Получил письма о атаке с моего сервера iabzalov.site

Письмо 1.

Здравствуйте, на ваш IP поступила жалоба, просим принять меры по ее устранению, и предоставить комментарии относительно сути жалобы. В противном случае, мы оставляем за собой право заблокировать порты на VPS.


-------- Перенаправленное сообщение --------

Тема:

[noreply] abuse report about 45.67.57.43 - Thu, 13 Jun 2019 09:17:22 +0200 -- service: ssh (First x 1) RID: 879188911

Дата:

Thu, 13 Jun 2019 09:18:10 +0200 (CEST)

От:

Abuse-Team (auto-generated) Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.

Отвечать:

Abuse-Team Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.

Кому:

Abuse-Team of IP: 45.67.57.43 Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.

Hello Abuse-Team,

your Server/Customer with the IP: *45.67.57.43* (45.67.57.43) has attacked one of our servers/partners.
The attackers used the method/service: *ssh* on: *Thu, 13 Jun 2019 09:17:22 +0200*.
The time listed is from the server-time of the Blocklist-user who submitted the report.
The attack was reported to the Blocklist.de-System on: *Thu, 13 Jun 2019 09:17:10 +0200*

!!! Do not answer to this Mail! Use support@ or contact-form for Questions (no resolve-messages, no updates....) !!!

The IP has been automatically blocked for a period of time. For an IP to be blocked, it needs to have made several failed logins (ssh, imap....), tried to log in for an "invalid user", or have
triggered several 5xx-Error-Codes (eg. Blacklist on email...), all during a short period of time.
The Server-Owner configures the number of failed attempts, and the time period they have to occur in, in order to trigger a ban and report. Blocklist has no control over these settings.

Please check the machine behind the IP 45.67.57.43 (45.67.57.43) and fix the problem.
To search for AS-Number/IPs that you control, to see if any others have been infected/blocked, please go to: https://www.blocklist.de/en/search.html?as=198610

If you need the logs in another format (rather than an attachment), please let us know.
You can see the Logfiles online again: https://www.blocklist.de/en/logs.html?rid=879188911&ip=45.67.57.43

You can parse this abuse report mail with X-ARF-Tools from http://www.xarf.org/tools.html e.g. validatexarf-php.tar.gz.
You can find more information about X-Arf V0.2 at http://www.xarf.org/specification.html

This message will be sent again in one day if more attacks are reported to Blocklist.
In the attachment of this message you can find the original logs from the attacked system.

To pause this message for one week, you can use our "Stop Reports" feature on Blocklist.de to submit
the IP you want to stop recieving emails about, and the email you want to stop receiving them on.
If more attacks from your network are recognized after the seven day grace period, the reports will start
being sent again.

To pause these reports for one week:
https://www.blocklist.de/en/insert.html?ip=45.67.57.43&email=Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.

We found this abuse email address in the Contact-Database abusix.org. This is because we could not parse
an abuse/security-Address (e.g. abuse-mailbox, abuse@....) in the Whois, or the Whois request has been
rejected (usually because of a registrar's limits on the number of Whois requests we can perform in a day).
If this is not the right address to send abuse reports to, please contact Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.: http://abusix.org/services/abuse-contact-db

Reply to this message to let us know if you want us to send future reports to a different email. (e.g. to abuse-quiet or a special address)

------------------------------
blocklist.de Abuse-Team
This message was sent automatically. For questions please use our Contact-Form (autogenerated@/abuse-team@ is not monitored!):
https://www.blocklist.de/en/contact.html?RID=879188911
Logfiles: https://www.blocklist.de/en/logs.html?rid=879188911&ip=45.67.57.43
------------------------------

Письмо 2.

Здравствуйте, на ваш сайт поступила жалоба, просим принять меры по ее устранению и дать комментарии относительно сути жалобы. В противном случае мы оставляем за собой право заблокировать ваш сайт в течении 3 дней.

-------- Перенаправленное сообщение --------

Тема:

Automatic abuse report for IP address 45.67.57.43

Дата:

Thu, 13 Jun 2019 15:56:45 +0600

От:

Fail2Ban Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.

Кому:

Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.

This is an email abuse report about the IP address 45.67.57.43 generated at Thu Jun 13 15:54:43 ALMT 2019
You get this email because you are listed as the official abuse contact for this IP address.

Please take appropriate actions to prevent this from happening again.

WHOIS report:

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/resources/registry/whois/tou/
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/registry/whois/inaccuracy_reporting/
#
# Copyright 1997-2019, American Registry for Internet Numbers, Ltd.
#

NetRange: 45.66.0.0 - 45.67.255.255
CIDR: 45.66.0.0/15
NetName: RIPE-ERX-45-66-0-0
NetHandle: NET-45-66-0-0-1
Parent: NET45 (NET-45-0-0-0-0)
NetType: Early Registrations, Transferred to RIPE NCC
OriginAS: Organization: RIPE Network Coordination Centre (RIPE)
RegDate: 2015-09-04
Updated: 2015-09-04
Comment: These addresses have been further assigned to users in Comment: the RIPE NCC region. Contact information can be found in Comment: the RIPE database at http://www.ripe.net/whois
Ref: https://rdap.arin.net/registry/ip/45.66.0.0

ResourceLink: http://wq.apnic.net/whois-search/static/search.html
ResourceLink: whois.ripe.net


OrgName: RIPE Network Coordination Centre
OrgId: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv: PostalCode: 1001EB
Country: NL
RegDate: Updated: 2013-07-29
Ref: https://rdap.arin.net/registry/entity/RIPE

ReferralServer: whois://whois.ripe.net
ResourceLink: https://apps.db.ripe.net/search/query.html

OrgAbuseHandle: ABUSE3850-ARIN
OrgAbuseName: Abuse Contact
OrgAbusePhone: +31205354444 OrgAbuseEmail: Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.
OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE3850-ARIN

OrgTechHandle: RNO29-ARIN
OrgTechName: RIPE NCC Operations
OrgTechPhone: +31 20 535 4444 OrgTechEmail: Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.
OrgTechRef: https://rdap.arin.net/registry/entity/RNO29-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/resources/registry/whois/tou/
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/registry/whois/inaccuracy_reporting/
#
# Copyright 1997-2019, American Registry for Internet Numbers, Ltd.
#

Found a referral to whois.ripe.net.

% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '45.67.56.0 - 45.67.59.255'

% Abuse contact for '45.67.56.0 - 45.67.59.255' is 'Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.'

inetnum: 45.67.56.0 - 45.67.59.255
netname: RU-BEGETLLC0119-20190215
country: RU
org: ORG-BL367-RIPE
admin-c: AI4802-RIPE
tech-c: AI4802-RIPE
status: ALLOCATED PA
mnt-by: RIPE-NCC-HM-MNT
mnt-by: BEGET-MNT
created: 2019-02-15T10:41:09Z
last-modified: 2019-02-15T10:41:09Z
source: RIPE

organisation: ORG-BL367-RIPE
org-name: Beget LLC
org-type: LIR
address: Karla Faberzhe st., n. 8B
address: 195112
address: Saint Petersburg
address: RUSSIAN FEDERATION
admin-c: AI4802-RIPE
tech-c: AI4802-RIPE
abuse-c: AR16577-RIPE
mnt-ref: BEGET-MNT
mnt-by: RIPE-NCC-HM-MNT
mnt-by: BEGET-MNT
created: 2019-02-12T08:29:05Z
last-modified: 2019-02-18T10:01:22Z
source: RIPE # Filtered
phone: +78007000608

person: Aleksander Ilyin
address: Karla Faberzhe st., n. 8B
address: 195112
address: Saint Petersburg
address: RUSSIAN FEDERATION
phone: +78007000608
nic-hdl: AI4802-RIPE
mnt-by: BEGET-MNT
created: 2019-02-12T08:29:05Z
last-modified: 2019-02-12T08:29:05Z
source: RIPE

% Information related to '45.67.57.0/24AS198610'

route: 45.67.57.0/24
origin: AS198610
descr: BEGET.RU
mnt-by: BEGET-MNT
created: 2019-02-20T14:07:38Z
last-modified: 2019-02-20T14:07:38Z
source: RIPE

% This query was served by the RIPE Database Query Service version 1.94 (WAGYU)

Процедура расследования причины

1. Состояние загрузки по процессору показывает 100% загрузку, начиная с 12.06.2019:

2. Состояние загрузки сервера по диску

 3. Вывод команды top

Выключение процесса xm64 ничего не дает, через некоторое время процесс появляется вновь.

Письмо 3.

Здравствуйте, поступила повторная жалоба на атаку с 45.67.57.43, просим устранить нарушение.

-------- Перенаправленное сообщение --------

Тема:

[June 13][TCP probes]IP addresses of suspected botnet computers listed inside, please notify their owners.

Дата:

Fri, 14 Jun 2019 06:20:12 -0700 (PDT)

От:

Botnet Tracker Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.

Кому:

Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.

Hello,

This is a notification of unauthorized use of systems or networks.
On June 13, 2019, a total of 2 IP addresses from your networks probed my servers for TCP open ports. Due to their dubious behavior, they are suspected to be compromised botnet computers.
The log of TCP port scans is included below for your reference (time zone is UTC). To prevent this mail from getting too big in size, at most 5 attempts from each attacker IP are included. If you regularly collect IP traffic information of your network, you will see the IPs listed connected to various TCP ports of my server at the time logged, and I suspect that they also connected to TCP ports of many other IPs.

Please notify the owners of those botnet computers so that they can take appropriate action to clean their computers, before even more severe incidents, like data leakage, DDoS, and the rumored NSA spying through hijacked botnets, arise. This also helps prevent botnets from taking up your network bandwidth.

Chih-Cherng Chin
Daily Botnet Statistics
http://botnet-tracker.blogspot.com/

*** Why is the USA "hawk" missing in 2019 CrowdStrike Global Threat Report?
*** Is this an indication of CrowdStrike's inability to detect cyber
*** infiltration from the US?
*** https://www.crowdstrike.com/blog/first-ever-adversary-ranking-in-2019-global-threat-report-highlights-the-importance-of-speed/

---- log of TCP port scans (time zone is UTC; sent to Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.) ----
-------------------------------------------------------------------------------
(time in UTC)=2019-06-13T07:10:15 (attacker's IP)=45.67.57.43 (IP being scanned)=66^23^246^124 (TCP port being scanned)=122
(time in UTC)=2019-06-13T07:11:03 (attacker's IP)=45.67.57.43 (IP being scanned)=185^219^132^53 (TCP port being scanned)=122
(time in UTC)=2019-06-13T07:11:06 (attacker's IP)=45.67.57.43 (IP being scanned)=185^164^137^31 (TCP port being scanned)=122
(time in UTC)=2019-06-13T08:12:05 (attacker's IP)=45.67.57.43 (IP being scanned)=185^106^122^18 (TCP port being scanned)=1022
(time in UTC)=2019-06-13T11:09:24 (attacker's IP)=45.67.57.43 (IP being scanned)=185^219^132^53 (TCP port being scanned)=22222
(time in UTC)=2019-06-13T00:36:14 (attacker's IP)=95.214.63.234 (IP being scanned)=45^124^65^92 (TCP port being scanned)=2211
(time in UTC)=2019-06-13T00:36:26 (attacker's IP)=95.214.63.234 (IP being scanned)=5^2^79^74 (TCP port being scanned)=2211
(time in UTC)=2019-06-13T06:31:26 (attacker's IP)=95.214.63.234 (IP being scanned)=5^2^79^74 (TCP port being scanned)=2022
(time in UTC)=2019-06-13T06:32:30 (attacker's IP)=95.214.63.234 (IP being scanned)=45^124^65^92 (TCP port being scanned)=2022
(time in UTC)=2019-06-13T11:11:10 (attacker's IP)=95.214.63.234 (IP being scanned)=5^2^79^74 (TCP port being scanned)=122

root@singularity:~# whois 95.214.63.234
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '95.214.60.0 - 95.214.63.255'

% Abuse contact for '95.214.60.0 - 95.214.63.255' is Этот адрес электронной почты защищён от спам-ботов. У вас должен быть включен JavaScript для просмотра.'

inetnum: 95.214.60.0 - 95.214.63.255
netname: RU-BEGETLLDEC-20181221
country: RU
org: ORG-BL358-RIPE
admin-c: AI4783-RIPE
tech-c: AI4783-RIPE
status: ALLOCATED PA
mnt-by: RIPE-NCC-HM-MNT
mnt-by: BEGET-MNT
created: 2018-12-21T14:24:27Z
last-modified: 2018-12-21T14:24:27Z
source: RIPE

organisation: ORG-BL358-RIPE
org-name: Beget LLC
org-type: LIR
address: Karla Faberzhe st., n. 8B
address: 195112
address: Saint Petersburg
address: RUSSIAN FEDERATION
admin-c: AI4783-RIPE
tech-c: AI4783-RIPE
abuse-c: AR16577-RIPE
mnt-ref: BEGET-MNT
mnt-by: RIPE-NCC-HM-MNT
mnt-by: BEGET-MNT
created: 2018-12-20T08:39:43Z
last-modified: 2018-12-24T13:43:16Z
source: RIPE # Filtered
phone: +78007000608

person: Aleksander Ilyin
address: Karla Faberzhe st., n. 8B
address: 195112
address: Saint Petersburg
address: RUSSIAN FEDERATION
phone: +78007000608
nic-hdl: AI4783-RIPE
mnt-by: BEGET-MNT
created: 2018-12-20T08:39:43Z
last-modified: 2018-12-20T08:39:43Z
source: RIPE

% Information related to '95.214.63.0/24AS198610'

route: 95.214.63.0/24
origin: AS198610
descr: BEGET.RU
mnt-by: BEGET-MNT
created: 2018-12-25T14:27:59Z
last-modified: 2018-12-25T14:27:59Z
source: RIPE

% This query was served by the RIPE Database Query Service version 1.94 (BLAARKOP)

Установка антивируса на сервер Singularity - 

root@singularity:~# rkhunter --versioncheck
Invalid WEB_CMD configuration option: Relative pathname: "/bin/false"

Решение:

nano /etc/rkhunter.conf
UPDATE_MIRRORS=1
MIRRORS_MODE=0
WEB_CMD=""

 Результат проверки:

rkhunter --update
rkhunter -c --enable all --disable none

Лог /var/log/rkhunter.log 

[22:53:19] Running Rootkit Hunter version 1.4.6 on singularity
[22:53:19]
[22:53:19] Info: Start date is Fri 14 Jun 2019 10:53:19 PM +07
[22:53:19]
[22:53:19] Checking configuration file and command-line options...
[22:53:19] Info: Detected operating system is 'Linux'
[22:53:19] Info: Found O/S name: Ubuntu 19.04
[22:53:19] Info: Command line is /usr/bin/rkhunter -c --enable all --disable none
[22:53:19] Info: Environment shell is /bin/bash; rkhunter is using dash
[22:53:19] Info: Using configuration file '/etc/rkhunter.conf'
[22:53:19] Info: Installation directory is '/usr'
[22:53:20] Info: Using language 'en'
[22:53:20] Info: Using '/var/lib/rkhunter/db' as the database directory
[22:53:20] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[22:53:20] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin /usr/games /usr/local/games /snap/bin /usr/local/vesta/bin /usr/libexec' as the command directories
[22:53:20] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[22:53:20] Info: No mail-on-warning address configured
[22:53:20] Info: X will be automatically detected
[22:53:20] Info: Found the 'basename' command: /usr/bin/basename
[22:53:20] Info: Found the 'diff' command: /usr/bin/diff
[22:53:20] Info: Found the 'dirname' command: /usr/bin/dirname
[22:53:20] Info: Found the 'file' command: /usr/bin/file
[22:53:20] Info: Found the 'find' command: /usr/bin/find
[22:53:20] Info: Found the 'ifconfig' command: /sbin/ifconfig
[22:53:20] Info: Found the 'ip' command: /sbin/ip
[22:53:20] Info: Found the 'ipcs' command: /usr/bin/ipcs
[22:53:20] Info: Found the 'ldd' command: /usr/bin/ldd
[22:53:20] Info: Found the 'lsattr' command: /usr/bin/lsattr
[22:53:20] Info: Found the 'lsmod' command: /sbin/lsmod
[22:53:20] Info: Found the 'lsof' command: /usr/bin/lsof
[22:53:20] Info: Found the 'mktemp' command: /bin/mktemp
[22:53:20] Info: Found the 'netstat' command: /bin/netstat
[22:53:20] Info: Found the 'numfmt' command: /usr/bin/numfmt
[22:53:20] Info: Found the 'perl' command: /usr/bin/perl
[22:53:20] Info: Found the 'pgrep' command: /usr/bin/pgrep
[22:53:20] Info: Found the 'ps' command: /bin/ps
[22:53:20] Info: Found the 'pwd' command: /bin/pwd
[22:53:20] Info: Found the 'readlink' command: /bin/readlink
[22:53:20] Info: Found the 'stat' command: /usr/bin/stat
[22:53:20] Info: Found the 'strings' command: /usr/bin/strings
[22:53:20] Info: System is not using prelinking
[22:53:20] Info: Using the '/usr/bin/sha256sum' command for the file hash checks
[22:53:20] Info: Stored hash values used hash function '/usr/bin/sha256sum'
[22:53:20] Info: Stored hash values did not use a package manager
[22:53:20] Info: The hash function field index is set to 1
[22:53:20] Info: No package manager specified: using hash function '/usr/bin/sha256sum'
[22:53:20] Info: Previous file attributes were stored
[22:53:20] Info: Enabled tests are: all
[22:53:20] Info: Disabled tests are: none
[22:53:20] Info: Found kernel symbols file '/proc/kallsyms'
[22:53:20] Info: Using syslog for some logging - facility/priority level is 'authpriv.warning'.
[22:53:20] Info: Found the 'logger' command: /usr/bin/logger
[22:53:20] Info: Using 'date' to process epoch second times
[22:53:20]
[22:53:20] Checking if the O/S has changed since last time...
[22:53:20] Info: Nothing seems to have changed.
[22:53:20] Info: Locking is not being used
[22:53:20]
[22:53:20] Starting system checks...
[22:53:20]
[22:53:20] Info: Starting test name 'system_commands'
[22:53:20] Checking system commands...
[22:53:20]
[22:53:20] Info: Starting test name 'strings'
[22:53:20] Performing 'strings' command checks
[22:53:20] Scanning for string /usr/sbin/ntpsx [ OK ]
[22:53:20] Scanning for string /usr/sbin/.../bkit-ava [ OK ]
[22:53:20] Scanning for string /usr/sbin/.../bkit-d [ OK ]
[22:53:20] Scanning for string /usr/sbin/.../bkit-shd [ OK ]
[22:53:20] Scanning for string /usr/sbin/.../bkit-f [ OK ]
[22:53:20] Scanning for string /usr/include/.../proc.h [ OK ]
[22:53:20] Scanning for string /usr/include/.../.bash_history [ OK ]
[22:53:20] Scanning for string /usr/include/.../bkit-get [ OK ]
[22:53:20] Scanning for string /usr/include/.../bkit-dl [ OK ]
[22:53:20] Scanning for string /usr/include/.../bkit-screen [ OK ]
[22:53:20] Scanning for string /usr/include/.../bkit-sleep [ OK ]
[22:53:20] Scanning for string /usr/lib/.../bkit-adore.o [ OK ]
[22:53:20] Scanning for string /usr/lib/.../ls [ OK ]
[22:53:20] Scanning for string /usr/lib/.../netstat [ OK ]
[22:53:20] Scanning for string /usr/lib/.../lsof [ OK ]
[22:53:20] Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[22:53:20] Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[22:53:20] Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[22:53:20] Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[22:53:20] Scanning for string /usr/lib/.../bkit-ssh/bkit-mots [ OK ]
[22:53:21] Scanning for string /usr/lib/.../uconf.inv [ OK ]
[22:53:21] Scanning for string /usr/lib/.../psr [ OK ]
[22:53:21] Scanning for string /usr/lib/.../find [ OK ]
[22:53:21] Scanning for string /usr/lib/.../pstree [ OK ]
[22:53:21] Scanning for string /usr/lib/.../slocate [ OK ]
[22:53:21] Scanning for string /usr/lib/.../du [ OK ]
[22:53:21] Scanning for string /usr/lib/.../top [ OK ]
[22:53:21] Scanning for string /usr/sbin/... [ OK ]
[22:53:21] Scanning for string /usr/include/... [ OK ]
[22:53:21] Scanning for string /usr/include/.../.tmp [ OK ]
[22:53:21] Scanning for string /usr/lib/... [ OK ]
[22:53:21] Scanning for string /usr/lib/.../.ssh [ OK ]
[22:53:21] Scanning for string /usr/lib/.../bkit-ssh [ OK ]
[22:53:21] Scanning for string /usr/lib/.bkit- [ OK ]
[22:53:21] Scanning for string /tmp/.bkp [ OK ]
[22:53:21] Scanning for string /tmp/.cinik [ OK ]
[22:53:21] Scanning for string /tmp/.font-unix/.cinik [ OK ]
[22:53:21] Scanning for string /lib/.sso [ OK ]
[22:53:21] Scanning for string /lib/.so [ OK ]
[22:53:21] Scanning for string /var/run/...dica/clean [ OK ]
[22:53:21] Scanning for string /var/run/...dica/dxr [ OK ]
[22:53:21] Scanning for string /var/run/...dica/read [ OK ]
[22:53:21] Scanning for string /var/run/...dica/write [ OK ]
[22:53:21] Scanning for string /var/run/...dica/lf [ OK ]
[22:53:21] Scanning for string /var/run/...dica/xl [ OK ]
[22:53:21] Scanning for string /var/run/...dica/xdr [ OK ]
[22:53:21] Scanning for string /var/run/...dica/psg [ OK ]
[22:53:21] Scanning for string /var/run/...dica/secure [ OK ]
[22:53:21] Scanning for string /var/run/...dica/rdx [ OK ]
[22:53:21] Scanning for string /var/run/...dica/va [ OK ]
[22:53:21] Scanning for string /var/run/...dica/cl.sh [ OK ]
[22:53:21] Scanning for string /var/run/...dica/last.log [ OK ]
[22:53:21] Scanning for string /usr/bin/.etc [ OK ]
[22:53:21] Scanning for string /etc/sshd_config [ OK ]
[22:53:21] Scanning for string /etc/ssh_host_key [ OK ]
[22:53:21] Scanning for string /etc/ssh_random_seed [ OK ]
[22:53:21] Scanning for string /dev/ptyp [ OK ]
[22:53:21] Scanning for string /dev/ptyq [ OK ]
[22:53:21] Scanning for string /dev/ptyr [ OK ]
[22:53:21] Scanning for string /dev/ptys [ OK ]
[22:53:21] Scanning for string /dev/ptyt [ OK ]
[22:53:21] Scanning for string /dev/fd/.88/freshb-bsd [ OK ]
[22:53:21] Scanning for string /dev/fd/.88/fresht [ OK ]
[22:53:21] Scanning for string /dev/fd/.88/zxsniff [ OK ]
[22:53:21] Scanning for string /dev/fd/.88/zxsniff.log [ OK ]
[22:53:21] Scanning for string /dev/fd/.99/.ttyf00 [ OK ]
[22:53:22] Scanning for string /dev/fd/.99/.ttyp00 [ OK ]
[22:53:22] Scanning for string /dev/fd/.99/.ttyq00 [ OK ]
[22:53:22] Scanning for string /dev/fd/.99/.ttys00 [ OK ]
[22:53:22] Scanning for string /dev/fd/.99/.pwsx00 [ OK ]
[22:53:22] Scanning for string /etc/.acid [ OK ]
[22:53:22] Scanning for string /usr/lib/.fx/sched_host.2 [ OK ]
[22:53:22] Scanning for string /usr/lib/.fx/random_d.2 [ OK ]
[22:53:22] Scanning for string /usr/lib/.fx/set_pid.2 [ OK ]
[22:53:22] Scanning for string /usr/lib/.fx/setrgrp.2 [ OK ]
[22:53:22] Scanning for string /usr/lib/.fx/TOHIDE [ OK ]
[22:53:22] Scanning for string /usr/lib/.fx/cons.saver [ OK ]
[22:53:22] Scanning for string /usr/lib/.fx/adore/ava/ava [ OK ]
[22:53:22] Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[22:53:22] Scanning for string /bin/sysback [ OK ]
[22:53:22] Scanning for string /usr/local/bin/sysback [ OK ]
[22:53:22] Scanning for string /usr/lib/.tbd [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/t0rns [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/du [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/ls [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/t0rnsb [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/ps [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/t0rnp [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/find [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/ifconfig [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/pg [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/ssh.tgz [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/top [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/sz [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/login [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/1i0n.sh [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/pstree [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/mjy [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/sush [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/tfn [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/name [ OK ]
[22:53:22] Scanning for string /dev/.lib/lib/lib/getip.sh [ OK ]
[22:53:22] Scanning for string /usr/info/.torn/sh* [ OK ]
[22:53:22] Scanning for string /usr/src/.puta/.1addr [ OK ]
[22:53:22] Scanning for string /usr/src/.puta/.1file [ OK ]
[22:53:22] Scanning for string /usr/src/.puta/.1proc [ OK ]
[22:53:22] Scanning for string /usr/src/.puta/.1logz [ OK ]
[22:53:23] Scanning for string /usr/info/.t0rn [ OK ]
[22:53:23] Scanning for string /dev/.lib [ OK ]
[22:53:23] Scanning for string /dev/.lib/lib [ OK ]
[22:53:23] Scanning for string /dev/.lib/lib/lib [ OK ]
[22:53:23] Scanning for string /dev/.lib/lib/lib/dev [ OK ]
[22:53:23] Scanning for string /dev/.lib/lib/scan [ OK ]
[22:53:23] Scanning for string /usr/src/.puta [ OK ]
[22:53:23] Scanning for string /usr/man/man1/man1 [ OK ]
[22:53:23] Scanning for string /usr/man/man1/man1/lib [ OK ]
[22:53:23] Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[22:53:23] Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[22:53:23]
[22:53:23] Info: Starting test name 'shared_libs'
[22:53:23] Performing 'shared libraries' checks
[22:53:23] Checking for preloading variables [ None found ]
[22:53:23] Checking for preloaded libraries [ None found ]
[22:53:23]
[22:53:23] Info: Starting test name 'shared_libs_path'
[22:53:23] Checking LD_LIBRARY_PATH variable [ Not found ]
[22:53:23]
[22:53:23] Info: Starting test name 'properties'
[22:53:23] Performing file properties checks
[22:53:23] Checking for prerequisites [ OK ]
[22:53:26] /usr/sbin/adduser [ OK ]
[22:53:26] Info: Found file '/usr/sbin/adduser': it is whitelisted for the 'script replacement' check.
[22:53:26] /usr/sbin/chroot [ OK ]
[22:53:27] /usr/sbin/cron [ OK ]
[22:53:27] /usr/sbin/groupadd [ OK ]
[22:53:27] /usr/sbin/groupdel [ OK ]
[22:53:27] /usr/sbin/groupmod [ OK ]
[22:53:27] /usr/sbin/grpck [ OK ]
[22:53:28] /usr/sbin/nologin [ OK ]
[22:53:28] /usr/sbin/pwck [ OK ]
[22:53:28] /usr/sbin/rsyslogd [ OK ]
[22:53:28] /usr/sbin/sshd [ OK ]
[22:53:28] /usr/sbin/useradd [ OK ]
[22:53:28] /usr/sbin/userdel [ OK ]
[22:53:28] /usr/sbin/usermod [ OK ]
[22:53:29] /usr/sbin/vipw [ OK ]
[22:53:29] /usr/sbin/unhide [ OK ]
[22:53:29] /usr/sbin/unhide-linux [ OK ]
[22:53:29] /usr/sbin/unhide-posix [ OK ]
[22:53:29] /usr/sbin/unhide-tcp [ OK ]
[22:53:29] /usr/bin/awk [ OK ]
[22:53:29] /usr/bin/basename [ OK ]
[22:53:29] /usr/bin/chattr [ OK ]
[22:53:30] /usr/bin/curl [ OK ]
[22:53:30] /usr/bin/cut [ OK ]
[22:53:30] /usr/bin/diff [ OK ]
[22:53:30] /usr/bin/dirname [ OK ]
[22:53:30] /usr/bin/dpkg [ OK ]
[22:53:30] /usr/bin/dpkg-query [ OK ]
[22:53:30] /usr/bin/du [ OK ]
[22:53:30] /usr/bin/env [ OK ]
[22:53:30] /usr/bin/file [ OK ]
[22:53:30] /usr/bin/find [ OK ]
[22:53:30] /usr/bin/GET [ OK ]
[22:53:31] /usr/bin/groups [ OK ]
[22:53:31] /usr/bin/head [ OK ]
[22:53:31] /usr/bin/id [ OK ]
[22:53:31] /usr/bin/ipcs [ OK ]
[22:53:31] /usr/bin/killall [ OK ]
[22:53:31] /usr/bin/last [ OK ]
[22:53:31] /usr/bin/lastlog [ OK ]
[22:53:31] /usr/bin/ldd [ OK ]
[22:53:31] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
[22:53:31] /usr/bin/less [ OK ]
[22:53:31] /usr/bin/locate [ OK ]
[22:53:32] /usr/bin/logger [ OK ]
[22:53:32] /usr/bin/lsattr [ OK ]
[22:53:32] /usr/bin/lsof [ OK ]
[22:53:32] /usr/bin/mail [ OK ]
[22:53:32] /usr/bin/md5sum [ OK ]
[22:53:32] /usr/bin/mlocate [ OK ]
[22:53:32] /usr/bin/newgrp [ OK ]
[22:53:32] /usr/bin/passwd [ OK ]
[22:53:32] /usr/bin/perl [ OK ]
[22:53:32] /usr/bin/pgrep [ OK ]
[22:53:33] /usr/bin/pkill [ OK ]
[22:53:33] /usr/bin/pstree [ OK ]
[22:53:33] /usr/bin/rkhunter [ OK ]
[22:53:33] /usr/bin/runcon [ OK ]
[22:53:33] /usr/bin/sha1sum [ OK ]
[22:53:33] /usr/bin/sha224sum [ OK ]
[22:53:33] /usr/bin/sha256sum [ OK ]
[22:53:33] /usr/bin/sha384sum [ OK ]
[22:53:33] /usr/bin/sha512sum [ OK ]
[22:53:34] /usr/bin/size [ OK ]
[22:53:34] /usr/bin/sort [ OK ]
[22:53:34] /usr/bin/ssh [ OK ]
[22:53:34] /usr/bin/stat [ OK ]
[22:53:34] /usr/bin/strace [ OK ]
[22:53:34] /usr/bin/strings [ OK ]
[22:53:34] /usr/bin/sudo [ OK ]
[22:53:34] /usr/bin/tail [ OK ]
[22:53:34] /usr/bin/telnet [ OK ]
[22:53:34] /usr/bin/test [ OK ]
[22:53:35] /usr/bin/top [ OK ]
[22:53:35] /usr/bin/touch [ OK ]
[22:53:35] /usr/bin/tr [ OK ]
[22:53:35] /usr/bin/uniq [ OK ]
[22:53:35] /usr/bin/users [ OK ]
[22:53:35] /usr/bin/vmstat [ OK ]
[22:53:35] /usr/bin/w [ OK ]
[22:53:35] /usr/bin/watch [ OK ]
[22:53:35] /usr/bin/wc [ OK ]
[22:53:35] /usr/bin/wget [ OK ]
[22:53:35] /usr/bin/whatis [ OK ]
[22:53:35] /usr/bin/whereis [ OK ]
[22:53:36] /usr/bin/which [ OK ]
[22:53:36] /usr/bin/who [ OK ]
[22:53:36] /usr/bin/whoami [ OK ]
[22:53:36] /usr/bin/numfmt [ OK ]
[22:53:36] /usr/bin/gawk [ OK ]
[22:53:36] /usr/bin/lwp-request [ Warning ]
[22:53:36] Warning: The command '/usr/bin/lwp-request' has been replaced by a script: /usr/bin/lwp-request: Perl script text executable
[22:53:36] /usr/bin/mail.mailutils [ OK ]
[22:53:36] /usr/bin/x86_64-linux-gnu-size [ OK ]
[22:53:36] /usr/bin/x86_64-linux-gnu-strings [ OK ]
[22:53:36] /usr/bin/telnet.netkit [ OK ]
[22:53:36] /usr/bin/w.procps [ OK ]
[22:53:37] /sbin/depmod [ OK ]
[22:53:37] /sbin/fsck [ OK ]
[22:53:37] /sbin/ifconfig [ OK ]
[22:53:37] /sbin/init [ OK ]
[22:53:37] /sbin/insmod [ OK ]
[22:53:37] /sbin/ip [ OK ]
[22:53:38] /sbin/lsmod [ OK ]
[22:53:38] /sbin/modinfo [ OK ]
[22:53:38] /sbin/modprobe [ OK ]
[22:53:38] /sbin/rmmod [ OK ]
[22:53:38] /sbin/route [ OK ]
[22:53:38] /sbin/runlevel [ OK ]
[22:53:39] /sbin/sulogin [ OK ]
[22:53:39] /sbin/sysctl [ OK ]
[22:53:39] /bin/bash [ OK ]
[22:53:39] /bin/cat [ OK ]
[22:53:40] /bin/chmod [ OK ]
[22:53:40] /bin/chown [ OK ]
[22:53:40] /bin/cp [ OK ]
[22:53:40] /bin/date [ OK ]
[22:53:40] /bin/df [ OK ]
[22:53:40] /bin/dmesg [ OK ]
[22:53:40] /bin/echo [ OK ]
[22:53:40] /bin/ed [ OK ]
