Jump to content


Photo
- - - - -

rkhunter falsepositive?


  • Please log in to reply
5 replies to this topic

#1 trem

trem

    The phorce is with me!

  • Members
  • 72 posts
  • Location:Awesome Bill From Dawsonville

Posted 27 January 2009 - 02:28 PM

I use wubi, and after running rkhunter on my original install (which gave me the same results below) I figured it was better to be safe than sorry so I reinstalled which takes something like 30 minutes to an hour, so no big deal. But after doing a system update on my new install and running rkhunter I get the same terrifying results.

In both instances there were no unnecessary services running and I had firestarter installed with outgoing whitelist rules for HTTP,HTTPS,MSN,IRC and Bittorrent. I'm aware that this is more than likely a false positive but is there any way to verify the checksums of the binrays installed or any other way to ease my paranoia? I apologize for ignoring the glaringly obvious but when red text tells you something's wrong, you'd might want to find out why.

CODE
trem@ubuntu:~$ uname -a
Linux ubuntu 2.6.27-9-generic #1 SMP Thu Nov 20 22:15:32 UTC 2008 x86_64 GNU/Linux


rkhunter results
CODE
[10:57:26] Running Rootkit Hunter version 1.3.2 on ubuntu
[10:57:26]
[10:57:26] Info: Start date is Tue Jan 27 10:57:26 PST 2009
[10:57:26]
[10:57:26] Checking configuration file and command-line options...
[10:57:26] Info: Detected operating system is 'Linux'
[10:57:27] Info: Found O/S name: Ubuntu 8.10
[10:57:27] Info: Command line is /usr/bin/rkhunter --check
[10:57:27] Info: Environment shell is /bin/bash; rkhunter is using dash
[10:57:27] Info: Using configuration file '/etc/rkhunter.conf'
[10:57:27] Info: Installation directory is '/usr'
[10:57:27] Info: Using language 'en'
[10:57:27] Info: Using '/var/lib/rkhunter/db' as the database directory
[10:57:27] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[10:57:27] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin /usr/X11R6/bin /bin /usr/bin /sbin /usr/sbin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec' as the command directories
[10:57:27] Info: Using '/' as the root directory
[10:57:27] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[10:57:27] Info: No mail-on-warning address configured
[10:57:27] Info: X will be automatically detected
[10:57:27] Info: Using second color set
[10:57:27] Info: Found the 'diff' command: /usr/bin/diff
[10:57:27] Info: Found the 'file' command: /usr/bin/file
[10:57:27] Info: Found the 'find' command: /usr/bin/find
[10:57:27] Info: Found the 'ifconfig' command: /sbin/ifconfig
[10:57:28] Info: Found the 'ip' command: /sbin/ip
[10:57:28] Info: Found the 'ldd' command: /usr/bin/ldd
[10:57:28] Info: Found the 'lsattr' command: /usr/bin/lsattr
[10:57:28] Info: Found the 'lsmod' command: /sbin/lsmod
[10:57:28] Info: Found the 'lsof' command: /usr/bin/lsof
[10:57:28] Info: Found the 'mktemp' command: /bin/mktemp
[10:57:28] Info: Found the 'netstat' command: /bin/netstat
[10:57:28] Info: Found the 'perl' command: /usr/bin/perl
[10:57:28] Info: Found the 'ps' command: /bin/ps
[10:57:28] Info: Found the 'pwd' command: /bin/pwd
[10:57:28] Info: Found the 'readlink' command: /bin/readlink
[10:57:28] Info: Found the 'sort' command: /usr/bin/sort
[10:57:28] Info: Found the 'stat' command: /usr/bin/stat
[10:57:28] Info: Found the 'strings' command: /usr/bin/strings
[10:57:28] Info: Found the 'uniq' command: /usr/bin/uniq
[10:57:28] Info: System is not using prelinking
[10:57:29] Info: Using the '/usr/bin/sha1sum' command for the file hash checks
[10:57:29] Info: Stored hash values used hash function '/usr/bin/sha1sum'
[10:57:29] Info: Stored hash values did not use a package manager
[10:57:29] Info: The hash function field index is set to 1
[10:57:29] Info: No package manager specified: using hash function '/usr/bin/sha1sum'
[10:57:29] Info: Previous file attributes were stored
[10:57:29] Info: Enabled tests are: all
[10:57:29] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps
[10:57:29] Info: Found ksym file '/proc/kallsyms'
[10:57:29]
[10:57:29] Checking if the O/S has changed since last time...
[10:57:29] Info: Nothing seems to have changed
[10:57:29]
[10:57:29] Starting system checks...
[10:57:29]
[10:57:29] Checking system commands...
[10:57:29] Info: Starting test name 'system_commands'
[10:57:30]
[10:57:30] Performing 'strings' command checks
[10:57:30] Info: Starting test name 'strings'
[10:57:30] Scanning for string /usr/sbin/ntpsx               [ OK ]
[10:57:30] Scanning for string /usr/lib/.../ls               [ OK ]
[10:57:30] Scanning for string /usr/lib/.../netstat          [ OK ]
[10:57:30] Scanning for string /usr/lib/.../lsof             [ OK ]
[10:57:30] Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[10:57:30] Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[10:57:30] Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[10:57:31] Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[10:57:31] Scanning for string /usr/lib/.../uconf.inv        [ OK ]
[10:57:31] Scanning for string /usr/lib/.../psr              [ OK ]
[10:57:31] Scanning for string /usr/lib/.../find             [ OK ]
[10:57:31] Scanning for string /usr/lib/.../pstree           [ OK ]
[10:57:31] Scanning for string /usr/lib/.../slocate          [ OK ]
[10:57:31] Scanning for string /usr/lib/.../du               [ OK ]
[10:57:31] Scanning for string /usr/lib/.../top              [ OK ]
[10:57:31] Scanning for string /usr/lib/...                  [ OK ]
[10:57:32] Scanning for string /usr/lib/.../bkit-ssh         [ OK ]
[10:57:32] Scanning for string /usr/lib/.bkit-               [ OK ]
[10:57:32] Scanning for string /tmp/.bkp                     [ OK ]
[10:57:32] Scanning for string /tmp/.cinik                   [ OK ]
[10:57:32] Scanning for string /tmp/.font-unix/.cinik        [ OK ]
[10:57:32] Scanning for string /lib/.sso                     [ OK ]
[10:57:32] Scanning for string /lib/.so                      [ OK ]
[10:57:32] Scanning for string /var/run/...dica/clean        [ OK ]
[10:57:32] Scanning for string /var/run/...dica/xl           [ OK ]
[10:57:32] Scanning for string /var/run/...dica/xdr          [ OK ]
[10:57:33] Scanning for string /var/run/...dica/psg          [ OK ]
[10:57:33] Scanning for string /var/run/...dica/secure       [ OK ]
[10:57:33] Scanning for string /var/run/...dica/rdx          [ OK ]
[10:57:33] Scanning for string /var/run/...dica/va           [ OK ]
[10:57:33] Scanning for string /var/run/...dica/cl.sh        [ OK ]
[10:57:33] Scanning for string /usr/bin/.etc                 [ OK ]
[10:57:33] Scanning for string /usr/lib/.fx/sched_host.2     [ OK ]
[10:57:33] Scanning for string /usr/lib/.fx/random_d.2       [ OK ]
[10:57:34] Scanning for string /usr/lib/.fx/set_pid.2        [ OK ]
[10:57:34] Scanning for string /usr/lib/.fx/cons.saver       [ OK ]
[10:57:34] Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[10:57:34] Scanning for string /bin/sysback                  [ OK ]
[10:57:34] Scanning for string /usr/local/bin/sysback        [ OK ]
[10:57:34] Scanning for string /usr/lib/.tbd                 [ OK ]
[10:57:34] Scanning for string /dev/.lib/lib/lib/t0rns       [ OK ]
[10:57:34] Scanning for string /dev/.lib/lib/lib/du          [ OK ]
[10:57:34] Scanning for string /dev/.lib/lib/lib/ls          [ OK ]
[10:57:35] Scanning for string /dev/.lib/lib/lib/t0rnsb      [ OK ]
[10:57:35] Scanning for string /dev/.lib/lib/lib/ps          [ OK ]
[10:57:35] Scanning for string /dev/.lib/lib/lib/t0rnp       [ OK ]
[10:57:35] Scanning for string /dev/.lib/lib/lib/find        [ OK ]
[10:57:35] Scanning for string /dev/.lib/lib/lib/ifconfig    [ OK ]
[10:57:35] Scanning for string /dev/.lib/lib/lib/pg          [ OK ]
[10:57:35] Scanning for string /dev/.lib/lib/lib/ssh.tgz     [ OK ]
[10:57:35] Scanning for string /dev/.lib/lib/lib/top         [ OK ]
[10:57:35] Scanning for string /dev/.lib/lib/lib/sz          [ OK ]
[10:57:36] Scanning for string /dev/.lib/lib/lib/login       [ OK ]
[10:57:36] Scanning for string /dev/.lib/lib/lib/in.fingerd  [ OK ]
[10:57:36] Scanning for string /dev/.lib/lib/lib/1i0n.sh     [ OK ]
[10:57:36] Scanning for string /dev/.lib/lib/lib/pstree      [ OK ]
[10:57:36] Scanning for string /dev/.lib/lib/lib/in.telnetd  [ OK ]
[10:57:36] Scanning for string /dev/.lib/lib/lib/mjy         [ OK ]
[10:57:36] Scanning for string /dev/.lib/lib/lib/sush        [ OK ]
[10:57:36] Scanning for string /dev/.lib/lib/lib/tfn         [ OK ]
[10:57:36] Scanning for string /dev/.lib/lib/lib/name        [ OK ]
[10:57:37] Scanning for string /dev/.lib/lib/lib/getip.sh    [ OK ]
[10:57:37] Scanning for string /usr/info/.torn/sh*           [ OK ]
[10:57:37] Scanning for string /usr/src/.puta/.1addr         [ OK ]
[10:57:37] Scanning for string /usr/src/.puta/.1file         [ OK ]
[10:57:37] Scanning for string /usr/src/.puta/.1proc         [ OK ]
[10:57:37] Scanning for string /usr/src/.puta/.1logz         [ OK ]
[10:57:37] Scanning for string /usr/info/.t0rn               [ OK ]
[10:57:38] Scanning for string /dev/.lib                     [ OK ]
[10:57:38] Scanning for string /dev/.lib/lib                 [ OK ]
[10:57:38] Scanning for string /dev/.lib/lib/lib             [ OK ]
[10:57:38] Scanning for string /dev/.lib/lib/lib/dev         [ OK ]
[10:57:38] Scanning for string /dev/.lib/lib/scan            [ OK ]
[10:57:38] Scanning for string /usr/src/.puta                [ OK ]
[10:57:38] Scanning for string /usr/man/man1/man1            [ OK ]
[10:57:38] Scanning for string /usr/man/man1/man1/lib        [ OK ]
[10:57:38] Scanning for string /usr/man/man1/man1/lib/.lib   [ OK ]
[10:57:39] Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[10:57:39]
[10:57:39] Performing 'shared libraries' checks
[10:57:39] Info: Starting test name 'shared_libs'
[10:57:39] Checking for preloading variables                 [ None found ]
[10:57:39] Checking for preload file                         [ Not found ]
[10:57:39] Info: Starting test name 'shared_libs_path'
[10:57:39] Checking LD_LIBRARY_PATH variable                 [ Not found ]
[10:57:39]
[10:57:39] Performing file properties checks
[10:57:40] Info: Starting test name 'properties'
[10:57:40] Checking for prerequisites                        [ OK ]
[10:57:40] /bin/bash                                         [ OK ]
[10:57:40] /bin/cat                                          [ OK ]
[10:57:41] /bin/chmod                                        [ OK ]
[10:57:41] /bin/chown                                        [ OK ]
[10:57:42] /bin/cp                                           [ OK ]
[10:57:42] /bin/date                                         [ OK ]
[10:57:42] /bin/df                                           [ OK ]
[10:57:43] /bin/dmesg                                        [ OK ]
[10:57:43] /bin/echo                                         [ OK ]
[10:57:43] /bin/ed                                           [ OK ]
[10:57:44] /bin/egrep                                        [ OK ]
[10:57:44] Info: Found file '/bin/egrep': it is whitelisted for the 'script replacement' check.
[10:57:44] /bin/fgrep                                        [ OK ]
[10:57:44] Info: Found file '/bin/fgrep': it is whitelisted for the 'script replacement' check.
[10:57:45] /bin/fuser                                        [ OK ]
[10:57:45] /bin/grep                                         [ OK ]
[10:57:46] /bin/ip                                           [ OK ]
[10:57:46] /bin/kill                                         [ Warning ]
[10:57:46] Warning: The file properties have changed:
[10:57:46]          File: /bin/kill
[10:57:46]          Current inode: 497764    Stored inode: 497814
[10:57:46]          Current file modification time: 1225339532
[10:57:46]          Stored file modification time : 1225106254
[10:57:47] /bin/login                                        [ Warning ]
[10:57:47] Warning: The file properties have changed:
[10:57:47]          File: /bin/login
[10:57:47]          Current hash: 670dfeceb51ad4d5ad6dafa41cc945e64eedb2a1
[10:57:47]          Stored hash : 97f4cfabfb93ebb831641a0c506092c59a189da0
[10:57:47]          Current inode: 497762    Stored inode: 497820
[10:57:47]          Current file modification time: 1228728173
[10:57:47]          Stored file modification time : 1213035048
[10:57:48] /bin/ls                                           [ OK ]
[10:57:48] /bin/lsmod                                        [ OK ]
[10:57:48] /bin/mktemp                                       [ OK ]
[10:57:49] /bin/more                                         [ OK ]
[10:57:49] /bin/mount                                        [ OK ]
[10:57:50] /bin/mv                                           [ OK ]
[10:57:50] /bin/netstat                                      [ OK ]
[10:57:50] /bin/ps                                           [ Warning ]
[10:57:51] Warning: The file properties have changed:
[10:57:51]          File: /bin/ps
[10:57:51]          Current inode: 497791    Stored inode: 497852
[10:57:51]          Current file modification time: 1225339532
[10:57:51]          Stored file modification time : 1225106254
[10:57:51] /bin/pwd                                          [ OK ]
[10:57:52] /bin/readlink                                     [ OK ]
[10:57:52] /bin/sed                                          [ OK ]
[10:57:52] /bin/sh                                           [ OK ]
[10:57:53] /bin/su                                           [ Warning ]
[10:57:53] Warning: The file properties have changed:
[10:57:53]          File: /bin/su
[10:57:53]          Current hash: 25f4a9bc772de924643b01141df06a1f567a6030
[10:57:53]          Stored hash : 4a47b548129adff24822e304bf29f77d88a2e587
[10:57:53]          Current inode: 497763    Stored inode: 497872
[10:57:53]          Current file modification time: 1228728173
[10:57:54]          Stored file modification time : 1213035048
[10:57:54] /bin/touch                                        [ OK ]
[10:57:54] /bin/uname                                        [ OK ]
[10:57:55] /bin/which                                        [ OK ]
[10:57:55] Info: Found file '/bin/which': it is whitelisted for the 'script replacement' check.
[10:57:55] /bin/dash                                         [ OK ]
[10:57:56] /usr/bin/awk                                      [ OK ]
[10:57:56] /usr/bin/basename                                 [ OK ]
[10:57:56] /usr/bin/chattr                                   [ OK ]
[10:57:57] /usr/bin/cut                                      [ OK ]
[10:57:57] /usr/bin/diff                                     [ OK ]
[10:57:58] /usr/bin/dirname                                  [ OK ]
[10:57:58] /usr/bin/dpkg                                     [ OK ]
[10:57:58] /usr/bin/dpkg-query                               [ OK ]
[10:57:59] /usr/bin/du                                       [ OK ]
[10:57:59] /usr/bin/env                                      [ OK ]
[10:57:59] /usr/bin/file                                     [ OK ]
[10:58:00] /usr/bin/find                                     [ OK ]
[10:58:00] /usr/bin/GET                                      [ OK ]
[10:58:00] /usr/bin/groups                                   [ OK ]
[10:58:01] Info: Found file '/usr/bin/groups': it is whitelisted for the 'script replacement' check.
[10:58:01] /usr/bin/head                                     [ OK ]
[10:58:01] /usr/bin/id                                       [ OK ]
[10:58:02] /usr/bin/killall                                  [ OK ]
[10:58:02] /usr/bin/last                                     [ OK ]
[10:58:02] /usr/bin/lastlog                                  [ Warning ]
[10:58:03] Warning: The file properties have changed:
[10:58:03]          File: /usr/bin/lastlog
[10:58:03]          Current hash: c329666243e17ffb5c48dd712140a2c376adc0c9
[10:58:03]          Stored hash : 5489a8b7687340f66d744f1b8cc9191e306708aa
[10:58:03]          Current inode: 1153438    Stored inode: 1151154
[10:58:03]          Current file modification time: 1228728173
[10:58:03]          Stored file modification time : 1213035048
[10:58:03] /usr/bin/ldd                                      [ OK ]
[10:58:03] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
[10:58:04] /usr/bin/less                                     [ OK ]
[10:58:04] /usr/bin/locate                                   [ OK ]
[10:58:04] /usr/bin/logger                                   [ OK ]
[10:58:05] /usr/bin/lsattr                                   [ OK ]
[10:58:05] /usr/bin/lsof                                     [ OK ]
[10:58:05] /usr/bin/md5sum                                   [ OK ]
