skanowanie chkrootkit/em niepokoj

Tematy związane z oprogramowaniem, instalacją, konfiguracją
Awatar użytkownika
Menel
Member
Posty: 1117
Rejestracja: 24 sierpnia 2013, 19:58
Lokalizacja: doktor informoparalityki

skanowanie chkrootkit/em niepokojące logi [+]

Post autor: Menel »

Po przeskanowaniu systemu chkrootkit'em (wiem, że skubaniec lubi fałszywe alarmy, ale wolę się upewnić, co do pierwszego loga jestem prawie pewny, że to fałszywy alarm ale drugi mnie zastanawia), sprawa wygląda następująco:

Kod: Zaznacz cały

 Searching for suspicious files and dirs, it may take a while... The following suspicious files and directories were found:  
 /usr/lib/python2.6/dist-packages/PyQt4/uic/widget-plugins/.noinit
 /usr/lib/jvm/java-8-oracle/lib/visualvm/platform/.lastModified
 /usr/lib/jvm/java-8-oracle/lib/visualvm/visualvm/.lastModified
 /usr/lib/jvm/java-8-oracle/lib/visualvm/profiler/.lastModified
 /usr/lib/jvm/.java-8-oracle.jinfo
 /usr/lib/jvm/.java-1.6.0-openjdk-amd64.jinfo
 /usr/lib/python2.7/dist-packages/PyQt4/uic/widget-plugins/.noinit
 /usr/lib/icedove/.autoreg
 /usr/lib/pymodules/python2.6/.path
 /usr/lib/pymodules/python2.7/.path
java pochodzi rzekomo z repo ubuntu:

Kod: Zaznacz cały

 deb [URL]http://ppa.launchpad.net/webupd8team/java/ubuntu[/URL] precise main
 deb-src [URL]http://ppa.launchpad.net/webupd8team/java/ubuntu[/URL] precise main 
i druga niepokojąca rzecz:

Kod: Zaznacz cały

wlan1: PACKET SNIFFER(/sbin/wpa_supplicant[2564], /sbin/dhclient[3290]) 



Czy to coś groźnego, proszę o odpowiedź...a i jeszcze jedno w jaki sposób pozbyć się tych zaśmiecających pozostałości po starszych wersjach javy, żeby nie uwalić tej której używam, usuwałem przez apt a widzę, że jeszcze coś zostało, orphan też nie wykrył mi żadnego zbędnego syfu?
proszę o wyrozumiałość i dziękuję z góry....menel
Awatar użytkownika
Rafal_F
Moderator
Posty: 2350
Rejestracja: 29 sierpnia 2008, 16:45

Post autor: Rafal_F »

Sprawdziłeś czym zajmują się programy w nawiasie?
http://ubuntuforums.org/showthread.php?t=1126452
Awatar użytkownika
Menel
Member
Posty: 1117
Rejestracja: 24 sierpnia 2013, 19:58
Lokalizacja: doktor informoparalityki

Post autor: Menel »

Z tego co wyczytałem to w porządku
Everything's normal. dhclient and wpa_supplicant are supposed to listen promiscuously to network traffic to do their job. Pulse does put SHM cookies which look "abnormal" to a rootkit hunter in /dev/pulse.
Jak pisałem proszę o wyrozumiałość, bo jestem kompletnym laikiem a możliwe, że wpadam w paranoje, bo niedawno jeden z użyszkodników mojej sieci domowej zabawiał się w węszenie i kto go wie co tam jeszcze majstruje, mniejsza z tym ale boję się gnoja a z tą javą ok jest? Po prostu potrzebuję się upewnić, że wszystko gra dla świętego spokoju...
Awatar użytkownika
Rafal_F
Moderator
Posty: 2350
Rejestracja: 29 sierpnia 2008, 16:45

Post autor: Rafal_F »

Według mnie wszystko OK, ale dla świętego spokoju możesz jeszcze zainstalować i uruchomić rkhunter:

Kod: Zaznacz cały

rkhunter --check
Co do usunięcia javy, jeżeli była instalowana przez repozytorium to spróbuj z opcją purge:

Kod: Zaznacz cały

aptitude purge nazwa_pakietu
Jak nie zadziała to pozostaje ręczne usuwanie plików. Tu występuje segregacja, jeżeli masz zainstalowaną nowszą wersje i napotykasz gdzieś ścieżkę ze starszą (nie zainstalowaną) to możesz to bezpiecznie usunąć.
Awatar użytkownika
Menel
Member
Posty: 1117
Rejestracja: 24 sierpnia 2013, 19:58
Lokalizacja: doktor informoparalityki

Post autor: Menel »

powywalałem te resztki javy ręcznie, przeskanowałem system rkhunterem, wykrył mi jeszcze jakiś pusty ukryty folder .java w /etc też go wykopałem, oprócz tego dwa raczej fałszywe alarmy z tego co piszą w sieci, bo przyczepił się do:

Kod: Zaznacz cały

 /usr/bin/curl 
i

Kod: Zaznacz cały

 /usr/bin/unhide.rb 
czyli chyba mogę spać spokojnie...dzięki za pomoc
Awatar użytkownika
Rafal_F
Moderator
Posty: 2350
Rejestracja: 29 sierpnia 2008, 16:45

Post autor: Rafal_F »

A o co się przyczepił do curl'a?
Awatar użytkownika
Menel
Member
Posty: 1117
Rejestracja: 24 sierpnia 2013, 19:58
Lokalizacja: doktor informoparalityki

Post autor: Menel »