[22:53:40] /bin/egrep [ OK ]
[22:53:40] Info: Found file '/bin/egrep': it is whitelisted for the 'script replacement' check.
[22:53:40] /bin/fgrep [ OK ]
[22:53:40] Info: Found file '/bin/fgrep': it is whitelisted for the 'script replacement' check.
[22:53:41] /bin/fuser [ OK ]
[22:53:41] /bin/grep [ OK ]
[22:53:41] /bin/ip [ OK ]
[22:53:41] /bin/kill [ OK ]
[22:53:41] /bin/less [ OK ]
[22:53:41] /bin/login [ OK ]
[22:53:41] /bin/ls [ OK ]
[22:53:41] /bin/lsmod [ OK ]
[22:53:42] /bin/mktemp [ OK ]
[22:53:42] /bin/more [ OK ]
[22:53:42] /bin/mount [ OK ]
[22:53:42] /bin/mv [ OK ]
[22:53:42] /bin/netstat [ OK ]
[22:53:42] /bin/ping [ OK ]
[22:53:42] /bin/ps [ OK ]
[22:53:42] /bin/pwd [ OK ]
[22:53:42] /bin/readlink [ OK ]
[22:53:43] /bin/sed [ OK ]
[22:53:43] /bin/sh [ OK ]
[22:53:43] /bin/su [ OK ]
[22:53:43] /bin/touch [ OK ]
[22:53:43] /bin/uname [ OK ]
[22:53:43] /bin/which [ OK ]
[22:53:43] Info: Found file '/bin/which': it is whitelisted for the 'script replacement' check.
[22:53:44] /bin/kmod [ OK ]
[22:53:44] /bin/systemd [ OK ]
[22:53:44] /bin/systemctl [ OK ]
[22:53:44] /bin/dash [ OK ]
[22:53:53] /lib/systemd/systemd [ OK ]
[22:57:04]
[22:57:04] Info: Starting test name 'rootkits'
[22:57:04] Checking for rootkits...
[22:57:04]
[22:57:04] Info: Starting test name 'known_rkts'
[22:57:04] Performing check of known rootkit files and directories
[22:57:04]
[22:57:04] Checking for 55808 Trojan - Variant A...
[22:57:04] Checking for file '/tmp/.../r' [ Not found ]
[22:57:04] Checking for file '/tmp/.../a' [ Not found ]
[22:57:04] 55808 Trojan - Variant A [ Not found ]
[22:57:04]
[22:57:04] Checking for ADM Worm...
[22:57:04] Checking for string 'w0rm' [ Not found ]
[22:57:04] ADM Worm [ Not found ]
[22:57:04]
[22:57:04] Checking for AjaKit Rootkit...
[22:57:04] Checking for file '/dev/tux/.addr' [ Not found ]
[22:57:04] Checking for file '/dev/tux/.proc' [ Not found ]
[22:57:04] Checking for file '/dev/tux/.file' [ Not found ]
[22:57:04] Checking for file '/lib/.libgh-gh/cleaner' [ Not found ]
[22:57:04] Checking for file '/lib/.libgh-gh/Patch/patch' [ Not found ]
[22:57:04] Checking for file '/lib/.libgh-gh/sb0k' [ Not found ]
[22:57:04] Checking for directory '/dev/tux' [ Not found ]
[22:57:04] Checking for directory '/lib/.libgh-gh' [ Not found ]
[22:57:04] AjaKit Rootkit [ Not found ]
[22:57:04]
[22:57:04] Checking for Adore Rootkit...
[22:57:04] Checking for file '/usr/secure' [ Not found ]
[22:57:04] Checking for file '/usr/doc/sys/qrt' [ Not found ]
[22:57:04] Checking for file '/usr/doc/sys/run' [ Not found ]
[22:57:04] Checking for file '/usr/doc/sys/crond' [ Not found ]
[22:57:04] Checking for file '/usr/sbin/kfd' [ Not found ]
[22:57:04] Checking for file '/usr/doc/kern/var' [ Not found ]
[22:57:04] Checking for file '/usr/doc/kern/string.o' [ Not found ]
[22:57:04] Checking for file '/usr/doc/kern/ava' [ Not found ]
[22:57:04] Checking for file '/usr/doc/kern/adore.o' [ Not found ]
[22:57:04] Checking for file '/var/log/ssh/old' [ Not found ]
[22:57:04] Checking for directory '/lib/security/.config/ssh' [ Not found ]
[22:57:04] Checking for directory '/usr/doc/kern' [ Not found ]
[22:57:04] Checking for directory '/usr/doc/backup' [ Not found ]
[22:57:04] Checking for directory '/usr/doc/backup/txt' [ Not found ]
[22:57:04] Checking for directory '/lib/backup' [ Not found ]
[22:57:04] Checking for directory '/lib/backup/txt' [ Not found ]
[22:57:04] Checking for directory '/usr/doc/work' [ Not found ]
[22:57:04] Checking for directory '/usr/doc/sys' [ Not found ]
[22:57:04] Checking for directory '/var/log/ssh' [ Not found ]
[22:57:04] Checking for directory '/usr/doc/.spool' [ Not found ]
[22:57:04] Checking for directory '/usr/lib/kterm' [ Not found ]
[22:57:04] Adore Rootkit [ Not found ]
[22:57:04]
[22:57:04] Checking for aPa Kit...
[22:57:04] Checking for file '/usr/share/.aPa' [ Not found ]
[22:57:04] aPa Kit [ Not found ]
[22:57:04]
[22:57:04] Checking for Apache Worm...
[22:57:04] Checking for file '/bin/.log' [ Not found ]
[22:57:04] Apache Worm [ Not found ]
[22:57:04]
[22:57:04] Checking for Ambient (ark) Rootkit...
[22:57:04] Checking for file '/usr/lib/.ark?' [ Not found ]
[22:57:04] Checking for file '/dev/ptyxx/.log' [ Not found ]
[22:57:05] Checking for file '/dev/ptyxx/.file' [ Not found ]
[22:57:05] Checking for file '/dev/ptyxx/.proc' [ Not found ]
[22:57:05] Checking for file '/dev/ptyxx/.addr' [ Not found ]
[22:57:05] Checking for directory '/dev/ptyxx' [ Not found ]
[22:57:05] Ambient (ark) Rootkit [ Not found ]
[22:57:05]
[22:57:05] Checking for Balaur Rootkit...
[22:57:05] Checking for file '/usr/lib/liblog.o' [ Not found ]
[22:57:05] Checking for directory '/usr/lib/.kinetic' [ Not found ]
[22:57:05] Checking for directory '/usr/lib/.egcs' [ Not found ]
[22:57:05] Checking for directory '/usr/lib/.wormie' [ Not found ]
[22:57:05] Balaur Rootkit [ Not found ]
[22:57:05]
[22:57:05] Checking for BeastKit Rootkit...
[22:57:05] Checking for file '/usr/sbin/arobia' [ Not found ]
[22:57:05] Checking for file '/usr/sbin/idrun' [ Not found ]
[22:57:05] Checking for file '/usr/lib/elm/arobia/elm' [ Not found ]
[22:57:05] Checking for file '/usr/lib/elm/arobia/elm/hk' [ Not found ]
[22:57:05] Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
[22:57:05] Checking for file '/usr/lib/elm/arobia/elm/sc' [ Not found ]
[22:57:05] Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
[22:57:05] Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
[22:57:05] Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
[22:57:05] Checking for directory '/lib/ldd.so/bktools' [ Not found ]
[22:57:05] BeastKit Rootkit [ Not found ]
[22:57:05]
[22:57:05] Checking for beX2 Rootkit...
[22:57:05] Checking for file '/usr/info/termcap.info-5.gz' [ Not found ]
[22:57:05] Checking for file '/usr/bin/sshd2' [ Not found ]
[22:57:05] Checking for directory '/usr/include/bex' [ Not found ]
[22:57:05] beX2 Rootkit [ Not found ]
[22:57:05]
[22:57:05] Checking for BOBKit Rootkit...
[22:57:05] Checking for file '/usr/sbin/ntpsx' [ Not found ]
[22:57:05] Checking for file '/usr/sbin/.../bkit-ava' [ Not found ]
[22:57:05] Checking for file '/usr/sbin/.../bkit-d' [ Not found ]
[22:57:05] Checking for file '/usr/sbin/.../bkit-shd' [ Not found ]
[22:57:05] Checking for file '/usr/sbin/.../bkit-f' [ Not found ]
[22:57:05] Checking for file '/usr/include/.../proc.h' [ Not found ]
[22:57:05] Checking for file '/usr/include/.../.bash_history' [ Not found ]
[22:57:05] Checking for file '/usr/include/.../bkit-get' [ Not found ]
[22:57:05] Checking for file '/usr/include/.../bkit-dl' [ Not found ]
[22:57:05] Checking for file '/usr/include/.../bkit-screen' [ Not found ]
[22:57:05] Checking for file '/usr/include/.../bkit-sleep' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../bkit-adore.o' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../ls' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../netstat' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../lsof' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../bkit-ssh/bkit-mots' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../uconf.inv' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../psr' [ Not found ]
[22:57:05] Checking for file '/usr/lib/.../find' [ Not found ]
[22:57:06] Checking for file '/usr/lib/.../pstree' [ Not found ]
[22:57:06] Checking for file '/usr/lib/.../slocate' [ Not found ]
[22:57:06] Checking for file '/usr/lib/.../du' [ Not found ]
[22:57:06] Checking for file '/usr/lib/.../top' [ Not found ]
[22:57:06] Checking for directory '/usr/sbin/...' [ Not found ]
[22:57:06] Checking for directory '/usr/include/...' [ Not found ]
[22:57:06] Checking for directory '/usr/include/.../.tmp' [ Not found ]
[22:57:06] Checking for directory '/usr/lib/...' [ Not found ]
[22:57:06] Checking for directory '/usr/lib/.../.ssh' [ Not found ]
[22:57:06] Checking for directory '/usr/lib/.../bkit-ssh' [ Not found ]
[22:57:06] Checking for directory '/usr/lib/.bkit-' [ Not found ]
[22:57:06] Checking for directory '/tmp/.bkp' [ Not found ]
[22:57:06] BOBKit Rootkit [ Not found ]
[22:57:06]
[22:57:06] Checking for cb Rootkit...
[22:57:06] Checking for file '/dev/srd0' [ Not found ]
[22:57:06] Checking for file '/lib/libproc.so.2.0.6' [ Not found ]
[22:57:06] Checking for file '/dev/mounnt' [ Not found ]
[22:57:06] Checking for file '/etc/rc.d/init.d/init' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/cl' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/.x.tgz' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/statdx' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/wted' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/write' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/scan' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/sc' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/sl2' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/wroot' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/wscan' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/wu' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/v' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/read' [ Not found ]
[22:57:06] Checking for file '/usr/lib/sshrc' [ Not found ]
[22:57:06] Checking for file '/usr/lib/ssh_host_key' [ Not found ]
[22:57:06] Checking for file '/usr/lib/ssh_host_key.pub' [ Not found ]
[22:57:06] Checking for file '/usr/lib/ssh_random_seed' [ Not found ]
[22:57:06] Checking for file '/usr/lib/sshd_config' [ Not found ]
[22:57:06] Checking for file '/usr/lib/shosts.equiv' [ Not found ]
[22:57:06] Checking for file '/usr/lib/ssh_known_hosts' [ Not found ]
[22:57:06] Checking for file '/u/zappa/.ssh/pid' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.system/..<SP>/tcp.log' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/curatare/attrib' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/curatare/chattr' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/curatare/ps' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.zeen/..<SP>/curatare/pstree' [ Not found ]
[22:57:06] Checking for file '/usr/bin/.system/..<SP>/.x/xC.o' [ Not found ]
[22:57:06] Checking for directory '/usr/bin/.zeen' [ Not found ]
[22:57:06] Checking for directory '/usr/bin/.zeen/..<SP>/curatare' [ Not found ]
[22:57:06] Checking for directory '/usr/bin/.zeen/..<SP>/scan' [ Not found ]
[22:57:06] Checking for directory '/usr/bin/.system/..<SP>' [ Not found ]
[22:57:06] cb Rootkit [ Not found ]
[22:57:06]
[22:57:06] Checking for CiNIK Worm (Slapper.B variant)...
[22:57:06] Checking for file '/tmp/.cinik' [ Not found ]
[22:57:07] Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
[22:57:07] CiNIK Worm (Slapper.B variant) [ Not found ]
[22:57:07]
[22:57:07] Checking for Danny-Boy's Abuse Kit...
[22:57:07] Checking for file '/dev/mdev' [ Not found ]
[22:57:07] Checking for file '/usr/lib/libX.a' [ Not found ]
[22:57:07] Danny-Boy's Abuse Kit [ Not found ]
[22:57:07]
[22:57:07] Checking for Devil RootKit...
[22:57:07] Checking for file '/var/lib/games/.src' [ Not found ]
[22:57:07] Checking for file '/dev/dsx' [ Not found ]
[22:57:07] Checking for file '/dev/caca' [ Not found ]
[22:57:07] Checking for file '/dev/pro' [ Not found ]
[22:57:07] Checking for file '/bin/bye' [ Not found ]
[22:57:07] Checking for file '/bin/homedir' [ Not found ]
[22:57:07] Checking for file '/usr/bin/xfss' [ Not found ]
[22:57:07] Checking for file '/usr/sbin/tzava' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/holber' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/sense' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/clear' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/tzava' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/citeste' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/killrk' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/searchlog' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/gaoaza' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/cleaner' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/shk' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/srs' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/utile.tgz' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/webpage' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/getpsy' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/getbnc' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/getemech' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/localroot.sh' [ Not found ]
[22:57:07] Checking for file '/usr/doc/tar/.../.dracusor/stuff/old/sense' [ Not found ]
[22:57:07] Checking for directory '/usr/doc/tar/.../.dracusor' [ Not found ]
[22:57:07] Devil RootKit [ Not found ]
[22:57:07]
[22:57:07] Checking for Diamorphine LKM...
[22:57:07] Checking for kernel symbol 'diamorphine' [ Not found ]
[22:57:07] Checking for kernel symbol 'module_hide' [ Not found ]
[22:57:07] Checking for kernel symbol 'module_hidden' [ Not found ]
[22:57:08] Checking for kernel symbol 'is_invisible' [ Not found ]
[22:57:08] Checking for kernel symbol 'hacked_getdents' [ Not found ]
[22:57:08] Checking for kernel symbol 'hacked_kill' [ Not found ]
[22:57:08] Diamorphine LKM [ Not found ]
[22:57:08]
[22:57:08] Checking for Dica-Kit Rootkit...
[22:57:08] Checking for file '/lib/.sso' [ Not found ]
[22:57:08] Checking for file '/lib/.so' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/clean' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/dxr' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/read' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/write' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/lf' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/xl' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/xdr' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/psg' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/secure' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/rdx' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/va' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/cl.sh' [ Not found ]
[22:57:08] Checking for file '/var/run/...dica/last.log' [ Not found ]
[22:57:08] Checking for file '/usr/bin/.etc' [ Not found ]
[22:57:08] Checking for file '/etc/sshd_config' [ Not found ]
[22:57:08] Checking for file '/etc/ssh_host_key' [ Not found ]
[22:57:08] Checking for file '/etc/ssh_random_seed' [ Not found ]
[22:57:08] Checking for directory '/var/run/...dica' [ Not found ]
[22:57:08] Checking for directory '/var/run/...dica/mh' [ Not found ]
[22:57:08] Checking for directory '/var/run/...dica/scan' [ Not found ]
[22:57:08] Dica-Kit Rootkit [ Not found ]
[22:57:08]
[22:57:08] Checking for Dreams Rootkit...
[22:57:08] Checking for file '/dev/ttyoa' [ Not found ]
[22:57:08] Checking for file '/dev/ttyof' [ Not found ]
[22:57:08] Checking for file '/dev/ttyop' [ Not found ]
[22:57:08] Checking for file '/usr/bin/sense' [ Not found ]
[22:57:08] Checking for file '/usr/bin/sl2' [ Not found ]
[22:57:08] Checking for file '/usr/bin/logclear' [ Not found ]
[22:57:08] Checking for file '/usr/bin/(swapd)' [ Not found ]
[22:57:08] Checking for file '/usr/bin/initrd' [ Not found ]
[22:57:08] Checking for file '/usr/bin/crontabs' [ Not found ]
[22:57:08] Checking for file '/usr/bin/snfs' [ Not found ]
[22:57:08] Checking for file '/usr/lib/libsss' [ Not found ]
[22:57:08] Checking for file '/usr/lib/libsnf.log' [ Not found ]
