ]
[16:57:10] Mood-NT Rootkit                                   [ Not found ]
[16:57:10]
[16:57:10] Checking for MRK Rootkit...
[16:57:10]   Checking for file '/dev/ida/.inet/pid'          [ Not found ]
[16:57:10]   Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[16:57:10]   Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[16:57:10]   Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
[16:57:10]   Checking for directory '/dev/ida/.inet'         [ Not found ]
[16:57:10]   Checking for directory '/var/spool/cron/.sh'    [ Not found ]
[16:57:10] MRK Rootkit                                       [ Not found ]
[16:57:10]
[16:57:10] Checking for Ni0 Rootkit...
[16:57:10]   Checking for file '/var/lock/subsys/...datafile.../...net...' [ Not found ]
[16:57:10]   Checking for file '/var/lock/subsys/...datafile.../...port...' [ Not found ]
[16:57:10]   Checking for file '/var/lock/subsys/...datafile.../...ps...' [ Not found ]
[16:57:10]   Checking for file '/var/lock/subsys/...datafile.../...file...' [ Not found ]
[16:57:10]   Checking for directory '/tmp/waza'              [ Not found ]
[16:57:10]   Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[16:57:10]   Checking for directory '/usr/sbin/es'           [ Not found ]
[16:57:10] Ni0 Rootkit                                       [ Not found ]
[16:57:10]
[16:57:10] Checking for Ohhara Rootkit...
[16:57:10]   Checking for file '/var/lock/subsys/...datafile.../...datafile.../in.smbd.log' [ Not found ]
[16:57:10]   Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[16:57:10]   Checking for directory '/var/lock/subsys/...datafile.../...datafile...' [ Not found ]
[16:57:10]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../bin' [ Not found ]
[16:57:10]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/bin' [ Not found ]
[16:57:10]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/sbin' [ Not found ]
[16:57:11]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../lib/security' [ Not found ]
[16:57:11] Ohhara Rootkit                                    [ Not found ]
[16:57:11]
[16:57:11] Checking for Optic Kit (Tux) Worm...
[16:57:11]   Checking for directory '/dev/tux'               [ Not found ]
[16:57:11]   Checking for directory '/usr/bin/xchk'          [ Not found ]
[16:57:11]   Checking for directory '/usr/bin/xsf'           [ Not found ]
[16:57:11]   Checking for directory '/usr/bin/ssh2d'         [ Not found ]
[16:57:11] Optic Kit (Tux) Worm                              [ Not found ]
[16:57:11]
[16:57:11] Checking for Oz Rootkit...
[16:57:11]   Checking for file '/dev/.oz/.nap/rkit/terror'   [ Not found ]
[16:57:11]   Checking for directory '/dev/.oz'               [ Not found ]
[16:57:11] Oz Rootkit                                        [ Not found ]
[16:57:11]
[16:57:11] Checking for Phalanx Rootkit...
[16:57:11]   Checking for file '/uNFuNF'                     [ Not found ]
[16:57:11]   Checking for file '/etc/host.ph1'               [ Not found ]
[16:57:11]   Checking for file '/bin/host.ph1'               [ Not found ]
[16:57:11]   Checking for file '/usr/share/.home.ph1/phalanx' [ Not found ]
[16:57:11]   Checking for file '/usr/share/.home.ph1/cb'     [ Not found ]
[16:57:11]   Checking for file '/usr/share/.home.ph1/kebab'  [ Not found ]
[16:57:11]   Checking for directory '/usr/share/.home.ph1'   [ Not found ]
[16:57:11]   Checking for directory '/usr/share/.home.ph1/tty' [ Not found ]
[16:57:11] Phalanx Rootkit                                   [ Not found ]
[16:57:11]
[16:57:11] Checking for Phalanx2 Rootkit...
[16:57:11]   Checking for file '/etc/khubd.p2/.p2rc'         [ Not found ]
[16:57:11]   Checking for file '/etc/khubd.p2/.phalanx2'     [ Not found ]
[16:57:11]   Checking for file '/etc/khubd.p2/.sniff'        [ Not found ]
[16:57:11]   Checking for file '/etc/khubd.p2/sshgrab.py'    [ Not found ]
[16:57:12]   Checking for file '/etc/lolzz.p2/.p2rc'         [ Not found ]
[16:57:12]   Checking for file '/etc/lolzz.p2/.phalanx2'     [ Not found ]
[16:57:12]   Checking for file '/etc/lolzz.p2/.sniff'        [ Not found ]
[16:57:12]   Checking for file '/etc/lolzz.p2/sshgrab.py'    [ Not found ]
[16:57:12]   Checking for file '/etc/cron.d/zupzzplaceholder' [ Not found ]
[16:57:12]   Checking for file '/usr/lib/zupzz.p2/.p-2.3d'   [ Not found ]
[16:57:12]   Checking for file '/usr/lib/zupzz.p2/.p2rc'     [ Not found ]
[16:57:12]   Checking for directory '/etc/khubd.p2'          [ Not found ]
[16:57:12]   Checking for directory '/etc/lolzz.p2'          [ Not found ]
[16:57:12]   Checking for directory '/usr/lib/zupzz.p2'      [ Not found ]
[16:57:12] Phalanx2 Rootkit                                  [ Not found ]
[16:57:12]
[16:57:12] Checking for Phalanx2 Rootkit (extended tests)...
[16:57:12]   Checking for directory '/etc/khubd.p2'          [ Not found ]
[16:57:12]   Checking for directory '/etc/lolzz.p2'          [ Not found ]
[16:57:12]   Checking for directory '/usr/lib/zupzz.p2'      [ Not found ]
[16:57:12] Phalanx2 Rootkit (extended tests)                 [ Not found ]
[16:57:12]
[16:57:12] Checking for Portacelo Rootkit...
[16:57:12]   Checking for file '/var/lib/.../.ak'            [ Not found ]
[16:57:12]   Checking for file '/var/lib/.../.hk'            [ Not found ]
[16:57:12]   Checking for file '/var/lib/.../.rs'            [ Not found ]
[16:57:12]   Checking for file '/var/lib/.../.p'             [ Not found ]
[16:57:12]   Checking for file '/var/lib/.../getty'          [ Not found ]
[16:57:12]   Checking for file '/var/lib/.../lkt.o'          [ Not found ]
[16:57:12]   Checking for file '/var/lib/.../show'           [ Not found ]
[16:57:12]   Checking for file '/var/lib/.../nlkt.o'         [ Not found ]
[16:57:12]   Checking for file '/var/lib/.../ssshrc'         [ Not found ]
[16:57:12]   Checking for file '/var/lib/.../sssh_equiv'     [ Not found ]
[16:57:12]   Checking for file '/var/lib/.../sssh_known_hosts' [ Not found ]
[16:57:13]   Checking for file '/var/lib/.../sssh_pid'       [ Not found ]
[16:57:13]   Checking for file '~/.sssh/known_hosts'         [ Not found ]
[16:57:13] Portacelo Rootkit                                 [ Not found ]
[16:57:13]
[16:57:13] Checking for R3dstorm Toolkit...
[16:57:13]   Checking for file '/var/log/tk02/see_all'       [ Not found ]
[16:57:13]   Checking for file '/var/log/tk02/.scris'        [ Not found ]
[16:57:13]   Checking for file '/bin/.../sshd/sbin/sshd1'    [ Not found ]
[16:57:13]   Checking for file '/bin/.../hate/sk'            [ Not found ]
[16:57:13]   Checking for file '/bin/.../see_all'            [ Not found ]
[16:57:13]   Checking for directory '/var/log/tk02'          [ Not found ]
[16:57:13]   Checking for directory '/var/log/tk02/old'      [ Not found ]
[16:57:13]   Checking for directory '/bin/...'               [ Not found ]
[16:57:13] R3dstorm Toolkit                                  [ Not found ]
[16:57:13]
[16:57:13] Checking for RH-Sharpe's Rootkit...
[16:57:13]   Checking for file '/bin/lps'                    [ Not found ]
[16:57:13]   Checking for file '/usr/bin/lpstree'            [ Not found ]
[16:57:13]   Checking for file '/usr/bin/ltop'               [ Not found ]
[16:57:13]   Checking for file '/usr/bin/lkillall'           [ Not found ]
[16:57:13]   Checking for file '/usr/bin/ldu'                [ Not found ]
[16:57:13]   Checking for file '/usr/bin/lnetstat'           [ Not found ]
[16:57:13]   Checking for file '/usr/bin/wp'                 [ Not found ]
[16:57:13]   Checking for file '/usr/bin/shad'               [ Not found ]
[16:57:13]   Checking for file '/usr/bin/vadim'              [ Not found ]
[16:57:13]   Checking for file '/usr/bin/slice'              [ Not found ]
[16:57:13]   Checking for file '/usr/bin/cleaner'            [ Not found ]
[16:57:13]   Checking for file '/usr/include/rpcsvc/du'      [ Not found ]
[16:57:13] RH-Sharpe's Rootkit                               [ Not found ]
[16:57:13]
[16:57:13] Checking for RSHA's Rootkit...
[16:57:14]   Checking for file '/bin/kr4p'                   [ Not found ]
[16:57:14]   Checking for file '/usr/bin/n3tstat'            [ Not found ]
[16:57:14]   Checking for file '/usr/bin/chsh2'              [ Not found ]
[16:57:14]   Checking for file '/usr/bin/slice2'             [ Not found ]
[16:57:14]   Checking for file '/usr/src/linux/arch/alpha/lib/.lib/.1proc' [ Not found ]
[16:57:14]   Checking for file '/etc/rc.d/arch/alpha/lib/.lib/.1addr' [ Not found ]
[16:57:14]   Checking for directory '/etc/rc.d/rsha'         [ Not found ]
[16:57:14]   Checking for directory '/etc/rc.d/arch/alpha/lib/.lib' [ Not found ]
[16:57:14] RSHA's Rootkit                                    [ Not found ]
[16:57:14]
[16:57:14] Checking for Scalper Worm...
