HOW TO: Linux Command For Checking Rootkit/Detecting Rootkit With Rkhunter
Tuxnoob - In the previous post my discussed about “https://tuxnoob.com/posts/how-to-linux-command-for-checking/”. This time i will explain about checking/detecting rootkits too, with Rkhunter.
Rkhunter (Hunter Rootkit) is common unix/linux tools platform, rkhunter of use for scanning rootkit, backdoor, and local-exploit our machine.
It also performs checks to see if commands have been modified, if the system startup files have been modified, and various checks on the network interfaces, including checks for listening applications.
Install Rkhunter
# For Ubuntu/Debian or Debian-Based
$ sudo apt-get install rkhunter# For Fedora/Redhat or Redhat Based
$ sudo yum install rkhunter# For Arch Linux or Arch-Based
$ sudo pacman -S rkhunter# For Gentoo/Gentoo-Based
$ sudo emerge rkhunter# For Slackware Linux/Slackware-Based
*Available on SBo
== With third-party ==
$ sudo sbopkg -b rkhunter (with sbopkg)
Run Rkhunter
# For use check various of system on local system
rkhunter –check
# For update new version
rkhunter –update
Here This Screenshot
Rkhunter also saved his result to log
cat /var/log/rkhunter.log
And this log result rkhunter :
[23:38:48] Checking for file ‘/lib/defs/q’ [ Not found ]
[23:38:48] Checking for file ‘/lib/defs/r’ [ Not found ]
[23:38:48] Checking for file ‘/lib/defs/s’ [ Not found ]
[23:38:48] Checking for file ‘/lib/defs/t’ [ Not found ]
[23:38:48] Checking for file ‘/usr/lib/defs/p’ [ Not found ]
[23:38:48] Checking for file ‘/usr/lib/defs/q’ [ Not found ]
[23:38:48] Checking for file ‘/usr/lib/defs/r’ [ Not found ]
[23:38:48] Checking for file ‘/usr/lib/defs/s’ [ Not found ]
[23:38:48] Checking for file ‘/usr/lib/defs/t’ [ Not found ]
[23:38:48] Checking for file ‘/usr/lib/.libigno/pkunsec’ [ Not found ]
[23:38:48] Checking for file ‘/usr/lib/.libigno/.igno/psybnc/psybnc’ [ Not found ]
[23:38:48] Checking for directory ‘/usr/lib/.libigno’ [ Not found ]
[23:38:48] Checking for directory ‘/usr/lib/.libigno/.igno’ [ Not found ]
[23:38:48] ignoKit Rootkit [ Not found ]
[23:38:48]
[23:38:48] Checking for IntoXonia-NG Rootkit…
[23:38:48] Checking for kernel symbol ‘funces’ [ Not found ]
[23:38:49] Checking for kernel symbol ‘ixinit’ [ Not found ]
[23:38:49] Checking for kernel symbol ‘tricks’ [ Not found ]
[23:38:49] Checking for kernel symbol ‘kernel_unlink’ [ Not found ]
[23:38:49] Checking for kernel symbol ‘rootme’ [ Not found ]
[23:38:49] Checking for kernel symbol ‘hide_module’ [ Not found ]
[23:38:49] Checking for kernel symbol ‘find_sys_call_tbl’ [ Not found ]
[23:38:49] IntoXonia-NG Rootkit [ Not found ]
[23:38:49]
[23:38:49] Checking for Irix Rootkit…
[23:38:49] Checking for directory ‘/dev/pts/01’ [ Not found ]
[23:38:49] Checking for directory ‘/dev/pts/01/backup’ [ Not found ]
[23:38:49] Checking for directory ‘/dev/pts/01/etc’ [ Not found ]
[23:38:49] Checking for directory ‘/dev/pts/01/tmp’ [ Not found ]
[23:38:49] Irix Rootkit [ Not found ]
[23:38:49]
[23:38:49] Checking for Jynx Rootkit…
[23:38:49] Checking for file ‘/xochikit/bc’ [ Not found ]
[23:38:49] Checking for file ‘/xochikit/ld_poison.so’ [ Not found ]
[23:38:49] Checking for file ‘/omgxochi/bc’ [ Not found ]
[23:38:49] Checking for file ‘/omgxochi/ld_poison.so’ [ Not found ]
[23:38:49] Checking for file ‘/var/local/^^/bc’ [ Not found ]
[23:38:49] Checking for file ‘/var/local/^^/ld_poison.so’ [ Not found ]
[23:38:49] Checking for directory ‘/xochikit’ [ Not found ]
[23:38:49] Checking for directory ‘/omgxochi’ [ Not found ]
[23:38:49] Checking for directory ‘/var/local/^^’ [ Not found ]
[23:38:50] Jynx Rootkit [ Not found ]
[23:38:50]
[23:38:50] Checking for KBeast Rootkit…
[23:38:50] Checking for file ‘/usr/h4x/ipsecs-kbeast-v1.ko’ [ Not found ]
[23:38:50] Checking for file ‘/usr/h4x/h4x_bd’ [ Not found ]
[23:38:50] Checking for file ‘/usr/_h4x/acctlog’ [ Not found ]
[23:38:50] Checking for directory ‘/usr/h4x‘ [ Not found ]
[23:38:50] Checking for kernel symbol ‘h4x_delete_module’ [ Not found ]
[23:38:50] Checking for kernel symbol ‘h4x_getdents64’ [ Not found ]
[23:38:50] Checking for kernel symbol ‘h4x_kill’ [ Not found ]
[23:38:50] Checking for kernel symbol ‘h4x_open’ [ Not found ]
[23:38:50] Checking for kernel symbol ‘h4x_read’ [ Not found ]
[23:38:50] Checking for kernel symbol ‘h4x_rename’ [ Not found ]
[23:38:50] Checking for kernel symbol ‘h4x_rmdir’ [ Not found ]
[23:38:50] Checking for kernel symbol ‘h4x_tcp4seq_show’ [ Not found ]
[23:38:50] Checking for kernel symbol ‘h4x_write’ [ Not found ]
[23:38:50] KBeast Rootkit [ Not found ]
[23:38:50]
[23:38:50] Checking for Kitko Rootkit…
[23:38:50] Checking for directory ‘/usr/src/redhat/SRPMS/…’ [ Not found ]
[23:38:50] Kitko Rootkit [ Not found ]
[23:38:50]
[23:38:50] Checking for Knark Rootkit…
[23:38:50] Checking for file ‘/proc/knark/pids’ [ Not found ]
[23:38:50] Checking for directory ‘/proc/knark’ [ Not found ]
[23:38:51] Knark Rootkit [ Not found ]
[23:38:51]
[23:38:51] Checking for ld-linuxv.so Rootkit…
[23:38:51] Checking for file ‘/lib/ld-linuxv.so.1’ [ Not found ]
[23:38:51] Checking for directory ‘/var/opt/_so_cache’ [ Not found ]
[23:38:51] Checking for directory ‘/var/opt/_so_cache/ld’ [ Not found ]
[23:38:51] Checking for directory ‘/var/opt/_so_cache/lc’ [ Not found ]
[23:38:51] ld-linuxv.so Rootkit [ Not found ]
[23:38:51]
[23:38:51] Checking for Li0n Worm…
[23:38:51] Checking for file ‘/bin/in.telnetd’ [ Not found ]
[23:38:51] Checking for file ‘/bin/mjy’ [ Not found ]
[23:38:54] Checking for file ‘/usr/man/man1/man1/lib/.lib/mjy’ [ Not found ]
[23:38:54] Checking for file ‘/usr/man/man1/man1/lib/.lib/in.telnetd’ [ Not found ]
[23:38:54] Checking for file ‘/usr/man/man1/man1/lib/.lib/.x’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/scan/1i0n.sh’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/scan/hack.sh’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/scan/bind’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/scan/randb’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/scan/scan.sh’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/scan/pscan’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/scan/star.sh’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/scan/bindx.sh’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/scan/bindname.log’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/1i0n.sh’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/lib/netstat’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/lib/dev/.1addr’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/lib/dev/.1logz’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/lib/dev/.1proc’ [ Not found ]
[23:38:54] Checking for file ‘/dev/.lib/lib/lib/dev/.1file’ [ Not found ]
[23:38:54] Li0n Worm [ Not found ]
[23:38:54]
[23:38:54] Checking for Lockit / LJK2 Rootkit…