[22:57:08] Checking for file '/usr/lib/libshtift/top' [ Not found ]
[22:57:08] Checking for file '/usr/lib/libshtift/ps' [ Not found ]
[22:57:08] Checking for file '/usr/lib/libshtift/netstat' [ Not found ]
[22:57:08] Checking for file '/usr/lib/libshtift/ls' [ Not found ]
[22:57:08] Checking for file '/usr/lib/libshtift/ifconfig' [ Not found ]
[22:57:08] Checking for file '/usr/include/linseed.h' [ Not found ]
[22:57:09] Checking for file '/usr/include/linpid.h' [ Not found ]
[22:57:09] Checking for file '/usr/include/linkey.h' [ Not found ]
[22:57:09] Checking for file '/usr/include/linconf.h' [ Not found ]
[22:57:09] Checking for file '/usr/include/iceseed.h' [ Not found ]
[22:57:09] Checking for file '/usr/include/icepid.h' [ Not found ]
[22:57:09] Checking for file '/usr/include/icekey.h' [ Not found ]
[22:57:09] Checking for file '/usr/include/iceconf.h' [ Not found ]
[22:57:09] Checking for directory '/dev/ida/.hpd' [ Not found ]
[22:57:09] Checking for directory '/usr/lib/libshtift' [ Not found ]
[22:57:09] Dreams Rootkit [ Not found ]
[22:57:09]
[22:57:09] Checking for Duarawkz Rootkit...
[22:57:09] Checking for file '/usr/bin/duarawkz/loginpass' [ Not found ]
[22:57:09] Checking for directory '/usr/bin/duarawkz' [ Not found ]
[22:57:09] Duarawkz Rootkit [ Not found ]
[22:57:09]
[22:57:09] Checking for Ebury backdoor...
[22:57:09] Checking for file '/lib/libns2.so' [ Not found ]
[22:57:09] Checking for file '/lib64/libns2.so' [ Not found ]
[22:57:09] Checking for file '/lib/libns5.so' [ Not found ]
[22:57:09] Checking for file '/lib64/libns5.so' [ Not found ]
[22:57:09] Checking for file '/lib/libpw3.so' [ Not found ]
[22:57:09] Checking for file '/lib64/libpw3.so' [ Not found ]
[22:57:09] Checking for file '/lib/libpw5.so' [ Not found ]
[22:57:09] Checking for file '/lib64/libpw5.so' [ Not found ]
[22:57:09] Checking for file '/lib/libsbr.so' [ Not found ]
[22:57:09] Checking for file '/lib64/libsbr.so' [ Not found ]
[22:57:09] Checking for file '/lib/libslr.so' [ Not found ]
[22:57:09] Checking for file '/lib64/libslr.so' [ Not found ]
[22:57:09] Checking for file '/lib/tls/libkeyutils.so.1' [ Not found ]
[22:57:09] Checking for file '/lib64/tls/libkeyutils.so.1' [ Not found ]
[22:57:09] Ebury backdoor [ Not found ]
[22:57:09]
[22:57:09] Checking for Enye LKM...
[22:57:09] Checking for file '/etc/.enyelkmHIDE^IT.ko' [ Not found ]
[22:57:09] Checking for file '/etc/.enyelkmOCULTAR.ko' [ Not found ]
[22:57:09] Enye LKM [ Not found ]
[22:57:09]
[22:57:09] Checking for Flea Linux Rootkit...
[22:57:09] Checking for file '/etc/ld.so.hash' [ Not found ]
[22:57:09] Checking for file '/lib/security/.config/ssh/sshd_config' [ Not found ]
[22:57:09] Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[22:57:09] Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[22:57:09] Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[22:57:09] Checking for file '/usr/bin/ssh2d' [ Not found ]
[22:57:09] Checking for file '/usr/lib/ldlibns.so' [ Not found ]
[22:57:09] Checking for file '/usr/lib/ldlibps.so' [ Not found ]
[22:57:09] Checking for file '/usr/lib/ldlibpst.so' [ Not found ]
[22:57:09] Checking for file '/usr/lib/ldlibdu.so' [ Not found ]
[22:57:09] Checking for file '/usr/lib/ldlibct.so' [ Not found ]
[22:57:09] Checking for directory '/lib/security/.config/ssh' [ Not found ]
[22:57:09] Checking for directory '/dev/..0' [ Not found ]
[22:57:09] Checking for directory '/dev/..0/backup' [ Not found ]
[22:57:09] Flea Linux Rootkit [ Not found ]
[22:57:09]
[22:57:09] Checking for Fu Rootkit...
[22:57:09] Checking for file '/sbin/xc' [ Not found ]
[22:57:09] Checking for file '/usr/include/ivtype.h' [ Not found ]
[22:57:10] Checking for file '/bin/.lib' [ Not found ]
[22:57:10] Fu Rootkit [ Not found ]
[22:57:10]
[22:57:10] Checking for Fuck`it Rootkit...
[22:57:10] Checking for file '/lib/libproc.so.2.0.7' [ Not found ]
[22:57:10] Checking for file '/dev/proc/.bash_profile' [ Not found ]
[22:57:10] Checking for file '/dev/proc/.bashrc' [ Not found ]
[22:57:10] Checking for file '/dev/proc/.cshrc' [ Not found ]
[22:57:10] Checking for file '/dev/proc/fuckit/hax0r' [ Not found ]
[22:57:10] Checking for file '/dev/proc/fuckit/hax0rshell' [ Not found ]
[22:57:10] Checking for file '/dev/proc/fuckit/config/lports' [ Not found ]
[22:57:10] Checking for file '/dev/proc/fuckit/config/rports' [ Not found ]
[22:57:10] Checking for file '/dev/proc/fuckit/config/rkconf' [ Not found ]
[22:57:10] Checking for file '/dev/proc/fuckit/config/password' [ Not found ]
[22:57:10] Checking for file '/dev/proc/fuckit/config/progs' [ Not found ]
[22:57:10] Checking for file '/dev/proc/fuckit/system-bins/init' [ Not found ]
[22:57:10] Checking for file '/usr/lib/libcps.a' [ Not found ]
[22:57:10] Checking for file '/usr/lib/libtty.a' [ Not found ]
[22:57:10] Checking for directory '/dev/proc' [ Not found ]
[22:57:10] Checking for directory '/dev/proc/fuckit' [ Not found ]
[22:57:10] Checking for directory '/dev/proc/fuckit/system-bins' [ Not found ]
[22:57:10] Checking for directory '/dev/proc/toolz' [ Not found ]
[22:57:10] Fuck`it Rootkit [ Not found ]
[22:57:10]
[22:57:10] Checking for GasKit Rootkit...
[22:57:10] Checking for file '/dev/dev/gaskit/sshd/sshdd' [ Not found ]
[22:57:10] Checking for directory '/dev/dev' [ Not found ]
[22:57:10] Checking for directory '/dev/dev/gaskit' [ Not found ]
[22:57:10] Checking for directory '/dev/dev/gaskit/sshd' [ Not found ]
[22:57:10] GasKit Rootkit [ Not found ]
[22:57:10]
[22:57:10] Checking for Heroin LKM...
[22:57:10] Checking for kernel symbol 'heroin' [ Not found ]
[22:57:10] Heroin LKM [ Not found ]
[22:57:10]
[22:57:10] Checking for HjC Kit...
[22:57:10] Checking for directory '/dev/.hijackerz' [ Not found ]
[22:57:10] HjC Kit [ Not found ]
[22:57:10]
[22:57:10] Checking for ignoKit Rootkit...
[22:57:10] Checking for file '/lib/defs/p' [ Not found ]
[22:57:10] Checking for file '/lib/defs/q' [ Not found ]
[22:57:10] Checking for file '/lib/defs/r' [ Not found ]
[22:57:10] Checking for file '/lib/defs/s' [ Not found ]
[22:57:10] Checking for file '/lib/defs/t' [ Not found ]
[22:57:10] Checking for file '/usr/lib/defs/p' [ Not found ]
[22:57:10] Checking for file '/usr/lib/defs/q' [ Not found ]
[22:57:10] Checking for file '/usr/lib/defs/r' [ Not found ]
[22:57:10] Checking for file '/usr/lib/defs/s' [ Not found ]
[22:57:10] Checking for file '/usr/lib/defs/t' [ Not found ]
[22:57:10] Checking for file '/usr/lib/.libigno/pkunsec' [ Not found ]
[22:57:10] Checking for file '/usr/lib/.libigno/.igno/psybnc/psybnc' [ Not found ]
[22:57:10] Checking for directory '/usr/lib/.libigno' [ Not found ]
[22:57:10] Checking for directory '/usr/lib/.libigno/.igno' [ Not found ]
[22:57:10] ignoKit Rootkit [ Not found ]
[22:57:10]
[22:57:10] Checking for IntoXonia-NG Rootkit...
[22:57:11] Checking for kernel symbol 'funces' [ Not found ]
[22:57:11] Checking for kernel symbol 'ixinit' [ Not found ]
[22:57:11] Checking for kernel symbol 'tricks' [ Not found ]
[22:57:11] Checking for kernel symbol 'kernel_unlink' [ Not found ]
[22:57:11] Checking for kernel symbol 'rootme' [ Not found ]
[22:57:11] Checking for kernel symbol 'hide_module' [ Not found ]
[22:57:11] Checking for kernel symbol 'find_sys_call_tbl' [ Not found ]
[22:57:11] IntoXonia-NG Rootkit [ Not found ]
[22:57:11]
[22:57:11] Checking for Irix Rootkit...
[22:57:11] Checking for directory '/dev/pts/01' [ Not found ]
[22:57:11] Checking for directory '/dev/pts/01/backup' [ Not found ]
[22:57:11] Checking for directory '/dev/pts/01/etc' [ Not found ]
[22:57:11] Checking for directory '/dev/pts/01/tmp' [ Not found ]
[22:57:11] Irix Rootkit [ Not found ]
[22:57:11]
[22:57:11] Checking for Jynx Rootkit...
[22:57:11] Checking for file '/xochikit/bc' [ Not found ]
[22:57:11] Checking for file '/xochikit/ld_poison.so' [ Not found ]
[22:57:11] Checking for file '/omgxochi/bc' [ Not found ]
[22:57:11] Checking for file '/omgxochi/ld_poison.so' [ Not found ]
[22:57:11] Checking for file '/var/local/^^/bc' [ Not found ]
[22:57:11] Checking for file '/var/local/^^/ld_poison.so' [ Not found ]
[22:57:11] Checking for directory '/xochikit' [ Not found ]
[22:57:11] Checking for directory '/omgxochi' [ Not found ]
[22:57:11] Checking for directory '/var/local/^^' [ Not found ]
[22:57:11] Jynx Rootkit [ Not found ]
[22:57:11]
[22:57:11] Checking for Jynx2 Rootkit...
[22:57:11] Checking for file '/XxJynx/reality.so' [ Not found ]
[22:57:11] Checking for directory '/XxJynx' [ Not found ]
[22:57:11] Jynx2 Rootkit [ Not found ]
[22:57:11]
[22:57:11] Checking for KBeast Rootkit...
[22:57:11] Checking for file '/usr/_h4x_/ipsecs-kbeast-v1.ko' [ Not found ]
[22:57:11] Checking for file '/usr/_h4x_/_h4x_bd' [ Not found ]
[22:57:11] Checking for file '/usr/_h4x_/acctlog' [ Not found ]
[22:57:11] Checking for directory '/usr/_h4x_' [ Not found ]
[22:57:12] Checking for kernel symbol 'h4x_delete_module' [ Not found ]
[22:57:12] Checking for kernel symbol 'h4x_getdents64' [ Not found ]
[22:57:12] Checking for kernel symbol 'h4x_kill' [ Not found ]
[22:57:12] Checking for kernel symbol 'h4x_open' [ Not found ]
[22:57:12] Checking for kernel symbol 'h4x_read' [ Not found ]
[22:57:12] Checking for kernel symbol 'h4x_rename' [ Not found ]
[22:57:12] Checking for kernel symbol 'h4x_rmdir' [ Not found ]
[22:57:12] Checking for kernel symbol 'h4x_tcp4_seq_show' [ Not found ]
[22:57:12] Checking for kernel symbol 'h4x_write' [ Not found ]
[22:57:12] KBeast Rootkit [ Not found ]
[22:57:12]
[22:57:12] Checking for Kitko Rootkit...
[22:57:12] Checking for directory '/usr/src/redhat/SRPMS/...' [ Not found ]
[22:57:12] Kitko Rootkit [ Not found ]
[22:57:12]
[22:57:12] Checking for Knark Rootkit...
[22:57:12] Checking for file '/proc/knark/pids' [ Not found ]
[22:57:12] Checking for directory '/proc/knark' [ Not found ]
[22:57:12] Knark Rootkit [ Not found ]
[22:57:12]
[22:57:12] Checking for ld-linuxv.so Rootkit...
[22:57:12] Checking for file '/lib/ld-linuxv.so.1' [ Not found ]
[22:57:12] Checking for directory '/var/opt/_so_cache' [ Not found ]
[22:57:12] Checking for directory '/var/opt/_so_cache/ld' [ Not found ]
[22:57:12] Checking for directory '/var/opt/_so_cache/lc' [ Not found ]
[22:57:12] ld-linuxv.so Rootkit [ Not found ]
[22:57:12]
[22:57:12] Checking for Li0n Worm...
[22:57:12] Checking for file '/bin/in.telnetd' [ Not found ]
[22:57:12] Checking for file '/bin/mjy' [ Not found ]
[22:57:12] Checking for file '/usr/man/man1/man1/lib/.lib/mjy' [ Not found ]
[22:57:13] Checking for file '/usr/man/man1/man1/lib/.lib/in.telnetd' [ Not found ]
[22:57:13] Checking for file '/usr/man/man1/man1/lib/.lib/.x' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/scan/1i0n.sh' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/scan/hack.sh' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/scan/bind' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/scan/randb' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/scan/scan.sh' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/scan/pscan' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/scan/star.sh' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/scan/bindx.sh' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/scan/bindname.log' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/1i0n.sh' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/lib/netstat' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/lib/dev/.1addr' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/lib/dev/.1logz' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/lib/dev/.1proc' [ Not found ]
[22:57:13] Checking for file '/dev/.lib/lib/lib/dev/.1file' [ Not found ]
[22:57:13] Li0n Worm [ Not found ]
[22:57:13]
[22:57:13] Checking for Lockit / LJK2 Rootkit...
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_config' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_random_seed*' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/sshd_config' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/du' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ifconfig' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/inetd.conf' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/locate' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/login' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ls' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/netstat' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ps' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/pstree' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/syslogd' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/tcpd' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/top' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1sauber' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1wted' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1parse' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1sniff' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1addr' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1dir' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1log' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1proc' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/README.modules' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1phide' [ Not found ]
[22:57:13] Checking for file '/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh' [ Not found ]
[22:57:13] Checking for directory '/usr/lib/libmen.oo/.LJK2' [ Not found ]
[22:57:13] Lockit / LJK2 Rootkit [ Not found ]
[22:57:13]
[22:57:13] Checking for Mokes backdoor...
[22:57:14] Checking for file '/tmp/ss0-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9].sst' [ Not found ]
[22:57:14] Checking for file '/tmp/aa0-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9].aat' [ Not found ]
[22:57:14] Checking for file '/tmp/kk0-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9].kkt' [ Not found ]
[22:57:14] Checking for file '/tmp/dd0-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9].ddt' [ Not found ]
[22:57:14] Mokes backdoor [ Not found ]
[22:57:14]
[22:57:14] Checking for Mood-NT Rootkit...
[22:57:14] Checking for file '/sbin/init__mood-nt-_-_cthulhu' [ Not found ]
[22:57:14] Checking for file '/_cthulhu/mood-nt.init' [ Not found ]
[22:57:14] Checking for file '/_cthulhu/mood-nt.conf' [ Not found ]
[22:57:14] Checking for file '/_cthulhu/mood-nt.sniff' [ Not found ]
[22:57:14] Checking for directory '/_cthulhu' [ Not found ]
[22:57:14] Mood-NT Rootkit [ Not found ]
[22:57:14]
[22:57:14] Checking for MRK Rootkit...
[22:57:14] Checking for file '/dev/ida/.inet/pid' [ Not found ]
[22:57:14] Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[22:57:14] Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[22:57:14] Checking for file '/dev/ida/.inet/tcp.log' [ Not found ]
[22:57:14] Checking for directory '/dev/ida/.inet' [ Not found ]
[22:57:14] Checking for directory '/var/spool/cron/.sh' [ Not found ]
[22:57:14] MRK Rootkit [ Not found ]
[22:57:14]
[22:57:14] Checking for Ni0 Rootkit...
[22:57:14] Checking for file '/var/lock/subsys/...datafile.../...net...' [ Not found ]
[22:57:14] Checking for file '/var/lock/subsys/...datafile.../...port...' [ Not found ]
[22:57:14] Checking for file '/var/lock/subsys/...datafile.../...ps...' [ Not found ]
[22:57:14] Checking for file '/var/lock/subsys/...datafile.../...file...' [ Not found ]