[16:57:14]   Checking for file '/tmp/.a'                     [ Not found ]
[16:57:14]   Checking for file '/tmp/.uua'                   [ Not found ]
[16:57:14] Scalper Worm                                      [ Not found ]
[16:57:14]
[16:57:14] Checking for Sebek LKM...
[16:57:14]   Checking for kernel symbol 'adore or sebek'     [ Not found ]
[16:57:14] Sebek LKM                                         [ Not found ]
[16:57:14]
[16:57:14] Checking for Shutdown Rootkit...
[16:57:14]   Checking for file '/usr/man/man5/..<SP>/.dir/scannah/asus' [ Not found ]
[16:57:14]   Checking for file '/usr/man/man5/..<SP>/.dir/see' [ Not found ]
[16:57:14]   Checking for file '/usr/man/man5/..<SP>/.dir/nscd' [ Not found ]
[16:57:14]   Checking for file '/usr/man/man5/..<SP>/.dir/alpd' [ Not found ]
[16:57:14]   Checking for file '/etc/rc.d/rc.local<SP>'      [ Not found ]
[16:57:14]   Checking for directory '/usr/man/man5/..<SP>/.dir' [ Not found ]
[16:57:14]   Checking for directory '/usr/man/man5/..<SP>/.dir/scannah' [ Not found ]
[16:57:14]   Checking for directory '/etc/rc.d/rc0.d/..<SP>/.dir' [ Not found ]
[16:57:14] Shutdown Rootkit                                  [ Not found ]
[16:57:14]
[16:57:14] Checking for SHV4 Rootkit...
[16:57:15]   Checking for file '/etc/ld.so.hash'             [ Not found ]
[16:57:15]   Checking for file '/lib/libext-2.so.7'          [ Not found ]
[16:57:15]   Checking for file '/lib/lidps1.so'              [ Not found ]
[16:57:15]   Checking for file '/lib/libproc.a'              [ Not found ]
[16:57:15]   Checking for file '/lib/libproc.so.2.0.6'       [ Not found ]
[16:57:15]   Checking for file '/lib/ldd.so/tks'             [ Not found ]
[16:57:15]   Checking for file '/lib/ldd.so/tkp'             [ Not found ]
[16:57:15]   Checking for file '/lib/ldd.so/tksb'            [ Not found ]
[16:57:15]   Checking for file '/lib/security/.config/sshd'  [ Not found ]
[16:57:15]   Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[16:57:15]   Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[16:57:15]   Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[16:57:15]   Checking for file '/usr/include/file.h'         [ Not found ]
[16:57:15]   Checking for file '/usr/include/hosts.h'        [ Not found ]
[16:57:15]   Checking for file '/usr/include/lidps1.so'      [ Not found ]
[16:57:15]   Checking for file '/usr/include/log.h'          [ Not found ]
[16:57:15]   Checking for file '/usr/include/proc.h'         [ Not found ]
[16:57:15]   Checking for file '/usr/sbin/xntps'             [ Not found ]
[16:57:15]   Checking for file '/dev/srd0'                   [ Not found ]
[16:57:15]   Checking for directory '/lib/ldd.so'            [ Not found ]
[16:57:15]   Checking for directory '/lib/security/.config'  [ Not found ]
[16:57:15]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[16:57:15] SHV4 Rootkit                                      [ Not found ]
[16:57:15]
[16:57:15] Checking for SHV5 Rootkit...
[16:57:15]   Checking for file '/etc/sh.conf'                [ Not found ]
[16:57:15]   Checking for file '/lib/libproc.a'              [ Not found ]
[16:57:16]   Checking for file '/lib/libproc.so.2.0.6'       [ Not found ]
[16:57:16]   Checking for file '/lib/lidps1.so'              [ Not found ]
[16:57:16]   Checking for file '/lib/libsh.so/bash'          [ Not found ]
[16:57:16]   Checking for file '/usr/include/file.h'         [ Not found ]
[16:57:16]   Checking for file '/usr/include/hosts.h'        [ Not found ]
[16:57:16]   Checking for file '/usr/include/log.h'          [ Not found ]
[16:57:16]   Checking for file '/usr/include/proc.h'         [ Not found ]
[16:57:16]   Checking for file '/lib/libsh.so/shdcf2'        [ Not found ]
[16:57:16]   Checking for file '/lib/libsh.so/shhk'          [ Not found ]
[16:57:16]   Checking for file '/lib/libsh.so/shhk.pub'      [ Not found ]
[16:57:16]   Checking for file '/lib/libsh.so/shrs'          [ Not found ]
[16:57:16]   Checking for file '/usr/lib/libsh/.bashrc'      [ Not found ]
[16:57:16]   Checking for file '/usr/lib/libsh/shsb'         [ Not found ]
[16:57:16]   Checking for file '/usr/lib/libsh/hide'         [ Not found ]
[16:57:16]   Checking for file '/usr/lib/libsh/.sniff/shsniff' [ Not found ]
[16:57:16]   Checking for file '/usr/lib/libsh/.sniff/shp'   [ Not found ]
[16:57:16]   Checking for file '/dev/srd0'                   [ Not found ]
[16:57:16]   Checking for directory '/lib/libsh.so'          [ Not found ]
[16:57:16]   Checking for directory '/usr/lib/libsh'         [ Not found ]
[16:57:16]   Checking for directory '/usr/lib/libsh/utilz'   [ Not found ]
[16:57:16]   Checking for directory '/usr/lib/libsh/.backup' [ Not found ]
[16:57:16] SHV5 Rootkit                                      [ Not found ]
[16:57:16]
[16:57:16] Checking for Sin Rootkit...
[16:57:16]   Checking for file '/dev/.haos/haos1/.f/Denyed'  [ Not found ]
[16:57:16]   Checking for file '/dev/ttyoa'                  [ Not found ]
[16:57:16]   Checking for file '/dev/ttyof'                  [ Not found ]
[16:57:17]   Checking for file '/dev/ttyop'                  [ Not found ]
[16:57:17]   Checking for file '/dev/ttyos'                  [ Not found ]
[16:57:17]   Checking for file '/usr/lib/.lib'               [ Not found ]
[16:57:17]   Checking for file '/usr/lib/sn/.X'              [ Not found ]
[16:57:17]   Checking for file '/usr/lib/sn/.sys'            [ Not found ]
[16:57:17]   Checking for file '/usr/lib/ld/.X'              [ Not found ]
[16:57:17]   Checking for file '/usr/man/man1/...'           [ Not found ]
[16:57:17]   Checking for file '/usr/man/man1/.../.m'        [ Not found ]
[16:57:17]   Checking for file '/usr/man/man1/.../.w'        [ Not found ]
[16:57:17]   Checking for directory '/usr/lib/sn'            [ Not found ]
[16:57:17]   Checking for directory '/usr/lib/man1/...'      [ Not found ]
[16:57:17]   Checking for directory '/dev/.haos'             [ Not found ]
[16:57:17] Sin Rootkit                                       [ Not found ]
[16:57:17]
[16:57:17] Checking for Slapper Worm...
[16:57:17]   Checking for file '/tmp/.bugtraq'               [ Not found ]
[16:57:17]   Checking for file '/tmp/.uubugtraq'             [ Not found ]
[16:57:17]   Checking for file '/tmp/.bugtraq.c'             [ Not found ]
[16:57:17]   Checking for file '/tmp/httpd'                  [ Not found ]
[16:57:17]   Checking for file '/tmp/.unlock'                [ Not found ]
[16:57:17]   Checking for file '/tmp/update'                 [ Not found ]
[16:57:17]   Checking for file '/tmp/.cinik'                 [ Not found ]
[16:57:17]   Checking for file '/tmp/.b'                     [ Not found ]
[16:57:17] Slapper Worm                                      [ Not found ]
[16:57:17]
[16:57:17] Checking for Sneakin Rootkit...
[16:57:17]   Checking for directory '/tmp/.X11-unix/.../rk'  [ Not found ]
[16:57:17] Sneakin Rootkit                                   [ Not found ]
[16:57:17]
[16:57:17] Checking for 'Spanish' Rootkit...
[16:57:17]   Checking for file '/dev/ptyq'                   [ Not found ]
[16:57:18]   Checking for file '/bin/ad'                     [ Not found ]
[16:57:18]   Checking for file '/bin/ava'                    [ Not found ]
[16:57:18]   Checking for file '/bin/server'                 [ Not found ]
[16:57:18]   Checking for file '/usr/sbin/rescue'            [ Not found ]
[16:57:18]   Checking for file '/usr/share/.../chrps'        [ Not found ]
[16:57:18]   Checking for file '/usr/share/.../chrifconfig'  [ Not found ]
[16:57:18]   Checking for file '/usr/share/.../netstat'      [ Not found ]
[16:57:18]   Checking for file '/usr/share/.../linsniffer'   [ Not found ]
[16:57:18]   Checking for file '/usr/share/.../charbd'       [ Not found ]
[16:57:18]   Checking for file '/usr/share/.../charbd2'      [ Not found ]
[16:57:18]   Checking for file '/usr/share/.../charbd3'      [ Not found ]
[16:57:18]   Checking for file '/usr/share/.../charbd4'      [ Not found ]
[16:57:18]   Checking for file '/usr/man/tmp/update.tgz'     [ Not found ]
[16:57:18]   Checking for file '/var/lib/rpm/db.rpm'         [ Not found ]
[16:57:18]   Checking for file '/var/cache/man/.cat'         [ Not found ]
[16:57:18]   Checking for file '/var/spool/lpd/remote/.lpq'  [ Not found ]
[16:57:18]   Checking for directory '/usr/share/...'         [ Not found ]
[16:57:18] 'Spanish' Rootkit                                 [ Not found ]
[16:57:18]
[16:57:18] Checking for Suckit Rootkit...
[16:57:18]   Checking for file '/sbin/initsk12'              [ Not found ]
[16:57:18]   Checking for file '/sbin/initxrk'               [ Not found ]
[16:57:18]   Checking for file '/usr/bin/null'               [ Not found ]
[16:57:18]   Checking for file '/usr/share/locale/sk/.sk12/sk' [ Not found ]