[23:38:54] Checking for file ‘/usr/lib/libmen.oo/.LJK2/ssh_config’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/ssh_host_key’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/ssh_random_seed*’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/sshd_config’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/du’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/ifconfig’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/inetd.conf’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/locate’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/login’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/ls’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/netstat’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/ps’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/pstree’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/syslogd’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/tcpd’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/top’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/clean/RK1sauber’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/clean/RK1wted’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hack/RK1parse’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hack/RK1sniff’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hide/.RK1addr’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hide/.RK1dir’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hide/.RK1log’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hide/.RK1proc’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/modules/README.modules’ [ Not found ]
[23:38:55] Checking for file ‘/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c’ [ Not found ]
[23:38:56] Checking for file ‘/usr/lib/libmen.oo/.LJK2/modules/RK1phide’ [ Not found ]
[23:38:56] Checking for file ‘/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh’ [ Not found ]
[23:38:56] Checking for directory ‘/usr/lib/libmen.oo/.LJK2’ [ Not found ]
[23:38:56] Lockit / LJK2 Rootkit [ Not found ]
[23:38:56]
[23:38:56] Checking for Mood-NT Rootkit…
[23:38:56] Checking for file ‘/sbin/init__mood-nt--cthulhu’ [ Not found ]
[23:38:56] Checking for file ‘/_cthulhu/mood-nt.init’ [ Not found ]
[23:38:56] Checking for file ‘/_cthulhu/mood-nt.conf’ [ Not found ]
[23:38:56] Checking for file ‘/_cthulhu/mood-nt.sniff’ [ Not found ]
[23:38:56] Checking for directory ‘/_cthulhu’ [ Not found ]
[23:38:57] Mood-NT Rootkit [ Not found ]
[23:38:57]
[23:38:57] Checking for MRK Rootkit…
[23:38:57] Checking for file ‘/dev/ida/.inet/pid’ [ Not found ]
[23:38:57] Checking for file ‘/dev/ida/.inet/ssh_host_key’ [ Not found ]
[23:38:57] Checking for file ‘/dev/ida/.inet/ssh_random_seed’ [ Not found ]
[23:38:57] Checking for file ‘/dev/ida/.inet/tcp.log’ [ Not found ]
[23:38:57] Checking for directory ‘/dev/ida/.inet’ [ Not found ]
[23:38:57] Checking for directory ‘/var/spool/cron/.sh’ [ Not found ]
[23:38:57] MRK Rootkit [ Not found ]
[23:38:57]
[23:38:57] Checking for Ni0 Rootkit…
[23:38:57] Checking for file ‘/var/lock/subsys/…datafile…/…net…’ [ Not found ]
[23:38:57] Checking for file ‘/var/lock/subsys/…datafile…/…port…’ [ Not found ]
[23:38:57] Checking for file ‘/var/lock/subsys/…datafile…/…ps…’ [ Not found ]
[23:38:57] Checking for file ‘/var/lock/subsys/…datafile…/…file…’ [ Not found ]
[23:38:57] Checking for directory ‘/tmp/waza’ [ Not found ]
[23:38:57] Checking for directory ‘/var/lock/subsys/…datafile…’ [ Not found ]
[23:38:57] Checking for directory ‘/usr/sbin/es’ [ Not found ]
[23:38:57] Ni0 Rootkit [ Not found ]
[23:38:57]
[23:38:57] Checking for Ohhara Rootkit…
[23:38:57] Checking for file ‘/var/lock/subsys/…datafile…/…datafile…/in.smbd.log’ [ Not found ]
[23:38:57] Checking for directory ‘/var/lock/subsys/…datafile…’ [ Not found ]
[23:38:57] Checking for directory ‘/var/lock/subsys/…datafile…/…datafile…’ [ Not found ]
[23:38:57] Checking for directory ‘/var/lock/subsys/…datafile…/…datafile…/bin’ [ Not found ]
[23:38:57] Checking for directory ‘/var/lock/subsys/…datafile…/…datafile…/usr/bin’ [ Not found ]
[23:38:57] Checking for directory ‘/var/lock/subsys/…datafile…/…datafile…/usr/sbin’ [ Not found ]
[23:38:57] Checking for directory ‘/var/lock/subsys/…datafile…/…datafile…/lib/security’ [ Not found ]
[23:38:57] Ohhara Rootkit [ Not found ]
[23:38:57]
[23:38:57] Checking for Optic Kit (Tux) Worm…
[23:38:57] Checking for directory ‘/dev/tux’ [ Not found ]
[23:38:57] Checking for directory ‘/usr/bin/xchk’ [ Not found ]
[23:38:58] Checking for directory ‘/usr/bin/xsf’ [ Not found ]
[23:38:58] Checking for directory ‘/usr/bin/ssh2d’ [ Not found ]
[23:38:58] Optic Kit (Tux) Worm [ Not found ]
[23:38:58]
[23:38:58] Checking for Oz Rootkit…
[23:38:58] Checking for file ‘/dev/.oz/.nap/rkit/terror’ [ Not found ]
[23:38:58] Checking for directory ‘/dev/.oz’ [ Not found ]
[23:38:58] Oz Rootkit [ Not found ]
[23:38:58]
[23:38:58] Checking for Phalanx Rootkit…
[23:38:58] Checking for file ‘/uNFuNF’ [ Not found ]
[23:38:58] Checking for file ‘/etc/host.ph1’ [ Not found ]
[23:38:58] Checking for file ‘/bin/host.ph1’ [ Not found ]
[23:38:58] Checking for file ‘/usr/share/.home.ph1/phalanx’ [ Not found ]
[23:38:58] Checking for file ‘/usr/share/.home.ph1/cb’ [ Not found ]
[23:38:58] Checking for file ‘/usr/share/.home.ph1/kebab’ [ Not found ]
[23:38:58] Checking for directory ‘/usr/share/.home.ph1’ [ Not found ]
[23:38:58] Checking for directory ‘/usr/share/.home.ph1/tty’ [ Not found ]
[23:38:58] Phalanx Rootkit [ Not found ]
[23:38:58]
[23:38:58] Checking for Phalanx2 Rootkit…
[23:38:58] Checking for file ‘/etc/khubd.p2/.p2rc’ [ Not found ]
[23:38:58] Checking for file ‘/etc/khubd.p2/.phalanx2’ [ Not found ]
[23:38:58] Checking for file ‘/etc/khubd.p2/.sniff’ [ Not found ]
[23:38:58] Checking for file ‘/etc/khubd.p2/sshgrab.py’ [ Not found ]
[23:38:58] Checking for file ‘/etc/lolzz.p2/.p2rc’ [ Not found ]
[23:38:58] Checking for file ‘/etc/lolzz.p2/.phalanx2’ [ Not found ]
[23:38:58] Checking for file ‘/etc/lolzz.p2/.sniff’ [ Not found ]
[23:38:58] Checking for file ‘/etc/lolzz.p2/sshgrab.py’ [ Not found ]
[23:38:58] Checking for file ‘/etc/cron.d/zupzzplaceholder’ [ Not found ]
[23:38:58] Checking for file ‘/usr/lib/zupzz.p2/.p-2.3d’ [ Not found ]
[23:38:58] Checking for file ‘/usr/lib/zupzz.p2/.p2rc’ [ Not found ]
[23:38:59] Checking for directory ‘/etc/khubd.p2’ [ Not found ]
[23:38:59] Checking for directory ‘/etc/lolzz.p2’ [ Not found ]
[23:38:59] Checking for directory ‘/usr/lib/zupzz.p2’ [ Not found ]
[23:38:59] Phalanx2 Rootkit [ Not found ]
[23:38:59]
[23:38:59] Checking for Phalanx2 Rootkit (extended tests)…
[23:38:59] Checking for directory ‘/etc/khubd.p2’ [ Not found ]
[23:38:59] Checking for directory ‘/etc/lolzz.p2’ [ Not found ]
[23:38:59] Checking for directory ‘/usr/lib/zupzz.p2’ [ Not found ]
[23:38:59] Phalanx2 Rootkit (extended tests) [ Not found ]
[23:38:59]
[23:38:59] Checking for Portacelo Rootkit…
[23:38:59] Checking for file ‘/var/lib/…/.ak’ [ Not found ]
[23:38:59] Checking for file ‘/var/lib/…/.hk’ [ Not found ]
[23:38:59] Checking for file ‘/var/lib/…/.rs’ [ Not found ]
[23:38:59] Checking for file ‘/var/lib/…/.p’ [ Not found ]
[23:38:59] Checking for file ‘/var/lib/…/getty’ [ Not found ]
[23:38:59] Checking for file ‘/var/lib/…/lkt.o’ [ Not found ]
[23:38:59] Checking for file ‘/var/lib/…/show’ [ Not found ]
[23:38:59] Checking for file ‘/var/lib/…/nlkt.o’ [ Not found ]
[23:38:59] Checking for file ‘/var/lib/…/ssshrc’ [ Not found ]
[23:38:59] Checking for file ‘/var/lib/…/sssh_equiv’ [ Not found ]
[23:38:59] Checking for file ‘/var/lib/…/sssh_known_hosts’ [ Not found ]