[10:58:06] /usr/bin/mlocate                                  [ OK ]
[10:58:06] /usr/bin/newgrp                                   [ Warning ]
[10:58:06] Warning: The file properties have changed:
[10:58:07]          File: /usr/bin/newgrp
[10:58:07]          Current hash: 7f354f3057ee3557bbb2ae9d7f08b6ba81823f5e
[10:58:07]          Stored hash : b5cd6e4e545fa3bfb2af2c24f8bc2292c982d0d9
[10:58:07]          Current inode: 1153439    Stored inode: 1151298
[10:58:07]          Current size: 28208    Stored size: 32304
[10:58:07]          Current file modification time: 1228728173
[10:58:07]          Stored file modification time : 1213035048
[10:58:07] /usr/bin/passwd                                   [ Warning ]
[10:58:07] Warning: The file properties have changed:
[10:58:07]          File: /usr/bin/passwd
[10:58:08]          Current hash: 35c5f7c6d30fa72e9fedea81f59109c9086d5953
[10:58:08]          Stored hash : c6703596a850c6b7d681eb3a6e97810795ff4035
[10:58:08]          Current inode: 1152500    Stored inode: 1151351
[10:58:08]          Current file modification time: 1228728171
[10:58:08]          Stored file modification time : 1213035045
[10:58:08] /usr/bin/perl                                     [ Warning ]
[10:58:08] Warning: The file properties have changed:
[10:58:09]          File: /usr/bin/perl
[10:58:09]          Current hash: a96c8d80317b8396d708941f8199446ca54eca80
[10:58:09]          Stored hash : 9c81bf31293a919f378949c44c996c3bbf422916
[10:58:09]          Current inode: 1150580    Stored inode: 1151372
[10:58:09]          Current file modification time: 1230001795
[10:58:09]          Stored file modification time : 1216891131
[10:58:09] /usr/bin/pstree                                   [ OK ]
[10:58:10] /usr/bin/rkhunter                                 [ OK ]
[10:58:10] /usr/bin/runcon                                   [ OK ]
[10:58:11] /usr/bin/sha1sum                                  [ OK ]
[10:58:11] /usr/bin/size                                     [ OK ]
[10:58:11] /usr/bin/sort                                     [ OK ]
[10:58:12] /usr/bin/stat                                     [ OK ]
[10:58:12] /usr/bin/strace                                   [ OK ]
[10:58:12] /usr/bin/strings                                  [ OK ]
[10:58:13] /usr/bin/sudo                                     [ OK ]
[10:58:13] /usr/bin/tail                                     [ OK ]
[10:58:13] /usr/bin/test                                     [ OK ]
[10:58:14] /usr/bin/top                                      [ Warning ]
[10:58:14] Warning: The file properties have changed:
[10:58:14]          File: /usr/bin/top
[10:58:14]          Current inode: 1150788    Stored inode: 1151715
[10:58:14]          Current file modification time: 1225339532
[10:58:14]          Stored file modification time : 1225106254
[10:58:14] /usr/bin/touch                                    [ OK ]
[10:58:15] /usr/bin/tr                                       [ OK ]
[10:58:15] /usr/bin/uniq                                     [ OK ]
[10:58:16] /usr/bin/users                                    [ OK ]
[10:58:16] /usr/bin/vmstat                                   [ Warning ]
[10:58:16] Warning: The file properties have changed:
[10:58:16]          File: /usr/bin/vmstat
[10:58:16]          Current inode: 1150805    Stored inode: 1151797
[10:58:16]          Current file modification time: 1225339532
[10:58:16]          Stored file modification time : 1225106254
[10:58:17] /usr/bin/w                                        [ OK ]
[10:58:17] /usr/bin/watch                                    [ Warning ]
[10:58:17] Warning: The file properties have changed:
[10:58:17]          File: /usr/bin/watch
[10:58:17]          Current inode: 1150851    Stored inode: 1151804
[10:58:17]          Current file modification time: 1225339532
[10:58:17]          Stored file modification time : 1225106254
[10:58:18] /usr/bin/wc                                       [ OK ]
[10:58:18] /usr/bin/wget                                     [ OK ]
[10:58:18] /usr/bin/whatis                                   [ OK ]
[10:58:19] /usr/bin/whereis                                  [ OK ]
[10:58:19] /usr/bin/which                                    [ OK ]
[10:58:19] /usr/bin/who                                      [ OK ]
[10:58:20] /usr/bin/whoami                                   [ OK ]
[10:58:20] /usr/bin/mawk                                     [ OK ]
[10:58:20] /usr/bin/lwp-request                              [ OK ]
[10:58:21] Info: Found file '/usr/bin/lwp-request': it is whitelisted for the 'script replacement' check.
[10:58:21] /usr/bin/w.procps                                 [ Warning ]
[10:58:21] Warning: The file properties have changed:
[10:58:21]          File: /usr/bin/w.procps
[10:58:21]          Current inode: 1151373    Stored inode: 1151800
[10:58:21]          Current file modification time: 1225339532
[10:58:21]          Stored file modification time : 1225106254
[10:58:22] /sbin/depmod                                      [ OK ]
[10:58:23] /sbin/ifconfig                                    [ OK ]
[10:58:23] /sbin/ifdown                                      [ OK ]
[10:58:23] /sbin/ifup                                        [ OK ]
[10:58:24] /sbin/init                                        [ OK ]
[10:58:24] /sbin/insmod                                      [ OK ]
[10:58:25] /sbin/ip                                          [ OK ]
[10:58:25] /sbin/lsmod                                       [ OK ]
[10:58:26] /sbin/modinfo                                     [ OK ]
[10:58:26] /sbin/modprobe                                    [ OK ]
[10:58:27] /sbin/rmmod                                       [ OK ]
[10:58:27] /sbin/runlevel                                    [ OK ]
[10:58:28] /sbin/sulogin                                     [ OK ]
[10:58:28] /sbin/sysctl                                      [ Warning ]
[10:58:28] Warning: The file properties have changed:
[10:58:28]          File: /sbin/sysctl
[10:58:28]          Current inode: 1705551    Stored inode: 1705584
[10:58:28]          Current file modification time: 1225339532
[10:58:28]          Stored file modification time : 1225106254
[10:58:29] /sbin/syslogd                                     [ OK ]
[10:58:29] /usr/sbin/adduser                                 [ OK ]
[10:58:30] Info: Found file '/usr/sbin/adduser': it is whitelisted for the 'script replacement' check.
[10:58:30] /usr/sbin/chroot                                  [ OK ]
[10:58:30] /usr/sbin/cron                                    [ OK ]
[10:58:31] /usr/sbin/groupadd                                [ Warning ]
[10:58:31] Warning: The file properties have changed:
[10:58:31]          File: /usr/sbin/groupadd
[10:58:31]          Current hash: 58f295ec41bb630adfb937da11fcf74dd24c426b
[10:58:31]          Stored hash : 5941927732f493c5fb551f60ab16acc803bca929
[10:58:31]          Current inode: 1152855    Stored inode: 1153204
[10:58:32]          Current file modification time: 1228728171
[10:58:32]          Stored file modification time : 1213035045
[10:58:32] /usr/sbin/groupdel                                [ Warning ]
[10:58:32] Warning: The file properties have changed:
[10:58:32]          File: /usr/sbin/groupdel
[10:58:32]          Current hash: 5b8166639a6d72076265df74d7d61375f463fac9
[10:58:32]          Stored hash : 4108684afc97afe3748d7098e3dc6109358d3399
[10:58:32]          Current inode: 1152857    Stored inode: 1153205
[10:58:32]          Current file modification time: 1228728171
[10:58:32]          Stored file modification time : 1213035045
[10:58:33] /usr/sbin/groupmod                                [ Warning ]
[10:58:33] Warning: The file properties have changed:
[10:58:33]          File: /usr/sbin/groupmod
[10:58:33]          Current hash: b94beaf692b7a7ba5fa9516299768cca2241173d
[10:58:33]          Stored hash : 0172848087391f8b53434a59e02b98038957a298
[10:58:33]          Current inode: 1152859    Stored inode: 1153206
[10:58:33]          Current file modification time: 1228728171
[10:58:33]          Stored file modification time : 1213035045
[10:58:34] /usr/sbin/grpck                                   [ Warning ]
[10:58:34] Warning: The file properties have changed:
[10:58:34]          File: /usr/sbin/grpck
[10:58:34]          Current hash: a8863e0f255d74c45bb3654b9151cbb3414471d0
[10:58:34]          Stored hash : 81d2d3bac0d72415cc52ccf2aa96c4058b96be61
[10:58:34]          Current inode: 1152863    Stored inode: 1153207
[10:58:34]          Current file modification time: 1228728171
[10:58:34]          Stored file modification time : 1213035045
[10:58:35] /usr/sbin/nologin                                 [ Warning ]
[10:58:35] Warning: The file properties have changed:
[10:58:35]          File: /usr/sbin/nologin
[10:58:35]          Current hash: 9317a6bbc0e8582a0bdffaa2bfa1202f2975e088
[10:58:35]          Stored hash : 524c606f92b6995427aee6d8e8730748364e77fb
[10:58:36]          Current inode: 1153436    Stored inode: 1153269
[10:58:36]          Current file modification time: 1228728173
[10:58:36]          Stored file modification time : 1213035048
[10:58:36] /usr/sbin/pwck                                    [ Warning ]
[10:58:36] Warning: The file properties have changed:
[10:58:36]          File: /usr/sbin/pwck
[10:58:36]          Current hash: c8d9f6452bc41c380b9006ff095f7ce6a6258481
[10:58:36]          Stored hash : 8508676884fd9a20193e2425846b2c1296a16d88
[10:58:36]          Current inode: 1153099    Stored inode: 1153292
[10:58:37]          Current file modification time: 1228728171
[10:58:37]          Stored file modification time : 1213035045
[10:58:37] /usr/sbin/tcpd                                    [ OK ]
[10:58:38] /usr/sbin/unhide                                  [ Warning ]
[10:58:38] Warning: The file '/usr/sbin/unhide' exists on the system, but it is not present in the rkhunter.dat file.
[10:58:38] /usr/sbin/useradd                                 [ Warning ]
[10:58:38] Warning: The file properties have changed:
[10:58:38]          File: /usr/sbin/useradd
[10:58:38]          Current hash: 61959dcb30e0f895ea650081c5959e42c9cf4213
[10:58:38]          Stored hash : 5dfec9ac96eca81961ecec424ce614e35b1309ba
[10:58:38]          Current inode: 1153273    Stored inode: 1153362
[10:58:38]          Current file modification time: 1228728171
[10:58:39]          Stored file modification time : 1213035045
[10:58:39] /usr/sbin/userdel                                 [ Warning ]
[10:58:39] Warning: The file properties have changed:
[10:58:39]          File: /usr/sbin/userdel
[10:58:39]          Current hash: 5adc9df6518049d2d091250d66d26d01b6271cab
[10:58:39]          Stored hash : a99715c44de3d17e935dd4faf54907f4f1298a0b
[10:58:39]          Current inode: 1153274    Stored inode: 1153363
[10:58:39]          Current file modification time: 1228728171
[10:58:39]          Stored file modification time : 1213035045
[10:58:40] /usr/sbin/usermod                                 [ Warning ]
[10:58:40] Warning: The file properties have changed:
[10:58:40]          File: /usr/sbin/usermod
[10:58:40]          Current hash: c42a4fa2a5bacc383f5d1c5d30c47155cb42e757
[10:58:40]          Stored hash : 4719502c60d5bdef3486279d5e0be6fe58a102c5
[10:58:40]          Current inode: 1153350    Stored inode: 1153364
[10:58:40]          Current file modification time: 1228728171
[10:58:40]          Stored file modification time : 1213035045
[10:58:41] /usr/sbin/vipw                                    [ Warning ]
[10:58:41] Warning: The file properties have changed:
[10:58:41]          File: /usr/sbin/vipw
[10:58:41]          Current hash: a22b222e396ee769bd278d05c7ed696984047934
[10:58:41]          Stored hash : d932b406f5331fa09c373ad68a7c260c727be55c
[10:58:41]          Current inode: 1153355    Stored inode: 1153372
[10:58:41]          Current file modification time: 1228728171
[10:58:41]          Stored file modification time : 1213035045
[10:58:42] /usr/sbin/unhide-linux26                          [ Warning ]
[10:58:42] Warning: The file '/usr/sbin/unhide-linux26' exists on the system, but it is not present in the rkhunter.dat file.
[11:00:42]
[11:00:42] Checking for rootkits...
[11:00:42] Info: Starting test name 'rootkits'
[11:00:42]
[11:00:42] Performing check of known rootkit files and directories
[11:00:42] Info: Starting test name 'known_rkts'
[11:00:42]
[11:00:42] Checking for 55808 Trojan - Variant A...
[11:00:42]   Checking for file '/tmp/.../r'                  [ Not found ]
[11:00:42]   Checking for file '/tmp/.../a'                  [ Not found ]
[11:00:42] 55808 Trojan - Variant A                          [ Not found ]
[11:00:43]
[11:00:43] Checking for ADM Worm...
[11:00:43]   Checking for string 'w0rm'                      [ Not found ]
[11:00:43] ADM Worm                                          [ Not found ]
[11:00:43]
[11:00:43] Checking for AjaKit Rootkit...
[11:00:43]   Checking for file '/dev/tux/.addr'              [ Not found ]
[11:00:43]   Checking for file '/dev/tux/.proc'              [ Not found ]
[11:00:43]   Checking for file '/dev/tux/.file'              [ Not found ]
[11:00:43]   Checking for file '/lib/.libgh-gh/cleaner'      [ Not found ]
[11:00:43]   Checking for file '/lib/.libgh-gh/Patch/patch'  [ Not found ]
[11:00:44]   Checking for file '/lib/.libgh-gh/sb0k'         [ Not found ]
[11:00:44]   Checking for directory '/dev/tux'               [ Not found ]
[11:00:44]   Checking for directory '/lib/.libgh-gh'         [ Not found ]
[11:00:44] AjaKit Rootkit                                    [ Not found ]
[11:00:44]
[11:00:44] Checking for aPa Kit...
[11:00:44]   Checking for file '/usr/share/.aPa'             [ Not found ]
[11:00:44] aPa Kit                                           [ Not found ]
[11:00:44]
[11:00:44] Checking for Apache Worm...
[11:00:44]   Checking for file '/bin/.log'                   [ Not found ]
[11:00:44] Apache Worm                                       [ Not found ]
[11:00:45]
[11:00:45] Checking for Ambient (ark) Rootkit...
[11:00:45]   Checking for file '/usr/lib/.ark?'              [ Not found ]
[11:00:45]   Checking for file '/dev/ptyxx/.log'             [ Not found ]
[11:00:45]   Checking for file '/dev/ptyxx/.file'            [ Not found ]
[11:00:45]   Checking for directory '/dev/ptyxx'             [ Not found ]
[11:00:45] Ambient (ark) Rootkit                             [ Not found ]
[11:00:45]
[11:00:45] Checking for Balaur Rootkit...
[11:00:45]   Checking for file '/usr/lib/liblog.o'           [ Not found ]
[11:00:45]   Checking for directory '/usr/lib/.kinetic'      [ Not found ]
[11:00:45]   Checking for directory '/usr/lib/.egcs'         [ Not found ]
[11:00:46]   Checking for directory '/usr/lib/.wormie'       [ Not found ]
[11:00:46] Balaur Rootkit                                    [ Not found ]
[11:00:46]
[11:00:46] Checking for BeastKit Rootkit...
[11:00:46]   Checking for file '/usr/sbin/arobia'            [ Not found ]
[11:00:46]   Checking for file '/usr/sbin/idrun'             [ Not found ]
[11:00:46]   Checking for file '/usr/lib/elm/arobia/elm'     [ Not found ]
[11:00:46]   Checking for file '/usr/lib/elm/arobia/elm/hk'  [ Not found ]
[11:00:46]   Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
[11:00:46]   Checking for file '/usr/lib/elm/arobia/elm/sc'  [ Not found ]
[11:00:47]   Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
[11:00:47]   Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
[11:00:47]   Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
[11:00:47]   Checking for directory '/lib/ldd.so/bktools'    [ Not found ]
[11:00:47] BeastKit Rootkit                                  [ Not found ]
[11:00:47]
[11:00:47] Checking for beX2 Rootkit...
[11:00:47]   Checking for directory '/usr/include/bex'       [ Not found ]
[11:00:47] beX2 Rootkit                                      [ Not found ]
[11:00:47]
[11:00:47] Checking for BOBKit Rootkit...
[11:00:47]   Checking for file '/usr/sbin/ntpsx'             [ Not found ]
[11:00:48]   Checking for file '/usr/lib/.../ls'             [ Not found ]
[11:00:48]   Checking for file '/usr/lib/.../netstat'        [ Not found ]
[11:00:48]   Checking for file '/usr/lib/.../lsof'           [ Not found ]
[11:00:48]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
[11:00:48]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
[11:00:48]   Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
[11:00:48]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
[11:00:48]   Checking for file '/usr/lib/.../uconf.inv'      [ Not found ]
[11:00:48]   Checking for file '/usr/lib/.../psr'            [ Not found ]