[16:57:18]   Checking for file '/etc/rc.d/rc0.d/S23kmdac'    [ Not found ]
[16:57:18]   Checking for file '/etc/rc.d/rc1.d/S23kmdac'    [ Not found ]
[16:57:18]   Checking for file '/etc/rc.d/rc2.d/S23kmdac'    [ Not found ]
[16:57:18]   Checking for file '/etc/rc.d/rc3.d/S23kmdac'    [ Not found ]
[16:57:19]   Checking for file '/etc/rc.d/rc4.d/S23kmdac'    [ Not found ]
[16:57:19]   Checking for file '/etc/rc.d/rc5.d/S23kmdac'    [ Not found ]
[16:57:19]   Checking for file '/etc/rc.d/rc6.d/S23kmdac'    [ Not found ]
[16:57:19]   Checking for directory '/dev/sdhu0/tehdrakg'    [ Not found ]
[16:57:19]   Checking for directory '/etc/.MG'               [ Not found ]
[16:57:19]   Checking for directory '/usr/share/locale/sk/.sk12' [ Not found ]
[16:57:19]   Checking for directory '/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist' [ Not found ]
[16:57:19] Suckit Rootkit                                    [ Not found ]
[16:57:19]
[16:57:19] Checking for Superkit Rootkit...
[16:57:19]   Checking for file '/usr/man/.sman/sk/backsh'    [ Not found ]
[16:57:19]   Checking for file '/usr/man/.sman/sk/izbtrag'   [ Not found ]
[16:57:19]   Checking for file '/usr/man/.sman/sk/sksniff'   [ Not found ]
[16:57:19]   Checking for file '/var/www/cgi-bin/cgiback.cgi' [ Not found ]
[16:57:19]   Checking for directory '/usr/man/.sman/sk'      [ Not found ]
[16:57:19] Superkit Rootkit                                  [ Not found ]
[16:57:19]
[16:57:19] Checking for TBD (Telnet BackDoor)...
[16:57:19]   Checking for file '/usr/lib/.tbd'               [ Not found ]
[16:57:19] TBD (Telnet BackDoor)                             [ Not found ]
[16:57:19]
[16:57:19] Checking for TeLeKiT Rootkit...
[16:57:19]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/sniff' [ Not found ]
[16:57:19]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/telnetd' [ Not found ]
[16:57:19]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/teleulo' [ Not found ]
[16:57:19]   Checking for file '/usr/man/man3/.../cl'        [ Not found ]
[16:57:19]   Checking for file '/dev/ptyr'                   [ Not found ]
[16:57:19]   Checking for file '/dev/ptyp'                   [ Not found ]
[16:57:20]   Checking for file '/dev/ptyq'                   [ Not found ]
[16:57:20]   Checking for file '/dev/hda06'                  [ Not found ]
[16:57:20]   Checking for file '/usr/info/libc1.so'          [ Not found ]
[16:57:20]   Checking for directory '/usr/man/man3/...'      [ Not found ]
[16:57:20]   Checking for directory '/usr/man/man3/.../lsniff' [ Not found ]
[16:57:20]   Checking for directory '/usr/man/man3/.../TeLeKiT' [ Not found ]
[16:57:20] TeLeKiT Rootkit                                   [ Not found ]
[16:57:20]
[16:57:20] Checking for T0rn Rootkit...
[16:57:20]   Checking for file '/dev/.lib/lib/lib/t0rns'     [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/du'        [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/ls'        [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/t0rnsb'    [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/ps'        [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/t0rnp'     [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/find'      [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/ifconfig'  [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/pg'        [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/ssh.tgz'   [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/top'       [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/sz'        [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/login'     [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/in.fingerd' [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/1i0n.sh'   [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/pstree'    [ Not found ]
[16:57:20]   Checking for file '/dev/.lib/lib/lib/in.telnetd' [ Not found ]
[16:57:21]   Checking for file '/dev/.lib/lib/lib/mjy'       [ Not found ]
[16:57:21]   Checking for file '/dev/.lib/lib/lib/sush'      [ Not found ]
[16:57:21]   Checking for file '/dev/.lib/lib/lib/tfn'       [ Not found ]
[16:57:21]   Checking for file '/dev/.lib/lib/lib/name'      [ Not found ]
[16:57:21]   Checking for file '/dev/.lib/lib/lib/getip.sh'  [ Not found ]
[16:57:21]   Checking for file '/usr/info/.torn/sh*'         [ Not found ]
[16:57:21]   Checking for file '/usr/src/.puta/.1addr'       [ Not found ]
[16:57:21]   Checking for file '/usr/src/.puta/.1file'       [ Not found ]
[16:57:21]   Checking for file '/usr/src/.puta/.1proc'       [ Not found ]
[16:57:21]   Checking for file '/usr/src/.puta/.1logz'       [ Not found ]
[16:57:21]   Checking for file '/usr/info/.t0rn'             [ Not found ]
[16:57:21]   Checking for directory '/dev/.lib'              [ Not found ]
[16:57:21]   Checking for directory '/dev/.lib/lib'          [ Not found ]
[16:57:21]   Checking for directory '/dev/.lib/lib/lib'      [ Not found ]
[16:57:21]   Checking for directory '/dev/.lib/lib/lib/dev'  [ Not found ]
[16:57:21]   Checking for directory '/dev/.lib/lib/scan'     [ Not found ]
[16:57:21]   Checking for directory '/usr/src/.puta'         [ Not found ]
[16:57:21]   Checking for directory '/usr/man/man1/man1'     [ Not found ]
[16:57:21]   Checking for directory '/usr/man/man1/man1/lib' [ Not found ]
[16:57:21]   Checking for directory '/usr/man/man1/man1/lib/.lib' [ Not found ]
[16:57:21]   Checking for directory '/usr/man/man1/man1/lib/.lib/.backup' [ Not found ]
[16:57:21] T0rn Rootkit                                      [ Not found ]
[16:57:21]
[16:57:21] Checking for trNkit Rootkit...
[16:57:21]   Checking for file '/usr/lib/libbins.la'         [ Not found ]
[16:57:22]   Checking for file '/usr/lib/libtcs.so'          [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/ulogin.sh'        [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/tcpshell.sh'      [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/bupdu'            [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/buloc'            [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/buloc1'           [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/buloc2'           [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/stat'             [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/backps'           [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/tree'             [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/topk'             [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/wold'             [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/whoold'           [ Not found ]
[16:57:22]   Checking for file '/dev/.ttpy/backdoors'        [ Not found ]
[16:57:22] trNkit Rootkit                                    [ Not found ]
[16:57:22]
[16:57:22] Checking for Trojanit Kit...
[16:57:22]   Checking for file '/bin/.ls'                    [ Not found ]
[16:57:22]   Checking for file '/bin/.ps'                    [ Not found ]
[16:57:22]   Checking for file '/bin/.netstat'               [ Not found ]
[16:57:22]   Checking for file '/usr/bin/.nop'               [ Not found ]
[16:57:22]   Checking for file '/usr/bin/.who'               [ Not found ]
[16:57:22] Trojanit Kit                                      [ Not found ]
[16:57:22]
[16:57:22] Checking for Tuxtendo Rootkit...
[16:57:22]   Checking for file '/lib/libproc.so.2.0.7'       [ Not found ]
[16:57:22]   Checking for file '/usr/bin/xchk'               [ Not found ]
[16:57:23]   Checking for file '/usr/bin/xsf'                [ Not found ]
[16:57:23]   Checking for file '/dev/tux/suidsh'             [ Not found ]
[16:57:23]   Checking for file '/dev/tux/.addr'              [ Not found ]
[16:57:23]   Checking for file '/dev/tux/.cron'              [ Not found ]
[16:57:23]   Checking for file '/dev/tux/.file'              [ Not found ]
[16:57:23]   Checking for file '/dev/tux/.log'               [ Not found ]
[16:57:23]   Checking for file '/dev/tux/.proc'              [ Not found ]
[16:57:23]   Checking for file '/dev/tux/.iface'             [ Not found ]
[16:57:23]   Checking for file '/dev/tux/.pw'                [ Not found ]
[16:57:23]   Checking for file '/dev/tux/.df'                [ Not found ]
[16:57:23]   Checking for file '/dev/tux/.ssh'               [ Not found ]
[16:57:23]   Checking for file '/dev/tux/.tux'               [ Not found ]
[16:57:23]   Checking for file '/dev/tux/ssh2/sshd2_config'  [ Not found ]
[16:57:23]   Checking for file '/dev/tux/ssh2/hostkey'       [ Not found ]
[16:57:23]   Checking for file '/dev/tux/ssh2/hostkey.pub'   [ Not found ]
[16:57:23]   Checking for file '/dev/tux/ssh2/logo'          [ Not found ]