nie wiem Ty mi powiedz wklejam loga

Kod: Zaznacz cały

 [17:37:13]   Checking for file '/usr/lib/.libigno/.igno/psybnc/psybnc' [ Not found ]
[17:37:13]   Checking for directory '/usr/lib/.libigno'      [ Not found ]
[17:37:13]   Checking for directory '/usr/lib/.libigno/.igno' [ Not found ]
[17:37:13] ignoKit Rootkit                                   [ Not found ]
[17:37:13]
[17:37:13] Checking for IntoXonia-NG Rootkit...
[17:37:13]   Checking for kernel symbol 'funces'             [ Not found ]
[17:37:13]   Checking for kernel symbol 'ixinit'             [ Not found ]
[17:37:13]   Checking for kernel symbol 'tricks'             [ Not found ]
[17:37:13]   Checking for kernel symbol 'kernel_unlink'      [ Not found ]
[17:37:13]   Checking for kernel symbol 'rootme'             [ Not found ]
[17:37:13]   Checking for kernel symbol 'hide_module'        [ Not found ]
[17:37:14]   Checking for kernel symbol 'find_sys_call_tbl'  [ Not found ]
[17:37:14] IntoXonia-NG Rootkit                              [ Not found ]
[17:37:14]
[17:37:14] Checking for Irix Rootkit...
[17:37:14]   Checking for directory '/dev/pts/01'            [ Not found ]
[17:37:14]   Checking for directory '/dev/pts/01/backup'     [ Not found ]
[17:37:14]   Checking for directory '/dev/pts/01/etc'        [ Not found ]
[17:37:14]   Checking for directory '/dev/pts/01/tmp'        [ Not found ]
[17:37:14] Irix Rootkit                                      [ Not found ]
[17:37:14]
[17:37:14] Checking for Jynx Rootkit...
[17:37:14]   Checking for file '/xochikit/bc'                [ Not found ]
[17:37:14]   Checking for file '/xochikit/ld_poison.so'      [ Not found ]
[17:37:14]   Checking for file '/omgxochi/bc'                [ Not found ]
[17:37:14]   Checking for file '/omgxochi/ld_poison.so'      [ Not found ]
[17:37:14]   Checking for directory '/xochikit'              [ Not found ]
[17:37:14]   Checking for directory '/omgxochi'              [ Not found ]
[17:37:14] Jynx Rootkit                                      [ Not found ]
[17:37:14]
[17:37:14] Checking for KBeast Rootkit...
[17:37:14]   Checking for file '/usr/_h4x_/ipsecs-kbeast-v1.ko' [ Not found ]
[17:37:15]   Checking for file '/usr/_h4x_/_h4x_bd'          [ Not found ]
[17:37:15]   Checking for file '/usr/_h4x_/acctlog'          [ Not found ]
[17:37:15]   Checking for directory '/usr/_h4x_'             [ Not found ]
[17:37:15]   Checking for kernel symbol 'h4x_delete_module'  [ Not found ]
[17:37:15]   Checking for kernel symbol 'h4x_getdents64'     [ Not found ]
[17:37:15]   Checking for kernel symbol 'h4x_kill'           [ Not found ]
[17:37:15]   Checking for kernel symbol 'h4x_open'           [ Not found ]
[17:37:15]   Checking for kernel symbol 'h4x_read'           [ Not found ]
[17:37:15]   Checking for kernel symbol 'h4x_rename'         [ Not found ]
[17:37:15]   Checking for kernel symbol 'h4x_rmdir'          [ Not found ]
[17:37:15]   Checking for kernel symbol 'h4x_tcp4_seq_show'  [ Not found ]
[17:37:15]   Checking for kernel symbol 'h4x_write'          [ Not found ]
[17:37:15] KBeast Rootkit                                    [ Not found ]
[17:37:15]
[17:37:15] Checking for Kitko Rootkit...
[17:37:16]   Checking for directory '/usr/src/redhat/SRPMS/...' [ Not found ]
[17:37:16] Kitko Rootkit                                     [ Not found ]
[17:37:16]
[17:37:16] Checking for Knark Rootkit...
[17:37:16]   Checking for file '/proc/knark/pids'            [ Not found ]
[17:37:16]   Checking for directory '/proc/knark'            [ Not found ]
[17:37:16] Knark Rootkit                                     [ Not found ]
[17:37:16]
[17:37:16] Checking for ld-linuxv.so Rootkit...
[17:37:16]   Checking for file '/lib/ld-linuxv.so.1'         [ Not found ]
[17:37:16]   Checking for directory '/var/opt/_so_cache'     [ Not found ]
[17:37:16]   Checking for directory '/var/opt/_so_cache/ld'  [ Not found ]
[17:37:16]   Checking for directory '/var/opt/_so_cache/lc'  [ Not found ]
[17:37:16] ld-linuxv.so Rootkit                              [ Not found ]
[17:37:16]
[17:37:16] Checking for Li0n Worm...
[17:37:16]   Checking for file '/bin/in.telnetd'             [ Not found ]
[17:37:16]   Checking for file '/bin/mjy'                    [ Not found ]
[17:37:16]   Checking for file '/usr/man/man1/man1/lib/.lib/mjy' [ Not found ]
[17:37:16]   Checking for file '/usr/man/man1/man1/lib/.lib/in.telnetd' [ Not found ]
[17:37:16]   Checking for file '/usr/man/man1/man1/lib/.lib/.x' [ Not found ]
[17:37:16]   Checking for file '/dev/.lib/lib/scan/1i0n.sh'  [ Not found ]
[17:37:16]   Checking for file '/dev/.lib/lib/scan/hack.sh'  [ Not found ]
[17:37:16]   Checking for file '/dev/.lib/lib/scan/bind'     [ Not found ]
[17:37:16]   Checking for file '/dev/.lib/lib/scan/randb'    [ Not found ]
[17:37:16]   Checking for file '/dev/.lib/lib/scan/scan.sh'  [ Not found ]
[17:37:16]   Checking for file '/dev/.lib/lib/scan/pscan'    [ Not found ]
[17:37:17]   Checking for file '/dev/.lib/lib/scan/star.sh'  [ Not found ]
[17:37:17]   Checking for file '/dev/.lib/lib/scan/bindx.sh' [ Not found ]
[17:37:17]   Checking for file '/dev/.lib/lib/scan/bindname.log' [ Not found ]
[17:37:17]   Checking for file '/dev/.lib/lib/1i0n.sh'       [ Not found ]
[17:37:17]   Checking for file '/dev/.lib/lib/lib/netstat'   [ Not found ]
[17:37:17]   Checking for file '/dev/.lib/lib/lib/dev/.1addr' [ Not found ]
[17:37:17]   Checking for file '/dev/.lib/lib/lib/dev/.1logz' [ Not found ]
[17:37:17]   Checking for file '/dev/.lib/lib/lib/dev/.1proc' [ Not found ]
[17:37:17]   Checking for file '/dev/.lib/lib/lib/dev/.1file' [ Not found ]
[17:37:17] Li0n Worm                                         [ Not found ]
[17:37:17]
[17:37:17] Checking for Lockit / LJK2 Rootkit...
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_config' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_random_seed*' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/sshd_config' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/du' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ifconfig' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/inetd.conf' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/locate' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/login' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ls' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/netstat' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ps' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/pstree' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/syslogd' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/tcpd' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/top' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1sauber' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1wted' [ Not found ]
[17:37:17]   Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1parse' [ Not found ]
[17:37:18]   Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1sniff' [ Not found ]
[17:37:18]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1addr' [ Not found ]
[17:37:18]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1dir' [ Not found ]
[17:37:18]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1log' [ Not found ]
[17:37:18]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1proc' [ Not found ]
[17:37:18]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c' [ Not found ]
[17:37:18]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/README.modules' [ Not found ]
[17:37:18]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c' [ Not found ]
[17:37:18]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1phide' [ Not found ]
[17:37:18]   Checking for file '/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh' [ Not found ]
[17:37:18]   Checking for directory '/usr/lib/libmen.oo/.LJK2' [ Not found ]
[17:37:18] Lockit / LJK2 Rootkit                             [ Not found ]
[17:37:18]
[17:37:18] Checking for Mood-NT Rootkit...
[17:37:18]   Checking for file '/sbin/init__mood-nt-_-_cthulhu' [ Not found ]
[17:37:18]   Checking for file '/_cthulhu/mood-nt.init'      [ Not found ]
[17:37:18]   Checking for file '/_cthulhu/mood-nt.conf'      [ Not found ]
[17:37:18]   Checking for file '/_cthulhu/mood-nt.sniff'     [ Not found ]
[17:37:18]   Checking for directory '/_cthulhu'              [ Not found ]
[17:37:18] Mood-NT Rootkit                                   [ Not found ]
[17:37:18]
[17:37:18] Checking for MRK Rootkit...
[17:37:18]   Checking for file '/dev/ida/.inet/pid'          [ Not found ]
[17:37:18]   Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[17:37:19]   Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[17:37:19]   Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
[17:37:19]   Checking for directory '/dev/ida/.inet'         [ Not found ]
[17:37:19]   Checking for directory '/var/spool/cron/.sh'    [ Not found ]
[17:37:19] MRK Rootkit                                       [ Not found ]
[17:37:19]
[17:37:19] Checking for Ni0 Rootkit...
[17:37:19]   Checking for file '/var/lock/subsys/...datafile.../...net...' [ Not found ]
[17:37:19]   Checking for file '/var/lock/subsys/...datafile.../...port...' [ Not found ]
[17:37:19]   Checking for file '/var/lock/subsys/...datafile.../...ps...' [ Not found ]
[17:37:19]   Checking for file '/var/lock/subsys/...datafile.../...file...' [ Not found ]
[17:37:19]   Checking for directory '/tmp/waza'              [ Not found ]
[17:37:19]   Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[17:37:19]   Checking for directory '/usr/sbin/es'           [ Not found ]
[17:37:19] Ni0 Rootkit                                       [ Not found ]
[17:37:19]
[17:37:19] Checking for Ohhara Rootkit...
[17:37:19]   Checking for file '/var/lock/subsys/...datafile.../...datafile.../in.smbd.log' [ Not found ]
[17:37:19]   Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[17:37:19]   Checking for directory '/var/lock/subsys/...datafile.../...datafile...' [ Not found ]
[17:37:19]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../bin' [ Not found ]
[17:37:20]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/bin' [ Not found ]
[17:37:20]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/sbin' [ Not found ]
[17:37:20]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../lib/security' [ Not found ]
[17:37:20] Ohhara Rootkit                                    [ Not found ]
[17:37:20]
[17:37:20] Checking for Optic Kit (Tux) Worm...
[17:37:20]   Checking for directory '/dev/tux'               [ Not found ]
[17:37:20]   Checking for directory '/usr/bin/xchk'          [ Not found ]
[17:37:20]   Checking for directory '/usr/bin/xsf'           [ Not found ]
[17:37:20]   Checking for directory '/usr/bin/ssh2d'         [ Not found ]
[17:37:20] Optic Kit (Tux) Worm                              [ Not found ]
[17:37:20]
[17:37:20] Checking for Oz Rootkit...
[17:37:20]   Checking for file '/dev/.oz/.nap/rkit/terror'   [ Not found ]
[17:37:20]   Checking for directory '/dev/.oz'               [ Not found ]
[17:37:20] Oz Rootkit                                        [ Not found ]
[17:37:20]
[17:37:20] Checking for Phalanx Rootkit...
[17:37:20]   Checking for file '/uNFuNF'                     [ Not found ]
[17:37:20]   Checking for file '/etc/host.ph1'               [ Not found ]