[11:00:48]   Checking for file '/usr/lib/.../find'           [ Not found ]
[11:00:49]   Checking for file '/usr/lib/.../pstree'         [ Not found ]
[11:00:49]   Checking for file '/usr/lib/.../slocate'        [ Not found ]
[11:00:49]   Checking for file '/usr/lib/.../du'             [ Not found ]
[11:00:49]   Checking for file '/usr/lib/.../top'            [ Not found ]
[11:00:49]   Checking for directory '/usr/lib/...'           [ Not found ]
[11:00:49]   Checking for directory '/usr/lib/.../bkit-ssh'  [ Not found ]
[11:00:49]   Checking for directory '/usr/lib/.bkit-'        [ Not found ]
[11:00:49]   Checking for directory '/tmp/.bkp'              [ Not found ]
[11:00:49] BOBKit Rootkit                                    [ Not found ]
[11:00:50]
[11:00:50] Checking for CiNIK Worm (Slapper.B variant)...
[11:00:50]   Checking for file '/tmp/.cinik'                 [ Not found ]
[11:00:50]   Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
[11:00:50] CiNIK Worm (Slapper.B variant)                    [ Not found ]
[11:00:50]
[11:00:50] Checking for Danny-Boy's Abuse Kit...
[11:00:50]   Checking for file '/dev/mdev'                   [ Not found ]
[11:00:50]   Checking for file '/usr/lib/libX.a'             [ Not found ]
[11:00:50] Danny-Boy's Abuse Kit                             [ Not found ]
[11:00:50]
[11:00:50] Checking for Devil RootKit...
[11:00:50]   Checking for file '/var/lib/games/.src'         [ Not found ]
[11:00:51]   Checking for file '/dev/dsx'                    [ Not found ]
[11:00:51]   Checking for file '/dev/caca'                   [ Not found ]
[11:00:51] Devil RootKit                                     [ Not found ]
[11:00:51]
[11:00:51] Checking for Dica-Kit Rootkit...
[11:00:51]   Checking for file '/lib/.sso'                   [ Not found ]
[11:00:51]   Checking for file '/lib/.so'                    [ Not found ]
[11:00:51]   Checking for file '/var/run/...dica/clean'      [ Not found ]
[11:00:51]   Checking for file '/var/run/...dica/xl'         [ Not found ]
[11:00:51]   Checking for file '/var/run/...dica/xdr'        [ Not found ]
[11:00:51]   Checking for file '/var/run/...dica/psg'        [ Not found ]
[11:00:52]   Checking for file '/var/run/...dica/secure'     [ Not found ]
[11:00:52]   Checking for file '/var/run/...dica/rdx'        [ Not found ]
[11:00:52]   Checking for file '/var/run/...dica/va'         [ Not found ]
[11:00:52]   Checking for file '/var/run/...dica/cl.sh'      [ Not found ]
[11:00:52]   Checking for file '/usr/bin/.etc'               [ Not found ]
[11:00:52]   Checking for directory '/var/run/...dica'       [ Not found ]
[11:00:52]   Checking for directory '/var/run/...dica/mh'    [ Not found ]
[11:00:52]   Checking for directory '/var/run/...dica/scan'  [ Not found ]
[11:00:52] Dica-Kit Rootkit                                  [ Not found ]
[11:00:53]
[11:00:53] Checking for Dreams Rootkit...
[11:00:53]   Checking for file '/dev/ttyoa'                  [ Not found ]
[11:00:53]   Checking for file '/dev/ttyof'                  [ Not found ]
[11:00:53]   Checking for file '/dev/ttyop'                  [ Not found ]
[11:00:53]   Checking for file '/usr/bin/sense'              [ Not found ]
[11:00:53]   Checking for file '/usr/bin/sl2'                [ Not found ]
[11:00:53]   Checking for file '/usr/bin/logclear'           [ Not found ]
[11:00:53]   Checking for file '/usr/bin/(swapd)'            [ Not found ]
[11:00:53]   Checking for file '/usr/bin/snfs'               [ Not found ]
[11:00:53]   Checking for file '/usr/lib/libsss'             [ Not found ]
[11:00:54]   Checking for directory '/dev/ida/.hpd'          [ Not found ]
[11:00:54] Dreams Rootkit                                    [ Not found ]
[11:00:54]
[11:00:54] Checking for Duarawkz Rootkit...
[11:00:54]   Checking for file '/usr/bin/duarawkz/loginpass' [ Not found ]
[11:00:54]   Checking for directory '/usr/bin/duarawkz'      [ Not found ]
[11:00:54] Duarawkz Rootkit                                  [ Not found ]
[11:00:54]
[11:00:54] Checking for Enye LKM...
[11:00:54]   Checking for file '/etc/.enyelkmHIDE^IT.ko'     [ Not found ]
[11:00:54] Enye LKM                                          [ Not found ]
[11:00:54]
[11:00:54] Checking for Flea Linux Rootkit...
[11:00:55]   Checking for file '/etc/ld.so.hash'             [ Not found ]
[11:00:55]   Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[11:00:55]   Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[11:00:55]   Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[11:00:55]   Checking for file '/usr/bin/ssh2d'              [ Not found ]
[11:00:55]   Checking for file '/usr/lib/ldlibns.so'         [ Not found ]
[11:00:55]   Checking for file '/usr/lib/ldlibpst.so'        [ Not found ]
[11:00:55]   Checking for file '/usr/lib/ldlibdu.so'         [ Not found ]
[11:00:55]   Checking for file '/usr/lib/ldlibct.so'         [ Not found ]
[11:00:55]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[11:00:56]   Checking for directory '/dev/..0'               [ Not found ]
[11:00:56]   Checking for directory '/dev/..0/backup'        [ Not found ]
[11:00:56] Flea Linux Rootkit                                [ Not found ]
[11:00:56]
[11:00:56] Checking for FreeBSD Rootkit...
[11:00:56]   Checking for file '/usr/lib/.fx/sched_host.2'   [ Not found ]
[11:00:56]   Checking for file '/usr/lib/.fx/random_d.2'     [ Not found ]
[11:00:56]   Checking for file '/usr/lib/.fx/set_pid.2'      [ Not found ]
[11:00:56]   Checking for file '/usr/lib/.fx/cons.saver'     [ Not found ]
[11:00:56]   Checking for file '/usr/lib/.fx/adore/adore/adore.ko' [ Not found ]
[11:00:57]   Checking for file '/bin/sysback'                [ Not found ]
[11:00:57]   Checking for file '/usr/local/bin/sysback'      [ Not found ]
[11:00:57]   Checking for directory '/usr/lib/.fx'           [ Not found ]
[11:00:57]   Checking for directory '/usr/lib/.fx/adore'     [ Not found ]
[11:00:57] FreeBSD Rootkit                                   [ Not found ]
[11:00:57]
[11:00:57] Checking for Fuck`it Rootkit...
[11:00:57]   Checking for file '/dev/proc/fuckit/hax0r'      [ Not found ]
[11:00:57]   Checking for file '/dev/proc/fuckit/hax0rshell' [ Not found ]
[11:00:57]   Checking for file '/dev/proc/fuckit/config/lports' [ Not found ]
[11:00:57]   Checking for file '/dev/proc/fuckit/config/rports' [ Not found ]
[11:00:58]   Checking for file '/dev/proc/fuckit/config/rkconf' [ Not found ]
[11:00:58]   Checking for file '/dev/proc/fuckit/config/password' [ Not found ]
[11:00:58]   Checking for file '/dev/proc/fuckit/config/progs' [ Not found ]
[11:00:58]   Checking for file '/dev/proc/system-bins/init'  [ Not found ]
[11:00:58] Fuck`it Rootkit                                   [ Not found ]
[11:00:58]
[11:00:58] Checking for GasKit Rootkit...
[11:00:58]   Checking for file '/dev/dev/gaskit/sshd/sshdd'  [ Not found ]
[11:00:58]   Checking for directory '/dev/dev'               [ Not found ]
[11:00:58]   Checking for directory '/dev/dev/gaskit'        [ Not found ]
[11:00:58]   Checking for directory '/dev/dev/gaskit/sshd'   [ Not found ]
[11:00:59] GasKit Rootkit                                    [ Not found ]
[11:00:59]
[11:00:59] Checking for Heroin LKM...
[11:00:59]   Checking for kernel symbol 'heroin'             [ Not found ]
[11:00:59] Heroin LKM                                        [ Not found ]
[11:00:59]
[11:00:59] Checking for HjC Kit...
[11:00:59]   Checking for directory '/dev/.hijackerz'        [ Not found ]
[11:00:59] HjC Kit                                           [ Not found ]
[11:00:59]
[11:00:59] Checking for ignoKit Rootkit...
[11:00:59]   Checking for file '/lib/defs/p'                 [ Not found ]
[11:01:00]   Checking for file '/lib/defs/q'                 [ Not found ]
[11:01:00]   Checking for file '/lib/defs/r'                 [ Not found ]
[11:01:00]   Checking for file '/lib/defs/s'                 [ Not found ]
[11:01:00]   Checking for file '/lib/defs/t'                 [ Not found ]
[11:01:00]   Checking for file '/usr/lib/defs/p'             [ Not found ]
[11:01:00]   Checking for file '/usr/lib/defs/q'             [ Not found ]
[11:01:00]   Checking for file '/usr/lib/defs/r'             [ Not found ]
[11:01:00]   Checking for file '/usr/lib/defs/s'             [ Not found ]
[11:01:00]   Checking for file '/usr/lib/defs/t'             [ Not found ]
[11:01:01]   Checking for file '/usr/lib/.libigno/pkunsec'   [ Not found ]
[11:01:01]   Checking for file '/usr/lib/.libigno/.igno/psybnc/psybnc' [ Not found ]
[11:01:01]   Checking for directory '/usr/lib/.libigno'      [ Not found ]
[11:01:01]   Checking for directory '/usr/lib/.libigno/.igno' [ Not found ]
[11:01:01] ignoKit Rootkit                                   [ Not found ]
[11:01:01]
[11:01:01] Checking for ImperalsS-FBRK Rootkit...
[11:01:01]   Checking for directory '/dev/fd/.88'            [ Not found ]
[11:01:01]   Checking for directory '/dev/fd/.99'            [ Not found ]
[11:01:01] ImperalsS-FBRK Rootkit                            [ Not found ]
[11:01:02]
[11:01:02] Checking for Irix Rootkit...
[11:01:02]   Checking for directory '/dev/pts/01'            [ Not found ]
[11:01:02]   Checking for directory '/dev/pts/01/backup'     [ Not found ]
[11:01:02]   Checking for directory '/dev/pts/01/etc'        [ Not found ]
[11:01:02]   Checking for directory '/dev/pts/01/tmp'        [ Not found ]
[11:01:02] Irix Rootkit                                      [ Not found ]
[11:01:02]
[11:01:02] Checking for Kitko Rootkit...
[11:01:02]   Checking for directory '/usr/src/redhat/SRPMS/...' [ Not found ]
[11:01:02] Kitko Rootkit                                     [ Not found ]
[11:01:03]
[11:01:03] Checking for Knark Rootkit...
[11:01:03]   Checking for file '/proc/knark/pids'            [ Not found ]
[11:01:03]   Checking for directory '/proc/knark'            [ Not found ]
[11:01:03] Knark Rootkit                                     [ Not found ]
[11:01:03]
[11:01:03] Checking for Li0n Worm...
[11:01:03]   Checking for file '/bin/in.telnetd'             [ Not found ]
[11:01:03]   Checking for file '/bin/mjy'                    [ Not found ]
[11:01:03]   Checking for file '/usr/man/man1/man1/lib/.lib/mjy' [ Not found ]
[11:01:03]   Checking for file '/usr/man/man1/man1/lib/.lib/in.telnetd' [ Not found ]
[11:01:03]   Checking for file '/usr/man/man1/man1/lib/.lib/.x' [ Not found ]
[11:01:04]   Checking for file '/dev/.lib/lib/scan/1i0n.sh'  [ Not found ]
[11:01:04]   Checking for file '/dev/.lib/lib/scan/hack.sh'  [ Not found ]
[11:01:04]   Checking for file '/dev/.lib/lib/scan/bind'     [ Not found ]
[11:01:04]   Checking for file '/dev/.lib/lib/scan/randb'    [ Not found ]
[11:01:04]   Checking for file '/dev/.lib/lib/scan/scan.sh'  [ Not found ]
[11:01:04]   Checking for file '/dev/.lib/lib/scan/pscan'    [ Not found ]
[11:01:04]   Checking for file '/dev/.lib/lib/scan/star.sh'  [ Not found ]
[11:01:04]   Checking for file '/dev/.lib/lib/scan/bindx.sh' [ Not found ]
[11:01:04]   Checking for file '/dev/.lib/lib/scan/bindname.log' [ Not found ]
[11:01:04]   Checking for file '/dev/.lib/lib/1i0n.sh'       [ Not found ]
[11:01:05]   Checking for file '/dev/.lib/lib/lib/netstat'   [ Not found ]
[11:01:05]   Checking for file '/dev/.lib/lib/lib/dev/.1addr' [ Not found ]
[11:01:05]   Checking for file '/dev/.lib/lib/lib/dev/.1logz' [ Not found ]
[11:01:05]   Checking for file '/dev/.lib/lib/lib/dev/.1proc' [ Not found ]
[11:01:05]   Checking for file '/dev/.lib/lib/lib/dev/.1file' [ Not found ]
[11:01:05] Li0n Worm                                         [ Not found ]
[11:01:05]
[11:01:05] Checking for Lockit / LJK2 Rootkit...
[11:01:05]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_config' [ Not found ]
[11:01:05]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key' [ Not found ]
[11:01:05]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub' [ Not found ]
[11:01:06]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_random_seed*' [ Not found ]
[11:01:06]   Checking for file '/usr/lib/libmen.oo/.LJK2/sshd_config' [ Not found ]
[11:01:06]   Checking for file '/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd' [ Not found ]
[11:01:06]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/du' [ Not found ]
[11:01:06]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ifconfig' [ Not found ]
[11:01:06]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/inetd.conf' [ Not found ]
[11:01:06]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/locate' [ Not found ]
[11:01:06]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/login' [ Not found ]
[11:01:06]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ls' [ Not found ]
[11:01:07]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/netstat' [ Not found ]
[11:01:07]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ps' [ Not found ]
[11:01:07]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/pstree' [ Not found ]
[11:01:07]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit' [ Not found ]
[11:01:07]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/syslogd' [ Not found ]
[11:01:07]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/tcpd' [ Not found ]
[11:01:07]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/top' [ Not found ]
[11:01:07]   Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1sauber' [ Not found ]
[11:01:07]   Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1wted' [ Not found ]
[11:01:07]   Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1parser' [ Not found ]
[11:01:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1sniff' [ Not found ]
[11:01:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1addr' [ Not found ]
[11:01:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1dir' [ Not found ]
[11:01:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1log' [ Not found ]
[11:01:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1proc' [ Not found ]
[11:01:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c' [ Not found ]
[11:01:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/README.modules' [ Not found ]
[11:01:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c' [ Not found ]
[11:01:08]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1phide' [ Not found ]
[11:01:09]   Checking for file '/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh' [ Not found ]
[11:01:09]   Checking for directory '/usr/lib/libmen.oo/.LJK2' [ Not found ]
[11:01:09] Lockit / LJK2 Rootkit                             [ Not found ]
[11:01:09]
[11:01:09] Checking for Mood-NT Rootkit...
[11:01:09]   Checking for file '/sbin/init__mood-nt-_-_cthulhu' [ Not found ]
[11:01:09]   Checking for file '/_cthulhu/mood-nt.init'      [ Not found ]
[11:01:09]   Checking for file '/_cthulhu/mood-nt.conf'      [ Not found ]
[11:01:09]   Checking for file '/_cthulhu/mood-nt.sniff'     [ Not found ]
[11:01:09]   Checking for directory '/_cthulhu'              [ Not found ]
[11:01:09] Mood-NT Rootkit                                   [ Not found ]
[11:01:10]
[11:01:10] Checking for MRK Rootkit...
[11:01:10]   Checking for file '/dev/ida/.inet/pid'          [ Not found ]
[11:01:10]   Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[11:01:10]   Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[11:01:10]   Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
[11:01:10]   Checking for directory '/dev/ida/.inet'         [ Not found ]
[11:01:10]   Checking for directory '/var/spool/cron/.sh'    [ Not found ]
[11:01:10] MRK Rootkit                                       [ Not found ]
[11:01:10]
[11:01:10] Checking for Ni0 Rootkit...
[11:01:10]   Checking for file '/var/lock/subsys/...datafile.../...net...' [ Not found ]
[11:01:11]   Checking for file '/var/lock/subsys/...datafile.../...port...' [ Not found ]
[11:01:11]   Checking for file '/var/lock/subsys/...datafile.../...ps...' [ Not found ]
[11:01:11]   Checking for file '/var/lock/subsys/...datafile.../...file...' [ Not found ]
[11:01:11]   Checking for directory '/tmp/waza'              [ Not found ]
[11:01:11]   Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[11:01:11]   Checking for directory '/usr/sbin/es'           [ Not found ]
[11:01:11] Ni0 Rootkit                                       [ Not found ]
[11:01:11]
[11:01:11] Checking for Ohhara Rootkit...
[11:01:11]   Checking for file '/var/lock/subsys/...datafile.../...datafile.../in.smbd.log' [ Not found ]
[11:01:12]   Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[11:01:12]   Checking for directory '/var/lock/subsys/...datafile.../...datafile...' [ Not found ]
[11:01:12]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../bin' [ Not found ]
[11:01:12]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/bin' [ Not found ]