[16:57:23]   Checking for file '/dev/tux/ssh2/random_seed'   [ Not found ]
[16:57:23]   Checking for file '/dev/tux/backup/crontab'     [ Not found ]
[16:57:23]   Checking for file '/dev/tux/backup/df'          [ Not found ]
[16:57:23]   Checking for file '/dev/tux/backup/dir'         [ Not found ]
[16:57:23]   Checking for file '/dev/tux/backup/find'        [ Not found ]
[16:57:23]   Checking for file '/dev/tux/backup/ifconfig'    [ Not found ]
[16:57:23]   Checking for file '/dev/tux/backup/locate'      [ Not found ]
[16:57:23]   Checking for file '/dev/tux/backup/netstat'     [ Not found ]
[16:57:23]   Checking for file '/dev/tux/backup/ps'          [ Not found ]
[16:57:23]   Checking for file '/dev/tux/backup/pstree'      [ Not found ]
[16:57:24]   Checking for file '/dev/tux/backup/syslogd'     [ Not found ]
[16:57:24]   Checking for file '/dev/tux/backup/tcpd'        [ Not found ]
[16:57:24]   Checking for file '/dev/tux/backup/top'         [ Not found ]
[16:57:24]   Checking for file '/dev/tux/backup/updatedb'    [ Not found ]
[16:57:24]   Checking for file '/dev/tux/backup/vdir'        [ Not found ]
[16:57:24]   Checking for directory '/dev/tux'               [ Not found ]
[16:57:24]   Checking for directory '/dev/tux/ssh2'          [ Not found ]
[16:57:24]   Checking for directory '/dev/tux/backup'        [ Not found ]
[16:57:24] Tuxtendo Rootkit                                  [ Not found ]
[16:57:24]
[16:57:24] Checking for URK Rootkit...
[16:57:24]   Checking for file '/dev/prom/sn.l'              [ Not found ]
[16:57:24]   Checking for file '/usr/lib/ldlibps.so'         [ Not found ]
[16:57:24]   Checking for file '/usr/lib/ldlibnet.so'        [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/uconf.inv'       [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/cleaner'         [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/bin/psniff'      [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/bin/du'          [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/bin/ls'          [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/bin/passwd'      [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/bin/ps'          [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/bin/psr'         [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/bin/su'          [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/bin/find'        [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/bin/netstat'     [ Not found ]
[16:57:24]   Checking for file '/dev/pts/01/bin/ping'        [ Not found ]
[16:57:25]   Checking for file '/dev/pts/01/bin/strings'     [ Not found ]
[16:57:25]   Checking for file '/dev/pts/01/bin/bash'        [ Not found ]
[16:57:25]   Checking for file '/usr/man/man1/xxxxxxbin/du'  [ Not found ]
[16:57:25]   Checking for file '/usr/man/man1/xxxxxxbin/ls'  [ Not found ]
[16:57:25]   Checking for file '/usr/man/man1/xxxxxxbin/passwd' [ Not found ]
[16:57:25]   Checking for file '/usr/man/man1/xxxxxxbin/ps'  [ Not found ]
[16:57:25]   Checking for file '/usr/man/man1/xxxxxxbin/psr' [ Not found ]
[16:57:25]   Checking for file '/usr/man/man1/xxxxxxbin/su'  [ Not found ]
[16:57:25]   Checking for file '/usr/man/man1/xxxxxxbin/find' [ Not found ]
[16:57:25]   Checking for file '/usr/man/man1/xxxxxxbin/netstat' [ Not found ]
[16:57:25]   Checking for file '/usr/man/man1/xxxxxxbin/ping' [ Not found ]
[16:57:25]   Checking for file '/usr/man/man1/xxxxxxbin/strings' [ Not found ]
[16:57:25]   Checking for file '/usr/man/man1/xxxxxxbin/bash' [ Not found ]
[16:57:25]   Checking for file '/tmp/conf.inv'               [ Not found ]
[16:57:25]   Checking for directory '/dev/prom'              [ Not found ]
[16:57:25]   Checking for directory '/dev/pts/01'            [ Not found ]
[16:57:25]   Checking for directory '/dev/pts/01/bin'        [ Not found ]
[16:57:25]   Checking for directory '/usr/man/man1/xxxxxxbin' [ Not found ]
[16:57:25] URK Rootkit                                       [ Not found ]
[16:57:25]
[16:57:25] Checking for Vampire Rootkit...
[16:57:25]   Checking for kernel symbol 'new_getdents'       [ Not found ]
[16:57:26]   Checking for kernel symbol 'old_getdents'       [ Not found ]
[16:57:26]   Checking for kernel symbol 'should_hide_file_name' [ Not found ]
[16:57:26]   Checking for kernel symbol 'should_hide_task_name' [ Not found ]
[16:57:26] Vampire Rootkit                                   [ Not found ]
[16:57:26]
[16:57:26] Checking for VcKit Rootkit...
[16:57:26]   Checking for directory '/usr/include/linux/modules/lib.so' [ Not found ]
[16:57:26]   Checking for directory '/usr/include/linux/modules/lib.so/bin' [ Not found ]
[16:57:26] VcKit Rootkit                                     [ Not found ]
[16:57:26]
[16:57:26] Checking for Volc Rootkit...
[16:57:26]   Checking for file '/usr/bin/volc'               [ Not found ]
[16:57:26]   Checking for file '/usr/lib/volc/backdoor/divine' [ Not found ]
[16:57:26]   Checking for file '/usr/lib/volc/linsniff'      [ Not found ]
[16:57:26]   Checking for file '/etc/rc.d/rc1.d/S25sysconf'  [ Not found ]
[16:57:26]   Checking for file '/etc/rc.d/rc2.d/S25sysconf'  [ Not found ]
[16:57:26]   Checking for file '/etc/rc.d/rc3.d/S25sysconf'  [ Not found ]
[16:57:26]   Checking for file '/etc/rc.d/rc4.d/S25sysconf'  [ Not found ]
[16:57:26]   Checking for file '/etc/rc.d/rc5.d/S25sysconf'  [ Not found ]
[16:57:26]   Checking for directory '/var/spool/.recent'     [ Not found ]
[16:57:27]   Checking for directory '/var/spool/.recent/.files' [ Not found ]
[16:57:27]   Checking for directory '/usr/lib/volc'          [ Not found ]
[16:57:27]   Checking for directory '/usr/lib/volc/backup'   [ Not found ]
[16:57:27] Volc Rootkit                                      [ Not found ]
[16:57:27]
[16:57:27] Checking for Xzibit Rootkit...
[16:57:27]   Checking for file '/dev/dsx'                    [ Not found ]
[16:57:27]   Checking for file '/dev/caca'                   [ Not found ]
[16:57:27]   Checking for file '/dev/ida/.inet/linsniffer'   [ Not found ]
[16:57:27]   Checking for file '/dev/ida/.inet/logclear'     [ Not found ]
[16:57:27]   Checking for file '/dev/ida/.inet/sense'        [ Not found ]
[16:57:27]   Checking for file '/dev/ida/.inet/sl2'          [ Not found ]
[16:57:27]   Checking for file '/dev/ida/.inet/sshdu'        [ Not found ]
[16:57:27]   Checking for file '/dev/ida/.inet/s'            [ Not found ]
[16:57:27]   Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[16:57:27]   Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[16:57:27]   Checking for file '/dev/ida/.inet/sl2new.c'     [ Not found ]
[16:57:27]   Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
[16:57:27]   Checking for file '/home/httpd/cgi-bin/becys.cgi' [ Not found ]
[16:57:27]   Checking for file '/usr/local/httpd/cgi-bin/becys.cgi' [ Not found ]
[16:57:27]   Checking for file '/usr/local/apache/cgi-bin/becys.cgi' [ Not found ]
[16:57:27]   Checking for file '/www/httpd/cgi-bin/becys.cgi' [ Not found ]
[16:57:27]   Checking for file '/www/cgi-bin/becys.cgi'      [ Not found ]
[16:57:27]   Checking for directory '/dev/ida/.inet'         [ Not found ]
[16:57:27] Xzibit Rootkit                                    [ Not found ]
[16:57:27]
[16:57:27] Checking for zaRwT.KiT Rootkit...
[16:57:28]   Checking for file '/dev/rd/s/sendmeil'          [ Not found ]
[16:57:28]   Checking for file '/dev/ttyf'                   [ Not found ]
[16:57:28]   Checking for file '/dev/ttyp'                   [ Not found ]
[16:57:28]   Checking for file '/dev/ttyn'                   [ Not found ]
[16:57:28]   Checking for file '/rk/tulz'                    [ Not found ]
[16:57:28]   Checking for directory '/rk'                    [ Not found ]
[16:57:28]   Checking for directory '/dev/rd/s'              [ Not found ]
[16:57:28] zaRwT.KiT Rootkit                                 [ Not found ]
[16:57:28]
[16:57:28] Checking for ZK Rootkit...
[16:57:28]   Checking for file '/usr/share/.zk/zk'           [ Not found ]
[16:57:28]   Checking for file '/usr/X11R6/.zk/xfs'          [ Not found ]
[16:57:28]   Checking for file '/usr/X11R6/.zk/echo'         [ Not found ]
[16:57:28]   Checking for file '/etc/1ssue.net'              [ Not found ]
[16:57:28]   Checking for file '/etc/sysconfig/console/load.zk' [ Not found ]
[16:57:28]   Checking for directory '/usr/share/.zk'         [ Not found ]
[16:57:28]   Checking for directory '/usr/X11R6/.zk'         [ Not found ]
[16:57:28] ZK Rootkit                                        [ Not found ]
[16:57:28]
[16:57:28] Info: Starting test name 'additional_rkts'
[16:57:28] Performing additional rootkit checks
[16:57:28]
[16:57:28]   Performing Suckit Rookit additional checks
[16:57:28]     Checking hard link count on '/sbin/init'      [ OK ]