[23:38:59] Checking for file ‘/var/lib/…/sssh_pid’ [ Not found ]
[23:38:59] Checking for file ‘~/.sssh/known_hosts’ [ Not found ]
[23:38:59] Portacelo Rootkit [ Not found ]
[23:38:59]
[23:38:59] Checking for R3dstorm Toolkit…
[23:38:59] Checking for file ‘/var/log/tk02/see_all’ [ Not found ]
[23:38:59] Checking for file ‘/var/log/tk02/.scris’ [ Not found ]
[23:38:59] Checking for file ‘/bin/…/sshd/sbin/sshd1’ [ Not found ]
[23:38:59] Checking for file ‘/bin/…/hate/sk’ [ Not found ]
[23:38:59] Checking for file ‘/bin/…/see_all’ [ Not found ]
[23:39:00] Checking for directory ‘/var/log/tk02’ [ Not found ]
[23:39:00] Checking for directory ‘/var/log/tk02/old’ [ Not found ]
[23:39:00] Checking for directory ‘/bin/…‘ [ Not found ]
[23:39:00] R3dstorm Toolkit [ Not found ]
[23:39:00]
[23:39:00] Checking for RH-Sharpe’s Rootkit…
[23:39:00] Checking for file ‘/bin/lps’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/lpstree’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/ltop’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/lkillall’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/ldu’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/lnetstat’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/wp’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/shad’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/vadim’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/slice’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/cleaner’ [ Not found ]
[23:39:00] Checking for file ‘/usr/include/rpcsvc/du’ [ Not found ]
[23:39:00] RH-Sharpe’s Rootkit [ Not found ]
[23:39:00]
[23:39:00] Checking for RSHA’s Rootkit…
[23:39:00] Checking for file ‘/bin/kr4p’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/n3tstat’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/chsh2’ [ Not found ]
[23:39:00] Checking for file ‘/usr/bin/slice2’ [ Not found ]
[23:39:00] Checking for file ‘/usr/src/linux/arch/alpha/lib/.lib/.1proc’ [ Not found ]
[23:39:00] Checking for file ‘/etc/rc.d/arch/alpha/lib/.lib/.1addr’ [ Not found ]
[23:39:00] Checking for directory ‘/etc/rc.d/rsha’ [ Not found ]
[23:39:00] Checking for directory ‘/etc/rc.d/arch/alpha/lib/.lib’ [ Not found ]
[23:39:00] RSHA’s Rootkit [ Not found ]
[23:39:00]
[23:39:00] Checking for Scalper Worm…
[23:39:01] Checking for file ‘/tmp/.a’ [ Not found ]
[23:39:01] Checking for file ‘/tmp/.uua’ [ Not found ]
[23:39:01] Scalper Worm [ Not found ]
[23:39:01]
[23:39:01] Checking for Sebek LKM…
[23:39:01] Checking for kernel symbol ‘adore or sebek’ [ Not found ]
[23:39:01] Sebek LKM [ Not found ]
[23:39:01]
[23:39:01] Checking for Shutdown Rootkit…
[23:39:01] Checking for file ‘/usr/man/man5/..<SP>/.dir/scannah/asus’ [ Not found ]
[23:39:01] Checking for file ‘/usr/man/man5/..<SP>/.dir/see’ [ Not found ]
[23:39:01] Checking for file ‘/usr/man/man5/..<SP>/.dir/nscd’ [ Not found ]
[23:39:01] Checking for file ‘/usr/man/man5/..<SP>/.dir/alpd’ [ Not found ]
[23:39:01] Checking for file ‘/etc/rc.d/rc.local<SP>‘ [ Not found ]
[23:39:01] Checking for directory ‘/usr/man/man5/..<SP>/.dir’ [ Not found ]
[23:39:01] Checking for directory ‘/usr/man/man5/..<SP>/.dir/scannah’ [ Not found ]
[23:39:01] Checking for directory ‘/etc/rc.d/rc0.d/..<SP>/.dir’ [ Not found ]
[23:39:01] Shutdown Rootkit [ Not found ]
[23:39:01]
[23:39:01] Checking for SHV4 Rootkit…
[23:39:01] Checking for file ‘/etc/ld.so.hash’ [ Not found ]
[23:39:01] Checking for file ‘/lib/libext-2.so.7’ [ Not found ]
[23:39:01] Checking for file ‘/lib/lidps1.so’ [ Not found ]
[23:39:01] Checking for file ‘/lib/libproc.a’ [ Not found ]
[23:39:01] Checking for file ‘/lib/libproc.so.2.0.6’ [ Not found ]
[23:39:01] Checking for file ‘/lib/ldd.so/tks’ [ Not found ]
[23:39:01] Checking for file ‘/lib/ldd.so/tkp’ [ Not found ]
[23:39:01] Checking for file ‘/lib/ldd.so/tksb’ [ Not found ]
[23:39:01] Checking for file ‘/lib/security/.config/sshd’ [ Not found ]
[23:39:02] Checking for file ‘/lib/security/.config/ssh/ssh_host_key’ [ Not found ]
[23:39:02] Checking for file ‘/lib/security/.config/ssh/ssh_host_key.pub’ [ Not found ]
[23:39:02] Checking for file ‘/lib/security/.config/ssh/ssh_random_seed’ [ Not found ]
[23:39:02] Checking for file ‘/usr/include/file.h’ [ Not found ]
[23:39:02] Checking for file ‘/usr/include/hosts.h’ [ Not found ]
[23:39:02] Checking for file ‘/usr/include/lidps1.so’ [ Not found ]
[23:39:02] Checking for file ‘/usr/include/log.h’ [ Not found ]
[23:39:02] Checking for file ‘/usr/include/proc.h’ [ Not found ]
[23:39:02] Checking for file ‘/usr/sbin/xntps’ [ Not found ]
[23:39:02] Checking for file ‘/dev/srd0’ [ Not found ]
[23:39:02] Checking for directory ‘/lib/ldd.so’ [ Not found ]
[23:39:02] Checking for directory ‘/lib/security/.config’ [ Not found ]
[23:39:02] Checking for directory ‘/lib/security/.config/ssh’ [ Not found ]
[23:39:02] SHV4 Rootkit [ Not found ]
[23:39:02]
[23:39:02] Checking for SHV5 Rootkit…
[23:39:02] Checking for file ‘/etc/sh.conf’ [ Not found ]
[23:39:02] Checking for file ‘/lib/libproc.a’ [ Not found ]
[23:39:02] Checking for file ‘/lib/libproc.so.2.0.6’ [ Not found ]
[23:39:02] Checking for file ‘/lib/lidps1.so’ [ Not found ]
[23:39:02] Checking for file ‘/lib/libsh.so/bash’ [ Not found ]
[23:39:02] Checking for file ‘/usr/include/file.h’ [ Not found ]
[23:39:02] Checking for file ‘/usr/include/hosts.h’ [ Not found ]
[23:39:02] Checking for file ‘/usr/include/log.h’ [ Not found ]
[23:39:02] Checking for file ‘/usr/include/proc.h’ [ Not found ]
[23:39:02] Checking for file ‘/lib/libsh.so/shdcf2’ [ Not found ]
[23:39:02] Checking for file ‘/lib/libsh.so/shhk’ [ Not found ]
[23:39:02] Checking for file ‘/lib/libsh.so/shhk.pub’ [ Not found ]
[23:39:02] Checking for file ‘/lib/libsh.so/shrs’ [ Not found ]
[23:39:03] Checking for file ‘/usr/lib/libsh/.bashrc’ [ Not found ]
[23:39:03] Checking for file ‘/usr/lib/libsh/shsb’ [ Not found ]
[23:39:03] Checking for file ‘/usr/lib/libsh/hide’ [ Not found ]
[23:39:03] Checking for file ‘/usr/lib/libsh/.sniff/shsniff’ [ Not found ]
[23:39:03] Checking for file ‘/usr/lib/libsh/.sniff/shp’ [ Not found ]
[23:39:03] Checking for file ‘/dev/srd0’ [ Not found ]
[23:39:03] Checking for directory ‘/lib/libsh.so’ [ Not found ]
[23:39:03] Checking for directory ‘/usr/lib/libsh’ [ Not found ]
[23:39:03] Checking for directory ‘/usr/lib/libsh/utilz’ [ Not found ]
[23:39:03] Checking for directory ‘/usr/lib/libsh/.backup’ [ Not found ]
[23:39:03] SHV5 Rootkit [ Not found ]
[23:39:03]
[23:39:03] Checking for Sin Rootkit…
[23:39:03] Checking for file ‘/dev/.haos/haos1/.f/Denyed’ [ Not found ]
[23:39:03] Checking for file ‘/dev/ttyoa’ [ Not found ]
[23:39:03] Checking for file ‘/dev/ttyof’ [ Not found ]
[23:39:03] Checking for file ‘/dev/ttyop’ [ Not found ]
[23:39:03] Checking for file ‘/dev/ttyos’ [ Not found ]
[23:39:03] Checking for file ‘/usr/lib/.lib’ [ Not found ]
[23:39:03] Checking for file ‘/usr/lib/sn/.X’ [ Not found ]
[23:39:03] Checking for file ‘/usr/lib/sn/.sys’ [ Not found ]
[23:39:03] Checking for file ‘/usr/lib/ld/.X’ [ Not found ]
[23:39:03] Checking for file ‘/usr/man/man1/…‘ [ Not found ]
[23:39:03] Checking for file ‘/usr/man/man1/…/.m’ [ Not found ]
[23:39:03] Checking for file ‘/usr/man/man1/…/.w’ [ Not found ]
[23:39:03] Checking for directory ‘/usr/lib/sn’ [ Not found ]