[17:37:20]   Checking for file '/bin/host.ph1'               [ Not found ]
[17:37:20]   Checking for file '/usr/share/.home.ph1/phalanx' [ Not found ]
[17:37:20]   Checking for file '/usr/share/.home.ph1/cb'     [ Not found ]
[17:37:21]   Checking for file '/usr/share/.home.ph1/kebab'  [ Not found ]
[17:37:21]   Checking for directory '/usr/share/.home.ph1'   [ Not found ]
[17:37:21]   Checking for directory '/usr/share/.home.ph1/tty' [ Not found ]
[17:37:21] Phalanx Rootkit                                   [ Not found ]
[17:37:21]
[17:37:21] Checking for Phalanx2 Rootkit...
[17:37:21]   Checking for file '/etc/khubd.p2/.p2rc'         [ Not found ]
[17:37:21]   Checking for file '/etc/khubd.p2/.phalanx2'     [ Not found ]
[17:37:21]   Checking for file '/etc/khubd.p2/.sniff'        [ Not found ]
[17:37:21]   Checking for file '/etc/khubd.p2/sshgrab.py'    [ Not found ]
[17:37:21]   Checking for file '/etc/lolzz.p2/.p2rc'         [ Not found ]
[17:37:21]   Checking for file '/etc/lolzz.p2/.phalanx2'     [ Not found ]
[17:37:21]   Checking for file '/etc/lolzz.p2/.sniff'        [ Not found ]
[17:37:21]   Checking for file '/etc/lolzz.p2/sshgrab.py'    [ Not found ]
[17:37:21]   Checking for file '/etc/cron.d/zupzzplaceholder' [ Not found ]
[17:37:21]   Checking for file '/usr/lib/zupzz.p2/.p-2.3d'   [ Not found ]
[17:37:21]   Checking for file '/usr/lib/zupzz.p2/.p2rc'     [ Not found ]
[17:37:21]   Checking for directory '/etc/khubd.p2'          [ Not found ]
[17:37:21]   Checking for directory '/etc/lolzz.p2'          [ Not found ]
[17:37:21]   Checking for directory '/usr/lib/zupzz.p2'      [ Not found ]
[17:37:21] Phalanx2 Rootkit                                  [ Not found ]
[17:37:21]
[17:37:21] Checking for Phalanx2 Rootkit (extended tests)...
[17:37:21]   Checking for directory '/etc/khubd.p2'          [ Not found ]
[17:37:21]   Checking for directory '/etc/lolzz.p2'          [ Not found ]
[17:37:21]   Checking for directory '/usr/lib/zupzz.p2'      [ Not found ]
[17:37:22] Phalanx2 Rootkit (extended tests)                 [ Not found ]
[17:37:22]
[17:37:22] Checking for Portacelo Rootkit...
[17:37:22]   Checking for file '/var/lib/.../.ak'            [ Not found ]
[17:37:22]   Checking for file '/var/lib/.../.hk'            [ Not found ]
[17:37:22]   Checking for file '/var/lib/.../.rs'            [ Not found ]
[17:37:22]   Checking for file '/var/lib/.../.p'             [ Not found ]
[17:37:22]   Checking for file '/var/lib/.../getty'          [ Not found ]
[17:37:22]   Checking for file '/var/lib/.../lkt.o'          [ Not found ]
[17:37:22]   Checking for file '/var/lib/.../show'           [ Not found ]
[17:37:22]   Checking for file '/var/lib/.../nlkt.o'         [ Not found ]
[17:37:22]   Checking for file '/var/lib/.../ssshrc'         [ Not found ]
[17:37:22]   Checking for file '/var/lib/.../sssh_equiv'     [ Not found ]
[17:37:22]   Checking for file '/var/lib/.../sssh_known_hosts' [ Not found ]
[17:37:22]   Checking for file '/var/lib/.../sssh_pid'       [ Not found ]
[17:37:22]   Checking for file '~/.sssh/known_hosts'         [ Not found ]
[17:37:23] Portacelo Rootkit                                 [ Not found ]
[17:37:23]
[17:37:23] Checking for R3dstorm Toolkit...
[17:37:23]   Checking for file '/var/log/tk02/see_all'       [ Not found ]
[17:37:23]   Checking for file '/var/log/tk02/.scris'        [ Not found ]
[17:37:23]   Checking for file '/bin/.../sshd/sbin/sshd1'    [ Not found ]
[17:37:23]   Checking for file '/bin/.../hate/sk'            [ Not found ]
[17:37:23]   Checking for file '/bin/.../see_all'            [ Not found ]
[17:37:23]   Checking for directory '/var/log/tk02'          [ Not found ]
[17:37:23]   Checking for directory '/var/log/tk02/old'      [ Not found ]
[17:37:23]   Checking for directory '/bin/...'               [ Not found ]
[17:37:23] R3dstorm Toolkit                                  [ Not found ]
[17:37:23]
[17:37:23] Checking for RH-Sharpe's Rootkit...
[17:37:23]   Checking for file '/bin/lps'                    [ Not found ]
[17:37:23]   Checking for file '/usr/bin/lpstree'            [ Not found ]
[17:37:23]   Checking for file '/usr/bin/ltop'               [ Not found ]
[17:37:23]   Checking for file '/usr/bin/lkillall'           [ Not found ]
[17:37:23]   Checking for file '/usr/bin/ldu'                [ Not found ]
[17:37:23]   Checking for file '/usr/bin/lnetstat'           [ Not found ]
[17:37:23]   Checking for file '/usr/bin/wp'                 [ Not found ]
[17:37:23]   Checking for file '/usr/bin/shad'               [ Not found ]
[17:37:23]   Checking for file '/usr/bin/vadim'              [ Not found ]
[17:37:23]   Checking for file '/usr/bin/slice'              [ Not found ]
[17:37:24]   Checking for file '/usr/bin/cleaner'            [ Not found ]
[17:37:24]   Checking for file '/usr/include/rpcsvc/du'      [ Not found ]
[17:37:24] RH-Sharpe's Rootkit                               [ Not found ]
[17:37:24]
[17:37:24] Checking for RSHA's Rootkit...
[17:37:24]   Checking for file '/bin/kr4p'                   [ Not found ]
[17:37:24]   Checking for file '/usr/bin/n3tstat'            [ Not found ]
[17:37:24]   Checking for file '/usr/bin/chsh2'              [ Not found ]
[17:37:24]   Checking for file '/usr/bin/slice2'             [ Not found ]
[17:37:24]   Checking for file '/usr/src/linux/arch/alpha/lib/.lib/.1proc' [ Not found ]
[17:37:24]   Checking for file '/etc/rc.d/arch/alpha/lib/.lib/.1addr' [ Not found ]
[17:37:24]   Checking for directory '/etc/rc.d/rsha'         [ Not found ]
[17:37:24]   Checking for directory '/etc/rc.d/arch/alpha/lib/.lib' [ Not found ]
[17:37:24] RSHA's Rootkit                                    [ Not found ]
[17:37:24]
[17:37:24] Checking for Scalper Worm...
[17:37:24]   Checking for file '/tmp/.a'                     [ Not found ]
[17:37:24]   Checking for file '/tmp/.uua'                   [ Not found ]
[17:37:24] Scalper Worm                                      [ Not found ]
[17:37:24]
[17:37:24] Checking for Sebek LKM...
[17:37:25]   Checking for kernel symbol 'adore or sebek'     [ Not found ]
[17:37:25] Sebek LKM                                         [ Not found ]
[17:37:25]
[17:37:25] Checking for Shutdown Rootkit...
[17:37:25]   Checking for file '/usr/man/man5/.. /.dir/scannah/asus' [ Not found ]
[17:37:25]   Checking for file '/usr/man/man5/.. /.dir/see'  [ Not found ]
[17:37:25]   Checking for file '/usr/man/man5/.. /.dir/nscd' [ Not found ]
[17:37:25]   Checking for file '/usr/man/man5/.. /.dir/alpd' [ Not found ]
[17:37:25]   Checking for file '/etc/rc.d/rc.local '         [ Not found ]
[17:37:25]   Checking for directory '/usr/man/man5/.. /.dir' [ Not found ]
[17:37:25]   Checking for directory '/usr/man/man5/.. /.dir/scannah' [ Not found ]
[17:37:25]   Checking for directory '/etc/rc.d/rc0.d/.. /.dir' [ Not found ]
[17:37:25] Shutdown Rootkit                                  [ Not found ]
[17:37:25]
[17:37:25] Checking for SHV4 Rootkit...
[17:37:25]   Checking for file '/etc/ld.so.hash'             [ Not found ]
[17:37:25]   Checking for file '/lib/libext-2.so.7'          [ Not found ]
[17:37:25]   Checking for file '/lib/lidps1.so'              [ Not found ]
[17:37:25]   Checking for file '/lib/libproc.a'              [ Not found ]
[17:37:25]   Checking for file '/lib/libproc.so.2.0.6'       [ Not found ]
[17:37:25]   Checking for file '/lib/ldd.so/tks'             [ Not found ]
[17:37:25]   Checking for file '/lib/ldd.so/tkp'             [ Not found ]
[17:37:25]   Checking for file '/lib/ldd.so/tksb'            [ Not found ]
[17:37:25]   Checking for file '/lib/security/.config/sshd'  [ Not found ]
[17:37:25]   Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[17:37:25]   Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[17:37:26]   Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[17:37:26]   Checking for file '/usr/include/file.h'         [ Not found ]
[17:37:26]   Checking for file '/usr/include/hosts.h'        [ Not found ]
[17:37:26]   Checking for file '/usr/include/lidps1.so'      [ Not found ]
[17:37:26]   Checking for file '/usr/include/log.h'          [ Not found ]
[17:37:26]   Checking for file '/usr/include/proc.h'         [ Not found ]
[17:37:26]   Checking for file '/usr/sbin/xntps'             [ Not found ]
[17:37:26]   Checking for file '/dev/srd0'                   [ Not found ]
[17:37:26]   Checking for directory '/lib/ldd.so'            [ Not found ]
[17:37:26]   Checking for directory '/lib/security/.config'  [ Not found ]
[17:37:26]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[17:37:26] SHV4 Rootkit                                      [ Not found ]
[17:37:26]
[17:37:26] Checking for SHV5 Rootkit...
[17:37:26]   Checking for file '/etc/sh.conf'                [ Not found ]
[17:37:26]   Checking for file '/lib/libproc.a'              [ Not found ]
[17:37:26]   Checking for file '/lib/libproc.so.2.0.6'       [ Not found ]
[17:37:26]   Checking for file '/lib/lidps1.so'              [ Not found ]
[17:37:26]   Checking for file '/lib/libsh.so/bash'          [ Not found ]
[17:37:26]   Checking for file '/usr/include/file.h'         [ Not found ]
[17:37:26]   Checking for file '/usr/include/hosts.h'        [ Not found ]
[17:37:26]   Checking for file '/usr/include/log.h'          [ Not found ]
[17:37:26]   Checking for file '/usr/include/proc.h'         [ Not found ]
[17:37:26]   Checking for file '/lib/libsh.so/shdcf2'        [ Not found ]
[17:37:27]   Checking for file '/lib/libsh.so/shhk'          [ Not found ]
[17:37:27]   Checking for file '/lib/libsh.so/shhk.pub'      [ Not found ]
[17:37:27]   Checking for file '/lib/libsh.so/shrs'          [ Not found ]
[17:37:27]   Checking for file '/usr/lib/libsh/.bashrc'      [ Not found ]
[17:37:27]   Checking for file '/usr/lib/libsh/shsb'         [ Not found ]
[17:37:27]   Checking for file '/usr/lib/libsh/hide'         [ Not found ]
[17:37:27]   Checking for file '/usr/lib/libsh/.sniff/shsniff' [ Not found ]
[17:37:27]   Checking for file '/usr/lib/libsh/.sniff/shp'   [ Not found ]
[17:37:27]   Checking for file '/dev/srd0'                   [ Not found ]
[17:37:27]   Checking for directory '/lib/libsh.so'          [ Not found ]
[17:37:27]   Checking for directory '/usr/lib/libsh'         [ Not found ]
[17:37:27]   Checking for directory '/usr/lib/libsh/utilz'   [ Not found ]
[17:37:27]   Checking for directory '/usr/lib/libsh/.backup' [ Not found ]
[17:37:27] SHV5 Rootkit                                      [ Not found ]
[17:37:27]
[17:37:27] Checking for Sin Rootkit...
[17:37:27]   Checking for file '/dev/.haos/haos1/.f/Denyed'  [ Not found ]
[17:37:27]   Checking for file '/dev/ttyoa'                  [ Not found ]
[17:37:27]   Checking for file '/dev/ttyof'                  [ Not found ]
[17:37:27]   Checking for file '/dev/ttyop'                  [ Not found ]
[17:37:27]   Checking for file '/dev/ttyos'                  [ Not found ]
[17:37:27]   Checking for file '/usr/lib/.lib'               [ Not found ]
[17:37:27]   Checking for file '/usr/lib/sn/.X'              [ Not found ]
[17:37:27]   Checking for file '/usr/lib/sn/.sys'            [ Not found ]
[17:37:27]   Checking for file '/usr/lib/ld/.X'              [ Not found ]