[16:57:28]     Checking for hidden file extensions           [ None found ]
[16:57:28]     Running skdet command                         [ Skipped ]
[16:57:28] Info: Unable to find the 'skdet' command
[16:57:28]   Suckit Rookit additional checks                 [ OK ]
[16:57:28]
[16:57:28] Info: Starting test name 'possible_rkt_files'
[16:57:29]   Performing check of possible rootkit files and directories
[16:57:29]     Checking for file '/dev/sdr0'                 [ Not found ]
[16:57:29]     Checking for file '/dev/pisu'                 [ Not found ]
[16:57:29]     Checking for file '/dev/xdta'                 [ Not found ]
[16:57:29]     Checking for file '/dev/saux'                 [ Not found ]
[16:57:29]     Checking for file '/dev/hdx'                  [ Not found ]
[16:57:29]     Checking for file '/dev/hdx1'                 [ Not found ]
[16:57:29]     Checking for file '/dev/hdx2'                 [ Not found ]
[16:57:29]     Checking for file '/dev/ptyy'                 [ Not found ]
[16:57:29]     Checking for file '/dev/ptyu'                 [ Not found ]
[16:57:29]     Checking for file '/dev/ptyv'                 [ Not found ]
[16:57:29]     Checking for file '/dev/hdbb'                 [ Not found ]
[16:57:29]     Checking for file '/tmp/.syshackfile'         [ Not found ]
[16:57:29]     Checking for file '/tmp/.bash_history'        [ Not found ]
[16:57:29]     Checking for file '/usr/info/.clib'           [ Not found ]
[16:57:29]     Checking for file '/usr/sbin/tcp.log'         [ Not found ]
[16:57:29]     Checking for file '/usr/bin/take/pid'         [ Not found ]
[16:57:29]     Checking for file '/sbin/create'              [ Not found ]
[16:57:30]     Checking for file '/dev/ttypz'                [ Not found ]
[16:57:30]     Checking for file '/var/log/tcp.log'          [ Not found ]
[16:57:30]     Checking for file '/usr/include/audit.h'      [ Not found ]
[16:57:30]     Checking for file '/usr/bin/sourcemask'       [ Not found ]
[16:57:30]     Checking for file '/usr/bin/ras2xm'           [ Not found ]
[16:57:30]     Checking for file '/dev/xmx'                  [ Not found ]
[16:57:30]     Checking for file '/usr/sbin/gpm.root'        [ Not found ]
[16:57:30]     Checking for file '/bin/vobiscum'             [ Not found ]
[16:57:30]     Checking for file '/bin/psr'                  [ Not found ]
[16:57:30]     Checking for file '/dev/kdx'                  [ Not found ]
[16:57:30]     Checking for file '/dev/dkx'                  [ Not found ]
[16:57:30]     Checking for file '/usr/sbin/sshd3'           [ Not found ]
[16:57:30]     Checking for file '/usr/sbin/jcd'             [ Not found ]
[16:57:30]     Checking for file '/etc/rc.d/init.d/jcd'      [ Not found ]
[16:57:30]     Checking for file '/usr/sbin/atd2'            [ Not found ]
[16:57:30]     Checking for file '/home/httpd/cgi-bin/linux.cgi' [ Not found ]
[16:57:30]     Checking for file '/home/httpd/cgi-bin/psid'  [ Not found ]
[16:57:30]     Checking for file '/home/httpd/cgi-bin/void.cgi' [ Not found ]
[16:57:30]     Checking for file '/etc/rc.d/init.d/system'   [ Not found ]
[16:57:31]     Checking for file '/etc/rc.d/rc3.d/S93users'  [ Not found ]
[16:57:31]     Checking for file '/tmp/.ush'                 [ Not found ]
[16:57:31]     Checking for file '/usr/lib/libhidefile.so'   [ Not found ]
[16:57:31]     Checking for file '/etc/cron.d/kmod'          [ Not found ]
[16:57:31]     Checking for file '/usr/lib/dmis/dmisd'       [ Not found ]
[16:57:31]     Checking for file '/lib/secure/libhij.so'     [ Not found ]
[16:57:31]     Checking for file '/usr/sbin/sshd3'           [ Not found ]
[16:57:31]     Checking for file '/etc/rc.d/init.d/crontab'  [ Not found ]
[16:57:31]     Checking for file '/etc/rc.d/init.d/jcd'      [ Not found ]
[16:57:31]     Checking for file '/usr/sbin/atd2'            [ Not found ]
[16:57:31]     Checking for file '/etc/rc.d/rc5.d/S93users'  [ Not found ]
[16:57:31]     Checking for file '/usr/include/mysql/mysql.hh1' [ Not found ]
[16:57:31]     Checking for file '/etc/init.d/xfs3'          [ Not found ]
[16:57:31]     Checking for file '/usr/sbin/t.txt'           [ Not found ]
[16:57:31]     Checking for file '/usr/sbin/change'          [ Not found ]
[16:57:31]     Checking for file '/usr/sbin/s'               [ Not found ]
[16:57:31]     Checking for file '/bin/f'                    [ Not found ]
[16:57:31]     Checking for file '/bin/i'                    [ Not found ]
[16:57:31]     Checking for file '/lib/libncom.so.4.0.1'     [ Not found ]
[16:57:32]     Checking for file '/sbin/zinit'               [ Not found ]
[16:57:32]     Checking for file '/tmp/pass_ssh.log'         [ Not found ]
[16:57:32]     Checking for file '/usr/include/gpm2.h'       [ Not found ]
[16:57:32]     Checking for file '/etc/ssh/.sshd_auth'       [ Not found ]
[16:57:32]     Checking for file '/usr/lib/.sshd.h'          [ Not found ]
[16:57:32]     Checking for file '/var/run/.defunct'         [ Not found ]
[16:57:32]     Checking for file '/etc/httpd/run/.defunct'   [ Not found ]
[16:57:32]     Checking for file '/usr/share/pci.r'          [ Not found ]
[16:57:32]     Checking for file '/etc/cron.daily/dnsquery'  [ Not found ]
[16:57:32]     Checking for file '/usr/lib/libutil1.2.1.2.so' [ Not found ]
[16:57:32]     Checking for file '/bin/ceva'                 [ Not found ]
[16:57:32]     Checking for file '/sbin/syslogd<SP>'         [ Not found ]
[16:57:32]     Checking for file '/usr/include/shup.h'       [ Not found ]
[16:57:32]     Checking for file '/etc/rpm/sshdOLD'          [ Not found ]
[16:57:32]     Checking for file '/etc/rpm/sshOLD'           [ Not found ]
[16:57:32]     Checking for file '/usr/share/passwd.h'       [ Not found ]
[16:57:32]     Checking for file '/lib/.xsyslog'             [ Not found ]
[16:57:33]     Checking for file '/etc/.xsyslog'             [ Not found ]
[16:57:33]     Checking for file '/lib/.ssyslog'             [ Not found ]
[16:57:33]     Checking for file '/tmp/.sendmail'            [ Not found ]
[16:57:33]     Checking for file '/usr/share/sshd.sync'      [ Not found ]
[16:57:33]     Checking for file '/bin/zcut'                 [ Not found ]
[16:57:33]     Checking for file '/usr/bin/zmuie'            [ Not found ]
[16:57:33]     Checking for file '/lib/libkeyutils.so.1.9'   [ Not found ]
[16:57:33]     Checking for file '/lib64/libkeyutils.so.1.9' [ Not found ]
[16:57:33]     Checking for file '/usr/lib/libkeyutils.so.1.9' [ Not found ]
[16:57:33]     Checking for file '/usr/lib64/libkeyutils.so.1.9' [ Not found ]
[16:57:33]     Checking for directory '/dev/ptyas'           [ Not found ]
[16:57:33]     Checking for directory '/usr/bin/take'        [ Not found ]
[16:57:33]     Checking for directory '/usr/src/.lib'        [ Not found ]
[16:57:33]     Checking for directory '/usr/share/man/man1/.1c' [ Not found ]
[16:57:33]     Checking for directory '/lib/lblip.tk'        [ Not found ]
[16:57:33]     Checking for directory '/usr/sbin/...'        [ Not found ]
[16:57:34]     Checking for directory '/usr/share/.gun'      [ Not found ]
[16:57:34]     Checking for directory '/unde/vrei/tu/sa/te/ascunzi/in/server' [ Not found ]
[16:57:34]     Checking for directory '/usr/man/man1/..<SP><SP>/.dir' [ Not found ]
[16:57:34]     Checking for directory '/usr/X11R6/include/X11/...' [ Not found ]
[16:57:34]     Checking for directory '/usr/X11R6/lib/X11/.fonts/misc/...' [ Not found ]
[16:57:34]     Checking for directory '/tmp/.sys'            [ Not found ]
[16:57:34]     Checking for directory '/tmp/''               [ Not found ]
[16:57:34]     Checking for directory '/tmp/.,'              [ Not found ]
[16:57:34]     Checking for directory '/tmp/,.,'             [ Not found ]
[16:57:34]     Checking for directory '/dev/shm/emilien'     [ Not found ]
[16:57:34]     Checking for directory '/var/tmp/.log'        [ Not found ]
[16:57:34]     Checking for directory '/tmp/zmeu/...<SP>'    [ Not found ]
[16:57:34]     Checking for directory '/var/log/ssh'         [ Not found ]
[16:57:34]     Checking for directory '/dev/ida'             [ Not found ]
[16:57:34]     Checking for directory '/var/lib/games/.src/ssk/shit' [ Not found ]
[16:57:34]     Checking for directory '/usr/lib/libshtift'   [ Not found ]
[16:57:34]     Checking for directory '/usr/src/.poop'       [ Not found ]
[16:57:35]     Checking for directory '/dev/wd4'             [ Not found ]
[16:57:35]     Checking for directory '/var/run/.tmp'        [ Not found ]
[16:57:35]     Checking for directory '/usr/man/man1/lib/.lib' [ Not found ]
[16:57:35]     Checking for directory '/dev/portd'           [ Not found ]
[16:57:35]     Checking for directory '/dev/...'             [ Not found ]