[23:39:03] Checking for directory ‘/usr/lib/man1/…‘ [ Not found ]
[23:39:03] Checking for directory ‘/dev/.haos’ [ Not found ]
[23:39:03] Sin Rootkit [ Not found ]
[23:39:04]
[23:39:04] Checking for Slapper Worm…
[23:39:04] Checking for file ‘/tmp/.bugtraq’ [ Not found ]
[23:39:04] Checking for file ‘/tmp/.uubugtraq’ [ Not found ]
[23:39:04] Checking for file ‘/tmp/.bugtraq.c’ [ Not found ]
[23:39:04] Checking for file ‘/tmp/httpd’ [ Not found ]
[23:39:04] Checking for file ‘/tmp/.unlock’ [ Not found ]
[23:39:04] Checking for file ‘/tmp/update’ [ Not found ]
[23:39:04] Checking for file ‘/tmp/.cinik’ [ Not found ]
[23:39:04] Checking for file ‘/tmp/.b’ [ Not found ]
[23:39:04] Slapper Worm [ Not found ]
[23:39:04]
[23:39:04] Checking for Sneakin Rootkit…
[23:39:04] Checking for directory ‘/tmp/.X11-unix/…/rk’ [ Not found ]
[23:39:04] Sneakin Rootkit [ Not found ]
[23:39:04]
[23:39:04] Checking for ‘Spanish’ Rootkit…
[23:39:04] Checking for file ‘/dev/ptyq’ [ Not found ]
[23:39:04] Checking for file ‘/bin/ad’ [ Not found ]
[23:39:04] Checking for file ‘/bin/ava’ [ Not found ]
[23:39:04] Checking for file ‘/bin/server’ [ Not found ]
[23:39:04] Checking for file ‘/usr/sbin/rescue’ [ Not found ]
[23:39:04] Checking for file ‘/usr/share/…/chrps’ [ Not found ]
[23:39:04] Checking for file ‘/usr/share/…/chrifconfig’ [ Not found ]
[23:39:04] Checking for file ‘/usr/share/…/netstat’ [ Not found ]
[23:39:04] Checking for file ‘/usr/share/…/linsniffer’ [ Not found ]
[23:39:04] Checking for file ‘/usr/share/…/charbd’ [ Not found ]
[23:39:04] Checking for file ‘/usr/share/…/charbd2’ [ Not found ]
[23:39:04] Checking for file ‘/usr/share/…/charbd3’ [ Not found ]
[23:39:04] Checking for file ‘/usr/share/…/charbd4’ [ Not found ]
[23:39:04] Checking for file ‘/usr/man/tmp/update.tgz’ [ Not found ]
[23:39:05] Checking for file ‘/var/lib/rpm/db.rpm’ [ Not found ]
[23:39:05] Checking for file ‘/var/cache/man/.cat’ [ Not found ]
[23:39:05] Checking for file ‘/var/spool/lpd/remote/.lpq’ [ Not found ]
[23:39:05] Checking for directory ‘/usr/share/…‘ [ Not found ]
[23:39:05] ‘Spanish’ Rootkit [ Not found ]
[23:39:05]
[23:39:05] Checking for Suckit Rootkit…
[23:39:05] Checking for file ‘/sbin/initsk12’ [ Not found ]
[23:39:05] Checking for file ‘/sbin/initxrk’ [ Not found ]
[23:39:05] Checking for file ‘/usr/bin/null’ [ Not found ]
[23:39:05] Checking for file ‘/usr/share/locale/sk/.sk12/sk’ [ Not found ]
[23:39:05] Checking for file ‘/etc/rc.d/rc0.d/S23kmdac’ [ Not found ]
[23:39:05] Checking for file ‘/etc/rc.d/rc1.d/S23kmdac’ [ Not found ]
[23:39:05] Checking for file ‘/etc/rc.d/rc2.d/S23kmdac’ [ Not found ]
[23:39:08] Checking for file ‘/etc/rc.d/rc3.d/S23kmdac’ [ Not found ]
[23:39:08] Checking for file ‘/etc/rc.d/rc4.d/S23kmdac’ [ Not found ]
[23:39:08] Checking for file ‘/etc/rc.d/rc5.d/S23kmdac’ [ Not found ]
[23:39:08] Checking for file ‘/etc/rc.d/rc6.d/S23kmdac’ [ Not found ]
[23:39:08] Checking for directory ‘/dev/sdhu0/tehdrakg’ [ Not found ]
[23:39:08] Checking for directory ‘/etc/.MG’ [ Not found ]
[23:39:08] Checking for directory ‘/usr/share/locale/sk/.sk12’ [ Not found ]
[23:39:08] Checking for directory ‘/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist’ [ Not found ]
[23:39:08] Suckit Rootkit [ Not found ]
[23:39:08]
[23:39:08] Checking for Superkit Rootkit…
[23:39:08] Checking for file ‘/usr/man/.sman/sk/backsh’ [ Not found ]
[23:39:08] Checking for file ‘/usr/man/.sman/sk/izbtrag’ [ Not found ]
[23:39:08] Checking for file ‘/usr/man/.sman/sk/sksniff’ [ Not found ]
[23:39:10] Checking for file ‘/var/www/cgi-bin/cgiback.cgi’ [ Not found ]
[23:39:10] Checking for directory ‘/usr/man/.sman/sk’ [ Not found ]
[23:39:10] Superkit Rootkit [ Not found ]
[23:39:10]
[23:39:10] Checking for TBD (Telnet BackDoor)…
[23:39:10] Checking for file ‘/usr/lib/.tbd’ [ Not found ]
[23:39:10] TBD (Telnet BackDoor) [ Not found ]
[23:39:10]
[23:39:10] Checking for TeLeKiT Rootkit…
[23:39:10] Checking for file ‘/usr/man/man3/…/TeLeKiT/bin/sniff’ [ Not found ]
[23:39:10] Checking for file ‘/usr/man/man3/…/TeLeKiT/bin/telnetd’ [ Not found ]
[23:39:11] Checking for file ‘/usr/man/man3/…/TeLeKiT/bin/teleulo’ [ Not found ]
[23:39:11] Checking for file ‘/usr/man/man3/…/cl’ [ Not found ]
[23:39:11] Checking for file ‘/dev/ptyr’ [ Not found ]
[23:39:11] Checking for file ‘/dev/ptyp’ [ Not found ]
[23:39:11] Checking for file ‘/dev/ptyq’ [ Not found ]
[23:39:11] Checking for file ‘/dev/hda06’ [ Not found ]
[23:39:11] Checking for file ‘/usr/info/libc1.so’ [ Not found ]
[23:39:11] Checking for directory ‘/usr/man/man3/…‘ [ Not found ]
[23:39:11] Checking for directory ‘/usr/man/man3/…/lsniff’ [ Not found ]
[23:39:11] Checking for directory ‘/usr/man/man3/…/TeLeKiT’ [ Not found ]
[23:39:11] TeLeKiT Rootkit [ Not found ]
[23:39:11]
[23:39:11] Checking for T0rn Rootkit…
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/t0rns’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/du’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/ls’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/t0rnsb’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/ps’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/t0rnp’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/find’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/ifconfig’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/pg’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/ssh.tgz’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/top’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/sz’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/login’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/in.fingerd’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/1i0n.sh’ [ Not found ]
[23:39:11] Checking for file ‘/dev/.lib/lib/lib/pstree’ [ Not found ]
[23:39:12] Checking for file ‘/dev/.lib/lib/lib/in.telnetd’ [ Not found ]
[23:39:12] Checking for file ‘/dev/.lib/lib/lib/mjy’ [ Not found ]
[23:39:12] Checking for file ‘/dev/.lib/lib/lib/sush’ [ Not found ]
[23:39:12] Checking for file ‘/dev/.lib/lib/lib/tfn’ [ Not found ]
[23:39:12] Checking for file ‘/dev/.lib/lib/lib/name’ [ Not found ]
[23:39:12] Checking for file ‘/dev/.lib/lib/lib/getip.sh’ [ Not found ]
[23:39:12] Checking for file ‘/usr/info/.torn/sh*‘ [ Not found ]
[23:39:12] Checking for file ‘/usr/src/.puta/.1addr’ [ Not found ]
[23:39:12] Checking for file ‘/usr/src/.puta/.1file’ [ Not found ]
[23:39:12] Checking for file ‘/usr/src/.puta/.1proc’ [ Not found ]
[23:39:12] Checking for file ‘/usr/src/.puta/.1logz’ [ Not found ]
[23:39:12] Checking for file ‘/usr/info/.t0rn’ [ Not found ]
[23:39:12] Checking for directory ‘/dev/.lib’ [ Not found ]
[23:39:12] Checking for directory ‘/dev/.lib/lib’ [ Not found ]
[23:39:12] Checking for directory ‘/dev/.lib/lib/lib’ [ Not found ]
[23:39:12] Checking for directory ‘/dev/.lib/lib/lib/dev’ [ Not found ]
[23:39:12] Checking for directory ‘/dev/.lib/lib/scan’ [ Not found ]
[23:39:12] Checking for directory ‘/usr/src/.puta’ [ Not found ]
[23:39:12] Checking for directory ‘/usr/man/man1/man1’ [ Not found ]
[23:39:12] Checking for directory ‘/usr/man/man1/man1/lib’ [ Not found ]
[23:39:12] Checking for directory ‘/usr/man/man1/man1/lib/.lib’ [ Not found ]