[11:01:12]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/sbin' [ Not found ]
[11:01:12]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../lib/security' [ Not found ]
[11:01:12] Ohhara Rootkit                                    [ Not found ]
[11:01:12]
[11:01:12] Checking for Optic Kit (Tux) Worm...
[11:01:12]   Checking for directory '/dev/tux'               [ Not found ]
[11:01:12]   Checking for directory '/usr/bin/xchk'          [ Not found ]
[11:01:13]   Checking for directory '/usr/bin/xsf'           [ Not found ]
[11:01:13]   Checking for directory '/usr/bin/ssh2d'         [ Not found ]
[11:01:13] Optic Kit (Tux) Worm                              [ Not found ]
[11:01:13]
[11:01:13] Checking for Oz Rootkit...
[11:01:13]   Checking for file '/dev/.oz/.nap/rkit/terror'   [ Not found ]
[11:01:13]   Checking for directory '/dev/.oz'               [ Not found ]
[11:01:13] Oz Rootkit                                        [ Not found ]
[11:01:13]
[11:01:13] Checking for Phalanx Rootkit...
[11:01:13]   Checking for file '/usr/share/.home.ph1/cb'     [ Not found ]
[11:01:14]   Checking for file '/etc/host.ph1'               [ Not found ]
[11:01:14]   Checking for file '/bin/host.ph1'               [ Not found ]
[11:01:14]   Checking for file '/usr/share/.home.ph1/phalanx' [ Not found ]
[11:01:14]   Checking for directory '/usr/share/.home.ph1'   [ Not found ]
[11:01:14] Phalanx Rootkit                                   [ Not found ]
[11:01:14]
[11:01:14] Checking for Phalanx Rootkit (strings)...
[11:01:14]   Checking for string 'phalanx'                   [ Not found ]
[11:01:14] Phalanx Rootkit (strings)                         [ Not found ]
[11:01:14]
[11:01:14] Checking for Portacelo Rootkit...
[11:01:14]   Checking for file '/var/lib/.../.ak'            [ Not found ]
[11:01:15]   Checking for file '/var/lib/.../.hk'            [ Not found ]
[11:01:15]   Checking for file '/var/lib/.../.rs'            [ Not found ]
[11:01:15]   Checking for file '/var/lib/.../.p'             [ Not found ]
[11:01:15]   Checking for file '/var/lib/.../getty'          [ Not found ]
[11:01:15]   Checking for file '/var/lib/.../lkt.o'          [ Not found ]
[11:01:15]   Checking for file '/var/lib/.../show'           [ Not found ]
[11:01:15]   Checking for file '/var/lib/.../nlkt.o'         [ Not found ]
[11:01:15]   Checking for file '/var/lib/.../ssshrc'         [ Not found ]
[11:01:15]   Checking for file '/var/lib/.../sssh_equiv'     [ Not found ]
[11:01:15]   Checking for file '/var/lib/.../sssh_known_hosts' [ Not found ]
[11:01:16]   Checking for file '/var/lib/.../sssh_pid'       [ Not found ]
[11:01:16]   Checking for file '~/.sssh/known_hosts'         [ Not found ]
[11:01:16] Portacelo Rootkit                                 [ Not found ]
[11:01:16]
[11:01:16] Checking for R3dstorm Toolkit...
[11:01:16]   Checking for file '/var/log/tk02/see_all'       [ Not found ]
[11:01:16]   Checking for file '/bin/.../sshd/sbin/sshd1'    [ Not found ]
[11:01:16]   Checking for file '/bin/.../hate/sk'            [ Not found ]
[11:01:16]   Checking for file '/bin/.../see_all'            [ Not found ]
[11:01:16]   Checking for directory '/var/log/tk02'          [ Not found ]
[11:01:17]   Checking for directory '/var/log/tk02/old'      [ Not found ]
[11:01:17]   Checking for directory '/bin/...'               [ Not found ]
[11:01:17] R3dstorm Toolkit                                  [ Not found ]
[11:01:17]
[11:01:17] Checking for RH-Sharpe's Rootkit...
[11:01:17]   Checking for file '/bin/lps'                    [ Not found ]
[11:01:17]   Checking for file '/usr/bin/lpstree'            [ Not found ]
[11:01:17]   Checking for file '/usr/bin/ltop'               [ Not found ]
[11:01:17]   Checking for file '/usr/bin/lkillall'           [ Not found ]
[11:01:17]   Checking for file '/usr/bin/ldu'                [ Not found ]
[11:01:17]   Checking for file '/usr/bin/lnetstat'           [ Not found ]
[11:01:18]   Checking for file '/usr/bin/wp'                 [ Not found ]
[11:01:18]   Checking for file '/usr/bin/shad'               [ Not found ]
[11:01:18]   Checking for file '/usr/bin/vadim'              [ Not found ]
[11:01:18]   Checking for file '/usr/bin/slice'              [ Not found ]
[11:01:18]   Checking for file '/usr/bin/cleaner'            [ Not found ]
[11:01:18]   Checking for file '/usr/include/rpcsvc/du'      [ Not found ]
[11:01:18] RH-Sharpe's Rootkit                               [ Not found ]
[11:01:18]
[11:01:18] Checking for RSHA's Rootkit...
[11:01:18]   Checking for file '/bin/kr4p'                   [ Not found ]
[11:01:18]   Checking for file '/usr/bin/n3tstat'            [ Not found ]
[11:01:19]   Checking for file '/usr/bin/chsh2'              [ Not found ]
[11:01:19]   Checking for file '/usr/bin/slice2'             [ Not found ]
[11:01:19]   Checking for file '/usr/src/linux/arch/alpha/lib/.lib/.1proc' [ Not found ]
[11:01:19]   Checking for file '/etc/rc.d/arch/alpha/lib/.lib/.1addr' [ Not found ]
[11:01:19]   Checking for directory '/etc/rc.d/rsha'         [ Not found ]
[11:01:19]   Checking for directory '/etc/rc.d/arch/alpha/lib/.lib' [ Not found ]
[11:01:19] RSHA's Rootkit                                    [ Not found ]
[11:01:19]
[11:01:19] Checking for Scalper Worm...
[11:01:19]   Checking for file '/tmp/.a'                     [ Not found ]
[11:01:20]   Checking for file '/tmp/.uua'                   [ Not found ]
[11:01:20] Scalper Worm                                      [ Not found ]
[11:01:20]
[11:01:20] Checking for Sebek LKM...
[11:01:21]   Checking for kernel symbol 'adore or sebek'     [ Not found ]
[11:01:21] Sebek LKM                                         [ Not found ]
[11:01:21]
[11:01:21] Checking for Shutdown Rootkit...
[11:01:21]   Checking for file '/usr/man/man5/.. /.dir/scannah/asus' [ Not found ]
[11:01:21]   Checking for file '/usr/man/man5/.. /.dir/see'  [ Not found ]
[11:01:21]   Checking for file '/usr/man/man5/.. /.dir/nscd' [ Not found ]
[11:01:21]   Checking for file '/usr/man/man5/.. /.dir/alpd' [ Not found ]
[11:01:21]   Checking for file '/etc/rc.d/rc.local '         [ Not found ]
[11:01:21]   Checking for directory '/usr/man/man5/.. /.dir' [ Not found ]
[11:01:21]   Checking for directory '/usr/man/man5/.. /.dir/scannah' [ Not found ]
[11:01:21]   Checking for directory '/etc/rc.d/rc0.d/.. /.dir' [ Not found ]
[11:01:21] Shutdown Rootkit                                  [ Not found ]
[11:01:21]
[11:01:21] Checking for SHV4 Rootkit...
[11:01:21]   Checking for file '/etc/ld.so.hash'             [ Not found ]
[11:01:21]   Checking for file '/lib/libext-2.so.7'          [ Not found ]
[11:01:21]   Checking for file '/lib/lidps1.so'              [ Not found ]
[11:01:21]   Checking for file '/usr/sbin/xntps'             [ Not found ]
[11:01:21]   Checking for directory '/lib/security/.config'  [ Not found ]
[11:01:22]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[11:01:22] SHV4 Rootkit                                      [ Not found ]
[11:01:22]
[11:01:22] Checking for SHV5 Rootkit...
[11:01:22]   Checking for file '/etc/sh.conf'                [ Not found ]
[11:01:22]   Checking for file '/dev/srd0'                   [ Not found ]
[11:01:22]   Checking for directory '/usr/lib/libsh'         [ Not found ]
[11:01:22] SHV5 Rootkit                                      [ Not found ]
[11:01:22]
[11:01:22] Checking for Sin Rootkit...
[11:01:22]   Checking for file '/dev/.haos/haos1/.f/Denyed'  [ Not found ]
[11:01:22]   Checking for file '/dev/ttyoa'                  [ Not found ]
[11:01:22]   Checking for file '/dev/ttyof'                  [ Not found ]
[11:01:22]   Checking for file '/dev/ttyop'                  [ Not found ]
[11:01:22]   Checking for file '/dev/ttyos'                  [ Not found ]
[11:01:22]   Checking for file '/usr/lib/.lib'               [ Not found ]
[11:01:22]   Checking for file '/usr/lib/sn/.X'              [ Not found ]
[11:01:22]   Checking for file '/usr/lib/sn/.sys'            [ Not found ]
[11:01:22]   Checking for file '/usr/lib/ld/.X'              [ Not found ]
[11:01:22]   Checking for file '/usr/man/man1/...'           [ Not found ]
[11:01:22]   Checking for file '/usr/man/man1/.../.m'        [ Not found ]
[11:01:22]   Checking for file '/usr/man/man1/.../.w'        [ Not found ]
[11:01:23]   Checking for directory '/usr/lib/sn'            [ Not found ]
[11:01:23]   Checking for directory '/usr/lib/man1/...'      [ Not found ]
[11:01:23]   Checking for directory '/dev/.haos'             [ Not found ]
[11:01:23] Sin Rootkit                                       [ Not found ]
[11:01:23]
[11:01:23] Checking for Slapper Worm...
[11:01:23]   Checking for file '/tmp/.bugtraq'               [ Not found ]
[11:01:23]   Checking for file '/tmp/.uubugtraq'             [ Not found ]
[11:01:23]   Checking for file '/tmp/.bugtraq.c'             [ Not found ]
[11:01:23]   Checking for file '/tmp/httpd'                  [ Not found ]
[11:01:23]   Checking for file '/tmp/.unlock'                [ Not found ]
[11:01:23]   Checking for file '/tmp/update'                 [ Not found ]
[11:01:23]   Checking for file '/tmp/.cinik'                 [ Not found ]
[11:01:23]   Checking for file '/tmp/.b'                     [ Not found ]
[11:01:23] Slapper Worm                                      [ Not found ]
[11:01:23]
[11:01:23] Checking for Sneakin Rootkit...
[11:01:23]   Checking for directory '/tmp/.X11-unix/.../rk'  [ Not found ]
[11:01:23] Sneakin Rootkit                                   [ Not found ]
[11:01:23]
[11:01:23] Checking for Suckit Rootkit...
[11:01:23]   Checking for file '/sbin/initsk12'              [ Not found ]
[11:01:24]   Checking for file '/sbin/initxrk'               [ Not found ]
[11:01:24]   Checking for file '/usr/bin/null'               [ Not found ]
[11:01:24]   Checking for file '/usr/share/locale/sk/.sk12/sk' [ Not found ]
[11:01:24]   Checking for file '/etc/rc.d/rc0.d/S23kmdac'    [ Not found ]
[11:01:24]   Checking for file '/etc/rc.d/rc1.d/S23kmdac'    [ Not found ]
[11:01:24]   Checking for file '/etc/rc.d/rc2.d/S23kmdac'    [ Not found ]
[11:01:24]   Checking for file '/etc/rc.d/rc3.d/S23kmdac'    [ Not found ]
[11:01:24]   Checking for file '/etc/rc.d/rc4.d/S23kmdac'    [ Not found ]
[11:01:24]   Checking for file '/etc/rc.d/rc5.d/S23kmdac'    [ Not found ]
[11:01:24]   Checking for file '/etc/rc.d/rc6.d/S23kmdac'    [ Not found ]
[11:01:24]   Checking for directory '/dev/sdhu0/tehdrakg'    [ Not found ]
[11:01:24]   Checking for directory '/etc/.MG'               [ Not found ]
[11:01:24]   Checking for directory '/usr/share/locale/sk/.sk12' [ Not found ]
[11:01:24]   Checking for directory '/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist' [ Not found ]
[11:01:24] Suckit Rootkit                                    [ Not found ]
[11:01:24]
[11:01:24] Checking for SunOS Rootkit...
[11:01:24]   Checking for file '/etc/ld.so.hash'             [ Not found ]
[11:01:24]   Checking for file '/lib/libext-2.so.7'          [ Not found ]
[11:01:24]   Checking for file '/usr/bin/ssh2d'              [ Not found ]
[11:01:25]   Checking for file '/bin/xlogin'                 [ Not found ]
[11:01:25]   Checking for file '/usr/lib/crth.o'             [ Not found ]
[11:01:25]   Checking for file '/usr/lib/crtz.o'             [ Not found ]
[11:01:25]   Checking for file '/sbin/login'                 [ Not found ]
[11:01:25]   Checking for file '/lib/security/.config/sn'    [ Not found ]
[11:01:25]   Checking for file '/lib/security/.config/lpsched' [ Not found ]
[11:01:25]   Checking for file '/dev/kmod'                   [ Not found ]
[11:01:25]   Checking for file '/dev/dos'                    [ Not found ]
[11:01:25] SunOS Rootkit                                     [ Not found ]
[11:01:25]
[11:01:25] Checking for SunOS / NSDAP Rootkit...
[11:01:25]   Checking for file '/usr/lib/vold/nsdap/.kit'    [ Not found ]
[11:01:25]   Checking for file '/usr/lib/vold/nsdap/defines' [ Not found ]
[11:01:25]   Checking for file '/usr/lib/vold/nsdap/patcher' [ Not found ]
[11:01:25]   Checking for file '/usr/lib/vold/nsdap/pg'      [ Not found ]
[11:01:25]   Checking for file '/usr/lib/vold/nsdap/cleaner' [ Not found ]
[11:01:25]   Checking for file '/usr/lib/vold/nsdap/utime'   [ Not found ]
[11:01:25]   Checking for file '/usr/lib/vold/nsdap/crypt'   [ Not found ]
[11:01:25]   Checking for file '/usr/lib/vold/nsdap/findkit' [ Not found ]
[11:01:26]   Checking for file '/usr/lib/vold/nsdap/sn2'     [ Not found ]
[11:01:26]   Checking for file '/usr/lib/vold/nsdap/sniffload' [ Not found ]
[11:01:26]   Checking for file '/usr/lib/vold/nsdap/runsniff' [ Not found ]
[11:01:26]   Checking for file '/usr/lib/lpset'              [ Not found ]
[11:01:26]   Checking for directory '/usr/lib/vold/nsdap'    [ Not found ]
[11:01:26] SunOS / NSDAP Rootkit                             [ Not found ]
[11:01:26]
[11:01:26] Checking for Superkit Rootkit...
[11:01:26]   Checking for file '/usr/man/.sman/sk'           [ Not found ]
[11:01:26] Superkit Rootkit                                  [ Not found ]
[11:01:26]
[11:01:26] Checking for TBD (Telnet BackDoor)...
[11:01:26]   Checking for file '/usr/lib/.tbd'               [ Not found ]
[11:01:26] TBD (Telnet BackDoor)                             [ Not found ]
[11:01:26]
[11:01:26] Checking for TeLeKiT Rootkit...
[11:01:26]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/sniff' [ Not found ]
[11:01:26]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/telnetd' [ Not found ]
[11:01:26]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/teleulo' [ Not found ]
[11:01:26]   Checking for file '/usr/man/man3/.../cl'        [ Not found ]
[11:01:26]   Checking for file '/dev/ptyr'                   [ Not found ]
[11:01:26]   Checking for file '/dev/ptyp'                   [ Not found ]
[11:01:27]   Checking for file '/dev/ptyq'                   [ Not found ]
[11:01:27]   Checking for file '/dev/hda06'                  [ Not found ]
[11:01:27]   Checking for file '/usr/info/libc1.so'          [ Not found ]
[11:01:27]   Checking for directory '/usr/man/man3/...'      [ Not found ]
[11:01:27]   Checking for directory '/usr/man/man3/.../lsniff' [ Not found ]
[11:01:27]   Checking for directory '/usr/man/man3/.../TeLeKiT' [ Not found ]
[11:01:27] TeLeKiT Rootkit                                   [ Not found ]
[11:01:27]
[11:01:27] Checking for T0rn Rootkit...
[11:01:27]   Checking for file '/dev/.lib/lib/lib/t0rns'     [ Not found ]
[11:01:27]   Checking for file '/dev/.lib/lib/lib/du'        [ Not found ]
[11:01:27]   Checking for file '/dev/.lib/lib/lib/ls'        [ Not found ]
[11:01:27]   Checking for file '/dev/.lib/lib/lib/t0rnsb'    [ Not found ]
[11:01:27]   Checking for file '/dev/.lib/lib/lib/ps'        [ Not found ]
[11:01:27]   Checking for file '/dev/.lib/lib/lib/t0rnp'     [ Not found ]
[11:01:27]   Checking for file '/dev/.lib/lib/lib/find'      [ Not found ]
[11:01:27]   Checking for file '/dev/.lib/lib/lib/ifconfig'  [ Not found ]
[11:01:27]   Checking for file '/dev/.lib/lib/lib/pg'        [ Not found ]
[11:01:27]   Checking for file '/dev/.lib/lib/lib/ssh.tgz'   [ Not found ]
[11:01:27]   Checking for file '/dev/.lib/lib/lib/top'       [ Not found ]
[11:01:28]   Checking for file '/dev/.lib/lib/lib/sz'        [ Not found ]
[11:01:28]   Checking for file '/dev/.lib/lib/lib/login'     [ Not found ]
[11:01:28]   Checking for file '/dev/.lib/lib/lib/in.fingerd' [ Not found ]
[11:01:28]   Checking for file '/dev/.lib/lib/lib/1i0n.sh'   [ Not found ]
[11:01:28]   Checking for file '/dev/.lib/lib/lib/pstree'    [ Not found ]
[11:01:28]   Checking for file '/dev/.lib/lib/lib/in.telnetd' [ Not found ]
[11:01:28]   Checking for file '/dev/.lib/lib/lib/mjy'       [ Not found ]
[11:01:28]   Checking for file '/dev/.lib/lib/lib/sush'      [ Not found ]
[11:01:28]   Checking for file '/dev/.lib/lib/lib/tfn'       [ Not found ]
[11:01:28]   Checking for file '/dev/.lib/lib/lib/name'      [ Not found ]
[11:01:28]   Checking for file '/dev/.lib/lib/lib/getip.sh'  [ Not found ]
[11:01:28]   Checking for file '/usr/info/.torn/sh*'         [ Not found ]
[11:01:28]   Checking for file '/usr/src/.puta/.1addr'       [ Not found ]
[11:01:28]   Checking for file '/usr/src/.puta/.1file'       [ Not found ]
[11:01:28]   Checking for file '/usr/src/.puta/.1proc'       [ Not found ]
[11:01:28]   Checking for file '/usr/src/.puta/.1logz'       [ Not found ]
[11:01:28]   Checking for file '/usr/info/.t0rn'             [ Not found ]
[11:01:28]   Checking for directory '/dev/.lib'              [ Not found ]
[11:01:28]   Checking for directory '/dev/.lib/lib'          [ Not found ]