[16:57:35]     Checking for directory '/usr/share/man/mansps' [ Not found ]
[16:57:35]     Checking for directory '/lib/.so'             [ Not found ]
[16:57:35]     Checking for directory '/lib/.sso'            [ Not found ]
[16:57:35]     Checking for directory '/usr/include/sslv3'   [ Not found ]
[16:57:35]     Checking for directory '/dev/shm/sshd'        [ Not found ]
[16:57:35]     Checking for directory '/usr/share/locale/mk/.dev/sk' [ Not found ]
[16:57:35]     Checking for directory '/usr/share/locale/mk/.dev' [ Not found ]
[16:57:35]     Checking for directory '/usr/include/netda.h' [ Not found ]
[16:57:35]     Checking for directory '/usr/include/.ssh'    [ Not found ]
[16:57:35]     Checking for directory '/usr/share/locale/jp/.<SP>' [ Not found ]
[16:57:35]     Checking for directory '/usr/share/.sqe'      [ Not found ]
[16:57:35]   Checking for possible rootkit files and directories [ None found ]
[16:57:35]
[16:57:35] Info: Starting test name 'possible_rkt_strings'
[16:57:35]   Performing check for possible rootkit strings
[16:57:35] Info: Using system startup paths: /etc/rc.local /etc/init.d
[16:57:36]     Checking for string 'phalanx'                 [ Not found ]
[16:57:36]     Checking for string '/dev/proc/fuckit'        [ Not found ]
[16:57:36]     Checking for string 'FUCK'                    [ Not found ]
[16:57:36]     Checking for string 'backdoor'                [ Not found ]
[16:57:36]     Checking for string '/usr/bin/rcpc'           [ Not found ]
[16:57:36]     Checking for string '/usr/sbin/login'         [ Not found ]
[16:57:36]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[16:57:36]     Checking for string 'vt200'                   [ Not found ]
[16:57:36]     Checking for string '/usr/bin/xstat'          [ Not found ]
[16:57:36]     Checking for string '/bin/envpc'              [ Not found ]
[16:57:36]     Checking for string 'L4m3r0x'                 [ Not found ]
[16:57:36]     Checking for string '/lib/libext'             [ Not found ]
[16:57:36]     Checking for string '/usr/sbin/login'         [ Not found ]
[16:57:36]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[16:57:37]     Checking for string 'sendmail'                [ Not found ]
[16:57:37]     Checking for string 'cocacola'                [ Not found ]
[16:57:37]     Checking for string 'joao'                    [ Not found ]
[16:57:37]     Checking for string '/dev/ptyxx/.file'        [ Not found ]
[16:57:37]     Checking for string '/dev/ptyxx/.file'        [ Not found ]
[16:57:37]     Checking for string '/dev/sgk'                [ Not found ]
[16:57:37]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[16:57:37]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[16:57:37]     Checking for string '/dev/proc/fuckit'        [ Not found ]
[16:57:37]     Checking for string '/lib/.sso'               [ Not found ]
[16:57:37]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[16:57:37]     Checking for string '/dev/caca'               [ Not found ]
[16:57:37]     Checking for string '/dev/ttyoa'              [ Not found ]
[16:57:37]     Checking for string '/usr/lib/ldlibns.so'     [ Not found ]
[16:57:37]     Checking for string '/dev/ptyxx/.addr'        [ Not found ]
[16:57:37]     Checking for string 'syg'                     [ Not found ]
[16:57:37]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[16:57:37]     Checking for string '/dev/pts/01'             [ Not found ]
[16:57:38]     Checking for string 'tw33dl3'                 [ Not found ]
[16:57:38]     Checking for string 'psniff'                  [ Not found ]
[16:57:38]     Checking for string 'uconf.inv'               [ Not found ]
[16:57:38]     Checking for string 'lib/ldlibps.so'          [ Not found ]
[16:57:38]     Checking for string '/usr/lib/ldlibpst.so'    [ Not found ]
[16:57:38]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[16:57:38]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[16:57:38]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[16:57:38]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[16:57:38]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[16:57:38]     Checking for string '/bin/bash'               [ Not found ]
[16:57:38]     Checking for string '/dev/xdta'               [ Not found ]
[16:57:38]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[16:57:39]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[16:57:39]     Checking for string 'in.inetd'                [ Not found ]
[16:57:40]     Checking for string '#<HIDE_.*>'              [ Not found ]
[16:57:40]     Checking for string 'bin/xchk'                [ Not found ]
[16:57:41]     Checking for string 'bin/xsf'                 [ Not found ]
[16:57:41]     Checking for string '/usr/bin/ssh2d'          [ Not found ]
[16:57:42]     Checking for string '/usr/sbin/xntps'         [ Not found ]
[16:57:42]     Checking for string 'ttyload'                 [ Not found ]
[16:57:43]     Checking for string '/etc/rc.d/init.d/init'   [ Not found ]
[16:57:43]     Checking for string 'usr/bin/xfss'            [ Not found ]
[16:57:44]     Checking for string '/usr/sbin/rpc.netinet'   [ Not found ]
[16:57:44]     Checking for string '/usr/lib/.fx/cons.saver' [ Not found ]
[16:57:45]     Checking for string '/usr/lib/.fx/xs'         [ Not found ]
[16:57:45]     Checking for string '/ssh2d'                  [ Not found ]
[16:57:46]     Checking for string '/dev/kmod'               [ Not found ]
[16:57:46]     Checking for string '/crth.o'                 [ Not found ]
[16:57:47]     Checking for string '/crtz.o'                 [ Not found ]
[16:57:47]     Checking for string '/dev/dos'                [ Not found ]
[16:57:48]     Checking for string '/lpq'                    [ Not found ]
[16:57:48]     Checking for string '/usr/sbin/rescue'        [ Not found ]
[16:57:48]     Checking for string '/usr/lib/lpstart'        [ Not found ]
[16:57:49]     Checking for string '/volc'                   [ Not found ]
[16:57:49]     Checking for string 'sourcemask'              [ Not found ]
[16:57:50]     Checking for string '/bin/vobiscum'           [ Not found ]
[16:57:50]     Checking for string '/usr/sbin/in.telnet'     [ Not found ]
[16:57:51]     Checking for string '/usr/bin/hdparm?-t1?-X53?-p' [ Not found ]
[16:57:51]     Checking for string '/lib/.xsyslog'           [ Not found ]
[16:57:52]     Checking for string '/etc/.xsyslog'           [ Not found ]
[16:57:52]     Checking for string '/lib/.ssyslog'           [ Not found ]
[16:57:52]     Checking for string '/tmp/.sendmail'          [ Not found ]
[16:57:53]     Checking for string '/lib/ldd.so/tkps'        [ Not found ]
[16:57:53]     Checking for string 't0rnkit'                 [ Not found ]
[16:57:53]     Checking for string '/dev/proc/fuckit'        [ Not found ]
[16:57:53]     Checking for string 'backdoor.h'              [ Not found ]
[16:57:53]     Checking for string 'backdoor_active'         [ Not found ]
[16:57:53]     Checking for string 'magic_pass_active'       [ Not found ]
[16:57:53]     Checking for string '/usr/include/gpm2.h'     [ Not found ]
[16:57:53]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[16:57:53]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[16:57:53]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[16:57:53]     Checking for string '/usr/lib/ldlibct.so'     [ Not found ]
[16:57:53]     Checking for string '/usr/lib/ldlibdu.so'     [ Not found ]
[16:57:53]     Checking for string '/dev/ptyxx/.file'        [ Not found ]
[16:57:53]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[16:57:54]     Checking for string '/dev/ida/.inet'          [ Not found ]
[16:57:54]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[16:57:54]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[16:57:54]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[16:57:54]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[16:57:54]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[16:57:54]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[16:57:54]     Checking for string 'backconnect'             [ Not found ]
[16:57:54]     Checking for string 'magic?packet?received'   [ Not found ]
[16:57:54]   Checking for possible rootkit strings           [ None found ]
[16:57:54]
[16:57:54] Info: Starting test name 'malware'
[16:57:54] Performing malware checks
[16:57:54]
[16:57:54] Info: Test 'deleted_files' disabled at users request.
[16:57:54]
[16:57:54] Info: Starting test name 'running_procs'
[16:58:00]   Checking running processes for suspicious files [ None found ]
[16:58:00]
[16:58:00] Info: Test 'hidden_procs' disabled at users request.
[16:58:00]
[16:58:00] Info: Test 'suspscan' disabled at users request.
[16:58:00]