[23:39:12] Checking for directory ‘/usr/man/man1/man1/lib/.lib/.backup’ [ Not found ]
[23:39:12] T0rn Rootkit [ Not found ]
[23:39:12]
[23:39:12] Checking for trNkit Rootkit…
[23:39:12] Checking for file ‘/usr/lib/libbins.la’ [ Not found ]
[23:39:12] Checking for file ‘/usr/lib/libtcs.so’ [ Not found ]
[23:39:12] Checking for file ‘/dev/.ttpy/ulogin.sh’ [ Not found ]
[23:39:12] Checking for file ‘/dev/.ttpy/tcpshell.sh’ [ Not found ]
[23:39:13] Checking for file ‘/dev/.ttpy/bupdu’ [ Not found ]
[23:39:13] Checking for file ‘/dev/.ttpy/buloc’ [ Not found ]
[23:39:13] Checking for file ‘/dev/.ttpy/buloc1’ [ Not found ]
[23:39:13] Checking for file ‘/dev/.ttpy/buloc2’ [ Not found ]
[23:39:13] Checking for file ‘/dev/.ttpy/stat’ [ Not found ]
[23:39:13] Checking for file ‘/dev/.ttpy/backps’ [ Not found ]
[23:39:13] Checking for file ‘/dev/.ttpy/tree’ [ Not found ]
[23:39:13] Checking for file ‘/dev/.ttpy/topk’ [ Not found ]
[23:39:13] Checking for file ‘/dev/.ttpy/wold’ [ Not found ]
[23:39:13] Checking for file ‘/dev/.ttpy/whoold’ [ Not found ]
[23:39:13] Checking for file ‘/dev/.ttpy/backdoors’ [ Not found ]
[23:39:13] trNkit Rootkit [ Not found ]
[23:39:13]
[23:39:13] Checking for Trojanit Kit…
[23:39:13] Checking for file ‘/bin/.ls’ [ Not found ]
[23:39:13] Checking for file ‘/bin/.ps’ [ Not found ]
[23:39:13] Checking for file ‘/bin/.netstat’ [ Not found ]
[23:39:13] Checking for file ‘/usr/bin/.nop’ [ Not found ]
[23:39:13] Checking for file ‘/usr/bin/.who’ [ Not found ]
[23:39:13] Trojanit Kit [ Not found ]
[23:39:14]
[23:39:14] Checking for Tuxtendo Rootkit…
[23:39:14] Checking for file ‘/lib/libproc.so.2.0.7’ [ Not found ]
[23:39:14] Checking for file ‘/usr/bin/xchk’ [ Not found ]
[23:39:14] Checking for file ‘/usr/bin/xsf’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/suidsh’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/.addr’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/.cron’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/.file’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/.log’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/.proc’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/.iface’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/.pw’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/.df’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/.ssh’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/.tux’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/ssh2/sshd2_config’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/ssh2/hostkey’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/ssh2/hostkey.pub’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/ssh2/logo’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/ssh2/random_seed’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/backup/crontab’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/backup/df’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/backup/dir’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/backup/find’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/backup/ifconfig’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/backup/locate’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/backup/netstat’ [ Not found ]
[23:39:14] Checking for file ‘/dev/tux/backup/ps’ [ Not found ]
[23:39:15] Checking for file ‘/dev/tux/backup/pstree’ [ Not found ]
[23:39:15] Checking for file ‘/dev/tux/backup/syslogd’ [ Not found ]
[23:39:15] Checking for file ‘/dev/tux/backup/tcpd’ [ Not found ]
[23:39:15] Checking for file ‘/dev/tux/backup/top’ [ Not found ]
[23:39:15] Checking for file ‘/dev/tux/backup/updatedb’ [ Not found ]
[23:39:15] Checking for file ‘/dev/tux/backup/vdir’ [ Not found ]
[23:39:15] Checking for directory ‘/dev/tux’ [ Not found ]
[23:39:15] Checking for directory ‘/dev/tux/ssh2’ [ Not found ]
[23:39:15] Checking for directory ‘/dev/tux/backup’ [ Not found ]
[23:39:15] Tuxtendo Rootkit [ Not found ]
[23:39:15]
[23:39:15] Checking for URK Rootkit…
[23:39:15] Checking for file ‘/dev/prom/sn.l’ [ Not found ]
[23:39:15] Checking for file ‘/usr/lib/ldlibps.so’ [ Not found ]
[23:39:15] Checking for file ‘/usr/lib/ldlibnet.so’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/uconf.inv’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/cleaner’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/psniff’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/du’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/ls’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/passwd’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/ps’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/psr’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/su’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/find’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/netstat’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/ping’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/strings’ [ Not found ]
[23:39:15] Checking for file ‘/dev/pts/01/bin/bash’ [ Not found ]
[23:39:16] Checking for file ‘/usr/man/man1/xxxxxxbin/du’ [ Not found ]
[23:39:16] Checking for file ‘/usr/man/man1/xxxxxxbin/ls’ [ Not found ]
[23:39:16] Checking for file ‘/usr/man/man1/xxxxxxbin/passwd’ [ Not found ]
[23:39:16] Checking for file ‘/usr/man/man1/xxxxxxbin/ps’ [ Not found ]
[23:39:16] Checking for file ‘/usr/man/man1/xxxxxxbin/psr’ [ Not found ]
[23:39:16] Checking for file ‘/usr/man/man1/xxxxxxbin/su’ [ Not found ]
[23:39:16] Checking for file ‘/usr/man/man1/xxxxxxbin/find’ [ Not found ]
[23:39:16] Checking for file ‘/usr/man/man1/xxxxxxbin/netstat’ [ Not found ]
[23:39:16] Checking for file ‘/usr/man/man1/xxxxxxbin/ping’ [ Not found ]
[23:39:16] Checking for file ‘/usr/man/man1/xxxxxxbin/strings’ [ Not found ]
[23:39:16] Checking for file ‘/usr/man/man1/xxxxxxbin/bash’ [ Not found ]
[23:39:16] Checking for file ‘/tmp/conf.inv’ [ Not found ]
[23:39:16] Checking for directory ‘/dev/prom’ [ Not found ]
[23:39:16] Checking for directory ‘/dev/pts/01’ [ Not found ]
[23:39:16] Checking for directory ‘/dev/pts/01/bin’ [ Not found ]
[23:39:16] Checking for directory ‘/usr/man/man1/xxxxxxbin’ [ Not found ]
[23:39:16] URK Rootkit [ Not found ]
[23:39:16]
[23:39:16] Checking for Vampire Rootkit…
[23:39:16] Checking for kernel symbol ‘new_getdents’ [ Not found ]
[23:39:16] Checking for kernel symbol ‘old_getdents’ [ Not found ]
[23:39:16] Checking for kernel symbol ‘should_hide_file_name’ [ Not found ]
[23:39:17] Checking for kernel symbol ‘should_hide_task_name’ [ Not found ]
[23:39:17] Vampire Rootkit [ Not found ]
[23:39:17]
[23:39:17] Checking for VcKit Rootkit…
[23:39:17] Checking for directory ‘/usr/include/linux/modules/lib.so’ [ Not found ]
[23:39:17] Checking for directory ‘/usr/include/linux/modules/lib.so/bin’ [ Not found ]
[23:39:17] VcKit Rootkit [ Not found ]
[23:39:17]
[23:39:17] Checking for Volc Rootkit…
[23:39:17] Checking for file ‘/usr/bin/volc’ [ Not found ]
[23:39:17] Checking for file ‘/usr/lib/volc/backdoor/divine’ [ Not found ]
[23:39:17] Checking for file ‘/usr/lib/volc/linsniff’ [ Not found ]
[23:39:17] Checking for file ‘/etc/rc.d/rc1.d/S25sysconf’ [ Not found ]
[23:39:17] Checking for file ‘/etc/rc.d/rc2.d/S25sysconf’ [ Not found ]