[17:37:27]   Checking for file '/usr/man/man1/...'           [ Not found ]
[17:37:27]   Checking for file '/usr/man/man1/.../.m'        [ Not found ]
[17:37:27]   Checking for file '/usr/man/man1/.../.w'        [ Not found ]
[17:37:27]   Checking for directory '/usr/lib/sn'            [ Not found ]
[17:37:27]   Checking for directory '/usr/lib/man1/...'      [ Not found ]
[17:37:27]   Checking for directory '/dev/.haos'             [ Not found ]
[17:37:27] Sin Rootkit                                       [ Not found ]
[17:37:28]
[17:37:28] Checking for Slapper Worm...
[17:37:28]   Checking for file '/tmp/.bugtraq'               [ Not found ]
[17:37:28]   Checking for file '/tmp/.uubugtraq'             [ Not found ]
[17:37:28]   Checking for file '/tmp/.bugtraq.c'             [ Not found ]
[17:37:28]   Checking for file '/tmp/httpd'                  [ Not found ]
[17:37:28]   Checking for file '/tmp/.unlock'                [ Not found ]
[17:37:28]   Checking for file '/tmp/update'                 [ Not found ]
[17:37:28]   Checking for file '/tmp/.cinik'                 [ Not found ]
[17:37:28]   Checking for file '/tmp/.b'                     [ Not found ]
[17:37:28] Slapper Worm                                      [ Not found ]
[17:37:28]
[17:37:28] Checking for Sneakin Rootkit...
[17:37:28]   Checking for directory '/tmp/.X11-unix/.../rk'  [ Not found ]
[17:37:28] Sneakin Rootkit                                   [ Not found ]
[17:37:28]
[17:37:28] Checking for 'Spanish' Rootkit...
[17:37:28]   Checking for file '/dev/ptyq'                   [ Not found ]
[17:37:28]   Checking for file '/bin/ad'                     [ Not found ]
[17:37:28]   Checking for file '/bin/ava'                    [ Not found ]
[17:37:28]   Checking for file '/bin/server'                 [ Not found ]
[17:37:28]   Checking for file '/usr/sbin/rescue'            [ Not found ]
[17:37:28]   Checking for file '/usr/share/.../chrps'        [ Not found ]
[17:37:28]   Checking for file '/usr/share/.../chrifconfig'  [ Not found ]
[17:37:28]   Checking for file '/usr/share/.../netstat'      [ Not found ]
[17:37:28]   Checking for file '/usr/share/.../linsniffer'   [ Not found ]
[17:37:28]   Checking for file '/usr/share/.../charbd'       [ Not found ]
[17:37:28]   Checking for file '/usr/share/.../charbd2'      [ Not found ]
[17:37:28]   Checking for file '/usr/share/.../charbd3'      [ Not found ]
[17:37:28]   Checking for file '/usr/share/.../charbd4'      [ Not found ]
[17:37:28]   Checking for file '/usr/man/tmp/update.tgz'     [ Not found ]
[17:37:28]   Checking for file '/var/lib/rpm/db.rpm'         [ Not found ]
[17:37:28]   Checking for file '/var/cache/man/.cat'         [ Not found ]
[17:37:28]   Checking for file '/var/spool/lpd/remote/.lpq'  [ Not found ]
[17:37:29]   Checking for directory '/usr/share/...'         [ Not found ]
[17:37:29] 'Spanish' Rootkit                                 [ Not found ]
[17:37:29]
[17:37:29] Checking for Suckit Rootkit...
[17:37:29]   Checking for file '/sbin/initsk12'              [ Not found ]
[17:37:29]   Checking for file '/sbin/initxrk'               [ Not found ]
[17:37:29]   Checking for file '/usr/bin/null'               [ Not found ]
[17:37:29]   Checking for file '/usr/share/locale/sk/.sk12/sk' [ Not found ]
[17:37:29]   Checking for file '/etc/rc.d/rc0.d/S23kmdac'    [ Not found ]
[17:37:29]   Checking for file '/etc/rc.d/rc1.d/S23kmdac'    [ Not found ]
[17:37:29]   Checking for file '/etc/rc.d/rc2.d/S23kmdac'    [ Not found ]
[17:37:29]   Checking for file '/etc/rc.d/rc3.d/S23kmdac'    [ Not found ]
[17:37:29]   Checking for file '/etc/rc.d/rc4.d/S23kmdac'    [ Not found ]
[17:37:29]   Checking for file '/etc/rc.d/rc5.d/S23kmdac'    [ Not found ]
[17:37:29]   Checking for file '/etc/rc.d/rc6.d/S23kmdac'    [ Not found ]
[17:37:29]   Checking for directory '/dev/sdhu0/tehdrakg'    [ Not found ]
[17:37:29]   Checking for directory '/etc/.MG'               [ Not found ]
[17:37:29]   Checking for directory '/usr/share/locale/sk/.sk12' [ Not found ]
[17:37:29]   Checking for directory '/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist' [ Not found ]
[17:37:29] Suckit Rootkit                                    [ Not found ]
[17:37:29]
[17:37:29] Checking for Superkit Rootkit...
[17:37:29]   Checking for file '/usr/man/.sman/sk/backsh'    [ Not found ]
[17:37:29]   Checking for file '/usr/man/.sman/sk/izbtrag'   [ Not found ]
[17:37:29]   Checking for file '/usr/man/.sman/sk/sksniff'   [ Not found ]
[17:37:29]   Checking for file '/var/www/cgi-bin/cgiback.cgi' [ Not found ]
[17:37:29]   Checking for directory '/usr/man/.sman/sk'      [ Not found ]
[17:37:29] Superkit Rootkit                                  [ Not found ]
[17:37:29]
[17:37:29] Checking for TBD (Telnet BackDoor)...
[17:37:29]   Checking for file '/usr/lib/.tbd'               [ Not found ]
[17:37:29] TBD (Telnet BackDoor)                             [ Not found ]
[17:37:29]
[17:37:29] Checking for TeLeKiT Rootkit...
[17:37:29]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/sniff' [ Not found ]
[17:37:30]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/telnetd' [ Not found ]
[17:37:30]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/teleulo' [ Not found ]
[17:37:30]   Checking for file '/usr/man/man3/.../cl'        [ Not found ]
[17:37:30]   Checking for file '/dev/ptyr'                   [ Not found ]
[17:37:30]   Checking for file '/dev/ptyp'                   [ Not found ]
[17:37:30]   Checking for file '/dev/ptyq'                   [ Not found ]
[17:37:30]   Checking for file '/dev/hda06'                  [ Not found ]
[17:37:30]   Checking for file '/usr/info/libc1.so'          [ Not found ]
[17:37:30]   Checking for directory '/usr/man/man3/...'      [ Not found ]
[17:37:30]   Checking for directory '/usr/man/man3/.../lsniff' [ Not found ]
[17:37:30]   Checking for directory '/usr/man/man3/.../TeLeKiT' [ Not found ]
[17:37:30] TeLeKiT Rootkit                                   [ Not found ]
[17:37:30]
[17:37:30] Checking for T0rn Rootkit...
[17:37:30]   Checking for file '/dev/.lib/lib/lib/t0rns'     [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/du'        [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/ls'        [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/t0rnsb'    [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/ps'        [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/t0rnp'     [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/find'      [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/ifconfig'  [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/pg'        [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/ssh.tgz'   [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/top'       [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/sz'        [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/login'     [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/in.fingerd' [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/1i0n.sh'   [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/pstree'    [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/in.telnetd' [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/mjy'       [ Not found ]
[17:37:30]   Checking for file '/dev/.lib/lib/lib/sush'      [ Not found ]
[17:37:31]   Checking for file '/dev/.lib/lib/lib/tfn'       [ Not found ]
[17:37:31]   Checking for file '/dev/.lib/lib/lib/name'      [ Not found ]
[17:37:31]   Checking for file '/dev/.lib/lib/lib/getip.sh'  [ Not found ]
[17:37:31]   Checking for file '/usr/info/.torn/sh*'         [ Not found ]
[17:37:31]   Checking for file '/usr/src/.puta/.1addr'       [ Not found ]
[17:37:31]   Checking for file '/usr/src/.puta/.1file'       [ Not found ]
[17:37:31]   Checking for file '/usr/src/.puta/.1proc'       [ Not found ]
[17:37:31]   Checking for file '/usr/src/.puta/.1logz'       [ Not found ]
[17:37:31]   Checking for file '/usr/info/.t0rn'             [ Not found ]
[17:37:31]   Checking for directory '/dev/.lib'              [ Not found ]
[17:37:31]   Checking for directory '/dev/.lib/lib'          [ Not found ]
[17:37:31]   Checking for directory '/dev/.lib/lib/lib'      [ Not found ]
[17:37:31]   Checking for directory '/dev/.lib/lib/lib/dev'  [ Not found ]
[17:37:31]   Checking for directory '/dev/.lib/lib/scan'     [ Not found ]
[17:37:31]   Checking for directory '/usr/src/.puta'         [ Not found ]
[17:37:31]   Checking for directory '/usr/man/man1/man1'     [ Not found ]
[17:37:31]   Checking for directory '/usr/man/man1/man1/lib' [ Not found ]
[17:37:31]   Checking for directory '/usr/man/man1/man1/lib/.lib' [ Not found ]
[17:37:31]   Checking for directory '/usr/man/man1/man1/lib/.lib/.backup' [ Not found ]
[17:37:31] T0rn Rootkit                                      [ Not found ]
[17:37:31]
[17:37:31] Checking for trNkit Rootkit...
[17:37:31]   Checking for file '/usr/lib/libbins.la'         [ Not found ]
[17:37:31]   Checking for file '/usr/lib/libtcs.so'          [ Not found ]
[17:37:31]   Checking for file '/dev/.ttpy/ulogin.sh'        [ Not found ]
[17:37:31]   Checking for file '/dev/.ttpy/tcpshell.sh'      [ Not found ]
[17:37:31]   Checking for file '/dev/.ttpy/bupdu'            [ Not found ]
[17:37:31]   Checking for file '/dev/.ttpy/buloc'            [ Not found ]
[17:37:31]   Checking for file '/dev/.ttpy/buloc1'           [ Not found ]
[17:37:31]   Checking for file '/dev/.ttpy/buloc2'           [ Not found ]
[17:37:31]   Checking for file '/dev/.ttpy/stat'             [ Not found ]
[17:37:31]   Checking for file '/dev/.ttpy/backps'           [ Not found ]
[17:37:31]   Checking for file '/dev/.ttpy/tree'             [ Not found ]
[17:37:31]   Checking for file '/dev/.ttpy/topk'             [ Not found ]
[17:37:32]   Checking for file '/dev/.ttpy/wold'             [ Not found ]
[17:37:32]   Checking for file '/dev/.ttpy/whoold'           [ Not found ]
[17:37:32]   Checking for file '/dev/.ttpy/backdoors'        [ Not found ]
[17:37:32] trNkit Rootkit                                    [ Not found ]
[17:37:32]
[17:37:32] Checking for Trojanit Kit...
[17:37:32]   Checking for file '/bin/.ls'                    [ Not found ]
[17:37:32]   Checking for file '/bin/.ps'                    [ Not found ]
[17:37:32]   Checking for file '/bin/.netstat'               [ Not found ]
[17:37:32]   Checking for file '/usr/bin/.nop'               [ Not found ]
[17:37:32]   Checking for file '/usr/bin/.who'               [ Not found ]
[17:37:32] Trojanit Kit                                      [ Not found ]
[17:37:32]
[17:37:32] Checking for Tuxtendo Rootkit...
[17:37:32]   Checking for file '/lib/libproc.so.2.0.7'       [ Not found ]
[17:37:32]   Checking for file '/usr/bin/xchk'               [ Not found ]
[17:37:32]   Checking for file '/usr/bin/xsf'                [ Not found ]
[17:37:32]   Checking for file '/dev/tux/suidsh'             [ Not found ]
[17:37:32]   Checking for file '/dev/tux/.addr'              [ Not found ]
[17:37:32]   Checking for file '/dev/tux/.cron'              [ Not found ]
[17:37:32]   Checking for file '/dev/tux/.file'              [ Not found ]
[17:37:32]   Checking for file '/dev/tux/.log'               [ Not found ]
[17:37:32]   Checking for file '/dev/tux/.proc'              [ Not found ]