[11:01:29]   Checking for directory '/dev/.lib/lib/lib'      [ Not found ]
[11:01:29]   Checking for directory '/dev/.lib/lib/lib/dev'  [ Not found ]
[11:01:29]   Checking for directory '/dev/.lib/lib/scan'     [ Not found ]
[11:01:29]   Checking for directory '/usr/src/.puta'         [ Not found ]
[11:01:29]   Checking for directory '/usr/man/man1/man1'     [ Not found ]
[11:01:29]   Checking for directory '/usr/man/man1/man1/lib' [ Not found ]
[11:01:29]   Checking for directory '/usr/man/man1/man1/lib/.lib' [ Not found ]
[11:01:29]   Checking for directory '/usr/man/man1/man1/lib/.lib/.backup' [ Not found ]
[11:01:29] T0rn Rootkit                                      [ Not found ]
[11:01:29]
[11:01:29] Checking for Trojanit Kit...
[11:01:29]   Checking for file '/bin/.ls'                    [ Not found ]
[11:01:29]   Checking for file '/bin/.ps'                    [ Not found ]
[11:01:29]   Checking for file '/bin/.netstat'               [ Not found ]
[11:01:29]   Checking for file '/usr/bin/.nop'               [ Not found ]
[11:01:29]   Checking for file '/usr/bin/.who'               [ Not found ]
[11:01:29] Trojanit Kit                                      [ Not found ]
[11:01:29]
[11:01:29] Checking for Tuxtendo Rootkit...
[11:01:29]   Checking for file '/dev/tux/.addr'              [ Not found ]
[11:01:29]   Checking for file '/dev/tux/.cron'              [ Not found ]
[11:01:30]   Checking for file '/dev/tux/.file'              [ Not found ]
[11:01:30]   Checking for file '/dev/tux/.log'               [ Not found ]
[11:01:30]   Checking for file '/dev/tux/.proc'              [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/crontab'     [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/df'          [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/dir'         [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/find'        [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/ifconfig'    [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/locate'      [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/netstat'     [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/ps'          [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/pstree'      [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/syslogd'     [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/tcpd'        [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/top'         [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/updatedb'    [ Not found ]
[11:01:30]   Checking for file '/dev/tux/backup/vdir'        [ Not found ]
[11:01:30]   Checking for directory '/dev/tux'               [ Not found ]
[11:01:30]   Checking for directory '/dev/tux/ssh2'          [ Not found ]
[11:01:31]   Checking for directory '/dev/tux/backup'        [ Not found ]
[11:01:31] Tuxtendo Rootkit                                  [ Not found ]
[11:01:31]
[11:01:31] Checking for URK Rootkit...
[11:01:31]   Checking for file '/usr/man/man1/xxxxxxbin/find' [ Not found ]
[11:01:31]   Checking for file '/usr/man/man1/xxxxxxbin/du'  [ Not found ]
[11:01:31]   Checking for file '/usr/man/man1/xxxxxxbin/ps'  [ Not found ]
[11:01:31]   Checking for file '/tmp/conf.inf'               [ Not found ]
[11:01:31]   Checking for directory '/usr/man/man1/xxxxxxbin' [ Not found ]
[11:01:31] URK Rootkit                                       [ Not found ]
[11:01:31]
[11:01:31] Checking for VcKit Rootkit...
[11:01:31]   Checking for directory '/usr/include/linux/modules/lib.so' [ Not found ]
[11:01:31]   Checking for directory '/usr/include/linux/modules/lib.so/bin' [ Not found ]
[11:01:31] VcKit Rootkit                                     [ Not found ]
[11:01:31]
[11:01:31] Checking for Volc Rootkit...
[11:01:31]   Checking for directory '/var/spool/.recent'     [ Not found ]
[11:01:31]   Checking for directory '/var/spool/.recent/.files' [ Not found ]
[11:01:31]   Checking for directory '/usr/lib/volc'          [ Not found ]
[11:01:31]   Checking for directory '/usr/lib/volc/backup'   [ Not found ]
[11:01:31] Volc Rootkit                                      [ Not found ]
[11:01:32]
[11:01:32] Checking for X-Org SunOS Rootkit...
[11:01:32]   Checking for file '/usr/lib/libX.a/bin/tmpfl'   [ Not found ]
[11:01:32]   Checking for file '/usr/lib/libX.a/bin/rps'     [ Not found ]
[11:01:32]   Checking for file '/usr/bin/srload'             [ Not found ]
[11:01:32]   Checking for file '/usr/lib/libX.a/bin/sparcv7/rps' [ Not found ]
[11:01:32]   Checking for file '/usr/sbin/modcheck'          [ Not found ]
[11:01:32]   Checking for directory '/usr/lib/libX.a'        [ Not found ]
[11:01:32]   Checking for directory '/usr/lib/libX.a/bin'    [ Not found ]
[11:01:32]   Checking for directory '/usr/lib/libX.a/bin/sparcv7' [ Not found ]
[11:01:32]   Checking for directory '/usr/share/man...'      [ Not found ]
[11:01:32] X-Org SunOS Rootkit                               [ Not found ]
[11:01:32]
[11:01:32] Checking for zaRwT.KiT Rootkit...
[11:01:32]   Checking for file '/dev/rd/s/sendmeil'          [ Not found ]
[11:01:32]   Checking for file '/dev/ttyf'                   [ Not found ]
[11:01:32]   Checking for file '/dev/ttyp'                   [ Not found ]
[11:01:32]   Checking for file '/dev/ttyn'                   [ Not found ]
[11:01:32]   Checking for file '/rk/tulz'                    [ Not found ]
[11:01:32]   Checking for directory '/rk'                    [ Not found ]
[11:01:32]   Checking for directory '/dev/rd/s'              [ Not found ]
[11:01:33] zaRwT.KiT Rootkit                                 [ Not found ]
[11:01:33]
[11:01:33] Performing additional rootkit checks
[11:01:33] Info: Starting test name 'additional_rkts'
[11:01:33]
[11:01:33]   Performing Suckit Rookit additional checks
[11:01:33]     Checking /sbin/init link count                [ OK ]
[11:01:33]     Checking for hidden file extensions           [ None found ]
[11:01:33]     Running skdet command                         [ Skipped ]
[11:01:33] Info: Unable to find the 'skdet' command
[11:01:33]   Suckit Rookit additional checks                 [ OK ]
[11:01:33]
[11:01:33]   Performing check of possible rootkit files and directories
[11:01:33] Info: Starting test name 'possible_rkt_files'
[11:01:33]     Checking for file '/dev/sdr0'                 [ Not found ]
[11:01:33]     Checking for file '/tmp/.syshackfile'         [ Not found ]
[11:01:33]     Checking for file '/tmp/.bash_history'        [ Not found ]
[11:01:33]     Checking for file '/usr/info/.clib'           [ Not found ]
[11:01:33]     Checking for file '/usr/sbin/tcp.log'         [ Not found ]
[11:01:33]     Checking for file '/usr/bin/take/pid'         [ Not found ]
[11:01:34]     Checking for file '/sbin/create'              [ Not found ]
[11:01:34]     Checking for file '/dev/ttypz'                [ Not found ]
[11:01:34]     Checking for directory '/usr/bin/take'        [ Not found ]
[11:01:34]     Checking for directory '/usr/src/.lib'        [ Not found ]
[11:01:34]     Checking for directory '/usr/share/man/man1/.1c' [ Not found ]
[11:01:34]     Checking for directory '/lib/lblip.tk'        [ Not found ]
[11:01:34]     Checking for directory '/usr/sbin/...'        [ Not found ]
[11:01:34]     Checking for directory '/usr/share/.gun'      [ Not found ]
[11:01:34]   Checking for possible rootkit files and directories [ None found ]
[11:01:34]
[11:01:34]   Performing check for possible rootkit strings
[11:01:34] Info: Starting test name 'possible_rkt_strings'
[11:01:34] Info: Found local startup file: /etc/rc.local
[11:01:34]     Checking for string '/dev/proc/fuckit'        [ Not found ]
[11:01:34]     Checking for string 'FUCK'                    [ Not found ]
[11:01:34]     Checking for string 'backdoor'                [ Not found ]
[11:01:34]     Checking for string 'vt200'                   [ Not found ]
[11:01:35]     Checking for string '/usr/bin/xstat'          [ Not found ]
[11:01:35]     Checking for string '/bin/envpc'              [ Not found ]
[11:01:35]     Checking for string 'L4m3r0x'                 [ Not found ]
[11:01:35]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[11:01:35]     Checking for string '/dev/ptyxx/.file'        [ Not found ]
[11:01:35]     Checking for string '/dev/sgk'                [ Not found ]
[11:01:35]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[11:01:35]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[11:01:35]     Checking for string '/dev/proc/fuckit'        [ Not found ]
[11:01:35]     Checking for string '/lib/.sso'               [ Not found ]
[11:01:35]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[11:01:35]     Checking for string '/dev/caca'               [ Not found ]
[11:01:36]     Checking for string '/dev/ttyoa'              [ Not found ]
[11:01:36]     Checking for string 'syg'                     [ Not found ]
[11:01:36]     Checking for string '/dev/pts/01'             [ Not found ]
[11:01:36]     Checking for string 'tw33dl3'                 [ Not found ]
[11:01:36]     Checking for string 'psniff'                  [ Not found ]
[11:01:36]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[11:01:36]     Checking for string 'promiscuous'             [ Not found ]
[11:01:36]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[11:01:36]     Checking for string '/dev/xdta'               [ Not found ]
[11:01:36]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[11:01:36]     Checking for string 'in.inetd'                [ Not found ]
[11:01:37]     Checking for string '#<HIDE_.*>'              [ Not found ]
[11:01:37]     Checking for string 'bin/xchk'                [ Not found ]
[11:01:37]     Checking for string 'bin/xsf'                 [ Not found ]
[11:01:37]   Checking for possible rootkit strings           [ None found ]
[11:01:37]
[11:01:37] Performing malware checks
[11:01:37] Info: Starting test name 'malware'
[11:01:37]
[11:01:37] Info: Test 'deleted_files' disabled at users request.
[11:01:37] Info: Starting test name 'running_procs'
[11:01:37]   Checking running processes for suspicious files [ None found ]
[11:01:37]
[11:01:37] Info: Test 'hidden_procs' disabled at users request.
[11:01:37]
[11:01:37] Info: Test 'suspscan' disabled at users request.
[11:01:38]
[11:01:38]   Performing check for login backdoors
[11:01:38] Info: Starting test name 'other_malware'
[11:01:38]     Checking for '/bin/.login'                    [ Not found ]
[11:01:38]     Checking for '/sbin/.login'                   [ Not found ]
[11:01:38]   Checking for login backdoors                    [ None found ]
[11:01:38]
[11:01:38]   Performing check for suspicious directories
[11:01:38]     Checking for directory '/usr/X11R6/bin/.,/copy' [ Not found ]
[11:01:38]     Checking for directory '/dev/rd/cdb'          [ Not found ]
[11:01:38]   Checking for suspicious directories             [ None found ]
[11:01:38]
[11:01:38]   Checking for software intrusions                [ Skipped ]
[11:01:38] Info: Check skipped - tripwire not installed
[11:01:38]
[11:01:38]   Performing check for sniffer log files
[11:01:38]     Checking for file '/usr/lib/libice.log'       [ Not found ]
[11:01:38]   Checking for sniffer log files                  [ None found ]
[11:01:38]
[11:01:38] Performing trojan specific checks
[11:01:38] Info: Starting test name 'trojans'
[11:01:38] Info: Using inetd configuration file '/etc/inetd.conf'
[11:01:38]   Checking for enabled inetd services             [ OK ]
[11:01:38]
[11:01:38]   Performing check for enabled xinetd services
[11:01:38]   Checking for enabled xinetd services            [ Skipped ]
[11:01:39] Info: Check skipped - file '/etc/xinetd.conf' does not exist.
[11:01:39] Info: Apache backdoor check skipped: Apache modules and configuration directories not found.
[11:01:39]
[11:01:39] Performing Linux specific checks
[11:01:39] Info: Starting test name 'os_specific'
[11:01:39]   Checking kernel module commands                 [ OK ]
[11:01:39] Info: Using modules pathname of '/lib/modules/2.6.27-9-generic'
[11:01:39]   Checking kernel module names                    [ OK ]
[11:06:00]
[11:06:00] Checking the network...
[11:06:00] Info: Starting test name 'network'
[11:06:00] Info: Starting test name 'ports'
[11:06:00]
[11:06:00] Performing check for backdoor ports
[11:06:00]   Checking for UDP port 2001                      [ Not found ]
[11:06:01]   Checking for TCP port 2006                      [ Not found ]
[11:06:01]   Checking for TCP port 2128                      [ Not found ]
[11:06:01]   Checking for TCP port 14856                     [ Not found ]
[11:06:02]   Checking for TCP port 47107                     [ Not found ]
[11:06:02]   Checking for TCP port 60922                     [ Not found ]
[11:06:02]
[11:06:02] Performing checks on the network interfaces
[11:06:02] Info: Starting test name 'promisc'
[11:06:02]   Checking for promiscuous interfaces             [ None found ]
[11:06:02]
[11:06:02] Info: Test 'packet_cap_apps' disabled at users request.
[11:06:04]
[11:06:04] Checking the local host...
[11:06:04] Info: Starting test name 'local_host'
[11:06:04]
[11:06:04] Performing system boot checks
[11:06:04] Info: Starting test name 'startup_files'
[11:06:04]   Checking for local host name                    [ Found ]
[11:06:04] Info: Starting test name 'startup_malware'
[11:06:05] Info: Found local startup file: /etc/rc.local
[11:06:05]   Checking for local startup files                [ Found ]
[11:06:05]   Checking local startup files for malware        [ None found ]
[11:06:05] Info: Found system startup directory: /etc/init.d
[11:06:08]   Checking system startup files for malware       [ None found ]
[11:06:08]
[11:06:08] Performing group and account checks
[11:06:09] Info: Starting test name 'group_accounts'
[11:06:09]   Checking for passwd file                        [ Found ]
[11:06:09] Info: Found password file: /etc/passwd
[11:06:09]   Checking for root equivalent (UID 0) accounts   [ None found ]
[11:06:09] Info: Found shadow file: /etc/shadow
[11:06:09]   Checking for passwordless accounts              [ None found ]
[11:06:09] Info: Starting test name 'passwd_changes'
[11:06:09]   Checking for passwd file changes                [ None found ]
[11:06:09] Info: Starting test name 'group_changes'
[11:06:10]   Checking for group file changes                 [ None found ]
[11:06:10]   Checking root account shell history files       [ None found ]
[11:06:10]
[11:06:10] Performing system configuration file checks
[11:06:10] Info: Starting test name 'system_configs'
[11:06:10]   Checking for SSH configuration file             [ Not found ]
[11:06:10]   Checking for running syslog daemon              [ Found ]
[11:06:10]   Checking for syslog configuration file          [ Found ]
[11:06:11] Info: Found syslog configuration file: /etc/syslog.conf
[11:06:11]   Checking if syslog remote logging is allowed    [ Not allowed ]
[11:06:11]
[11:06:11] Performing filesystem checks
[11:06:11] Info: Starting test name 'filesystem'
[11:06:11] Info: SCAN_MODE_DEV set to 'THOROUGH'
[11:06:18]   Checking /dev for suspicious file types         [ Warning ]
[11:06:18] Warning: Suspicious file types found in /dev:
[11:06:18]          /dev/shm/pulse-shm-2709095802: data
[11:06:19]   Checking for hidden files and directories       [ None found ]
[11:16:54]
[11:16:54] Checking application versions...
[11:16:55] Info: Starting test name 'apps'
[11:16:55] Info: Application 'exim' not found.
[11:16:55]   Checking version of GnuPG                       [ OK ]
[11:16:55] Info: Application 'gpg' version '1.4.9' found.
[11:16:55] Info: Application 'httpd' not found.
[11:16:56] Info: Application 'named' not found.
[11:16:56]   Checking version of OpenSSL                     [ OK ]
[11:16:56] Info: Application 'openssl' version '0.9.8g' found.
[11:16:56] Info: Application 'php' not found.
[11:16:56]   Checking version of Procmail MTA                [ OK ]
[11:16:56] Info: Application 'procmail' version '3.22' found.
[11:16:56] Info: Application 'proftpd' not found.
[11:16:56] Info: Application 'sshd' not found.
[11:16:56] Info: Applications checked: 3 out of 9
[11:16:56]
[11:16:56] System checks summary
[11:16:57] =====================
[11:16:57]
[11:16:57] File properties checks...
[11:16:57] Files checked: 125
[11:16:57] Suspect files: 25
[11:16:57]
[11:16:57] Rootkit checks...
[11:16:57] Rootkits checked : 109
[11:16:57] Possible rootkits: 0
[11:16:57]
[11:16:57] Applications checks...
[11:16:57] Applications checked: 3
[11:16:57] Suspect applications: 0
[11:16:57]
[11:16:57] The system checks took: 19 minutes and 27 seconds
[11:16:58]
[11:16:58] Info: End date is Tue Jan 27 11:16:58 PST 2009