[23:39:18] Checking for file ‘/etc/rc.d/rc3.d/S25sysconf’ [ Not found ]
[23:39:18] Checking for file ‘/etc/rc.d/rc4.d/S25sysconf’ [ Not found ]
[23:39:18] Checking for file ‘/etc/rc.d/rc5.d/S25sysconf’ [ Not found ]
[23:39:18] Checking for directory ‘/var/spool/.recent’ [ Not found ]
[23:39:18] Checking for directory ‘/var/spool/.recent/.files’ [ Not found ]
[23:39:20] Checking for directory ‘/usr/lib/volc’ [ Not found ]
[23:39:20] Checking for directory ‘/usr/lib/volc/backup’ [ Not found ]
[23:39:20] Volc Rootkit [ Not found ]
[23:39:20]
[23:39:20] Checking for Xzibit Rootkit…
[23:39:20] Checking for file ‘/dev/dsx’ [ Not found ]
[23:39:20] Checking for file ‘/dev/caca’ [ Not found ]
[23:39:20] Checking for file ‘/dev/ida/.inet/linsniffer’ [ Not found ]
[23:39:20] Checking for file ‘/dev/ida/.inet/logclear’ [ Not found ]
[23:39:20] Checking for file ‘/dev/ida/.inet/sense’ [ Not found ]
[23:39:20] Checking for file ‘/dev/ida/.inet/sl2’ [ Not found ]
[23:39:20] Checking for file ‘/dev/ida/.inet/sshdu’ [ Not found ]
[23:39:20] Checking for file ‘/dev/ida/.inet/s’ [ Not found ]
[23:39:20] Checking for file ‘/dev/ida/.inet/ssh_host_key’ [ Not found ]
[23:39:20] Checking for file ‘/dev/ida/.inet/ssh_random_seed’ [ Not found ]
[23:39:20] Checking for file ‘/dev/ida/.inet/sl2new.c’ [ Not found ]
[23:39:20] Checking for file ‘/dev/ida/.inet/tcp.log’ [ Not found ]
[23:39:20] Checking for file ‘/home/httpd/cgi-bin/becys.cgi’ [ Not found ]
[23:39:20] Checking for file ‘/usr/local/httpd/cgi-bin/becys.cgi’ [ Not found ]
[23:39:20] Checking for file ‘/usr/local/apache/cgi-bin/becys.cgi’ [ Not found ]
[23:39:20] Checking for file ‘/www/httpd/cgi-bin/becys.cgi’ [ Not found ]
[23:39:20] Checking for file ‘/www/cgi-bin/becys.cgi’ [ Not found ]
[23:39:20] Checking for directory ‘/dev/ida/.inet’ [ Not found ]
[23:39:21] Xzibit Rootkit [ Not found ]
[23:39:21]
[23:39:21] Checking for zaRwT.KiT Rootkit…
[23:39:21] Checking for file ‘/dev/rd/s/sendmeil’ [ Not found ]
[23:39:21] Checking for file ‘/dev/ttyf’ [ Not found ]
[23:39:21] Checking for file ‘/dev/ttyp’ [ Not found ]
[23:39:21] Checking for file ‘/dev/ttyn’ [ Not found ]
[23:39:21] Checking for file ‘/rk/tulz’ [ Not found ]
[23:39:21] Checking for directory ‘/rk’ [ Not found ]
[23:39:21] Checking for directory ‘/dev/rd/s’ [ Not found ]
[23:39:21] zaRwT.KiT Rootkit [ Not found ]
[23:39:21]
[23:39:21] Checking for ZK Rootkit…
[23:39:21] Checking for file ‘/usr/share/.zk/zk’ [ Not found ]
[23:39:21] Checking for file ‘/usr/X11R6/.zk/xfs’ [ Not found ]
[23:39:21] Checking for file ‘/usr/X11R6/.zk/echo’ [ Not found ]
[23:39:21] Checking for file ‘/etc/1ssue.net’ [ Not found ]
[23:39:21] Checking for file ‘/etc/sysconfig/console/load.zk’ [ Not found ]
[23:39:21] Checking for directory ‘/usr/share/.zk’ [ Not found ]
[23:39:21] Checking for directory ‘/usr/X11R6/.zk’ [ Not found ]
[23:39:21] ZK Rootkit [ Not found ]
[23:41:42]
[23:41:42] Info: Starting test name ‘additional_rkts’
[23:41:42] Performing additional rootkit checks
[23:41:42]
[23:41:42] Performing Suckit Rookit additional checks
[23:41:42] Checking hard link count on ‘/sbin/init’ [ OK ]
[23:41:43] Checking for hidden file extensions [ None found ]
[23:41:43] Running skdet command [ Skipped ]
[23:41:43] Info: Unable to find the ‘skdet’ command
[23:41:43] Suckit Rookit additional checks [ OK ]
[23:41:43]
[23:41:43] Info: Starting test name ‘possible_rkt_files’
[23:41:43] Performing check of possible rootkit files and directories
[23:41:43] Checking for file ‘/dev/sdr0’ [ Not found ]
[23:41:43] Checking for file ‘/dev/pisu’ [ Not found ]
[23:41:43] Checking for file ‘/dev/xdta’ [ Not found ]
[23:41:43] Checking for file ‘/dev/saux’ [ Not found ]
[23:41:43] Checking for file ‘/dev/hdx’ [ Not found ]
[23:41:43] Checking for file ‘/dev/hdx1’ [ Not found ]
[23:41:43] Checking for file ‘/dev/hdx2’ [ Not found ]
[23:41:43] Checking for file ‘/dev/ptyy’ [ Not found ]
[23:41:43] Checking for file ‘/dev/ptyu’ [ Not found ]
[23:41:43] Checking for file ‘/dev/ptyv’ [ Not found ]
[23:41:43] Checking for file ‘/dev/hdbb’ [ Not found ]
[23:41:43] Checking for file ‘/tmp/.syshackfile’ [ Not found ]
[23:41:43] Checking for file ‘/tmp/.bash_history’ [ Not found ]
[23:41:43] Checking for file ‘/usr/info/.clib’ [ Not found ]
[23:41:43] Checking for file ‘/usr/sbin/tcp.log’ [ Not found ]
[23:41:43] Checking for file ‘/usr/bin/take/pid’ [ Not found ]
[23:41:43] Checking for file ‘/sbin/create’ [ Not found ]
[23:41:43] Checking for file ‘/dev/ttypz’ [ Not found ]
[23:41:44] Checking for file ‘/var/log/tcp.log’ [ Not found ]
[23:41:44] Checking for file ‘/usr/include/audit.h’ [ Not found ]
[23:41:44] Checking for file ‘/usr/bin/sourcemask’ [ Not found ]
[23:41:44] Checking for file ‘/usr/bin/ras2xm’ [ Not found ]
[23:41:44] Checking for file ‘/dev/xmx’ [ Not found ]
[23:41:44] Checking for file ‘/usr/sbin/gpm.root’ [ Not found ]
[23:41:44] Checking for file ‘/bin/vobiscum’ [ Not found ]
[23:41:44] Checking for file ‘/bin/psr’ [ Not found ]
[23:41:44] Checking for file ‘/dev/kdx’ [ Not found ]
[23:41:44] Checking for file ‘/dev/dkx’ [ Not found ]
[23:41:44] Checking for file ‘/usr/sbin/sshd3’ [ Not found ]
[23:41:44] Checking for file ‘/usr/sbin/jcd’ [ Not found ]
[23:41:44] Checking for file ‘/etc/rc.d/init.d/jcd’ [ Not found ]
[23:41:44] Checking for file ‘/usr/sbin/atd2’ [ Not found ]
[23:41:44] Checking for file ‘/home/httpd/cgi-bin/linux.cgi’ [ Not found ]
[23:41:44] Checking for file ‘/home/httpd/cgi-bin/psid’ [ Not found ]
[23:41:44] Checking for file ‘/home/httpd/cgi-bin/void.cgi’ [ Not found ]
[23:41:44] Checking for file ‘/etc/rc.d/init.d/system’ [ Not found ]
[23:41:44] Checking for file ‘/etc/rc.d/rc3.d/S93users’ [ Not found ]
[23:41:44] Checking for file ‘/tmp/.ush’ [ Not found ]
[23:41:44] Checking for file ‘/usr/lib/libhidefile.so’ [ Not found ]
[23:41:45] Checking for file ‘/etc/cron.d/kmod’ [ Not found ]
[23:41:45] Checking for file ‘/usr/lib/dmis/dmisd’ [ Not found ]
[23:41:45] Checking for file ‘/lib/secure/libhij.so’ [ Not found ]
[23:41:45] Checking for file ‘/usr/sbin/sshd3’ [ Not found ]
[23:41:45] Checking for file ‘/etc/rc.d/init.d/crontab’ [ Not found ]
[23:41:45] Checking for file ‘/etc/rc.d/init.d/jcd’ [ Not found ]
[23:41:45] Checking for file ‘/usr/sbin/atd2’ [ Not found ]
[23:41:45] Checking for file ‘/etc/rc.d/rc5.d/S93users’ [ Not found ]
[23:41:46] Checking for file ‘/usr/include/mysql/mysql.hh1’ [ Not found ]
[23:41:46] Checking for file ‘/etc/init.d/xfs3’ [ Not found ]
[23:41:46] Checking for file ‘/usr/sbin/t.txt’ [ Not found ]
[23:41:46] Checking for file ‘/usr/sbin/change’ [ Not found ]
[23:41:46] Checking for file ‘/usr/sbin/s’ [ Not found ]
[23:41:46] Checking for file ‘/bin/f’ [ Not found ]
[23:41:46] Checking for file ‘/bin/i’ [ Not found ]
[23:41:46] Checking for file ‘/lib/libncom.so.4.0.1’ [ Not found ]
[23:41:46] Checking for file ‘/sbin/zinit’ [ Not found ]
[23:41:46] Checking for file ‘/tmp/pass_ssh.log’ [ Not found ]
[23:41:46] Checking for file ‘/usr/include/gpm2.h’ [ Not found ]
[23:41:48] Checking for file ‘/etc/ssh/.sshd_auth’ [ Not found ]
[23:41:48] Checking for file ‘/usr/lib/.sshd.h’ [ Not found ]
[23:41:48] Checking for file ‘/var/run/.defunct’ [ Not found ]
[23:41:48] Checking for file ‘/etc/httpd/run/.defunct’ [ Not found ]