[22:57:14] Checking for directory '/tmp/waza' [ Not found ]
[22:57:14] Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[22:57:14] Checking for directory '/usr/sbin/es' [ Not found ]
[22:57:14] Ni0 Rootkit [ Not found ]
[22:57:14]
[22:57:14] Checking for Ohhara Rootkit...
[22:57:14] Checking for file '/var/lock/subsys/...datafile.../...datafile.../in.smbd.log' [ Not found ]
[22:57:14] Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[22:57:14] Checking for directory '/var/lock/subsys/...datafile.../...datafile...' [ Not found ]
[22:57:14] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../bin' [ Not found ]
[22:57:14] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/bin' [ Not found ]
[22:57:14] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/sbin' [ Not found ]
[22:57:14] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../lib/security' [ Not found ]
[22:57:14] Ohhara Rootkit [ Not found ]
[22:57:14]
[22:57:14] Checking for Optic Kit (Tux) Worm...
[22:57:14] Checking for directory '/dev/tux' [ Not found ]
[22:57:14] Checking for directory '/usr/bin/xchk' [ Not found ]
[22:57:14] Checking for directory '/usr/bin/xsf' [ Not found ]
[22:57:14] Checking for directory '/usr/bin/ssh2d' [ Not found ]
[22:57:14] Optic Kit (Tux) Worm [ Not found ]
[22:57:14]
[22:57:14] Checking for Oz Rootkit...
[22:57:14] Checking for file '/dev/.oz/.nap/rkit/terror' [ Not found ]
[22:57:14] Checking for directory '/dev/.oz' [ Not found ]
[22:57:14] Oz Rootkit [ Not found ]
[22:57:14]
[22:57:14] Checking for Phalanx Rootkit...
[22:57:14] Checking for file '/uNFuNF' [ Not found ]
[22:57:14] Checking for file '/etc/host.ph1' [ Not found ]
[22:57:14] Checking for file '/bin/host.ph1' [ Not found ]
[22:57:14] Checking for file '/usr/share/.home.ph1/phalanx' [ Not found ]
[22:57:14] Checking for file '/usr/share/.home.ph1/cb' [ Not found ]
[22:57:15] Checking for file '/usr/share/.home.ph1/kebab' [ Not found ]
[22:57:15] Checking for directory '/usr/share/.home.ph1' [ Not found ]
[22:57:15] Checking for directory '/usr/share/.home.ph1/tty' [ Not found ]
[22:57:15] Phalanx Rootkit [ Not found ]
[22:57:15]
[22:57:15] Checking for Phalanx2 Rootkit...
[22:57:15] Checking for file '/etc/khubd.p2/.p2rc' [ Not found ]
[22:57:15] Checking for file '/etc/khubd.p2/.phalanx2' [ Not found ]
[22:57:15] Checking for file '/etc/khubd.p2/.sniff' [ Not found ]
[22:57:15] Checking for file '/etc/khubd.p2/sshgrab.py' [ Not found ]
[22:57:15] Checking for file '/etc/lolzz.p2/.p2rc' [ Not found ]
[22:57:15] Checking for file '/etc/lolzz.p2/.phalanx2' [ Not found ]
[22:57:15] Checking for file '/etc/lolzz.p2/.sniff' [ Not found ]
[22:57:15] Checking for file '/etc/lolzz.p2/sshgrab.py' [ Not found ]
[22:57:15] Checking for file '/etc/cron.d/zupzzplaceholder' [ Not found ]
[22:57:15] Checking for file '/usr/lib/zupzz.p2/.p-2.3d' [ Not found ]
[22:57:15] Checking for file '/usr/lib/zupzz.p2/.p2rc' [ Not found ]
[22:57:15] Checking for directory '/etc/khubd.p2' [ Not found ]
[22:57:15] Checking for directory '/etc/lolzz.p2' [ Not found ]
[22:57:15] Checking for directory '/usr/lib/zupzz.p2' [ Not found ]
[22:57:15] Phalanx2 Rootkit [ Not found ]
[22:57:15]
[22:57:15] Checking for Phalanx2 Rootkit (extended tests)...
[22:57:15] Checking for directory '/etc/khubd.p2' [ Not found ]
[22:57:15] Checking for directory '/etc/lolzz.p2' [ Not found ]
[22:57:15] Checking for directory '/usr/lib/zupzz.p2' [ Not found ]
[22:57:15] Phalanx2 Rootkit (extended tests) [ Not found ]
[22:57:15]
[22:57:15] Checking for Portacelo Rootkit...
[22:57:15] Checking for file '/var/lib/.../.ak' [ Not found ]
[22:57:15] Checking for file '/var/lib/.../.hk' [ Not found ]
[22:57:15] Checking for file '/var/lib/.../.rs' [ Not found ]
[22:57:15] Checking for file '/var/lib/.../.p' [ Not found ]
[22:57:15] Checking for file '/var/lib/.../getty' [ Not found ]
[22:57:15] Checking for file '/var/lib/.../lkt.o' [ Not found ]
[22:57:15] Checking for file '/var/lib/.../show' [ Not found ]
[22:57:15] Checking for file '/var/lib/.../nlkt.o' [ Not found ]
[22:57:15] Checking for file '/var/lib/.../ssshrc' [ Not found ]
[22:57:15] Checking for file '/var/lib/.../sssh_equiv' [ Not found ]
[22:57:15] Checking for file '/var/lib/.../sssh_known_hosts' [ Not found ]
[22:57:15] Checking for file '/var/lib/.../sssh_pid' [ Not found ]
[22:57:15] Checking for file '~/.sssh/known_hosts' [ Not found ]
[22:57:15] Portacelo Rootkit [ Not found ]
[22:57:15]
[22:57:15] Checking for R3dstorm Toolkit...
[22:57:15] Checking for file '/var/log/tk02/see_all' [ Not found ]
[22:57:15] Checking for file '/var/log/tk02/.scris' [ Not found ]
[22:57:15] Checking for file '/bin/.../sshd/sbin/sshd1' [ Not found ]
[22:57:15] Checking for file '/bin/.../hate/sk' [ Not found ]
[22:57:15] Checking for file '/bin/.../see_all' [ Not found ]
[22:57:15] Checking for directory '/var/log/tk02' [ Not found ]
[22:57:15] Checking for directory '/var/log/tk02/old' [ Not found ]
[22:57:15] Checking for directory '/bin/...' [ Not found ]
[22:57:15] R3dstorm Toolkit [ Not found ]
[22:57:16]
[22:57:16] Checking for RH-Sharpe's Rootkit...
[22:57:16] Checking for file '/bin/lps' [ Not found ]
[22:57:16] Checking for file '/usr/bin/lpstree' [ Not found ]
[22:57:16] Checking for file '/usr/bin/ltop' [ Not found ]
[22:57:16] Checking for file '/usr/bin/lkillall' [ Not found ]
[22:57:16] Checking for file '/usr/bin/ldu' [ Not found ]
[22:57:16] Checking for file '/usr/bin/lnetstat' [ Not found ]
[22:57:16] Checking for file '/usr/bin/wp' [ Not found ]
[22:57:16] Checking for file '/usr/bin/shad' [ Not found ]
[22:57:16] Checking for file '/usr/bin/vadim' [ Not found ]
[22:57:16] Checking for file '/usr/bin/slice' [ Not found ]
[22:57:16] Checking for file '/usr/bin/cleaner' [ Not found ]
[22:57:16] Checking for file '/usr/include/rpcsvc/du' [ Not found ]
[22:57:16] RH-Sharpe's Rootkit [ Not found ]
[22:57:16]
[22:57:16] Checking for RSHA's Rootkit...
[22:57:16] Checking for file '/bin/kr4p' [ Not found ]
[22:57:16] Checking for file '/usr/bin/n3tstat' [ Not found ]
[22:57:16] Checking for file '/usr/bin/chsh2' [ Not found ]
[22:57:16] Checking for file '/usr/bin/slice2' [ Not found ]
[22:57:16] Checking for file '/usr/src/linux/arch/alpha/lib/.lib/.1proc' [ Not found ]
[22:57:16] Checking for file '/etc/rc.d/arch/alpha/lib/.lib/.1addr' [ Not found ]
[22:57:16] Checking for directory '/etc/rc.d/rsha' [ Not found ]
[22:57:16] Checking for directory '/etc/rc.d/arch/alpha/lib/.lib' [ Not found ]
[22:57:16] RSHA's Rootkit [ Not found ]
[22:57:16]
[22:57:16] Checking for Scalper Worm...
[22:57:16] Checking for file '/tmp/.a' [ Not found ]
[22:57:16] Checking for file '/tmp/.uua' [ Not found ]
[22:57:16] Scalper Worm [ Not found ]
[22:57:16]
[22:57:16] Checking for Sebek LKM...
[22:57:16] Checking for kernel symbol 'adore or sebek' [ Not found ]
[22:57:16] Sebek LKM [ Not found ]
[22:57:16]
[22:57:16] Checking for Shutdown Rootkit...
[22:57:16] Checking for file '/usr/man/man5/..<SP>/.dir/scannah/asus' [ Not found ]
[22:57:16] Checking for file '/usr/man/man5/..<SP>/.dir/see' [ Not found ]
[22:57:16] Checking for file '/usr/man/man5/..<SP>/.dir/nscd' [ Not found ]
[22:57:16] Checking for file '/usr/man/man5/..<SP>/.dir/alpd' [ Not found ]
[22:57:16] Checking for file '/etc/rc.d/rc.local<SP>' [ Not found ]
[22:57:16] Checking for directory '/usr/man/man5/..<SP>/.dir' [ Not found ]
[22:57:16] Checking for directory '/usr/man/man5/..<SP>/.dir/scannah' [ Not found ]
[22:57:16] Checking for directory '/etc/rc.d/rc0.d/..<SP>/.dir' [ Not found ]
[22:57:16] Shutdown Rootkit [ Not found ]
[22:57:16]
[22:57:16] Checking for SHV4 Rootkit...
[22:57:16] Checking for file '/etc/ld.so.hash' [ Not found ]
[22:57:16] Checking for file '/lib/libext-2.so.7' [ Not found ]
[22:57:16] Checking for file '/lib/lidps1.so' [ Not found ]
[22:57:16] Checking for file '/lib/libproc.a' [ Not found ]
[22:57:16] Checking for file '/lib/libproc.so.2.0.6' [ Not found ]
[22:57:16] Checking for file '/lib/ldd.so/tks' [ Not found ]
[22:57:16] Checking for file '/lib/ldd.so/tkp' [ Not found ]
[22:57:16] Checking for file '/lib/ldd.so/tksb' [ Not found ]
[22:57:17] Checking for file '/lib/security/.config/sshd' [ Not found ]
[22:57:17] Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[22:57:17] Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[22:57:17] Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[22:57:17] Checking for file '/usr/include/file.h' [ Not found ]
[22:57:17] Checking for file '/usr/include/hosts.h' [ Not found ]
[22:57:17] Checking for file '/usr/include/lidps1.so' [ Not found ]
[22:57:17] Checking for file '/usr/include/log.h' [ Not found ]
[22:57:17] Checking for file '/usr/include/proc.h' [ Not found ]
[22:57:17] Checking for file '/usr/sbin/xntps' [ Not found ]
[22:57:17] Checking for file '/dev/srd0' [ Not found ]
[22:57:17] Checking for directory '/lib/ldd.so' [ Not found ]
[22:57:17] Checking for directory '/lib/security/.config' [ Not found ]
[22:57:17] Checking for directory '/lib/security/.config/ssh' [ Not found ]
[22:57:17] SHV4 Rootkit [ Not found ]
[22:57:17]
[22:57:17] Checking for SHV5 Rootkit...
[22:57:17] Checking for file '/etc/sh.conf' [ Not found ]
[22:57:17] Checking for file '/lib/libproc.a' [ Not found ]
[22:57:17] Checking for file '/lib/libproc.so.2.0.6' [ Not found ]
[22:57:17] Checking for file '/lib/lidps1.so' [ Not found ]
[22:57:17] Checking for file '/lib/libsh.so/bash' [ Not found ]
[22:57:17] Checking for file '/usr/include/file.h' [ Not found ]
[22:57:17] Checking for file '/usr/include/hosts.h' [ Not found ]
[22:57:17] Checking for file '/usr/include/log.h' [ Not found ]
[22:57:17] Checking for file '/usr/include/proc.h' [ Not found ]
[22:57:17] Checking for file '/lib/libsh.so/shdcf2' [ Not found ]
[22:57:17] Checking for file '/lib/libsh.so/shhk' [ Not found ]
[22:57:17] Checking for file '/lib/libsh.so/shhk.pub' [ Not found ]
[22:57:17] Checking for file '/lib/libsh.so/shrs' [ Not found ]
[22:57:17] Checking for file '/usr/lib/libsh/.bashrc' [ Not found ]
[22:57:17] Checking for file '/usr/lib/libsh/shsb' [ Not found ]
[22:57:17] Checking for file '/usr/lib/libsh/hide' [ Not found ]
[22:57:17] Checking for file '/usr/lib/libsh/.sniff/shsniff' [ Not found ]
[22:57:17] Checking for file '/usr/lib/libsh/.sniff/shp' [ Not found ]
[22:57:17] Checking for file '/dev/srd0' [ Not found ]
[22:57:17] Checking for directory '/lib/libsh.so' [ Not found ]
[22:57:17] Checking for directory '/usr/lib/libsh' [ Not found ]
[22:57:17] Checking for directory '/usr/lib/libsh/utilz' [ Not found ]
[22:57:17] Checking for directory '/usr/lib/libsh/.backup' [ Not found ]
[22:57:17] SHV5 Rootkit [ Not found ]
[22:57:17]
[22:57:17] Checking for Sin Rootkit...
[22:57:17] Checking for file '/dev/.haos/haos1/.f/Denyed' [ Not found ]
[22:57:17] Checking for file '/dev/ttyoa' [ Not found ]
[22:57:17] Checking for file '/dev/ttyof' [ Not found ]
[22:57:17] Checking for file '/dev/ttyop' [ Not found ]
[22:57:17] Checking for file '/dev/ttyos' [ Not found ]
[22:57:17] Checking for file '/usr/lib/.lib' [ Not found ]
[22:57:17] Checking for file '/usr/lib/sn/.X' [ Not found ]
[22:57:17] Checking for file '/usr/lib/sn/.sys' [ Not found ]
[22:57:17] Checking for file '/usr/lib/ld/.X' [ Not found ]
[22:57:17] Checking for file '/usr/man/man1/...' [ Not found ]
[22:57:17] Checking for file '/usr/man/man1/.../.m' [ Not found ]
[22:57:18] Checking for file '/usr/man/man1/.../.w' [ Not found ]
[22:57:18] Checking for directory '/usr/lib/sn' [ Not found ]
[22:57:18] Checking for directory '/usr/lib/man1/...' [ Not found ]
[22:57:18] Checking for directory '/dev/.haos' [ Not found ]
[22:57:18] Sin Rootkit [ Not found ]
[22:57:18]
[22:57:18] Checking for Slapper Worm...
[22:57:18] Checking for file '/tmp/.bugtraq' [ Not found ]
[22:57:18] Checking for file '/tmp/.uubugtraq' [ Not found ]
[22:57:18] Checking for file '/tmp/.bugtraq.c' [ Not found ]
[22:57:18] Checking for file '/tmp/httpd' [ Not found ]
[22:57:18] Checking for file '/tmp/.unlock' [ Not found ]
[22:57:18] Checking for file '/tmp/update' [ Not found ]
[22:57:18] Checking for file '/tmp/.cinik' [ Not found ]
[22:57:18] Checking for file '/tmp/.b' [ Not found ]
[22:57:18] Slapper Worm [ Not found ]
[22:57:18]
[22:57:18] Checking for Sneakin Rootkit...
[22:57:18] Checking for directory '/tmp/.X11-unix/.../rk' [ Not found ]
[22:57:18] Sneakin Rootkit [ Not found ]
[22:57:18]
[22:57:18] Checking for 'Spanish' Rootkit...
[22:57:18] Checking for file '/dev/ptyq' [ Not found ]
[22:57:18] Checking for file '/bin/ad' [ Not found ]
[22:57:18] Checking for file '/bin/ava' [ Not found ]
[22:57:18] Checking for file '/bin/server' [ Not found ]
[22:57:18] Checking for file '/usr/sbin/rescue' [ Not found ]
[22:57:18] Checking for file '/usr/share/.../chrps' [ Not found ]
[22:57:18] Checking for file '/usr/share/.../chrifconfig' [ Not found ]
[22:57:18] Checking for file '/usr/share/.../netstat' [ Not found ]
[22:57:18] Checking for file '/usr/share/.../linsniffer' [ Not found ]
[22:57:18] Checking for file '/usr/share/.../charbd' [ Not found ]
[22:57:18] Checking for file '/usr/share/.../charbd2' [ Not found ]
[22:57:18] Checking for file '/usr/share/.../charbd3' [ Not found ]
[22:57:18] Checking for file '/usr/share/.../charbd4' [ Not found ]
[22:57:18] Checking for file '/usr/man/tmp/update.tgz' [ Not found ]
[22:57:18] Checking for file '/var/lib/rpm/db.rpm' [ Not found ]
[22:57:18] Checking for file '/var/cache/man/.cat' [ Not found ]
[22:57:18] Checking for file '/var/spool/lpd/remote/.lpq' [ Not found ]
[22:57:18] Checking for directory '/usr/share/...' [ Not found ]
[22:57:18] 'Spanish' Rootkit [ Not found ]
[22:57:18]
[22:57:18] Checking for Suckit Rootkit...
[22:57:18] Checking for file '/sbin/initsk12' [ Not found ]
[22:57:18] Checking for file '/sbin/initxrk' [ Not found ]
[22:57:18] Checking for file '/usr/bin/null' [ Not found ]
[22:57:18] Checking for file '/usr/share/locale/sk/.sk12/sk' [ Not found ]
[22:57:18] Checking for file '/etc/rc.d/rc0.d/S23kmdac' [ Not found ]
[22:57:18] Checking for file '/etc/rc.d/rc1.d/S23kmdac' [ Not found ]
[22:57:18] Checking for file '/etc/rc.d/rc2.d/S23kmdac' [ Not found ]
[22:57:18] Checking for file '/etc/rc.d/rc3.d/S23kmdac' [ Not found ]
[22:57:18] Checking for file '/etc/rc.d/rc4.d/S23kmdac' [ Not found ]
[22:57:18] Checking for file '/etc/rc.d/rc5.d/S23kmdac' [ Not found ]
[22:57:18] Checking for file '/etc/rc.d/rc6.d/S23kmdac' [ Not found ]
[22:57:18] Checking for directory '/dev/sdhu0/tehdrakg' [ Not found ]
[22:57:19] Checking for directory '/etc/.MG' [ Not found ]
[22:57:19] Checking for directory '/usr/share/locale/sk/.sk12' [ Not found ]
[22:57:19] Checking for directory '/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist' [ Not found ]
[22:57:19] Suckit Rootkit [ Not found ]
[22:57:19]
[22:57:19] Checking for Superkit Rootkit...
[22:57:19] Checking for file '/usr/man/.sman/sk/backsh' [ Not found ]
[22:57:19] Checking for file '/usr/man/.sman/sk/izbtrag' [ Not found ]
[22:57:19] Checking for file '/usr/man/.sman/sk/sksniff' [ Not found ]
[22:57:19] Checking for file '/var/www/cgi-bin/cgiback.cgi' [ Not found ]
[22:57:19] Checking for directory '/usr/man/.sman/sk' [ Not found ]
[22:57:19] Superkit Rootkit [ Not found ]
[22:57:19]
[22:57:19] Checking for TBD (Telnet BackDoor)...