[17:37:32]   Checking for file '/dev/tux/.iface'             [ Not found ]
[17:37:32]   Checking for file '/dev/tux/.pw'                [ Not found ]
[17:37:32]   Checking for file '/dev/tux/.df'                [ Not found ]
[17:37:32]   Checking for file '/dev/tux/.ssh'               [ Not found ]
[17:37:32]   Checking for file '/dev/tux/.tux'               [ Not found ]
[17:37:32]   Checking for file '/dev/tux/ssh2/sshd2_config'  [ Not found ]
[17:37:32]   Checking for file '/dev/tux/ssh2/hostkey'       [ Not found ]
[17:37:32]   Checking for file '/dev/tux/ssh2/hostkey.pub'   [ Not found ]
[17:37:32]   Checking for file '/dev/tux/ssh2/logo'          [ Not found ]
[17:37:32]   Checking for file '/dev/tux/ssh2/random_seed'   [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/crontab'     [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/df'          [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/dir'         [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/find'        [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/ifconfig'    [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/locate'      [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/netstat'     [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/ps'          [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/pstree'      [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/syslogd'     [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/tcpd'        [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/top'         [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/updatedb'    [ Not found ]
[17:37:33]   Checking for file '/dev/tux/backup/vdir'        [ Not found ]
[17:37:33]   Checking for directory '/dev/tux'               [ Not found ]
[17:37:33]   Checking for directory '/dev/tux/ssh2'          [ Not found ]
[17:37:33]   Checking for directory '/dev/tux/backup'        [ Not found ]
[17:37:33] Tuxtendo Rootkit                                  [ Not found ]
[17:37:33]
[17:37:33] Checking for URK Rootkit...
[17:37:33]   Checking for file '/dev/prom/sn.l'              [ Not found ]
[17:37:33]   Checking for file '/usr/lib/ldlibps.so'         [ Not found ]
[17:37:33]   Checking for file '/usr/lib/ldlibnet.so'        [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/uconf.inv'       [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/cleaner'         [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/bin/psniff'      [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/bin/du'          [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/bin/ls'          [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/bin/passwd'      [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/bin/ps'          [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/bin/psr'         [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/bin/su'          [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/bin/find'        [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/bin/netstat'     [ Not found ]
[17:37:33]   Checking for file '/dev/pts/01/bin/ping'        [ Not found ]
[17:37:34]   Checking for file '/dev/pts/01/bin/strings'     [ Not found ]
[17:37:34]   Checking for file '/dev/pts/01/bin/bash'        [ Not found ]
[17:37:34]   Checking for file '/usr/man/man1/xxxxxxbin/du'  [ Not found ]
[17:37:34]   Checking for file '/usr/man/man1/xxxxxxbin/ls'  [ Not found ]
[17:37:34]   Checking for file '/usr/man/man1/xxxxxxbin/passwd' [ Not found ]
[17:37:34]   Checking for file '/usr/man/man1/xxxxxxbin/ps'  [ Not found ]
[17:37:34]   Checking for file '/usr/man/man1/xxxxxxbin/psr' [ Not found ]
[17:37:34]   Checking for file '/usr/man/man1/xxxxxxbin/su'  [ Not found ]
[17:37:34]   Checking for file '/usr/man/man1/xxxxxxbin/find' [ Not found ]
[17:37:34]   Checking for file '/usr/man/man1/xxxxxxbin/netstat' [ Not found ]
[17:37:34]   Checking for file '/usr/man/man1/xxxxxxbin/ping' [ Not found ]
[17:37:34]   Checking for file '/usr/man/man1/xxxxxxbin/strings' [ Not found ]
[17:37:34]   Checking for file '/usr/man/man1/xxxxxxbin/bash' [ Not found ]
[17:37:34]   Checking for file '/tmp/conf.inv'               [ Not found ]
[17:37:34]   Checking for directory '/dev/prom'              [ Not found ]
[17:37:34]   Checking for directory '/dev/pts/01'            [ Not found ]
[17:37:34]   Checking for directory '/dev/pts/01/bin'        [ Not found ]
[17:37:34]   Checking for directory '/usr/man/man1/xxxxxxbin' [ Not found ]
[17:37:34] URK Rootkit                                       [ Not found ]
[17:37:34]
[17:37:34] Checking for Vampire Rootkit...
[17:37:34]   Checking for kernel symbol 'new_getdents'       [ Not found ]
[17:37:34]   Checking for kernel symbol 'old_getdents'       [ Not found ]
[17:37:35]   Checking for kernel symbol 'should_hide_file_name' [ Not found ]
[17:37:35]   Checking for kernel symbol 'should_hide_task_name' [ Not found ]
[17:37:35] Vampire Rootkit                                   [ Not found ]
[17:37:35]
[17:37:35] Checking for VcKit Rootkit...
[17:37:35]   Checking for directory '/usr/include/linux/modules/lib.so' [ Not found ]
[17:37:35]   Checking for directory '/usr/include/linux/modules/lib.so/bin' [ Not found ]
[17:37:35] VcKit Rootkit                                     [ Not found ]
[17:37:35]
[17:37:35] Checking for Volc Rootkit...
[17:37:35]   Checking for file '/usr/bin/volc'               [ Not found ]
[17:37:35]   Checking for file '/usr/lib/volc/backdoor/divine' [ Not found ]
[17:37:35]   Checking for file '/usr/lib/volc/linsniff'      [ Not found ]
[17:37:35]   Checking for file '/etc/rc.d/rc1.d/S25sysconf'  [ Not found ]
[17:37:35]   Checking for file '/etc/rc.d/rc2.d/S25sysconf'  [ Not found ]
[17:37:35]   Checking for file '/etc/rc.d/rc3.d/S25sysconf'  [ Not found ]
[17:37:35]   Checking for file '/etc/rc.d/rc4.d/S25sysconf'  [ Not found ]
[17:37:35]   Checking for file '/etc/rc.d/rc5.d/S25sysconf'  [ Not found ]
[17:37:35]   Checking for directory '/var/spool/.recent'     [ Not found ]
[17:37:35]   Checking for directory '/var/spool/.recent/.files' [ Not found ]
[17:37:35]   Checking for directory '/usr/lib/volc'          [ Not found ]
[17:37:35]   Checking for directory '/usr/lib/volc/backup'   [ Not found ]
[17:37:36] Volc Rootkit                                      [ Not found ]
[17:37:36]
[17:37:36] Checking for Xzibit Rootkit...
[17:37:36]   Checking for file '/dev/dsx'                    [ Not found ]
[17:37:36]   Checking for file '/dev/caca'                   [ Not found ]
[17:37:36]   Checking for file '/dev/ida/.inet/linsniffer'   [ Not found ]
[17:37:36]   Checking for file '/dev/ida/.inet/logclear'     [ Not found ]
[17:37:36]   Checking for file '/dev/ida/.inet/sense'        [ Not found ]
[17:37:36]   Checking for file '/dev/ida/.inet/sl2'          [ Not found ]
[17:37:36]   Checking for file '/dev/ida/.inet/sshdu'        [ Not found ]
[17:37:36]   Checking for file '/dev/ida/.inet/s'            [ Not found ]
[17:37:36]   Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[17:37:36]   Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[17:37:36]   Checking for file '/dev/ida/.inet/sl2new.c'     [ Not found ]
[17:37:36]   Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
[17:37:36]   Checking for file '/home/httpd/cgi-bin/becys.cgi' [ Not found ]
[17:37:36]   Checking for file '/usr/local/httpd/cgi-bin/becys.cgi' [ Not found ]
[17:37:36]   Checking for file '/usr/local/apache/cgi-bin/becys.cgi' [ Not found ]
[17:37:36]   Checking for file '/www/httpd/cgi-bin/becys.cgi' [ Not found ]
[17:37:36]   Checking for file '/www/cgi-bin/becys.cgi'      [ Not found ]
[17:37:36]   Checking for directory '/dev/ida/.inet'         [ Not found ]
[17:37:36] Xzibit Rootkit                                    [ Not found ]
[17:37:36]
[17:37:36] Checking for zaRwT.KiT Rootkit...
[17:37:36]   Checking for file '/dev/rd/s/sendmeil'          [ Not found ]
[17:37:36]   Checking for file '/dev/ttyf'                   [ Not found ]
[17:37:36]   Checking for file '/dev/ttyp'                   [ Not found ]
[17:37:37]   Checking for file '/dev/ttyn'                   [ Not found ]
[17:37:37]   Checking for file '/rk/tulz'                    [ Not found ]
[17:37:37]   Checking for directory '/rk'                    [ Not found ]
[17:37:37]   Checking for directory '/dev/rd/s'              [ Not found ]
[17:37:37] zaRwT.KiT Rootkit                                 [ Not found ]
[17:37:37]
[17:37:37] Checking for ZK Rootkit...
[17:37:37]   Checking for file '/usr/share/.zk/zk'           [ Not found ]
[17:37:37]   Checking for file '/usr/X11R6/.zk/xfs'          [ Not found ]
[17:37:37]   Checking for file '/usr/X11R6/.zk/echo'         [ Not found ]
[17:37:37]   Checking for file '/etc/1ssue.net'              [ Not found ]
[17:37:37]   Checking for file '/etc/sysconfig/console/load.zk' [ Not found ]
[17:37:37]   Checking for directory '/usr/share/.zk'         [ Not found ]
[17:37:37]   Checking for directory '/usr/X11R6/.zk'         [ Not found ]
[17:37:37] ZK Rootkit                                        [ Not found ]
[17:38:21]
[17:38:21] Info: Starting test name 'additional_rkts'
[17:38:21] Performing additional rootkit checks
[17:38:21]
[17:38:21]   Performing Suckit Rookit additional checks
[17:38:21]     Checking hard link count on '/sbin/init'      [ OK ]
[17:38:21]     Checking for hidden file extensions           [ None found ]
[17:38:21]     Running skdet command                         [ Skipped ]
[17:38:21] Info: Unable to find the 'skdet' command
[17:38:21]   Suckit Rookit additional checks                 [ OK ]
[17:38:21]
[17:38:21] Info: Starting test name 'possible_rkt_files'
[17:38:21]   Performing check of possible rootkit files and directories
[17:38:21]     Checking for file '/dev/sdr0'                 [ Not found ]
[17:38:21]     Checking for file '/dev/pisu'                 [ Not found ]
[17:38:22]     Checking for file '/dev/xdta'                 [ Not found ]
[17:38:22]     Checking for file '/dev/saux'                 [ Not found ]
[17:38:22]     Checking for file '/dev/hdx'                  [ Not found ]
[17:38:22]     Checking for file '/dev/hdx1'                 [ Not found ]
[17:38:22]     Checking for file '/dev/hdx2'                 [ Not found ]
[17:38:22]     Checking for file '/dev/ptyy'                 [ Not found ]
[17:38:22]     Checking for file '/dev/ptyu'                 [ Not found ]
[17:38:22]     Checking for file '/dev/ptyv'                 [ Not found ]
[17:38:22]     Checking for file '/dev/hdbb'                 [ Not found ]
[17:38:22]     Checking for file '/tmp/.syshackfile'         [ Not found ]
[17:38:22]     Checking for file '/tmp/.bash_history'        [ Not found ]
[17:38:22]     Checking for file '/usr/info/.clib'           [ Not found ]
[17:38:22]     Checking for file '/usr/sbin/tcp.log'         [ Not found ]
[17:38:22]     Checking for file '/usr/bin/take/pid'         [ Not found ]
[17:38:22]     Checking for file '/sbin/create'              [ Not found ]
[17:38:22]     Checking for file '/dev/ttypz'                [ Not found ]
[17:38:22]     Checking for file '/var/log/tcp.log'          [ Not found ]