[23:41:48] Checking for file ‘/usr/share/pci.r’ [ Not found ]
[23:41:48] Checking for file ‘/etc/cron.daily/dnsquery’ [ Not found ]
[23:41:49] Checking for file ‘/usr/lib/libutil1.2.1.2.so’ [ Not found ]
[23:41:49] Checking for file ‘/bin/ceva’ [ Not found ]
[23:41:49] Checking for file ‘/sbin/syslogd<SP>‘ [ Not found ]
[23:41:49] Checking for file ‘/usr/include/shup.h’ [ Not found ]
[23:41:49] Checking for file ‘/etc/rpm/sshdOLD’ [ Not found ]
[23:41:49] Checking for file ‘/etc/rpm/sshOLD’ [ Not found ]
[23:41:49] Checking for file ‘/usr/share/passwd.h’ [ Not found ]
[23:41:49] Checking for file ‘/lib/.xsyslog’ [ Not found ]
[23:41:49] Checking for file ‘/etc/.xsyslog’ [ Not found ]
[23:41:49] Checking for file ‘/lib/.ssyslog’ [ Not found ]
[23:41:49] Checking for file ‘/tmp/.sendmail’ [ Not found ]
[23:41:49] Checking for file ‘/usr/share/sshd.sync’ [ Not found ]
[23:41:49] Checking for file ‘/bin/zcut’ [ Not found ]
[23:41:49] Checking for file ‘/usr/bin/zmuie’ [ Not found ]
[23:41:49] Checking for file ‘/lib/libkeyutils.so.1.9’ [ Not found ]
[23:41:49] Checking for file ‘/lib64/libkeyutils.so.1.9’ [ Not found ]
[23:41:49] Checking for file ‘/usr/lib/libkeyutils.so.1.9’ [ Not found ]
[23:41:49] Checking for file ‘/usr/lib64/libkeyutils.so.1.9’ [ Not found ]
[23:41:49] Checking for directory ‘/dev/ptyas’ [ Not found ]
[23:41:49] Checking for directory ‘/usr/bin/take’ [ Not found ]
[23:41:49] Checking for directory ‘/usr/src/.lib’ [ Not found ]
[23:41:50] Checking for directory ‘/usr/share/man/man1/.1c’ [ Not found ]
[23:41:50] Checking for directory ‘/lib/lblip.tk’ [ Not found ]
[23:41:50] Checking for directory ‘/usr/sbin/…‘ [ Not found ]
[23:41:50] Checking for directory ‘/usr/share/.gun’ [ Not found ]
[23:41:50] Checking for directory ‘/unde/vrei/tu/sa/te/ascunzi/in/server’ [ Not found ]
[23:41:50] Checking for directory ‘/usr/man/man1/..<SP><SP>/.dir’ [ Not found ]
[23:41:50] Checking for directory ‘/usr/X11R6/include/X11/…’ [ Not found ]
[23:41:50] Checking for directory ‘/usr/X11R6/lib/X11/.fonts/misc/…’ [ Not found ]
[23:41:50] Checking for directory ‘/tmp/.sys’ [ Not found ]
[23:41:51] Checking for directory ‘/tmp/’‘ [ Not found ]
[23:41:51] Checking for directory ‘/tmp/.,’ [ Not found ]
[23:41:51] Checking for directory ‘/tmp/,.,’ [ Not found ]
[23:41:51] Checking for directory ‘/dev/shm/emilien’ [ Not found ]
[23:41:51] Checking for directory ‘/var/tmp/.log’ [ Not found ]
[23:41:51] Checking for directory ‘/tmp/zmeu/…<SP>‘ [ Not found ]
[23:41:51] Checking for directory ‘/var/log/ssh’ [ Not found ]
[23:41:51] Checking for directory ‘/dev/ida’ [ Not found ]
[23:41:51] Checking for directory ‘/var/lib/games/.src/ssk/shit’ [ Not found ]
[23:41:51] Checking for directory ‘/usr/lib/libshtift’ [ Not found ]
[23:41:51] Checking for directory ‘/usr/src/.poop’ [ Not found ]
[23:41:51] Checking for directory ‘/dev/wd4’ [ Not found ]
[23:41:51] Checking for directory ‘/var/run/.tmp’ [ Not found ]
[23:41:51] Checking for directory ‘/usr/man/man1/lib/.lib’ [ Not found ]
[23:41:51] Checking for directory ‘/dev/portd’ [ Not found ]
[23:41:51] Checking for directory ‘/dev/…‘ [ Not found ]
[23:41:51] Checking for directory ‘/usr/share/man/mansps’ [ Not found ]
[23:41:51] Checking for directory ‘/lib/.so’ [ Not found ]
[23:41:51] Checking for directory ‘/lib/.sso’ [ Not found ]
[23:41:54] Checking for directory ‘/usr/include/sslv3’ [ Not found ]
[23:41:54] Checking for directory ‘/dev/shm/sshd’ [ Not found ]
[23:41:54] Checking for directory ‘/usr/share/locale/mk/.dev/sk’ [ Not found ]
[23:41:55] Checking for directory ‘/usr/share/locale/mk/.dev’ [ Not found ]
[23:41:55] Checking for directory ‘/usr/include/netda.h’ [ Not found ]
[23:41:55] Checking for directory ‘/usr/include/.ssh’ [ Not found ]
[23:41:55] Checking for directory ‘/usr/share/locale/jp/.<SP>’ [ Not found ]
[23:41:55] Checking for directory ‘/usr/share/.sqe’ [ Not found ]
[23:41:55] Checking for possible rootkit files and directories [ None found ]
[23:41:55]
[23:41:55] Info: Starting test name ‘possible_rkt_strings’
[23:41:55] Performing check for possible rootkit strings
[23:41:55] Info: Using system startup paths: /etc/rc.d /etc/inittab
[23:41:55] Checking for string ‘LOGNAME=root’ [ Not found ]
[23:41:55] Checking for string ‘phalanx’ [ Not found ]
[23:41:55] Checking for string ‘/dev/proc/fuckit’ [ Not found ]
[23:41:55] Checking for string ‘FUCK’ [ Not found ]
[23:41:55] Checking for string ‘backdoor’ [ Not found ]
[23:41:55] Checking for string ‘/usr/bin/rcpc’ [ Not found ]
[23:41:55] Checking for string ‘/usr/sbin/login’ [ Not found ]
[23:41:55] Checking for string ‘/dev/ptyxx/.proc’ [ Not found ]
[23:41:55] Checking for string ‘vt200’ [ Not found ]
[23:41:55] Checking for string ‘/usr/bin/xstat’ [ Not found ]
[23:41:55] Checking for string ‘/bin/envpc’ [ Not found ]
[23:41:55] Checking for string ‘L4m3r0x’ [ Not found ]
[23:41:55] Checking for string ‘/lib/libext’ [ Not found ]
[23:41:55] Checking for string ‘/usr/sbin/login’ [ Not found ]
[23:41:56] Checking for string ‘/usr/lib/.tbd’ [ Not found ]
[23:41:56] Checking for string ‘sendmail’ [ Not found ]
[23:41:56] Checking for string ‘cocacola’ [ Not found ]
[23:41:56] Checking for string ‘joao’ [ Not found ]
[23:41:56] Checking for string ‘/dev/ptyxx/.file’ [ Not found ]
[23:41:56] Checking for string ‘/dev/ptyxx/.file’ [ Not found ]
[23:41:56] Checking for string ‘/dev/sgk’ [ Not found ]
[23:41:56] Checking for string ‘/var/lock/subsys/…datafile…’ [ Not found ]
[23:41:56] Checking for string ‘/usr/lib/.tbd’ [ Not found ]
[23:41:56] Checking for string ‘/dev/proc/fuckit’ [ Not found ]
[23:41:56] Checking for string ‘/lib/.sso’ [ Not found ]
[23:41:56] Checking for string ‘/var/lock/subsys/…datafile…’ [ Not found ]
[23:41:56] Checking for string ‘/dev/caca’ [ Not found ]
[23:41:56] Checking for string ‘/dev/ttyoa’ [ Not found ]
[23:41:56] Checking for string ‘/usr/lib/ldlibns.so’ [ Not found ]
[23:41:56] Checking for string ‘/dev/ptyxx/.addr’ [ Not found ]
[23:41:56] Checking for string ‘syg’ [ Not found ]
[23:41:59] Checking for string ‘sshd_config’ [ Not found ]
[23:41:59] Checking for string ‘/var/lock/subsys/…datafile…’ [ Not found ]
[23:41:59] Checking for string ‘/dev/pts/01’ [ Not found ]
[23:41:59] Checking for string ‘tw33dl3’ [ Not found ]
[23:41:59] Checking for string ‘psniff’ [ Not found ]
[23:41:59] Checking for string ‘uconf.inv’ [ Not found ]
[23:41:59] Checking for string ‘lib/ldlibps.so’ [ Not found ]
[23:41:59] Checking for string ‘/usr/lib/ldlibpst.so’ [ Not found ]
[23:41:59] Checking for string ‘libproc.so.2.0.7’ [ Not found ]
[23:41:59] Checking for string ‘/dev/ptyxx/.proc’ [ Not found ]
[23:41:59] Checking for string ‘/dev/ptyxx/.proc’ [ Not found ]
[23:42:02] Checking for string ‘libproc.so.2.0.7’ [ Not found ]
[23:42:02] Checking for string ‘libproc.so.2.0.7’ [ Not found ]
[23:42:02] Checking for string ‘/bin/bash’ [ Not found ]
[23:42:03] Checking for string ‘cant open log’ [ Not found ]
[23:42:03] Checking for string ‘sniff.pid’ [ Not found ]
[23:42:04] Checking for string ‘tcp.log’ [ Not found ]
[23:42:04] Checking for string ‘/dev/ptyxx’ [ Not found ]
[23:42:04] Checking for string ‘/.config’ [ Not found ]
[23:42:04] Checking for string ‘$.*$!.*!!$’ [ Not found ]