[22:57:19] Checking for file '/usr/lib/.tbd' [ Not found ]
[22:57:19] TBD (Telnet BackDoor) [ Not found ]
[22:57:19]
[22:57:19] Checking for TeLeKiT Rootkit...
[22:57:19] Checking for file '/usr/man/man3/.../TeLeKiT/bin/sniff' [ Not found ]
[22:57:19] Checking for file '/usr/man/man3/.../TeLeKiT/bin/telnetd' [ Not found ]
[22:57:19] Checking for file '/usr/man/man3/.../TeLeKiT/bin/teleulo' [ Not found ]
[22:57:19] Checking for file '/usr/man/man3/.../cl' [ Not found ]
[22:57:19] Checking for file '/dev/ptyr' [ Not found ]
[22:57:19] Checking for file '/dev/ptyp' [ Not found ]
[22:57:19] Checking for file '/dev/ptyq' [ Not found ]
[22:57:19] Checking for file '/dev/hda06' [ Not found ]
[22:57:19] Checking for file '/usr/info/libc1.so' [ Not found ]
[22:57:19] Checking for directory '/usr/man/man3/...' [ Not found ]
[22:57:19] Checking for directory '/usr/man/man3/.../lsniff' [ Not found ]
[22:57:19] Checking for directory '/usr/man/man3/.../TeLeKiT' [ Not found ]
[22:57:19] TeLeKiT Rootkit [ Not found ]
[22:57:19]
[22:57:19] Checking for T0rn Rootkit...
[22:57:19] Checking for file '/dev/.lib/lib/lib/t0rns' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/du' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/ls' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/t0rnsb' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/ps' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/t0rnp' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/find' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/ifconfig' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/pg' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/ssh.tgz' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/top' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/sz' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/login' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/in.fingerd' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/1i0n.sh' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/pstree' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/in.telnetd' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/mjy' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/sush' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/tfn' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/name' [ Not found ]
[22:57:19] Checking for file '/dev/.lib/lib/lib/getip.sh' [ Not found ]
[22:57:19] Checking for file '/usr/info/.torn/sh*' [ Not found ]
[22:57:20] Checking for file '/usr/src/.puta/.1addr' [ Not found ]
[22:57:20] Checking for file '/usr/src/.puta/.1file' [ Not found ]
[22:57:20] Checking for file '/usr/src/.puta/.1proc' [ Not found ]
[22:57:20] Checking for file '/usr/src/.puta/.1logz' [ Not found ]
[22:57:20] Checking for file '/usr/info/.t0rn' [ Not found ]
[22:57:20] Checking for directory '/dev/.lib' [ Not found ]
[22:57:20] Checking for directory '/dev/.lib/lib' [ Not found ]
[22:57:20] Checking for directory '/dev/.lib/lib/lib' [ Not found ]
[22:57:20] Checking for directory '/dev/.lib/lib/lib/dev' [ Not found ]
[22:57:20] Checking for directory '/dev/.lib/lib/scan' [ Not found ]
[22:57:20] Checking for directory '/usr/src/.puta' [ Not found ]
[22:57:20] Checking for directory '/usr/man/man1/man1' [ Not found ]
[22:57:20] Checking for directory '/usr/man/man1/man1/lib' [ Not found ]
[22:57:20] Checking for directory '/usr/man/man1/man1/lib/.lib' [ Not found ]
[22:57:20] Checking for directory '/usr/man/man1/man1/lib/.lib/.backup' [ Not found ]
[22:57:20] T0rn Rootkit [ Not found ]
[22:57:20]
[22:57:20] Checking for trNkit Rootkit...
[22:57:20] Checking for file '/usr/lib/libbins.la' [ Not found ]
[22:57:20] Checking for file '/usr/lib/libtcs.so' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/ulogin.sh' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/tcpshell.sh' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/bupdu' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/buloc' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/buloc1' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/buloc2' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/stat' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/backps' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/tree' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/topk' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/wold' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/whoold' [ Not found ]
[22:57:20] Checking for file '/dev/.ttpy/backdoors' [ Not found ]
[22:57:20] trNkit Rootkit [ Not found ]
[22:57:20]
[22:57:20] Checking for Trojanit Kit...
[22:57:20] Checking for file '/bin/.ls' [ Not found ]
[22:57:20] Checking for file '/bin/.ps' [ Not found ]
[22:57:20] Checking for file '/bin/.netstat' [ Not found ]
[22:57:20] Checking for file '/usr/bin/.nop' [ Not found ]
[22:57:20] Checking for file '/usr/bin/.who' [ Not found ]
[22:57:20] Trojanit Kit [ Not found ]
[22:57:20]
[22:57:20] Checking for Tuxtendo Rootkit...
[22:57:20] Checking for file '/lib/libproc.so.2.0.7' [ Not found ]
[22:57:20] Checking for file '/usr/bin/xchk' [ Not found ]
[22:57:20] Checking for file '/usr/bin/xsf' [ Not found ]
[22:57:20] Checking for file '/dev/tux/suidsh' [ Not found ]
[22:57:20] Checking for file '/dev/tux/.addr' [ Not found ]
[22:57:20] Checking for file '/dev/tux/.cron' [ Not found ]
[22:57:20] Checking for file '/dev/tux/.file' [ Not found ]
[22:57:20] Checking for file '/dev/tux/.log' [ Not found ]
[22:57:21] Checking for file '/dev/tux/.proc' [ Not found ]
[22:57:21] Checking for file '/dev/tux/.iface' [ Not found ]
[22:57:21] Checking for file '/dev/tux/.pw' [ Not found ]
[22:57:21] Checking for file '/dev/tux/.df' [ Not found ]
[22:57:21] Checking for file '/dev/tux/.ssh' [ Not found ]
[22:57:21] Checking for file '/dev/tux/.tux' [ Not found ]
[22:57:21] Checking for file '/dev/tux/ssh2/sshd2_config' [ Not found ]
[22:57:21] Checking for file '/dev/tux/ssh2/hostkey' [ Not found ]
[22:57:21] Checking for file '/dev/tux/ssh2/hostkey.pub' [ Not found ]
[22:57:21] Checking for file '/dev/tux/ssh2/logo' [ Not found ]
[22:57:21] Checking for file '/dev/tux/ssh2/random_seed' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/crontab' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/df' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/dir' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/find' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/ifconfig' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/locate' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/netstat' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/ps' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/pstree' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/syslogd' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/tcpd' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/top' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/updatedb' [ Not found ]
[22:57:21] Checking for file '/dev/tux/backup/vdir' [ Not found ]
[22:57:21] Checking for directory '/dev/tux' [ Not found ]
[22:57:21] Checking for directory '/dev/tux/ssh2' [ Not found ]
[22:57:21] Checking for directory '/dev/tux/backup' [ Not found ]
[22:57:21] Tuxtendo Rootkit [ Not found ]
[22:57:21]
[22:57:21] Checking for URK Rootkit...
[22:57:21] Checking for file '/dev/prom/sn.l' [ Not found ]
[22:57:21] Checking for file '/usr/lib/ldlibps.so' [ Not found ]
[22:57:21] Checking for file '/usr/lib/ldlibnet.so' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/uconf.inv' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/cleaner' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/psniff' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/du' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/ls' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/passwd' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/ps' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/psr' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/su' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/find' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/netstat' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/ping' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/strings' [ Not found ]
[22:57:21] Checking for file '/dev/pts/01/bin/bash' [ Not found ]
[22:57:21] Checking for file '/usr/man/man1/xxxxxxbin/du' [ Not found ]
[22:57:21] Checking for file '/usr/man/man1/xxxxxxbin/ls' [ Not found ]
[22:57:21] Checking for file '/usr/man/man1/xxxxxxbin/passwd' [ Not found ]
[22:57:21] Checking for file '/usr/man/man1/xxxxxxbin/ps' [ Not found ]
[22:57:21] Checking for file '/usr/man/man1/xxxxxxbin/psr' [ Not found ]
[22:57:22] Checking for file '/usr/man/man1/xxxxxxbin/su' [ Not found ]
[22:57:22] Checking for file '/usr/man/man1/xxxxxxbin/find' [ Not found ]
[22:57:22] Checking for file '/usr/man/man1/xxxxxxbin/netstat' [ Not found ]
[22:57:22] Checking for file '/usr/man/man1/xxxxxxbin/ping' [ Not found ]
[22:57:22] Checking for file '/usr/man/man1/xxxxxxbin/strings' [ Not found ]
[22:57:22] Checking for file '/usr/man/man1/xxxxxxbin/bash' [ Not found ]
[22:57:22] Checking for file '/tmp/conf.inv' [ Not found ]
[22:57:22] Checking for directory '/dev/prom' [ Not found ]
[22:57:22] Checking for directory '/dev/pts/01' [ Not found ]
[22:57:22] Checking for directory '/dev/pts/01/bin' [ Not found ]
[22:57:22] Checking for directory '/usr/man/man1/xxxxxxbin' [ Not found ]
[22:57:22] URK Rootkit [ Not found ]
[22:57:22]
[22:57:22] Checking for Vampire Rootkit...
[22:57:22] Checking for kernel symbol 'new_getdents' [ Not found ]
[22:57:22] Checking for kernel symbol 'old_getdents' [ Not found ]
[22:57:22] Checking for kernel symbol 'should_hide_file_name' [ Not found ]
[22:57:22] Checking for kernel symbol 'should_hide_task_name' [ Not found ]
[22:57:22] Vampire Rootkit [ Not found ]
[22:57:22]
[22:57:22] Checking for VcKit Rootkit...
[22:57:22] Checking for directory '/usr/include/linux/modules/lib.so' [ Not found ]
[22:57:22] Checking for directory '/usr/include/linux/modules/lib.so/bin' [ Not found ]
[22:57:22] VcKit Rootkit [ Not found ]
[22:57:22]
[22:57:22] Checking for Volc Rootkit...
[22:57:22] Checking for file '/usr/bin/volc' [ Not found ]
[22:57:22] Checking for file '/usr/lib/volc/backdoor/divine' [ Not found ]
[22:57:22] Checking for file '/usr/lib/volc/linsniff' [ Not found ]
[22:57:22] Checking for file '/etc/rc.d/rc1.d/S25sysconf' [ Not found ]
[22:57:22] Checking for file '/etc/rc.d/rc2.d/S25sysconf' [ Not found ]
[22:57:22] Checking for file '/etc/rc.d/rc3.d/S25sysconf' [ Not found ]
[22:57:22] Checking for file '/etc/rc.d/rc4.d/S25sysconf' [ Not found ]
[22:57:22] Checking for file '/etc/rc.d/rc5.d/S25sysconf' [ Not found ]
[22:57:22] Checking for directory '/var/spool/.recent' [ Not found ]
[22:57:22] Checking for directory '/var/spool/.recent/.files' [ Not found ]
[22:57:22] Checking for directory '/usr/lib/volc' [ Not found ]
[22:57:22] Checking for directory '/usr/lib/volc/backup' [ Not found ]
[22:57:22] Volc Rootkit [ Not found ]
[22:57:22]
[22:57:22] Checking for Xzibit Rootkit...
[22:57:22] Checking for file '/dev/dsx' [ Not found ]
[22:57:22] Checking for file '/dev/caca' [ Not found ]
[22:57:22] Checking for file '/dev/ida/.inet/linsniffer' [ Not found ]
[22:57:23] Checking for file '/dev/ida/.inet/logclear' [ Not found ]
[22:57:23] Checking for file '/dev/ida/.inet/sense' [ Not found ]
[22:57:23] Checking for file '/dev/ida/.inet/sl2' [ Not found ]
[22:57:23] Checking for file '/dev/ida/.inet/sshdu' [ Not found ]
[22:57:23] Checking for file '/dev/ida/.inet/s' [ Not found ]
[22:57:23] Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[22:57:23] Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[22:57:23] Checking for file '/dev/ida/.inet/sl2new.c' [ Not found ]
[22:57:23] Checking for file '/dev/ida/.inet/tcp.log' [ Not found ]
[22:57:23] Checking for file '/home/httpd/cgi-bin/becys.cgi' [ Not found ]
[22:57:23] Checking for file '/usr/local/httpd/cgi-bin/becys.cgi' [ Not found ]
[22:57:23] Checking for file '/usr/local/apache/cgi-bin/becys.cgi' [ Not found ]
[22:57:23] Checking for file '/www/httpd/cgi-bin/becys.cgi' [ Not found ]
[22:57:23] Checking for file '/www/cgi-bin/becys.cgi' [ Not found ]
[22:57:23] Checking for directory '/dev/ida/.inet' [ Not found ]
[22:57:23] Xzibit Rootkit [ Not found ]
[22:57:23]
[22:57:23] Checking for zaRwT.KiT Rootkit...
[22:57:23] Checking for file '/dev/rd/s/sendmeil' [ Not found ]
[22:57:23] Checking for file '/dev/ttyf' [ Not found ]
[22:57:23] Checking for file '/dev/ttyp' [ Not found ]
[22:57:23] Checking for file '/dev/ttyn' [ Not found ]
[22:57:23] Checking for file '/rk/tulz' [ Not found ]
[22:57:23] Checking for directory '/rk' [ Not found ]
[22:57:23] Checking for directory '/dev/rd/s' [ Not found ]
[22:57:23] zaRwT.KiT Rootkit [ Not found ]
[22:57:23]
[22:57:23] Checking for ZK Rootkit...
[22:57:23] Checking for file '/usr/share/.zk/zk' [ Not found ]
[22:57:23] Checking for file '/usr/X11R6/.zk/xfs' [ Not found ]
[22:57:23] Checking for file '/usr/X11R6/.zk/echo' [ Not found ]
[22:57:23] Checking for file '/etc/1ssue.net' [ Not found ]
[22:57:23] Checking for file '/etc/sysconfig/console/load.zk' [ Not found ]
[22:57:23] Checking for directory '/usr/share/.zk' [ Not found ]
[22:57:23] Checking for directory '/usr/X11R6/.zk' [ Not found ]
[22:57:23] ZK Rootkit [ Not found ]
[22:58:14]
[22:58:14] Info: Starting test name 'additional_rkts'
[22:58:14] Performing additional rootkit checks
[22:58:14]
[22:58:14] Performing Suckit Rootkit additional checks
[22:58:14] Checking hard link count on '/sbin/init' [ OK ]
[22:58:14] Checking for hidden file extensions [ None found ]
[22:58:14] Running skdet command [ Skipped ]
[22:58:14] Info: Unable to find the 'skdet' command
[22:58:14] Suckit Rootkit additional checks [ OK ]
[22:58:14]
[22:58:14] Info: Starting test name 'possible_rkt_files'
[22:58:14] Performing check of possible rootkit files and directories
[22:58:14] Checking for file '/dev/sdr0' [ Not found ]
[22:58:14] Checking for file '/dev/pisu' [ Not found ]
[22:58:14] Checking for file '/dev/xdta' [ Not found ]
[22:58:14] Checking for file '/dev/saux' [ Not found ]
[22:58:14] Checking for file '/dev/hdx' [ Not found ]
[22:58:14] Checking for file '/dev/hdx1' [ Not found ]
[22:58:14] Checking for file '/dev/hdx2' [ Not found ]
[22:58:14] Checking for file '/dev/ptyy' [ Not found ]
[22:58:14] Checking for file '/dev/ptyu' [ Not found ]
[22:58:14] Checking for file '/dev/ptyv' [ Not found ]
[22:58:14] Checking for file '/dev/hdbb' [ Not found ]
[22:58:14] Checking for file '/tmp/.syshackfile' [ Not found ]
[22:58:14] Checking for file '/tmp/.bash_history' [ Not found ]
[22:58:14] Checking for file '/usr/info/.clib' [ Not found ]
[22:58:14] Checking for file '/usr/sbin/tcp.log' [ Not found ]
[22:58:14] Checking for file '/usr/bin/take/pid' [ Not found ]
[22:58:14] Checking for file '/sbin/create' [ Not found ]
[22:58:14] Checking for file '/dev/ttypz' [ Not found ]
[22:58:14] Checking for file '/var/log/tcp.log' [ Not found ]
[22:58:14] Checking for file '/usr/include/audit.h' [ Not found ]
[22:58:14] Checking for file '/usr/bin/sourcemask' [ Not found ]
[22:58:14] Checking for file '/usr/bin/ras2xm' [ Not found ]
[22:58:14] Checking for file '/dev/xmx' [ Not found ]