chkrootkit
CODE
ROOTDIR is `/'
Checking `amd'... not found
Checking `basename'... not infected
Checking `biff'... not found
Checking `chfn'... not infected
Checking `chsh'... not infected
Checking `cron'... not infected
Checking `crontab'... not infected
Checking `date'... not infected
Checking `du'... not infected
Checking `dirname'... not infected
Checking `echo'... not infected
Checking `egrep'... not infected
Checking `env'... not infected
Checking `find'... not infected
Checking `fingerd'... not found
Checking `gpm'... not found
Checking `grep'... not infected
Checking `hdparm'... not infected
Checking `su'... not infected
Checking `ifconfig'... not infected
Checking `inetd'... not infected
Checking `inetdconf'... not infected
Checking `identd'... not found
Checking `init'... not infected
Checking `killall'... not infected
Checking `ldsopreload'... not infected
Checking `login'... not infected
Checking `ls'... not infected
Checking `lsof'... not infected
Checking `mail'... not found
Checking `mingetty'... not found
Checking `netstat'... not infected
Checking `named'... not found
Checking `passwd'... not infected
Checking `pidof'... not infected
Checking `pop2'... not found
Checking `pop3'... not found
Checking `ps'... not infected
Checking `pstree'... not infected
Checking `rpcinfo'... not infected
Checking `rlogind'... not found
Checking `rshd'... not found
Checking `slogin'... not infected
Checking `sendmail'... not infected
Checking `sshd'... not found
Checking `syslogd'... not infected
Checking `tar'... not infected
Checking `tcpd'... not infected
Checking `tcpdump'... not infected
Checking `top'... not infected
Checking `telnetd'... not found
Checking `timed'... not found
Checking `traceroute'... not found
Checking `vdir'... not infected
Checking `w'... not infected
Checking `write'... not infected
Checking `aliens'... no suspect files
Searching for sniffer's logs, it may take a while... nothing found
Searching for HiDrootkit's default dir... nothing found
Searching for t0rn's default files and dirs... nothing found
Searching for t0rn's v8 defaults... nothing found
Searching for Lion Worm default files and dirs... nothing found
Searching for RSHA's default files and dir... nothing found
Searching for RH-Sharpe's default files... nothing found
Searching for Ambient's rootkit (ark) default files and dirs... nothing found
Searching for suspicious files and dirs, it may take a while...
/usr/lib/xulrunner-1.9.0.5/.autoreg /usr/lib/firefox-3.0.5/.autoreg /lib/modules/2.6.27-9-generic/volatile/.mounted /lib/init/rw/.ramfs