[23:42:04] Checking for string ‘backdoor.h’ [ Not found ]
[23:42:04] Checking for string ‘backdoor_active’ [ Not found ]
[23:42:04] Checking for string ‘magic_pass_active’ [ Not found ]
[23:42:04] Checking for string ‘/usr/include/gpm2.h’ [ Not found ]
[23:42:04] Checking for string ‘/usr/include/openssl’ [ Not found ]
[23:42:04] Checking for string ‘aion’ [ Not found ]
[23:42:04] Checking for string ‘pcszPass’ [ Not found ]
[23:42:04] Checking for string ‘LogPass’ [ Not found ]
[23:42:04] Checking for string ‘Login_Check’ [ Not found ]
[23:42:04] Checking for string ‘includes.h’ [ Not found ]
[23:42:05] Checking for string ‘DecodeString’ [ Not found ]
[23:42:06] Checking for string ‘EncodeString’ [ Not found ]
[23:42:06] Checking for string ‘promiscuous’ [ Not found ]
[23:42:06] Checking for string ‘/usr/lib/.tbd’ [ Not found ]
[23:42:06] Checking for string ‘/dev/ptyxx/.log’ [ Not found ]
[23:42:06] Checking for string ‘/usr/share/pci.r’ [ Not found ]
[23:42:06] Checking for string ‘/dev/xdta’ [ Not found ]
[23:42:06] Checking for string ‘/usr/lib/.tbd’ [ Not found ]
[23:42:06] Checking for string ‘/dev/ptyxx/.proc’ [ Not found ]
[23:42:09] Checking for string ‘in.inetd’ [ Not found ]
[23:42:09] Checking for string ‘#<HIDE.*>‘ [ Not found ]
[23:42:10] Checking for string ‘bin/xchk’ [ Not found ]
[23:42:10] Checking for string ‘bin/xsf’ [ Not found ]
[23:42:12] Checking for string ‘/usr/bin/ssh2d’ [ Not found ]
[23:42:12] Checking for string ‘/usr/sbin/xntps’ [ Not found ]
[23:42:12] Checking for string ‘ttyload’ [ Not found ]
[23:42:13] Checking for string ‘/etc/rc.d/init.d/init’ [ Not found ]
[23:42:13] Checking for string ‘usr/bin/xfss’ [ Not found ]
[23:42:14] Checking for string ‘/usr/sbin/rpc.netinet’ [ Not found ]
[23:42:14] Checking for string ‘/usr/lib/.fx/cons.saver’ [ Not found ]
[23:42:15] Checking for string ‘/usr/lib/.fx/xs’ [ Not found ]
[23:42:15] Checking for string ‘/ssh2d’ [ Not found ]
[23:42:16] Checking for string ‘/dev/kmod’ [ Not found ]
[23:42:16] Checking for string ‘/crth.o’ [ Not found ]
[23:42:16] Checking for string ‘/crtz.o’ [ Not found ]
[23:42:17] Checking for string ‘/dev/dos’ [ Not found ]
[23:42:17] Checking for string ‘/lpq’ [ Not found ]
[23:42:18] Checking for string ‘/usr/sbin/rescue’ [ Not found ]
[23:42:18] Checking for string ‘/usr/lib/lpstart’ [ Not found ]
[23:42:19] Checking for string ‘/volc’ [ Not found ]
[23:42:19] Checking for string ‘sourcemask’ [ Not found ]
[23:42:20] Checking for string ‘/bin/vobiscum’ [ Not found ]
[23:42:20] Checking for string ‘/usr/sbin/in.telnet’ [ Not found ]
[23:42:21] Checking for string ‘/usr/bin/hdparm?-t1?-X53?-p’ [ Not found ]
[23:42:21] Checking for string ‘/lib/.xsyslog’ [ Not found ]
[23:42:24] Checking for string ‘/etc/.xsyslog’ [ Not found ]
[23:42:25] Checking for string ‘/lib/.ssyslog’ [ Not found ]
[23:42:25] Checking for string ‘/tmp/.sendmail’ [ Not found ]
[23:42:25] Checking for string ‘/lib/ldd.so/tkps’ [ Not found ]
[23:42:25] Checking for string ‘t0rnkit’ [ Not found ]
[23:42:25] Checking for string ‘/dev/proc/fuckit’ [ Not found ]
[23:42:26] Checking for string ‘backdoor.h’ [ Not found ]
[23:42:26] Checking for string ‘backdoor_active’ [ Not found ]
[23:42:26] Checking for string ‘magic_pass_active’ [ Not found ]
[23:42:26] Checking for string ‘/usr/include/gpm2.h’ [ Not found ]
[23:42:26] Checking for string ‘libproc.so.2.0.7’ [ Not found ]
[23:42:28] Checking for string ‘libproc.so.2.0.7’ [ Not found ]
[23:42:28] Checking for string ‘libproc.so.2.0.7’ [ Not found ]
[23:42:28] Checking for string ‘/usr/lib/ldlibct.so’ [ Not found ]
[23:42:29] Checking for string ‘/usr/lib/ldlibct.so’ [ Not found ]
[23:42:29] Checking for string ‘/usr/lib/ldlibdu.so’ [ Not found ]
[23:42:29] Checking for string ‘/dev/ptyxx/.file’ [ Not found ]
[23:42:29] Checking for string ‘libproc.so.2.0.7’ [ Not found ]
[23:42:29] Checking for string ‘/dev/ida/.inet’ [ Not found ]
[23:42:29] Checking for string ‘/usr/include/mysql/mysql.hh1’ [ Not found ]
[23:42:29] Checking for string ‘/usr/include/mysql/mysql.hh1’ [ Not found ]
[23:42:33] Checking for string ‘/usr/include/mysql/mysql.hh1’ [ Not found ]
[23:42:33] Checking for string ‘/usr/include/mysql/mysql.hh1’ [ Not found ]
[23:42:33] Checking for string ‘/usr/include/mysql/mysql.hh1’ [ Not found ]
[23:42:33] Checking for string ‘/usr/include/mysql/mysql.hh1’ [ Not found ]
[23:42:33] Checking for string ‘backconnect’ [ Not found ]
[23:42:33] Checking for string ‘magic?packet?received’ [ Not found ]
[23:42:33] Checking for possible rootkit strings [ None found ]
[23:42:33]
[23:42:33] Info: Starting test name ‘malware’
[23:42:33] Performing malware checks
[23:42:33]
[23:42:33] Info: Test ‘deleted_files’ disabled at users request.
[23:42:33]
[23:42:33] Info: Starting test name ‘running_procs’
[23:42:37] Checking running processes for suspicious files [ None found ]
[23:42:37]
[23:42:37] Info: Test ‘hidden_procs’ disabled at users request.
[23:42:37]
[23:42:37] Info: Test ‘suspscan’ disabled at users request.
[23:42:38]
[23:42:38] Info: Starting test name ‘other_malware’
[23:42:38] Performing check for login backdoors
[23:42:38] Checking for ‘/bin/.login’ [ Not found ]
[23:42:38] Checking for ‘/sbin/.login’ [ Not found ]
[23:42:38] Checking for login backdoors [ None found ]
[23:42:38]
[23:42:38] Performing check for suspicious directories
[23:42:38] Checking for directory ‘/usr/X11R6/bin/.,/copy’ [ Not found ]
[23:42:38] Checking for directory ‘/dev/rd/cdb’ [ Not found ]
[23:42:38] Checking for suspicious directories [ None found ]
[23:42:38]
[23:42:38] Checking for software intrusions [ Skipped ]
[23:42:40] Info: Check skipped - tripwire not installed
[23:42:40]
[23:42:40] Performing check for sniffer log files
[23:42:40] Checking for file ‘/usr/lib/libice.log’ [ Not found ]
[23:42:40] Checking for file ‘/dev/prom/sn.l’ [ Not found ]
[23:42:40] Checking for file ‘/dev/fd/.88/zxsniff.log’ [ Not found ]
[23:42:40] Checking for sniffer log files [ None found ]
[23:42:40]
[23:42:40] Suspicious Shared Memory segments
[23:42:42] Suspicious Shared Memory segments [ None found ]
[23:42:42]
[23:42:42] Info: Starting test name ‘trojans’
[23:42:42] Performing trojan specific checks
[23:42:42] Info: Using inetd configuration file ‘/etc/inetd.conf’
[23:42:42] Checking for enabled inetd services [ Warning ]
[23:42:42] Warning: Found enabled inetd service: time
[23:42:42] Warning: Found enabled inetd service: time
[23:42:42] Warning: Found enabled inetd service: comsat
[23:42:42] Warning: Found enabled inetd service: auth
[23:42:42]
[23:42:42] Performing check for enabled xinetd services
[23:42:42] Checking for enabled xinetd services [ Skipped ]
[23:42:42] Info: Check skipped - file ‘/etc/xinetd.conf’ does not exist.
[23:42:42] Info: Apache backdoor check skipped: Apache modules and configuration directories not found.
[23:42:42]
[23:42:42] Info: Starting test name ‘os_specific’
[23:42:42] Performing Linux specific checks
[23:42:42] Checking loaded kernel modules [ OK ]
[23:42:42] Info: Using modules pathname of ‘/lib/modules/4.1.15’
[23:42:42] Checking kernel module names [ OK ]
There is tutorial use rkhunter for detecting rootkit or backdoor.
Thanks, may be useful and good luck!!!