[16:58:00] Info: Starting test name 'other_malware'
[16:58:00]   Performing check for login backdoors
[16:58:00]     Checking for '/bin/.login'                    [ Not found ]
[16:58:00]     Checking for '/sbin/.login'                   [ Not found ]
[16:58:00]   Checking for login backdoors                    [ None found ]
[16:58:00]
[16:58:00]   Performing check for suspicious directories
[16:58:00]     Checking for directory '/usr/X11R6/bin/.,/copy' [ Not found ]
[16:58:00]     Checking for directory '/dev/rd/cdb'          [ Not found ]
[16:58:00]   Checking for suspicious directories             [ None found ]
[16:58:00]
[16:58:00]   Checking for software intrusions                [ Skipped ]
[16:58:01] Info: Check skipped - tripwire not installed
[16:58:01]
[16:58:01]   Performing check for sniffer log files
[16:58:01]     Checking for file '/usr/lib/libice.log'       [ Not found ]
[16:58:01]     Checking for file '/dev/prom/sn.l'            [ Not found ]
[16:58:01]     Checking for file '/dev/fd/.88/zxsniff.log'   [ Not found ]
[16:58:01]   Checking for sniffer log files                  [ None found ]
[16:58:01]
[16:58:01] Suspicious Shared Memory segments
[16:58:01]   Suspicious Shared Memory segments               [ None found ]
[16:58:01]
[16:58:01] Info: Starting test name 'trojans'
[16:58:01] Performing trojan specific checks
[16:58:01]   Checking for enabled inetd services             [ Skipped ]
[16:58:01] Info: Check skipped - file '/etc/inetd.conf' does not exist.
[16:58:01]
[16:58:01]   Performing check for enabled xinetd services
[16:58:01]   Checking for enabled xinetd services            [ Skipped ]
[16:58:01] Info: Check skipped - file '/etc/xinetd.conf' does not exist.
[16:58:01] Info: Apache backdoor check skipped: Apache modules and configuration directories not found.
[16:58:01]
[16:58:01] Info: Starting test name 'os_specific'
[16:58:01] Performing Linux specific checks
[16:58:01]   Checking loaded kernel modules                  [ OK ]
[16:58:01] Info: Using modules pathname of '/lib/modules/4.4.0-38-generic'
[16:58:01]   Checking kernel module names                    [ OK ]
[16:58:01]
[16:58:01] Info: Starting test name 'network'
[16:58:01] Checking the network...
[16:58:01]
[16:58:01] Performing checks on the network ports
[16:58:01] Info: Starting test name 'ports'
[16:58:01]   Performing check for backdoor ports
[16:58:01]     Checking for TCP port 1524                    [ Not found ]
[16:58:02]     Checking for TCP port 1984                    [ Not found ]
[16:58:02]     Checking for UDP port 2001                    [ Not found ]
[16:58:02]     Checking for TCP port 2006                    [ Not found ]
[16:58:02]     Checking for TCP port 2128                    [ Not found ]
[16:58:02]     Checking for TCP port 6666                    [ Not found ]
[16:58:02]     Checking for TCP port 6667                    [ Not found ]
[16:58:02]     Checking for TCP port 6668                    [ Not found ]
[16:58:02]     Checking for TCP port 6669                    [ Not found ]
[16:58:02]     Checking for TCP port 7000                    [ Not found ]
[16:58:03]     Checking for TCP port 13000                   [ Not found ]
[16:58:03]     Checking for TCP port 14856                   [ Not found ]
[16:58:03]     Checking for TCP port 25000                   [ Not found ]
[16:58:03]     Checking for TCP port 29812                   [ Not found ]
[16:58:03]     Checking for TCP port 31337                   [ Not found ]
[16:58:03]     Checking for TCP port 32982                   [ Not found ]
[16:58:03]     Checking for TCP port 33369                   [ Not found ]
[16:58:03]     Checking for TCP port 47107                   [ Not found ]
[16:58:04]     Checking for TCP port 47018                   [ Not found ]
[16:58:04]     Checking for TCP port 60922                   [ Not found ]
[16:58:04]     Checking for TCP port 62883                   [ Not found ]
[16:58:04]     Checking for TCP port 65535                   [ Not found ]
[16:58:04]   Checking for backdoor ports                     [ None found ]
[16:58:04]
[16:58:04] Info: Starting test name 'hidden_ports'
[16:58:04] Info: Found the 'unhide-tcp' command: /usr/sbin/unhide-tcp 
[16:58:05]   Checking for hidden ports                       [ None found ]
[16:58:05]
[16:58:05] Performing checks on the network interfaces
[16:58:05] Info: Starting test name 'promisc'
[16:58:05]   Checking for promiscuous interfaces             [ None found ]
[16:58:05]
[16:58:05] Info: Test 'packet_cap_apps' disabled at users request.
[16:58:05]
[16:58:05] Info: Starting test name 'local_host'
[16:58:05] Checking the local host...
[16:58:05]
[16:58:05] Info: Starting test name 'startup_files'
[16:58:05] Performing system boot checks
[16:58:05]   Checking for local host name                    [ Found ]
[16:58:05]
[16:58:05] Info: Starting test name 'startup_malware'
[16:58:05]   Checking for system startup files               [ Found ]
[16:58:07]   Checking system startup files for malware       [ None found ]
[16:58:07]
[16:58:07] Info: Starting test name 'group_accounts'
[16:58:07] Performing group and account checks
[16:58:07]   Checking for passwd file                        [ Found ]
[16:58:07] Info: Found password file: /etc/passwd
[16:58:07]   Checking for root equivalent (UID 0) accounts   [ None found ]
[16:58:07] Info: Found shadow file: /etc/shadow
[16:58:07]   Checking for passwordless accounts              [ None found ]
[16:58:07]
[16:58:07] Info: Starting test name 'passwd_changes'
[16:58:08]   Checking for passwd file changes                [ None found ]
[16:58:08]
[16:58:08] Info: Starting test name 'group_changes'
[16:58:08]   Checking for group file changes                 [ None found ]
[16:58:08]   Checking root account shell history files       [ OK ]
[16:58:08]
[16:58:08] Info: Starting test name 'system_configs'
[16:58:08] Performing system configuration file checks
[16:58:08]   Checking for an SSH configuration file          [ Found ]
[16:58:08] Info: Found an SSH configuration file: /etc/ssh/sshd_config
[16:58:08] Info: Rkhunter option ALLOW_SSH_ROOT_USER set to 'no'.
[16:58:08] Info: Rkhunter option ALLOW_SSH_PROT_V1 set to '0'.
[16:58:08]   Checking if SSH root access is allowed          [ Warning ]
[16:58:08] Warning: The SSH and rkhunter configuration options should be the same:
[16:58:08]          SSH configuration option 'PermitRootLogin': prohibit-password
[16:58:08]          Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no
[16:58:08]   Checking if SSH protocol v1 is allowed          [ Not allowed ]
[16:58:08]   Checking for a running system logging daemon    [ Found ]
[16:58:08] Info: A running 'rsyslog' daemon has been found.
[16:58:08] Info: A running 'systemd-journald' daemon has been found.
[16:58:08] Info: Found an rsyslog configuration file: /etc/rsyslog.conf
[16:58:08] Info: Found a systemd configuration file: /etc/systemd/journald.conf
[16:58:08]   Checking for a system logging configuration file [ Found ]
[16:58:08]   Checking if syslog remote logging is allowed    [ Not allowed ]
[16:58:08]
[16:58:08] Info: Starting test name 'filesystem'
[16:58:08] Performing filesystem checks
[16:58:08] Info: SCAN_MODE_DEV set to 'THOROUGH'
[16:58:12]   Checking /dev for suspicious file types         [ Warning ]
[16:58:12] Warning: Suspicious file types found in /dev:
[16:58:12]          /dev/shm/pulse-shm-1673721254: data
[16:58:12]          /dev/shm/pulse-shm-4052801653: data
[16:58:12]          /dev/shm/pulse-shm-132324202: data
[16:58:12]          /dev/shm/pulse-shm-3975175099: data
[16:58:12]          /dev/shm/pulse-shm-3441172232: data
[16:58:12]          /dev/shm/pulse-shm-21482027: data
[16:58:12]          /dev/shm/pulse-shm-1190472284: data
[16:58:12]          /dev/shm/pulse-shm-1059657955: data
[16:58:12]          /dev/shm/pulse-shm-930879024: data
[16:58:12]          /dev/shm/pulse-shm-1651184676: data
[16:58:13]   Checking for hidden files and directories       [ None found ]
[16:58:13]   Checking for missing log files                  [ Skipped ]
[16:58:13]   Checking for empty log files                    [ Skipped ]
[16:58:13]
[16:58:13] Info: Test 'apps' disabled at users request.
[16:58:13]
[16:58:13] System checks summary
[16:58:13] =====================
[16:58:13]
[16:58:13] File properties checks...
[16:58:13] Files checked: 150
[16:58:13] Suspect files: 1
[16:58:13]
[16:58:13] Rootkit checks...
[16:58:13] Rootkits checked : 365
[16:58:13] Possible rootkits: 0
[16:58:13]
[16:58:13] Applications checks...
[16:58:13] All checks skipped
[16:58:13]
[16:58:13] The system checks took: 2 minutes and 8 seconds
[16:58:13]
[16:58:13] Info: End date is mardi 4 octobre 2016, 16:58:13 (UTC+0200)