[17:38:22]     Checking for file '/usr/include/audit.h'      [ Not found ]
[17:38:22]     Checking for file '/usr/bin/sourcemask'       [ Not found ]
[17:38:22]     Checking for file '/usr/bin/ras2xm'           [ Not found ]
[17:38:22]     Checking for file '/dev/xmx'                  [ Not found ]
[17:38:22]     Checking for file '/usr/sbin/gpm.root'        [ Not found ]
[17:38:22]     Checking for file '/bin/vobiscum'             [ Not found ]
[17:38:22]     Checking for file '/bin/psr'                  [ Not found ]
[17:38:23]     Checking for file '/dev/kdx'                  [ Not found ]
[17:38:23]     Checking for file '/dev/dkx'                  [ Not found ]
[17:38:23]     Checking for file '/usr/sbin/sshd3'           [ Not found ]
[17:38:23]     Checking for file '/usr/sbin/jcd'             [ Not found ]
[17:38:23]     Checking for file '/etc/rc.d/init.d/jcd'      [ Not found ]
[17:38:23]     Checking for file '/usr/sbin/atd2'            [ Not found ]
[17:38:23]     Checking for file '/home/httpd/cgi-bin/linux.cgi' [ Not found ]
[17:38:23]     Checking for file '/home/httpd/cgi-bin/psid'  [ Not found ]
[17:38:23]     Checking for file '/home/httpd/cgi-bin/void.cgi' [ Not found ]
[17:38:23]     Checking for file '/etc/rc.d/init.d/system'   [ Not found ]
[17:38:23]     Checking for file '/etc/rc.d/rc3.d/S93users'  [ Not found ]
[17:38:23]     Checking for file '/tmp/.ush'                 [ Not found ]
[17:38:23]     Checking for file '/usr/lib/libhidefile.so'   [ Not found ]
[17:38:23]     Checking for file '/etc/cron.d/kmod'          [ Not found ]
[17:38:23]     Checking for file '/usr/lib/dmis/dmisd'       [ Not found ]
[17:38:23]     Checking for file '/lib/secure/libhij.so'     [ Not found ]
[17:38:23]     Checking for file '/usr/sbin/sshd3'           [ Not found ]
[17:38:23]     Checking for file '/etc/rc.d/init.d/crontab'  [ Not found ]
[17:38:23]     Checking for file '/etc/rc.d/init.d/jcd'      [ Not found ]
[17:38:23]     Checking for file '/usr/sbin/atd2'            [ Not found ]
[17:38:23]     Checking for file '/etc/rc.d/rc5.d/S93users'  [ Not found ]
[17:38:23]     Checking for file '/usr/include/mysql/mysql.hh1' [ Not found ]
[17:38:23]     Checking for file '/etc/init.d/xfs3'          [ Not found ]
[17:38:23]     Checking for file '/usr/sbin/t.txt'           [ Not found ]
[17:38:24]     Checking for file '/usr/sbin/change'          [ Not found ]
[17:38:24]     Checking for file '/usr/sbin/s'               [ Not found ]
[17:38:24]     Checking for file '/bin/f'                    [ Not found ]
[17:38:24]     Checking for file '/bin/i'                    [ Not found ]
[17:38:24]     Checking for file '/lib/libncom.so.4.0.1'     [ Not found ]
[17:38:24]     Checking for file '/sbin/zinit'               [ Not found ]
[17:38:24]     Checking for file '/tmp/pass_ssh.log'         [ Not found ]
[17:38:24]     Checking for file '/usr/include/gpm2.h'       [ Not found ]
[17:38:24]     Checking for file '/etc/ssh/.sshd_auth'       [ Not found ]
[17:38:24]     Checking for file '/usr/lib/.sshd.h'          [ Not found ]
[17:38:24]     Checking for file '/var/run/.defunct'         [ Not found ]
[17:38:24]     Checking for file '/etc/httpd/run/.defunct'   [ Not found ]
[17:38:24]     Checking for file '/usr/share/pci.r'          [ Not found ]
[17:38:24]     Checking for file '/etc/cron.daily/dnsquery'  [ Not found ]
[17:38:24]     Checking for file '/usr/lib/libutil1.2.1.2.so' [ Not found ]
[17:38:24]     Checking for file '/bin/ceva'                 [ Not found ]
[17:38:24]     Checking for file '/sbin/syslogd '            [ Not found ]
[17:38:24]     Checking for file '/usr/include/shup.h'       [ Not found ]
[17:38:24]     Checking for file '/etc/rpm/sshdOLD'          [ Not found ]
[17:38:24]     Checking for file '/etc/rpm/sshOLD'           [ Not found ]
[17:38:24]     Checking for file '/usr/share/passwd.h'       [ Not found ]
[17:38:24]     Checking for file '/lib/.xsyslog'             [ Not found ]
[17:38:24]     Checking for file '/etc/.xsyslog'             [ Not found ]
[17:38:25]     Checking for file '/lib/.ssyslog'             [ Not found ]
[17:38:25]     Checking for file '/tmp/.sendmail'            [ Not found ]
[17:38:25]     Checking for file '/usr/share/sshd.sync'      [ Not found ]
[17:38:25]     Checking for file '/bin/zcut'                 [ Not found ]
[17:38:25]     Checking for file '/usr/bin/zmuie'            [ Not found ]
[17:38:25]     Checking for directory '/dev/ptyas'           [ Not found ]
[17:38:25]     Checking for directory '/usr/bin/take'        [ Not found ]
[17:38:25]     Checking for directory '/usr/src/.lib'        [ Not found ]
[17:38:25]     Checking for directory '/usr/share/man/man1/.1c' [ Not found ]
[17:38:25]     Checking for directory '/lib/lblip.tk'        [ Not found ]
[17:38:25]     Checking for directory '/usr/sbin/...'        [ Not found ]
[17:38:25]     Checking for directory '/usr/share/.gun'      [ Not found ]
[17:38:25]     Checking for directory '/unde/vrei/tu/sa/te/ascunzi/in/server' [ Not found ]
[17:38:25]     Checking for directory '/usr/man/man1/..  /.dir' [ Not found ]
[17:38:25]     Checking for directory '/usr/X11R6/include/X11/...' [ Not found ]
[17:38:25]     Checking for directory '/usr/X11R6/lib/X11/.fonts/misc/...' [ Not found ]
[17:38:25]     Checking for directory '/tmp/.sys'            [ Not found ]
[17:38:25]     Checking for directory '/tmp/''               [ Not found ]
[17:38:25]     Checking for directory '/tmp/.,'              [ Not found ]
[17:38:25]     Checking for directory '/tmp/,.,'             [ Not found ]
[17:38:25]     Checking for directory '/dev/shm/emilien'     [ Not found ]
[17:38:25]     Checking for directory '/var/tmp/.log'        [ Not found ]
[17:38:25]     Checking for directory '/tmp/zmeu/... '       [ Not found ]
[17:38:25]     Checking for directory '/var/log/ssh'         [ Not found ]
[17:38:26]     Checking for directory '/dev/ida'             [ Not found ]
[17:38:26]     Checking for directory '/var/lib/games/.src/ssk/shit' [ Not found ]
[17:38:26]     Checking for directory '/usr/lib/libshtift'   [ Not found ]
[17:38:26]     Checking for directory '/usr/src/.poop'       [ Not found ]
[17:38:26]     Checking for directory '/dev/wd4'             [ Not found ]
[17:38:26]     Checking for directory '/var/run/.tmp'        [ Not found ]
[17:38:26]     Checking for directory '/usr/man/man1/lib/.lib' [ Not found ]
[17:38:26]     Checking for directory '/dev/portd'           [ Not found ]
[17:38:26]     Checking for directory '/dev/...'             [ Not found ]
[17:38:26]     Checking for directory '/usr/share/man/mansps' [ Not found ]
[17:38:26]     Checking for directory '/lib/.so'             [ Not found ]
[17:38:26]     Checking for directory '/lib/.sso'            [ Not found ]
[17:38:26]     Checking for directory '/usr/include/sslv3'   [ Not found ]
[17:38:26]     Checking for directory '/dev/shm/sshd'        [ Not found ]
[17:38:26]     Checking for directory '/usr/share/locale/mk/.dev/sk' [ Not found ]
[17:38:26]     Checking for directory '/usr/share/locale/mk/.dev' [ Not found ]
[17:38:26]     Checking for directory '/usr/include/netda.h' [ Not found ]
[17:38:26]     Checking for directory '/usr/include/.ssh'    [ Not found ]
[17:38:26]     Checking for directory '/usr/share/locale/jp/. ' [ Not found ]
[17:38:26]     Checking for directory '/usr/share/.sqe'      [ Not found ]
[17:38:26]   Checking for possible rootkit files and directories [ None found ]
[17:38:26]
[17:38:26] Info: Starting test name 'possible_rkt_strings'
[17:38:27]   Performing check for possible rootkit strings
[17:38:27] Info: Using system startup paths: /etc/rc.local /etc/init.d /etc/inittab
[17:38:27]     Checking for string 'phalanx'                 [ Not found ]
[17:38:27]     Checking for string '/dev/proc/fuckit'        [ Not found ]
[17:38:27]     Checking for string 'FUCK'                    [ Not found ]
[17:38:27]     Checking for string 'backdoor'                [ Not found ]
[17:38:27]     Checking for string '/usr/bin/rcpc'           [ Not found ]
[17:38:27]     Checking for string '/usr/sbin/login'         [ Not found ]
[17:38:27]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[17:38:27]     Checking for string 'vt200'                   [ Not found ]
[17:38:27]     Checking for string '/usr/bin/xstat'          [ Not found ]
[17:38:27]     Checking for string '/bin/envpc'              [ Not found ]
[17:38:27]     Checking for string 'L4m3r0x'                 [ Not found ]
[17:38:27]     Checking for string '/lib/libext'             [ Not found ]
[17:38:27]     Checking for string '/usr/sbin/login'         [ Not found ]
[17:38:27]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[17:38:27]     Checking for string 'sendmail'                [ Not found ]
[17:38:27]     Checking for string 'cocacola'                [ Not found ]
[17:38:28]     Checking for string 'joao'                    [ Not found ]
[17:38:28]     Checking for string '/dev/ptyxx/.file'        [ Not found ]
[17:38:28]     Checking for string '/dev/ptyxx/.file'        [ Not found ]
[17:38:28]     Checking for string '/dev/sgk'                [ Not found ]
[17:38:28]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[17:38:28]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[17:38:28]     Checking for string '/dev/proc/fuckit'        [ Not found ]
[17:38:28]     Checking for string '/lib/.sso'               [ Not found ]
[17:38:28]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[17:38:28]     Checking for string '/dev/caca'               [ Not found ]
[17:38:28]     Checking for string '/dev/ttyoa'              [ Not found ]
[17:38:28]     Checking for string '/usr/lib/ldlibns.so'     [ Not found ]
[17:38:28]     Checking for string '/dev/ptyxx/.addr'        [ Not found ]
[17:38:28]     Checking for string 'syg'                     [ Not found ]
[17:38:28]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[17:38:28]     Checking for string '/dev/pts/01'             [ Not found ]
[17:38:28]     Checking for string 'tw33dl3'                 [ Not found ]
[17:38:28]     Checking for string 'psniff'                  [ Not found ]
[17:38:29]     Checking for string 'uconf.inv'               [ Not found ]
[17:38:29]     Checking for string 'lib/ldlibps.so'          [ Not found ]
[17:38:29]     Checking for string '/usr/lib/ldlibpst.so'    [ Not found ]
[17:38:29]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[17:38:29]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[17:38:29]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[17:38:29]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[17:38:29]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[17:38:29]     Checking for string '/bin/bash'               [ Not found ]
[17:38:29]     Checking for string '/dev/xdta'               [ Not found ]
[17:38:29]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[17:38:29]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[17:38:31]     Checking for string 'in.inetd'                [ Not found ]
[17:38:31]     Checking for string '#<HIDE_.*>'              [ Not found ]
[17:38:31]     Checking for string 'bin/xchk'                [ Not found ]
[17:38:32]     Checking for string 'bin/xsf'                 [ Not found ]