[22:58:14] Checking for file '/usr/sbin/gpm.root' [ Not found ]
[22:58:14] Checking for file '/bin/vobiscum' [ Not found ]
[22:58:14] Checking for file '/bin/psr' [ Not found ]
[22:58:14] Checking for file '/dev/kdx' [ Not found ]
[22:58:14] Checking for file '/dev/dkx' [ Not found ]
[22:58:14] Checking for file '/usr/sbin/sshd3' [ Not found ]
[22:58:15] Checking for file '/usr/sbin/jcd' [ Not found ]
[22:58:15] Checking for file '/usr/sbin/atd2' [ Not found ]
[22:58:15] Checking for file '/home/httpd/cgi-bin/linux.cgi' [ Not found ]
[22:58:15] Checking for file '/home/httpd/cgi-bin/psid' [ Not found ]
[22:58:15] Checking for file '/home/httpd/cgi-bin/void.cgi' [ Not found ]
[22:58:15] Checking for file '/etc/rc.d/init.d/system' [ Not found ]
[22:58:15] Checking for file '/etc/rc.d/rc3.d/S93users' [ Not found ]
[22:58:15] Checking for file '/tmp/.ush' [ Not found ]
[22:58:15] Checking for file '/usr/lib/libhidefile.so' [ Not found ]
[22:58:15] Checking for file '/etc/cron.d/kmod' [ Not found ]
[22:58:15] Checking for file '/usr/lib/dmis/dmisd' [ Not found ]
[22:58:15] Checking for file '/lib/secure/libhij.so' [ Not found ]
[22:58:15] Checking for file '/usr/sbin/sshd3' [ Not found ]
[22:58:15] Checking for file '/etc/rc.d/init.d/crontab' [ Not found ]
[22:58:15] Checking for file '/etc/rc.d/init.d/jcd' [ Not found ]
[22:58:15] Checking for file '/usr/sbin/atd2' [ Not found ]
[22:58:15] Checking for file '/etc/rc.d/rc5.d/S93users' [ Not found ]
[22:58:15] Checking for file '/usr/include/mysql/mysql.hh1' [ Not found ]
[22:58:15] Checking for file '/etc/init.d/xfs3' [ Not found ]
[22:58:15] Checking for file '/usr/sbin/t.txt' [ Not found ]
[22:58:15] Checking for file '/usr/sbin/change' [ Not found ]
[22:58:15] Checking for file '/usr/sbin/s' [ Not found ]
[22:58:15] Checking for file '/bin/f' [ Not found ]
[22:58:15] Checking for file '/bin/i' [ Not found ]
[22:58:15] Checking for file '/lib/libncom.so.4.0.1' [ Not found ]
[22:58:15] Checking for file '/sbin/zinit' [ Not found ]
[22:58:15] Checking for file '/tmp/pass_ssh.log' [ Not found ]
[22:58:15] Checking for file '/usr/include/gpm2.h' [ Not found ]
[22:58:15] Checking for file '/etc/ssh/.sshd_auth' [ Not found ]
[22:58:15] Checking for file '/usr/lib/.sshd.h' [ Not found ]
[22:58:15] Checking for file '/var/run/.defunct' [ Not found ]
[22:58:15] Checking for file '/etc/httpd/run/.defunct' [ Not found ]
[22:58:15] Checking for file '/usr/share/pci.r' [ Not found ]
[22:58:15] Checking for file '/etc/cron.daily/dnsquery' [ Not found ]
[22:58:15] Checking for file '/usr/lib/libutil1.2.1.2.so' [ Not found ]
[22:58:15] Checking for file '/usr/lib/libppopen.so' [ Not found ]
[22:58:15] Checking for file '/usr/include/libutil2.1.h' [ Not found ]
[22:58:15] Checking for file '/usr/bin/munchhausen' [ Not found ]
[22:58:15] Checking for file '/bin/ceva' [ Not found ]
[22:58:15] Checking for file '/sbin/syslogd<SP>' [ Not found ]
[22:58:16] Checking for file '/usr/include/shup.h' [ Not found ]
[22:58:16] Checking for file '/etc/rpm/sshdOLD' [ Not found ]
[22:58:16] Checking for file '/etc/rpm/sshOLD' [ Not found ]
[22:58:16] Checking for file '/usr/share/passwd.h' [ Not found ]
[22:58:16] Checking for file '/lib/.xsyslog' [ Not found ]
[22:58:16] Checking for file '/etc/.xsyslog' [ Not found ]
[22:58:16] Checking for file '/lib/.ssyslog' [ Not found ]
[22:58:16] Checking for file '/tmp/.sendmail' [ Not found ]
[22:58:16] Checking for file '/usr/share/sshd.sync' [ Not found ]
[22:58:16] Checking for file '/bin/zcut' [ Not found ]
[22:58:16] Checking for file '/usr/bin/zmuie' [ Not found ]
[22:58:16] Checking for file '/lib/libkeyutils.so.1.9' [ Not found ]
[22:58:16] Checking for file '/lib64/libkeyutils.so.1.9' [ Not found ]
[22:58:16] Checking for file '/usr/lib/libkeyutils.so.1.9' [ Not found ]
[22:58:16] Checking for file '/usr/lib64/libkeyutils.so.1.9' [ Not found ]
[22:58:16] Checking for file '/IptabLes' [ Not found ]
[22:58:16] Checking for file '/.IptabLex' [ Not found ]
[22:58:16] Checking for file '/boot/.IptabLex' [ Not found ]
[22:58:16] Checking for file '/boot/.IptabLes' [ Not found ]
[22:58:16] Checking for file '/boot/IptabLes' [ Not found ]
[22:58:16] Checking for file '/tmp/IptabLes' [ Not found ]
[22:58:16] Checking for file '/etc/rc.d/init.d/IptabLex' [ Not found ]
[22:58:16] Checking for file '/etc/rc.d/init.d/IptabLes' [ Not found ]
[22:58:16] Checking for file '/etc/rc.d/rc0.d/S55IptabLex' [ Not found ]
[22:58:16] Checking for file '/etc/rc.d/rc1.d/S55IptabLex' [ Not found ]
[22:58:16] Checking for file '/etc/rc.d/rc2.d/S55IptabLex' [ Not found ]
[22:58:16] Checking for file '/etc/rc.d/rc3.d/S55IptabLex' [ Not found ]
[22:58:16] Checking for file '/etc/rc.d/rc4.d/S55IptabLex' [ Not found ]
[22:58:16] Checking for file '/etc/rc.d/rc5.d/S55IptabLex' [ Not found ]
[22:58:16] Checking for file '/etc/rc.d/rc6.d/S55IptabLex' [ Not found ]
[22:58:16] Checking for file '/var/lib/update-rc.d/IptabLex' [ Not found ]
[22:58:16] Checking for file '/delallmykkk' [ Not found ]
[22:58:16] Checking for file '/usr/.IptabLes' [ Not found ]
[22:58:16] Checking for file '/usr/IptabLes' [ Not found ]
[22:58:16] Checking for file '/tmp/.flush' [ Not found ]
[22:58:16] Checking for file '/var/log/.flush' [ Not found ]
[22:58:16] Checking for file '/usr/.flush' [ Not found ]
[22:58:16] Checking for file '/etc/init.d/bluetoothdaemon' [ Not found ]
[22:58:16] Checking for file '/usr/bin/btdaemon' [ Not found ]
[22:58:16] Checking for file '/etc/rc1.d/S90bluetooth' [ Not found ]
[22:58:17] Checking for file '/etc/rc2.d/S90bluetooth' [ Not found ]
[22:58:17] Checking for file '/etc/rc3.d/S90bluetooth' [ Not found ]
[22:58:17] Checking for file '/etc/rc4.d/S90bluetooth' [ Not found ]
[22:58:17] Checking for file '/etc/rc5.d/S90bluetooth' [ Not found ]
[22:58:17] Checking for file '/etc/rc6.d/S90bluetooth' [ Not found ]
[22:58:17] Checking for file '/boot/pro' [ Not found ]
[22:58:17] Checking for file '/boot/proh' [ Not found ]
[22:58:17] Checking for file '/etc/atdd' [ Not found ]
[22:58:17] Checking for file '/etc/atddd' [ Not found ]
[22:58:17] Checking for file '/etc/cupsdd' [ Not found ]
[22:58:17] Checking for file '/etc/cupsddd' [ Not found ]
[22:58:17] Checking for file '/etc/cupsddh' [ Not found ]
[22:58:17] Checking for file '/etc/dsfrefr' [ Not found ]
[22:58:17] Checking for file '/etc/fdsfsfvff' [ Not found ]
[22:58:17] Checking for file '/etc/ferwfrre' [ Not found ]
[22:58:17] Checking for file '/etc/fwke.cfg' [ Not found ]
[22:58:17] Checking for file '/etc/gdmorpen' [ Not found ]
[22:58:17] Checking for file '/etc/gfhddsfew' [ Not found ]
[22:58:17] Checking for file '/etc/gfhjrtfyhuf' [ Not found ]
[22:58:17] Checking for file '/etc/ksapd' [ Not found ]
[22:58:17] Checking for file '/etc/ksapdd' [ Not found ]
[22:58:17] Checking for file '/etc/kysapd' [ Not found ]
[22:58:17] Checking for file '/etc/kysapdd' [ Not found ]
[22:58:17] Checking for file '/etc/rewgtf3er4t' [ Not found ]
[22:58:17] Checking for file '/etc/sdmfdsfhjfe' [ Not found ]
[22:58:17] Checking for file '/etc/sfewfesfs' [ Not found ]
[22:58:17] Checking for file '/etc/sfewfesfsh' [ Not found ]
[22:58:17] Checking for file '/etc/sksapd' [ Not found ]
[22:58:17] Checking for file '/etc/sksapdd' [ Not found ]
[22:58:17] Checking for file '/etc/skysapd' [ Not found ]
[22:58:17] Checking for file '/etc/skysapdd' [ Not found ]
[22:58:17] Checking for file '/etc/smarvtd' [ Not found ]
[22:58:17] Checking for file '/etc/whitptabil' [ Not found ]
[22:58:17] Checking for file '/etc/xfsdx' [ Not found ]
[22:58:17] Checking for file '/etc/xfsdxd' [ Not found ]
[22:58:17] Checking for file '/tmp/bill.lock' [ Not found ]
[22:58:17] Checking for file '/tmp/gates.lock' [ Not found ]
[22:58:17] Checking for file '/tmp/gates.lod' [ Not found ]
[22:58:17] Checking for file '/tmp/moni.lock' [ Not found ]
[22:58:18] Checking for file '/tmp/moni.lod' [ Not found ]
[22:58:18] Checking for file '/tmp/notify.file' [ Not found ]
[22:58:18] Checking for file '/usr/bin/.sshd' [ Not found ]
[22:58:18] Checking for file '/usr/bin/bsd-port/getty' [ Not found ]
[22:58:18] Checking for file '/usr/bin/bsd-port/getty.lock' [ Not found ]
[22:58:18] Checking for file '/usr/bin/bsd-port/udevd.lock' [ Not found ]
[22:58:18] Checking for file '/usr/bin/pojie' [ Not found ]
[22:58:18] Checking for file '/usr/lib/libamplify.so' [ Not found ]
[22:58:18] Checking for file '/etc/init.d/DbSecuritySpt' [ Not found ]
[22:58:18] Checking for file '/etc/rc.d/init.d/DbSecuritySpt' [ Not found ]
[22:58:18] Checking for file '/etc/cron.hourly/gcc.sh' [ Not found ]
[22:58:18] Checking for file '/root/2016ttfacai' [ Not found ]
[22:58:18] Checking for file '/proc/rs_dev' [ Not found ]
[22:58:18] Checking for file '/var/run/sftp.pid' [ Not found ]
[22:58:18] Checking for file '/var/run/udev.pid' [ Not found ]
[22:58:18] Checking for file '/var/run/mount.pid' [ Not found ]
[22:58:18] Checking for file '/etc/cron.hourly/cron.sh' [ Not found ]
[22:58:18] Checking for file '/etc/cron.hourly/udev.sh' [ Not found ]
[22:58:18] Checking for file '/etc/cron.hourly/udev.sh' [ Not found ]
[22:58:18] Checking for file '/lib/libgcc.so' [ Not found ]
[22:58:18] Checking for file '/lib/libgcc.so.bak' [ Not found ]
[22:58:18] Checking for file '/lib/libgcc4.so' [ Not found ]
[22:58:18] Checking for file '/lib/libgcc4.4.so' [ Not found ]
[22:58:18] Checking for file '/lib/udev/udev' [ Not found ]
[22:58:18] Checking for file '/lib/udev/debug' [ Not found ]
[22:58:18] Checking for directory '/dev/ptyas' [ Not found ]
[22:58:18] Checking for directory '/usr/bin/take' [ Not found ]
[22:58:18] Checking for directory '/usr/src/.lib' [ Not found ]
[22:58:18] Checking for directory '/usr/share/man/man1/.1c' [ Not found ]
[22:58:18] Checking for directory '/lib/lblip.tk' [ Not found ]
[22:58:18] Checking for directory '/usr/sbin/...' [ Not found ]
[22:58:18] Checking for directory '/usr/share/.gun' [ Not found ]
[22:58:18] Checking for directory '/unde/vrei/tu/sa/te/ascunzi/in/server' [ Not found ]
[22:58:18] Checking for directory '/usr/man/man1/..<SP><SP>/.dir' [ Not found ]
[22:58:18] Checking for directory '/usr/X11R6/include/X11/...' [ Not found ]
[22:58:18] Checking for directory '/usr/X11R6/lib/X11/.fonts/misc/...' [ Not found ]
[22:58:18] Checking for directory '/tmp/.sys' [ Not found ]
[22:58:18] Checking for directory '/tmp/'' [ Not found ]
[22:58:18] Checking for directory '/tmp/.,' [ Not found ]
[22:58:18] Checking for directory '/tmp/,.,' [ Not found ]
[22:58:18] Checking for directory '/dev/shm/emilien' [ Not found ]
[22:58:18] Checking for directory '/var/tmp/.log' [ Not found ]
[22:58:19] Checking for directory '/tmp/zmeu/...<SP>' [ Not found ]
[22:58:19] Checking for directory '/var/log/ssh' [ Not found ]
[22:58:19] Checking for directory '/dev/ida' [ Not found ]
[22:58:19] Checking for directory '/var/lib/games/.src/ssk/shit' [ Not found ]
[22:58:19] Checking for directory '/usr/lib/libshtift' [ Not found ]
[22:58:19] Checking for directory '/usr/src/.poop' [ Not found ]
[22:58:19] Checking for directory '/dev/wd4' [ Not found ]
[22:58:19] Checking for directory '/var/run/.tmp' [ Not found ]
[22:58:19] Checking for directory '/usr/man/man1/lib/.lib' [ Not found ]
[22:58:19] Checking for directory '/dev/portd' [ Not found ]
[22:58:19] Checking for directory '/dev/...' [ Not found ]
[22:58:19] Checking for directory '/usr/share/man/mansps' [ Not found ]
[22:58:19] Checking for directory '/lib/.so' [ Not found ]
[22:58:19] Checking for directory '/lib/.sso' [ Not found ]
[22:58:19] Checking for directory '/usr/include/sslv3' [ Not found ]
[22:58:19] Checking for directory '/dev/shm/sshd' [ Not found ]
[22:58:19] Checking for directory '/usr/share/locale/mk/.dev/sk' [ Not found ]
[22:58:19] Checking for directory '/usr/share/locale/mk/.dev' [ Not found ]
[22:58:19] Checking for directory '/usr/include/netda.h' [ Not found ]
[22:58:19] Checking for directory '/usr/include/.ssh' [ Not found ]
[22:58:19] Checking for directory '/usr/share/locale/jp/.<SP>' [ Not found ]
[22:58:19] Checking for directory '/usr/share/.sqe' [ Not found ]
[22:58:19] Checking for possible rootkit files and directories [ None found ]
[22:58:19]
[22:58:19] Info: Starting test name 'possible_rkt_strings'
[22:58:19] Performing check for possible rootkit strings
[22:58:19] Info: Using system startup paths: /etc/rc.local /etc/init.d /etc/systemd/system
[22:58:19] Checking for string 'phalanx' [ Not found ]
[22:58:19] Checking for string '/dev/proc/fuckit' [ Not found ]
[22:58:19] Checking for string 'FUCK' [ Not found ]
[22:58:19] Checking for string 'backdoor' [ Not found ]
[22:58:19] Checking for string '/usr/bin/rcpc' [ Not found ]
[22:58:19] Checking for string '/usr/sbin/login' [ Not found ]
[22:58:19] Checking for string '/dev/ptyxx/.proc' [ Not found ]
[22:58:19] Checking for string 'vt200' [ Not found ]
[22:58:19] Checking for string '/usr/bin/xstat' [ Not found ]
[22:58:19] Checking for string '/bin/envpc' [ Not found ]
[22:58:19] Checking for string 'L4m3r0x' [ Not found ]
[22:58:20] Checking for string '/lib/libext' [ Not found ]
[22:58:20] Checking for string '/usr/sbin/login' [ Not found ]
[22:58:20] Checking for string '/usr/lib/.tbd' [ Not found ]
[22:58:20] Checking for string 'sendmail' [ Not found ]
[22:58:20] Checking for string 'cocacola' [ Not found ]
[22:58:20] Checking for string 'joao' [ Not found ]
[22:58:20] Checking for string '/dev/ptyxx/.file' [ Not found ]
[22:58:20] Checking for string '/dev/ptyxx/.file' [ Not found ]
[22:58:20] Checking for string '/dev/sgk' [ Not found ]
[22:58:20] Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[22:58:20] Checking for string '/usr/lib/.tbd' [ Not found ]
[22:58:20] Checking for string '/dev/proc/fuckit' [ Not found ]
[22:58:20] Checking for string '/lib/.sso' [ Not found ]
[22:58:20] Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[22:58:20] Checking for string '/dev/caca' [ Not found ]
[22:58:20] Checking for string '/dev/ttyoa' [ Not found ]
[22:58:20] Checking for string '/usr/lib/ldlibns.so' [ Not found ]
[22:58:20] Checking for string '/dev/ptyxx/.addr' [ Not found ]
[22:58:20] Checking for string 'syg' [ Not found ]
[22:58:20] Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[22:58:20] Checking for string '/dev/pts/01' [ Not found ]
[22:58:20] Checking for string 'tw33dl3' [ Not found ]
[22:58:20] Checking for string 'psniff' [ Not found ]
[22:58:20] Checking for string 'uconf.inv' [ Not found ]
[22:58:20] Checking for string 'lib/ldlibps.so' [ Not found ]
[22:58:20] Checking for string '/usr/lib/ldlibpst.so' [ Not found ]
[22:58:20] Checking for string 'libproc.so.2.0.7' [ Not found ]
[22:58:20] Checking for string '/dev/ptyxx/.proc' [ Not found ]
[22:58:20] Checking for string '/dev/ptyxx/.proc' [ Not found ]
[22:58:20] Checking for string 'libproc.so.2.0.7' [ Not found ]
[22:58:20] Checking for string 'libproc.so.2.0.7' [ Not found ]
[22:58:20] Checking for string '/bin/bash' [ Not found ]
[22:58:21] Checking for string '/dev/ptyxx' [ Not found ]
[22:58:21] Checking for string '/.config' [ Not found ]
[22:58:21] Checking for string '\$.*\$\!.*\!\!\$' [ Not found ]
[22:58:21] Checking for string 'backdoor.h' [ Not found ]
[22:58:21] Checking for string 'backdoor_active' [ Not found ]
[22:58:21] Checking for string 'magic_pass_active' [ Not found ]