Searching for LPD Worm files and dirs... nothing found
Searching for Ramen Worm files and dirs... nothing found
Searching for Maniac files and dirs... nothing found
Searching for RK17 files and dirs... nothing found
Searching for Ducoci rootkit... nothing found
Searching for Adore Worm... nothing found
Searching for ShitC Worm... nothing found
Searching for Omega Worm... nothing found
Searching for Sadmind/IIS Worm... nothing found
Searching for MonKit... nothing found
Searching for Showtee... nothing found
Searching for OpticKit... nothing found
Searching for T.R.K... nothing found
Searching for Mithra... nothing found
Searching for LOC rootkit... nothing found
Searching for Romanian rootkit... nothing found
Searching for Suckit rootkit... nothing found
Searching for Volc rootkit... nothing found
Searching for Gold2 rootkit... nothing found
Searching for TC2 Worm default files and dirs... nothing found
Searching for Anonoying rootkit default files and dirs... nothing found
Searching for ZK rootkit default files and dirs... nothing found
Searching for ShKit rootkit default files and dirs... nothing found
Searching for AjaKit rootkit default files and dirs... nothing found
Searching for zaRwT rootkit default files and dirs... nothing found
Searching for Madalin rootkit default files... nothing found
Searching for Fu rootkit default files... nothing found
Searching for ESRK rootkit default files... nothing found
Searching for rootedoor... nothing found
Searching for ENYELKM rootkit default files... nothing found
Searching for common ssh-scanners default files... nothing found
Searching for suspect PHP files... nothing found
Searching for anomalies in shell history files... nothing found
Checking `asp'... not infected
Checking `bindshell'... not infected
Checking `lkm'... chkproc: nothing detected
chkdirs: nothing detected
Checking `rexedcs'... not found
Checking `sniffer'... lo: not promisc and no packet sniffer sockets
eth0: PACKET SNIFFER(/sbin/dhclient3[7341])
Checking `w55808'... not infected
Checking `wted'... chkwtmp: nothing deleted
Checking `scalper'... not infected
Checking `slapper'... not infected
Checking `z2'... user trem deleted or never logged from lastlog!