[17:38:32]     Checking for string '/usr/bin/ssh2d'          [ Not found ]
[17:38:33]     Checking for string '/usr/sbin/xntps'         [ Not found ]
[17:38:33]     Checking for string 'ttyload'                 [ Not found ]
[17:38:34]     Checking for string '/etc/rc.d/init.d/init'   [ Not found ]
[17:38:34]     Checking for string 'usr/bin/xfss'            [ Not found ]
[17:38:35]     Checking for string '/usr/sbin/rpc.netinet'   [ Not found ]
[17:38:35]     Checking for string '/usr/lib/.fx/cons.saver' [ Not found ]
[17:38:36]     Checking for string '/usr/lib/.fx/xs'         [ Not found ]
[17:38:36]     Checking for string '/ssh2d'                  [ Not found ]
[17:38:36]     Checking for string '/dev/kmod'               [ Not found ]
[17:38:37]     Checking for string '/crth.o'                 [ Not found ]
[17:38:37]     Checking for string '/crtz.o'                 [ Not found ]
[17:38:38]     Checking for string '/dev/dos'                [ Not found ]
[17:38:38]     Checking for string '/lpq'                    [ Not found ]
[17:38:39]     Checking for string '/usr/sbin/rescue'        [ Not found ]
[17:38:39]     Checking for string '/usr/lib/lpstart'        [ Not found ]
[17:38:40]     Checking for string '/volc'                   [ Not found ]
[17:38:40]     Checking for string 'sourcemask'              [ Not found ]
[17:38:41]     Checking for string '/bin/vobiscum'           [ Not found ]
[17:38:41]     Checking for string '/usr/sbin/in.telnet'     [ Not found ]
[17:38:42]     Checking for string '/usr/bin/hdparm?-t1?-X53?-p' [ Not found ]
[17:38:42]     Checking for string '/lib/.xsyslog'           [ Not found ]
[17:38:43]     Checking for string '/etc/.xsyslog'           [ Not found ]
[17:38:43]     Checking for string '/lib/.ssyslog'           [ Not found ]
[17:38:44]     Checking for string '/tmp/.sendmail'          [ Not found ]
[17:38:44]     Checking for string '/lib/ldd.so/tkps'        [ Not found ]
[17:38:44]     Checking for string 't0rnkit'                 [ Not found ]
[17:38:44]     Checking for string '/dev/proc/fuckit'        [ Not found ]
[17:38:44]     Checking for string 'backdoor.h'              [ Not found ]
[17:38:44]     Checking for string 'backdoor_active'         [ Not found ]
[17:38:44]     Checking for string 'magic_pass_active'       [ Not found ]
[17:38:44]     Checking for string '/usr/include/gpm2.h'     [ Not found ]
[17:38:44]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[17:38:44]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[17:38:44]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[17:38:44]     Checking for string '/usr/lib/ldlibct.so'     [ Not found ]
[17:38:45]     Checking for string '/usr/lib/ldlibdu.so'     [ Not found ]
[17:38:45]     Checking for string '/dev/ptyxx/.file'        [ Not found ]
[17:38:45]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[17:38:45]     Checking for string '/dev/ida/.inet'          [ Not found ]
[17:38:45]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[17:38:45]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[17:38:45]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[17:38:45]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[17:38:45]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[17:38:45]     Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[17:38:45]     Checking for string 'backconnect'             [ Not found ]
[17:38:45]     Checking for string 'magic?packet?received'   [ Not found ]
[17:38:45]   Checking for possible rootkit strings           [ None found ]
[17:38:45]
[17:38:45] Info: Starting test name 'malware'
[17:38:45] Performing malware checks
[17:38:45]
[17:38:45] Info: Test 'deleted_files' disabled at users request.
[17:38:45]
[17:38:45] Info: Starting test name 'running_procs'
[17:38:48]   Checking running processes for suspicious files [ None found ]
[17:38:48]
[17:38:48] Info: Test 'hidden_procs' disabled at users request.
[17:38:48]
[17:38:48] Info: Test 'suspscan' disabled at users request.
[17:38:48]
[17:38:48] Info: Starting test name 'other_malware'
[17:38:48]   Performing check for login backdoors
[17:38:48]     Checking for '/bin/.login'                    [ Not found ]
[17:38:48]     Checking for '/sbin/.login'                   [ Not found ]
[17:38:48]   Checking for login backdoors                    [ None found ]
[17:38:48]
[17:38:48]   Performing check for suspicious directories
[17:38:48]     Checking for directory '/usr/X11R6/bin/.,/copy' [ Not found ]
[17:38:48]     Checking for directory '/dev/rd/cdb'          [ Not found ]
[17:38:48]   Checking for suspicious directories             [ None found ]
[17:38:48]
[17:38:48]   Checking for software intrusions                [ Skipped ]
[17:38:48] Info: Check skipped - tripwire not installed
[17:38:48]
[17:38:48]   Performing check for sniffer log files
[17:38:48]     Checking for file '/usr/lib/libice.log'       [ Not found ]
[17:38:48]     Checking for file '/dev/prom/sn.l'            [ Not found ]
[17:38:48]     Checking for file '/dev/fd/.88/zxsniff.log'   [ Not found ]
[17:38:48]   Checking for sniffer log files                  [ None found ]
[17:38:48]
[17:38:48] Info: Starting test name 'trojans'
[17:38:48] Performing trojan specific checks
[17:38:48]   Checking for enabled inetd services             [ Skipped ]
[17:38:48] Info: Check skipped - file '/etc/inetd.conf' does not exist.
[17:38:48]
[17:38:48]   Performing check for enabled xinetd services
[17:38:48]   Checking for enabled xinetd services            [ Skipped ]
[17:38:48] Info: Check skipped - file '/etc/xinetd.conf' does not exist.
[17:38:48] Info: Apache backdoor check skipped: Apache modules and configuration directories not found.
[17:38:48]
[17:38:48] Info: Starting test name 'os_specific'
[17:38:48] Performing Linux specific checks
[17:38:48]   Checking loaded kernel modules                  [ OK ]
[17:38:48] Info: Using modules pathname of '/lib/modules/3.2.0-4-amd64'
[17:38:49]   Checking kernel module names                    [ OK ]
[17:38:51]
[17:38:51] Info: Starting test name 'network'
[17:38:51] Checking the network...
[17:38:51]
[17:38:51] Performing checks on the network ports
[17:38:51] Info: Starting test name 'ports'
[17:38:51]   Performing check for backdoor ports
[17:38:51]     Checking for TCP port 1524                    [ Not found ]
[17:38:51]     Checking for TCP port 1984                    [ Not found ]
[17:38:51]     Checking for UDP port 2001                    [ Not found ]
[17:38:51]     Checking for TCP port 2006                    [ Not found ]
[17:38:51]     Checking for TCP port 2128                    [ Not found ]
[17:38:51]     Checking for TCP port 6666                    [ Not found ]
[17:38:51]     Checking for TCP port 6667                    [ Not found ]
[17:38:51]     Checking for TCP port 6668                    [ Not found ]
[17:38:51]     Checking for TCP port 6669                    [ Not found ]
[17:38:52]     Checking for TCP port 7000                    [ Not found ]
[17:38:52]     Checking for TCP port 13000                   [ Not found ]
[17:38:52]     Checking for TCP port 14856                   [ Not found ]
[17:38:52]     Checking for TCP port 25000                   [ Not found ]
[17:38:52]     Checking for TCP port 29812                   [ Not found ]
[17:38:52]     Checking for TCP port 31337                   [ Not found ]
[17:38:52]     Checking for TCP port 32982                   [ Not found ]
[17:38:52]     Checking for TCP port 33369                   [ Not found ]
[17:38:52]     Checking for TCP port 47107                   [ Not found ]
[17:38:52]     Checking for TCP port 47018                   [ Not found ]
[17:38:52]     Checking for TCP port 60922                   [ Not found ]
[17:38:52]     Checking for TCP port 62883                   [ Not found ]
[17:38:53]     Checking for TCP port 65535                   [ Not found ]
[17:38:53]   Checking for backdoor ports                     [ None found ]
[17:38:53]
[17:38:53] Info: Starting test name 'hidden_ports'
[17:38:53] Checking for hidden ports                         [ Skipped ]
[17:38:53] Info: Unable to find the 'unhide-tcp' command
[17:38:53]
[17:38:53] Performing checks on the network interfaces
[17:38:53] Info: Starting test name 'promisc'
[17:38:53]   Checking for promiscuous interfaces             [ None found ]
[17:38:53]
[17:38:53] Info: Test 'packet_cap_apps' disabled at users request.
[17:38:53]
[17:38:53] Info: Starting test name 'local_host'
[17:38:53] Checking the local host...
[17:38:53]
[17:38:53] Info: Starting test name 'startup_files'
[17:38:53] Performing system boot checks
[17:38:53]   Checking for local host name                    [ Found ]
[17:38:53]
[17:38:53] Info: Starting test name 'startup_malware'
[17:38:53]   Checking for system startup files               [ Found ]
[17:38:54]   Checking system startup files for malware       [ None found ]
[17:38:54]
[17:38:54] Info: Starting test name 'group_accounts'
[17:38:54] Performing group and account checks
[17:38:55]   Checking for passwd file                        [ Found ]
[17:38:55] Info: Found password file: /etc/passwd
[17:38:55]   Checking for root equivalent (UID 0) accounts   [ None found ]
[17:38:55] Info: Found shadow file: /etc/shadow
[17:38:55]   Checking for passwordless accounts              [ None found ]
[17:38:55]
[17:38:55] Info: Starting test name 'passwd_changes'
[17:38:55]   Checking for passwd file changes                [ None found ]
[17:38:55]
[17:38:55] Info: Starting test name 'group_changes'
[17:38:55]   Checking for group file changes                 [ None found ]
[17:38:55]   Checking root account shell history files       [ OK ]
[17:38:55]
[17:38:55] Info: Starting test name 'system_configs'
[17:38:55] Performing system configuration file checks
[17:38:55]   Checking for SSH configuration file             [ Not found ]
[17:38:55]   Checking for running syslog daemon              [ Found ]
[17:38:55] Info: Found rsyslog configuration file: /etc/rsyslog.conf
[17:38:55]   Checking for syslog configuration file          [ Found ]
[17:38:55]   Checking if syslog remote logging is allowed    [ Not allowed ]
[17:38:55]
[17:38:55] Info: Starting test name 'filesystem'
[17:38:55] Performing filesystem checks
[17:38:55] Info: SCAN_MODE_DEV set to 'THOROUGH'
[17:38:55]   Checking /dev for suspicious file types         [ None found ]
[17:38:56]   Checking for hidden files and directories       [ None found ]
[17:38:58]
[17:38:58] Info: Test 'apps' disabled at users request.
[17:38:58]
[17:38:58] System checks summary
[17:38:58] =====================
[17:38:58]
[17:38:58] File properties checks...
[17:38:58] Files checked: 136
[17:38:58] Suspect files: 2
[17:38:58]
[17:38:58] Rootkit checks...
[17:38:58] Rootkits checked : 292
[17:38:58] Possible rootkits: 0
[17:38:58]
[17:38:58] Applications checks...
[17:38:58] All checks skipped
[17:38:58]
[17:38:58] The system checks took: 3 minutes and 38 seconds
[17:38:59]
[17:38:59] Info: End date is nie, 25 sie 2013, 17:38:59 CEST 
niby wszystko gra... eee nie wiem o co mu chodzi z tym curl'em, nawet w logu go nie widać ale oznaczył go jako podejrzany...
Awatar użytkownika
Rafal_F
Moderator
Posty: 2350
Rejestracja: 29 sierpnia 2008, 16:45