[22:58:21] Checking for string '/usr/include/gpm2.h' [ Not found ]
[22:58:21] Checking for string '/usr/include/openssl' [ Not found ]
[22:58:21] Checking for string 'aion' [ Not found ]
[22:58:21] Checking for string 'pcszPass' [ Not found ]
[22:58:21] Checking for string 'LogPass' [ Not found ]
[22:58:21] Checking for string 'Login_Check' [ Not found ]
[22:58:21] Checking for string 'includes.h' [ Not found ]
[22:58:21] Checking for string 'DecodeString' [ Not found ]
[22:58:21] Checking for string 'EncodeString' [ Not found ]
[22:58:21] Checking for string 'libns2.so' [ Not found ]
[22:58:21] Checking for string 'libns5.so' [ Not found ]
[22:58:21] Checking for string 'libpw3.so' [ Not found ]
[22:58:21] Checking for string 'libpw5.so' [ Not found ]
[22:58:21] Checking for string 'libsbr.so' [ Not found ]
[22:58:21] Checking for string 'libslr.so' [ Not found ]
[22:58:21] Checking for string '/usr/lib/.tbd' [ Not found ]
[22:58:21] Checking for string '/dev/ptyxx/.proc' [ Not found ]
[22:58:22] Checking for string 'in.inetd' [ Not found ]
[22:58:23] Checking for string '#<HIDE_.*>' [ Not found ]
[22:58:24] Checking for string 'bin/xchk' [ Not found ]
[22:58:24] Checking for string 'bin/xsf' [ Not found ]
[22:58:25] Checking for string '/usr/bin/ssh2d' [ Not found ]
[22:58:26] Checking for string '/usr/sbin/xntps' [ Not found ]
[22:58:26] Checking for string 'ttyload' [ Not found ]
[22:58:27] Checking for string '/etc/rc.d/init.d/init' [ Not found ]
[22:58:28] Checking for string 'usr/bin/xfss' [ Not found ]
[22:58:29] Checking for string '/usr/sbin/rpc.netinet' [ Not found ]
[22:58:30] Checking for string '/usr/lib/.fx/cons.saver' [ Not found ]
[22:58:30] Checking for string '/usr/lib/.fx/xs' [ Not found ]
[22:58:31] Checking for string '/ssh2d' [ Not found ]
[22:58:32] Checking for string '/dev/kmod' [ Not found ]
[22:58:32] Checking for string '/crth.o' [ Not found ]
[22:58:33] Checking for string '/crtz.o' [ Not found ]
[22:58:34] Checking for string '/dev/dos' [ Not found ]
[22:58:35] Checking for string '/lpq' [ Not found ]
[22:58:35] Checking for string '/usr/sbin/rescue' [ Not found ]
[22:58:36] Checking for string '/usr/lib/lpstart' [ Not found ]
[22:58:37] Checking for string '/volc' [ Not found ]
[22:58:37] Checking for string 'sourcemask' [ Not found ]
[22:58:38] Checking for string '/bin/vobiscum' [ Not found ]
[22:58:39] Checking for string '/usr/sbin/in.telnet' [ Not found ]
[22:58:40] Checking for string '/usr/bin/hdparm?-t1?-X53?-p' [ Not found ]
[22:58:40] Checking for string '/lib/.xsyslog' [ Not found ]
[22:58:41] Checking for string '/etc/.xsyslog' [ Not found ]
[22:58:42] Checking for string '/lib/.ssyslog' [ Not found ]
[22:58:43] Checking for string '/tmp/.sendmail' [ Not found ]
[22:58:43] Checking for string 'IptabLex' [ Not found ]
[22:58:44] Checking for string 'IptabLes' [ Not found ]
[22:58:44] Checking for string '/lib/ldd.so/tkps' [ Not found ]
[22:58:44] Checking for string 't0rnkit' [ Not found ]
[22:58:44] Checking for string '/dev/proc/fuckit' [ Not found ]
[22:58:44] Checking for string 'backdoor.h' [ Not found ]
[22:58:44] Checking for string 'backdoor_active' [ Not found ]
[22:58:44] Checking for string 'magic_pass_active' [ Not found ]
[22:58:44] Checking for string '/usr/include/gpm2.h' [ Not found ]
[22:58:44] Checking for string 'libproc.so.2.0.7' [ Not found ]
[22:58:44] Checking for string 'libproc.so.2.0.7' [ Not found ]
[22:58:44] Checking for string 'libproc.so.2.0.7' [ Not found ]
[22:58:45] Checking for string '/usr/lib/ldlibct.so' [ Not found ]
[22:58:45] Checking for string '/usr/lib/ldlibdu.so' [ Not found ]
[22:58:45] Checking for string '/dev/ptyxx/.file' [ Not found ]
[22:58:45] Checking for string 'libproc.so.2.0.7' [ Not found ]
[22:58:45] Checking for string '/dev/ida/.inet' [ Not found ]
[22:58:45] Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[22:58:45] Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[22:58:45] Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[22:58:45] Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[22:58:45] Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[22:58:45] Checking for string '/usr/include/mysql/mysql.hh1' [ Not found ]
[22:58:45] Checking for string 'backconnect' [ Not found ]
[22:58:45] Checking for string 'magic?packet?received' [ Not found ]
[22:58:45] Checking for possible rootkit strings [ None found ]
[22:58:45]
[22:58:45] Info: Starting test name 'malware'
[22:58:45] Performing malware checks
[22:58:45]
[22:58:45] Info: Starting test name 'deleted_files'
[22:58:47] Checking running processes for deleted files [ Warning ]
[22:58:47] Warning: The following processes are using deleted files:
[22:58:47] Process: /usr/bin/dbus-daemon PID: 1027 File: /usr/bin/dbus-daemon
[22:58:47] Process: /lib/systemd/systemd-logind PID: 1037 File: /lib/systemd/systemd-logind
[22:58:47] Process: /usr/sbin/mysqld PID: 1211 File: /tmp/ibKywJ2E
[22:58:47] Process: /usr/sbin/dovecot PID: 1262 File: /run/dovecot/login-master-notifydd53eaede07c063a
[22:58:47] Process: /usr/sbin/apache2 PID: 1399 File: /tmp/.ZendSem.cc4qQ7
[22:58:47] Process: /usr/sbin/apache2 PID: 1444 File: /tmp/.ZendSem.cc4qQ7
[22:58:47] Process: /usr/sbin/apache2 PID: 1446 File: /tmp/.ZendSem.cc4qQ7
[22:58:47] Process: /usr/sbin/apache2 PID: 1452 File: /tmp/.ZendSem.cc4qQ7
[22:58:47] Process: /usr/sbin/apache2 PID: 1453 File: /tmp/.ZendSem.cc4qQ7
[22:58:47] Process: /usr/sbin/apache2 PID: 1455 File: /tmp/.ZendSem.cc4qQ7
[22:58:47] Process: /usr/sbin/apache2 PID: 11947 File: /tmp/.ZendSem.cc4qQ7
[22:58:47] Process: /lib/systemd/systemd PID: 27365 File: /lib/systemd/systemd
[22:58:47] Process: /lib/systemd/systemd PID: 27367 File: /lib/systemd/systemd
[22:58:47]
[22:58:47] Info: Starting test name 'running_procs'
[22:58:48] Checking running processes for suspicious files [ None found ]
[22:58:48]
[22:58:48] Info: Starting test name 'hidden_procs'
[22:58:48] Info: Found the 'unhide' command: /usr/sbin/unhide
[22:58:48] Info: Found 'unhide' command version: 20130526
[22:59:10] Using command '/usr/sbin/unhide sys' [ None found ]
[22:59:10] Checking for hidden processes [ None found ]
[22:59:10]
[22:59:10] Info: Starting test name 'suspscan'
[22:59:10] Performing check of files with suspicious contents
[22:59:10] Info: Directories to check are: /tmp /var/tmp
[22:59:10] Info: Temporary directory to use: /dev/shm
[22:59:10] Info: Maximum file size to check (in bytes): 1024000
[22:59:10] Info: Score threshold is set to: 200
[22:59:11] Checking for files with suspicious contents [ None found ]
[22:59:11]
[22:59:11] Info: Starting test name 'login_backdoors'
[22:59:11] Checking for '/bin/.login' [ Not found ]
[22:59:11] Checking for '/sbin/.login' [ Not found ]
[22:59:11] Checking for login backdoors [ None found ]
[22:59:11]
[22:59:11] Info: Starting test name 'sniffer_logs'
[22:59:11] Checking for file '/usr/lib/libice.log' [ Not found ]
[22:59:11] Checking for file '/dev/prom/sn.l' [ Not found ]
[22:59:11] Checking for file '/dev/fd/.88/zxsniff.log' [ Not found ]
[22:59:11] Checking for sniffer log files [ None found ]
[22:59:11]
[22:59:11] Info: Starting test name 'tripwire'
[22:59:11] Checking for software intrusions [ Skipped ]
[22:59:11] Info: Check skipped - tripwire not installed
[22:59:11]
[22:59:11] Info: Starting test name 'susp_dirs'
[22:59:11] Checking for directory '/usr/X11R6/bin/.,/copy' [ Not found ]
[22:59:11] Checking for directory '/dev/rd/cdb' [ Not found ]
[22:59:11] Checking for suspicious directories [ None found ]
[22:59:11]
[22:59:11] Info: Starting test name 'ipc_shared_mem'
[22:59:11] Info: The minimum shared memory segment size to be checked (in bytes): 1048576 (1.0MB)
[22:59:11] Checking for suspicious (large) shared memory segments [ Warning ]
[22:59:11] Warning: The following suspicious (large) shared memory segments have been found:
[22:59:11] Process: /usr/sbin/apache2 PID: 1399 Owner: root Size: 1.2MB (configured size allowed: 1.0MB)
[22:59:11]
[22:59:11] Info: Starting test name 'trojans'
[22:59:11] Performing trojan specific checks
[22:59:12] Checking for enabled inetd services [ Skipped ]
[22:59:12] Info: Check skipped - file '/etc/inetd.conf' does not exist.
[22:59:12] Checking for enabled xinetd services [ Skipped ]
[22:59:12] Info: Check skipped - file '/etc/xinetd.conf' does not exist.
[22:59:12] Checking for Apache backdoor [ Not found ]
[22:59:12]
[22:59:12] Info: Starting test name 'os_specific'
[22:59:12] Performing Linux specific checks
[22:59:12] Checking loaded kernel modules [ OK ]
[22:59:12] Info: Using modules pathname of '/lib/modules/4.15.0-48-generic'
[22:59:12] Checking kernel module names [ OK ]
[23:03:41]
[23:03:41] Info: Starting test name 'network'
[23:03:41] Checking the network...
[23:03:41]
[23:03:41] Performing checks on the network ports
[23:03:41] Info: Starting test name 'ports'
[23:03:41] Performing check for backdoor ports
[23:03:41] Checking for TCP port 1524 [ Not found ]
[23:03:41] Checking for TCP port 1984 [ Not found ]
[23:03:41] Checking for UDP port 2001 [ Not found ]
[23:03:41] Checking for TCP port 2006 [ Not found ]
[23:03:41] Checking for TCP port 2128 [ Not found ]
[23:03:41] Checking for TCP port 6666 [ Not found ]
[23:03:41] Checking for TCP port 6667 [ Not found ]
[23:03:41] Checking for TCP port 6668 [ Not found ]
[23:03:41] Checking for TCP port 6669 [ Not found ]
[23:03:41] Checking for TCP port 7000 [ Not found ]
[23:03:41] Checking for TCP port 13000 [ Not found ]
[23:03:41] Checking for TCP port 14856 [ Not found ]
[23:03:41] Checking for TCP port 25000 [ Not found ]
[23:03:41] Checking for TCP port 29812 [ Not found ]
[23:03:41] Checking for TCP port 31337 [ Not found ]
[23:03:42] Checking for TCP port 32982 [ Not found ]
[23:03:42] Checking for TCP port 33369 [ Not found ]
[23:03:42] Checking for TCP port 47107 [ Not found ]
[23:03:42] Checking for TCP port 47018 [ Not found ]
[23:03:42] Checking for TCP port 60922 [ Not found ]
[23:03:42] Checking for TCP port 62883 [ Not found ]
[23:03:42] Checking for TCP port 65535 [ Not found ]
[23:03:42] Checking for backdoor ports [ None found ]
[23:03:42]
[23:03:42] Info: Starting test name 'hidden_ports'
[23:03:42] Info: Found the 'unhide-tcp' command: /usr/sbin/unhide-tcp
[23:03:42] Checking for hidden ports [ None found ]
[23:03:43]
[23:03:43] Performing checks on the network interfaces
[23:03:43] Info: Starting test name 'promisc'
[23:03:43] Checking for promiscuous interfaces [ None found ]
[23:03:43]
[23:03:43] Info: Starting test name 'packet_cap_apps'
[23:03:43] Checking for packet capturing applications [ Warning ]
[23:03:43] Warning: Process '/lib/systemd/systemd-networkd' (PID 29716) is listening on the network.
[23:03:43]
[23:03:43] Info: Starting test name 'local_host'
[23:03:43] Checking the local host...
[23:03:43]
[23:03:43] Info: Starting test name 'startup_files'
[23:03:43] Performing system boot checks
[23:03:43] Checking for local host name [ Found ]
[23:03:43]
[23:03:43] Info: Starting test name 'startup_malware'
[23:03:43] Checking for system startup files [ Found ]
[23:03:45] Checking system startup files for malware [ None found ]
[23:03:45]
[23:03:45] Info: Starting test name 'group_accounts'
[23:03:45] Performing group and account checks
[23:03:45] Checking for passwd file [ Found ]
[23:03:45] Info: Found password file: /etc/passwd
[23:03:45] Checking for root equivalent (UID 0) accounts [ None found ]
[23:03:45] Info: Found shadow file: /etc/shadow
[23:03:45] Checking for passwordless accounts [ None found ]
[23:03:45]
[23:03:45] Info: Starting test name 'passwd_changes'
[23:03:45] Checking for passwd file changes [ None found ]
[23:03:45]
[23:03:45] Info: Starting test name 'group_changes'
[23:03:45] Checking for group file changes [ None found ]
[23:03:45] Checking root account shell history files [ OK ]
[23:03:45]
[23:03:45] Info: Starting test name 'system_configs'
[23:03:45] Performing system configuration file checks
[23:03:45]
[23:03:45] Info: Starting test name 'system_configs_ssh'
[23:03:45] Checking for an SSH configuration file [ Found ]
[23:03:45] Info: Found an SSH configuration file: /etc/ssh/sshd_config
[23:03:45] Info: Rkhunter option ALLOW_SSH_ROOT_USER set to 'no'.
[23:03:45] Info: Rkhunter option ALLOW_SSH_PROT_V1 set to '2'.
[23:03:45] Checking if SSH root access is allowed [ Warning ]
[23:03:45] Warning: The SSH and rkhunter configuration options should be the same:
[23:03:45] SSH configuration option 'PermitRootLogin': yes
[23:03:45] Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no
[23:03:45] Checking if SSH protocol v1 is allowed [ Not set ]
[23:03:45] Checking for other suspicious configuration settings [ None found ]
[23:03:45]
[23:03:45] Info: Starting test name 'system_configs_syslog'
[23:03:45] Checking for a running system logging daemon [ Found ]
[23:03:45] Info: A running 'rsyslog' daemon has been found.
[23:03:45] Info: A running 'systemd-journald' daemon has been found.
[23:03:45] Info: Found an rsyslog configuration file: /etc/rsyslog.conf
[23:03:45] Info: Found a systemd configuration file: /etc/systemd/journald.conf
[23:03:45] Checking for a system logging configuration file [ Found ]
[23:03:46] Checking if syslog remote logging is allowed [ Not allowed ]
[23:03:46]
[23:03:46] Info: Starting test name 'filesystem'
[23:03:46] Performing filesystem checks
[23:03:46] Info: SCAN_MODE_DEV set to 'THOROUGH'
[23:03:47] Checking /dev for suspicious file types [ Warning ]
[23:03:47] Warning: Suspicious file types found in /dev:
[23:03:47] /dev/shm/PostgreSQL.288288730: data
[23:03:47] Checking for hidden files and directories [ None found ]
[23:03:47] Checking for missing log files [ Skipped ]
[23:03:47] Info: No missing log file names configured.
[23:03:47] Checking for empty log files [ Skipped ]
[23:03:47] Info: No empty log file names configured.
[23:04:00]
[23:04:00] Info: Starting test name 'apps'
[23:04:00] Checking application versions...
[23:04:00] Checking version of Exim MTA [ OK ]
[23:04:00] Info: Application 'exim' version '4.92' found.
[23:04:00] Checking version of GnuPG [ OK ]
[23:04:00] Info: Application 'gpg' version '2.2.12' found.
[23:04:00] Info: Application 'httpd' not found.
[23:04:00] Checking version of Bind DNS [ OK ]
[23:04:00] Info: Application 'named' version '9.11.5-P1' found.
[23:04:00] Checking version of OpenSSL [ OK ]
[23:04:00] Info: Application 'openssl' version '1.1.1b' found.
[23:04:00] Checking version of PHP [ OK ]
[23:04:00] Info: Application 'php' version '7.2.19' found.
[23:04:00] Info: Application 'procmail' not found.
[23:04:00] Info: Application 'proftpd' not found.
[23:04:00] Checking version of OpenSSH [ OK ]
[23:04:00] Info: Application 'sshd' version '7.9,' found.
[23:04:00] Info: Applications checked: 6 out of 9
[23:04:00]
[23:04:00] System checks summary
[23:04:00] =====================
[23:04:00]
[23:04:00] File properties checks...
[23:04:00] Files checked: 149
[23:04:00] Suspect files: 1
[23:04:00]
[23:04:00] Rootkit checks...
[23:04:00] Rootkits checked : 503
[23:04:00] Possible rootkits: 2
[23:04:01]
[23:04:01] Applications checks...
[23:04:01] Applications checked: 6
[23:04:01] Suspect applications: 0
[23:04:01]
[23:04:01] The system checks took: 10 minutes and 40 seconds
[23:04:01]
[23:04:01] Info: End date is Fri 14 Jun 2019 11:04:01 PM +07

1 1 1 1 1 1 1 1 1 1 Rating 0.00 (0 Votes)