Dernière modification par imost (Le 05/10/2016, à 12:58)


Ubuntu 22.04 LTS

Hors ligne

#13 Le 16/10/2016, à 11:17

imost

Re : [Résolu] fichier suspect détecté via rkhunter

plus de 10 jours sans réponse. Que passa?


Ubuntu 22.04 LTS

Hors ligne

#14 Le 18/10/2016, à 14:03

koshieIsYourDaddy

Re : [Résolu] fichier suspect détecté via rkhunter

Salut,

Je doute que via wine un virus Windows puisse infecter un Linux (mais comme j'aime à dire, en informatique tout est possible ou presque).

imost a écrit :

hier j ai fais un scan complet avec clamav en ligne de commande. il m'a dit que j avais un fichier infesté mais je n'ai su que faire en suite

Il est censé te donner le chemin du fichier, si tu le copie/colle ici on pourra voir ensemble.

imost a écrit :

et si j ai bien compris tu me dis d'installer un anti rookit.

Si tu cherche des virus Linux, oui.

Concernant le retour de RKHunter, je m'en suis jamais véritablement servit et du peu que j'en ai lu il est difficile de faire la part des choses entre vrai risque et faux positif.

Après de ma lecture rapide du retour de RKHunter, je ne vois rien de grave, mais il te prévient quand même que:

RKHunter a écrit :

[16:58:08]   Checking if SSH root access is allowed          [ Warning ]
[16:58:08] Warning: The SSH and rkhunter configuration options should be the same:
[16:58:08]          SSH configuration option 'PermitRootLogin': prohibit-password

Là il gueule un peu car il aimerait que la config d'SSH et d'RKHunter soit identique pour l'option "PermitRootLogin" (autoriser root à se connecter à distance sur ta machine), rien de bien grave et je suppose que tu as laissé ce qu'il y avait par défaut. C'est pas le sujet, en plus.

Par contre il a trouvé UN fichier suspect:

RKHunter a écrit :

[16:58:13] Suspect files: 1

Je ne connais pas assez RKHunter pour en dire plus, j'espère que quelqu'un qui s'y connait plus que moi pourra t'aider ici.

koshicalement

Hors ligne

#15 Le 18/10/2016, à 15:53

imost

Re : [Résolu] fichier suspect détecté via rkhunter

Tu as peut-être un anti-rooKit de prédilection ? Je ne trouve pas le chemin du fichier clamav infesté...

Je me recentre sur mon probleme le plus urgent apparemment


Si quelqu'un pouvait me dire que faire suite a ce retour de rkhunter et si j ai un soucis sérieux?



marc@marc-Inspiron-1545:~$ sudo rkhunter --checkall --report-warnings-only
Warning: The file '/usr/sbin/sshd' does not exist on the system, but it is present in the 'rkhunter.dat' file.
Warning: The command '/usr/bin/lwp-request' has been replaced by a script: /usr/bin/lwp-request: a /usr/bin/perl -w script, ASCII text executable
Warning: The SSH and rkhunter configuration options should be the same:
         SSH configuration option 'PermitRootLogin': prohibit-password
         Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no
Warning: Suspicious file types found in /dev:
         /dev/shm/pulse-shm-2189069648: data
         /dev/shm/pulse-shm-3588272156: data
         /dev/shm/pulse-shm-642352209: data
         /dev/shm/pulse-shm-1648531528: data
         /dev/shm/pulse-shm-1890780259: data
         /dev/shm/pulse-shm-3536363206: data
         /dev/shm/pulse-shm-3111596173: data
         /dev/shm/pulse-shm-203307461: data
         /dev/shm/pulse-shm-67647740: data
         /dev/shm/pulse-shm-2441703675: data
marc@marc-Inspiron-1545:~$ 

Dernière modification par imost (Le 18/10/2016, à 16:18)


Ubuntu 22.04 LTS

Hors ligne

#16 Le 18/10/2016, à 22:35

Unix revient

Re : [Résolu] fichier suspect détecté via rkhunter

Bonsoir,

Juste une chose, as-tu fait "sudo rkhunter --propupd" ? Cela te permet d'avoir ta base de données à jour.

Sinon, il y a une chose que tu peux faire lorsque tu trouves des warning avec rkhunter, c'est vérifier s'il ne s'agit pas de faux-positifs. Tapes sur google rkhunter, ta version d'ubuntu et entre ton warning. Généralement, tu tombes sur d'autres personnes qui partagent les mêmes faux-positifs. D'ailleurs, si tu regardes le fichier "white list" de rkhunter (/etc/rkhunter.conf.local), tu verras que "/dev/shm/pulse-shm" et "/usr/bin/lwp-request", de mémoire, doivent faire parties des fichiers qui sont prêts à être white-listés. Sur 14.04, c'était "unhibe.rb" qui sortait toujours dans les warnings.

Dernière modification par Unix revient (Le 18/10/2016, à 22:37)


Allez sur ubuntuforums, définitivement !

Ubuntu 16.04, Kali Linux

Hors ligne

#17 Le 21/10/2016, à 12:46

imost

Re : [Résolu] fichier suspect détecté via rkhunter

La mise a jour de base de données est faite, rien de grave si je comprends bien, je te remercie...


Ubuntu 22.04 LTS

Hors ligne

#18 Le 22/11/2016, à 20:47

holacabron

Re : [Résolu] fichier suspect détecté via rkhunter

Salut,

Pour régler ton problème:
1) Déconnecte ton ordinateur infecté du réseau et de internet.
2) Scan ton ordinateur infecté avec l'antivirus
3) Sert toi d'un ordinateur non infecté pour changer ton mot de passe WoW. Met en un très difficile, une longue phrase avec majuscule et symboles genre "JeMeSuisFaitHackFaitChier!!__2016"
3) Va t'acheter un battlenet authentificator (dispo à la fnac par exemple). C'est pas cher et ca vaut la peine.
4) Change aussi le mdp de ta boite mail liée à ton compte WoW et ajoute l'authentification en 2 étapes sur ta boite mail si disponible.

Avec ca t'es inhackable.

Hors ligne