Also, this is a far better rootkit question than my last post.



#2 rocky

rocky

    I broke 10 posts and all I got was this lousy title!

  • Members
  • 19 posts
  • Location:California

Posted 27 January 2009 - 04:32 PM

I've never used rkhunter but it appears to use a database and then does a comparison of the database against the current state of your system. I wouldn't be too worried about the inode number change. You said that you updated your system? That is most likely the culprit.

#3 duper

duper

    Dangerous free thinker

  • Members
  • 816 posts
  • Location:NYC

Posted 28 January 2009 - 05:45 AM

Isn't it practically impossible to detect rootkits (well, advanced ones, anyway) since they can hijack memory management in kernel space?

Also, it looks like rkhunter uses SHA-1 for hash calculation. Since MD5 has already pretty much officially fallen, I don't expect SHA-1 to last much longer as a widely-accepted hashing algorithm.

#4 Dirk Chestnut

Dirk Chestnut

    SUP3R 31337 P1MP

  • Members
  • 268 posts
  • Location:248

Posted 28 January 2009 - 11:09 PM

Check out the --propupd switch for rkhunter.

Also, check out http://www.manpagez....man/8/rkhunter/ and search for the "propupd" switch.

It looks like checking the physical location (inode)/checksum/modtime of popular binaries is only one facet of what rkhunter does. For individual files (and their inode/checksum/modtime), it would appear the "baseline" for rkhunter is determined by being run on the local system, and generating a database of those stats.

My knowledge of rkhunter isn't 100%, but I can't imagine your distro (or the rkhunter dev team) holds a database of ALL possible values for inode, checksum, or modification time of a particular program. If they did, they'd need to maintain a checksum for all possible supported versions of any given program. It would be nearly impossible to maintain mod times on binaries (this depends largely on your package manager - many do preserve mod timestamps from when the binary was created in the repos). However, it would be COMPLETELY IMPOSSIBLE to store a known baselines for inode usage.

Considering these factors brings me to this conclusion: I think the intended usage of rkhunter, as far as system admin related files are concerned, is that you update only from 100% trusted sources, after which you run the --propupd routine. I haven't the foggiest on what Wubi's package manager is, but my guess is when it is run to update a system, it doesn't automatically run "rkhunter --propupd". Thus, if you see warnings of the type above, they're likely due to updates (which rocky already stated). I suggest running the program with this switch, then running he check again. If you don't see any warnings, I think it'd be a pretty good indicator that this is the case.

If my understanding of rkhunter is correct, than it also looks like a lot of what it does is also basically what tripwire does. That is, it is run to determine a "baseline" for the system, and every time it is run after that, it compares the "current" state with the "baseline". With tripwire, of course, it's common to see a whole slew of warnings as soon as you run an update.

#5 rocky

rocky

    I broke 10 posts and all I got was this lousy title!

  • Members
  • 19 posts
  • Location:California

Posted 28 January 2009 - 11:42 PM

Hi Dirk Chesnut,

Not really knowing much about rkhunter, I actually went and downloaded rkhunter and ran it and it must do some sort of generic profiling which then is compared to the current state of your system, because I got some errors, mostly innocuous ones though. After that it must store information of the last known state, being the last time it was run, into the /var/lib/rkhunter directory in a file called db, which I'm assuming is for database. Now I'm parroting you, however that is what I meant by database in my previous post, a file that contains the profile of your local machine of the last known state which is then compared against the current state when you run rkhunter, which is bound to produce false positives.

Good post by the way.

Edited by rocky, 28 January 2009 - 11:43 PM.


#6 duper

duper

    Dangerous free thinker

  • Members
  • 816 posts
  • Location:NYC

Posted 30 January 2009 - 07:35 PM

It looks like checking the physical location (inode)/checksum/modtime of popular binaries is only one facet of what rkhunter does. For individual files (and their inode/checksum/modtime), it would appear the "baseline" for rkhunter is determined by being run on the local system, and generating a database of those stats.

My knowledge of rkhunter isn't 100%, but I can't imagine your distro (or the rkhunter dev team) holds a database of ALL possible values for inode, checksum, or modification time of a particular program. If they did, they'd need to maintain a checksum for all possible supported versions of any given program. It would be nearly impossible to maintain mod times on binaries (this depends largely on your package manager - many do preserve mod timestamps from when the binary was created in the repos). However, it would be COMPLETELY IMPOSSIBLE to store a known baselines for inode usage.


Yeah, filesystem meta-data is only semi-useful for information assurance. Even if the inodes match, what do they do next? Go through all the blocklists for each individual inode? :) False positives and negatives are the problem with signature-based detection methods. This is why the security industry is moving towards hash trees (to counter polymorphism.)




BinRev is hosted by the great people at Lunarpages!