Post autor: Rafal_F »

Log jest ucięty (brakuje 2 minut działania aplikacji), to jest chyba listing z konsoli, a nie z pliku.
Sprawdź zawartość:

Kod: Zaznacz cały

/var/log/rkhunter.log
Tam jest zapisywany log w standardowej konfiguracji rkhunter.
Awatar użytkownika
Menel
Member
Posty: 1117
Rejestracja: 24 sierpnia 2013, 19:58
Lokalizacja: doktor informoparalityki

Post autor: Menel »

Kod: Zaznacz cały

....
[17:35:31]   /usr/bin/curl                                   [ Warning ]
[17:35:31] Warning: The file '/usr/bin/curl' exists on the system, but it is not present in the rkhunter.dat file.
...
[17:35:39]   /usr/bin/unhide.rb                              [ Warning ]
[17:35:39] Warning: The command '/usr/bin/unhide.rb' has been replaced by a script: /usr/bin/unhide.rb: Ruby script, ASCII text
...
Awatar użytkownika
Rafal_F
Moderator
Posty: 2350
Rejestracja: 29 sierpnia 2008, 16:45

Post autor: Rafal_F »

Na temat pierwszego ostrzeżenia możesz poczytać w:

Kod: Zaznacz cały

man rkhunter
w podpunkcie opisującym znacznik: "--propupd".
Generalnie chodzi o to, że rkhunter może stworzyć bazę informacji o niektórych plikach i jeżeli podczas skanowania zauważy, że plik został zmieniony wyświetli ostrzeżenie. Taką bazę trzeba sobie utworzyć właśnie przy pomocy przełącznika "--propupd".

Drugie ostrzeżenie mówi o tym, że dany plik jest skryptem. Czasem developerzy aplikacji "otaczają" swój program skryptem, i użytkownik wpisujący nazwę aplikacji tak naprawdę uruchamia skrypt, który uruchamia program.
Problem polega na tym, że jest to transparentne. Wredny użytkownik, albo program z odpowiednimi uprawnieniami sam może podmienić jakiś program na skrypt, który przed uruchomieniem oryginalnej aplikacji zrobi coś niepożądanego. Dlatego rkhunter zgłasza takie skrypty jako ostrzeżenia.

Obydwa ostrzeżenia możesz zignorować.
ODPOWIEDZ