Home Forums Newsletter Plugin Support Weird server message

Viewing 1 post (of 1 total)
  • Author
    Posts
  • #15438
    MKJ
    Participant

    Hallo,

    since the last update to 3.6.7 we get a strange server message (see below). Can you make any sense of that? We use the WordPress mail function. No external email server, no SMTP. The provider support can’t help They say, server information and OS do not match the server configuration. Any ideas?

    Thanks!

    
    To: xxx
    Subject: [rkhunter] Warnings found for euve34390.vserver.de
    From: watchdog@euve34390.vserver.de
    Answer to: watchdog@euve34390.vserver.de
    Date: 16. März 2015 01:02:11 MEZ
    
    Please inspect this machine, because it may be infected. Scan log:
    [01:00:21] Running Rootkit Hunter version 1.3.4 on euve34390
    [01:00:21]
    [01:00:21] Info: Start date is Mon Mar 16 01:00:21 CET 2015
    [01:00:21]
    [01:00:21] Checking configuration file and command-line options...
    [01:00:21] Info: Detected operating system is 'Linux'
    [01:00:21] Info: Found O/S name: Debian 6.0.8
    [01:00:21] Info: Command line is /opt/psa/admin/sbin/modules//watchdog/rkhunter -c --configfile /opt/psa/etc/modules/watchdog/rkhunter.conf --cronjob --propupd --createlogfile
    [01:00:21] Info: Environment shell is /bin/sh; rkhunter is using bash
    [01:00:21] Info: Using configuration file '/opt/psa/etc/modules/watchdog/rkhunter.conf'
    [01:00:21] Info: Installation directory is '/opt/psa'
    [01:00:21] Info: Using language 'en'
    [01:00:21] Info: Using '/opt/psa/var/modules/watchdog/lib/rkhunter/lib/rkhunter/db' as the database directory
    [01:00:21] Info: Using '/opt/psa/var/modules/watchdog/lib/rkhunter/rkhunter/scripts' as the support script directory
    [01:00:21] Info: Using '/opt/psa/admin/bin/modules/watchdog /usr/local/bin /usr/local/sbin /bin /sbin /usr/bin /usr/sbin /bin /usr/bin /sbin /usr/sbin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec' as the command directories
    [01:00:21] Info: Using '/' as the root directory by default
    [01:00:21] Info: Using '/opt/psa/var/modules/watchdog/lib/rkhunter/lib/rkhunter/tmp' as the temporary directory
    [01:00:21] Info: Emailing warnings to 'online@findyournose.com' using command '/opt/psa/admin/bin/modules/watchdog/send-mail'
    [01:00:22] Info: X will be automatically detected
    [01:00:22] Info: Found the 'diff' command: /usr/bin/diff
    [01:00:22] Info: Found the 'file' command: /usr/bin/file
    [01:00:22] Info: Found the 'find' command: /usr/bin/find
    [01:00:22] Info: Found the 'ifconfig' command: /sbin/ifconfig
    [01:00:22] Info: Found the 'ip' command: /bin/ip
    [01:00:22] Info: Found the 'ldd' command: /usr/bin/ldd
    [01:00:22] Info: Found the 'lsattr' command: /usr/bin/lsattr
    [01:00:22] Info: Found the 'lsmod' command: /bin/lsmod
    [01:00:22] Info: Found the 'lsof' command: /usr/bin/lsof
    [01:00:22] Info: Found the 'mktemp' command: /bin/mktemp
    [01:00:22] Info: Found the 'netstat' command: /bin/netstat
    [01:00:22] Info: Found the 'perl' command: /usr/bin/perl
    [01:00:22] Info: Found the 'ps' command: /bin/ps
    [01:00:22] Info: Found the 'pwd' command: /bin/pwd
    [01:00:22] Info: Found the 'readlink' command: /bin/readlink
    [01:00:22] Info: Found the 'sort' command: /usr/bin/sort
    [01:00:22] Info: Found the 'stat' command: /usr/bin/stat
    [01:00:22] Info: Found the 'strings' command: /usr/bin/strings
    [01:00:22] Info: Found the 'uniq' command: /usr/bin/uniq
    [01:00:22] Info: System is not using prelinking
    [01:00:22] Info: Using the '/usr/bin/sha1sum' command for the file hash checks
    [01:00:22] Info: Stored hash values used hash function '/usr/bin/sha1sum'
    [01:00:22] Info: Stored hash values used package manager 'DPKG' (md5 function)
    [01:00:22] Info: The hash function field index is set to 1
    [01:00:22] Info: Using package manager 'DPKG' to update the file hash values
    [01:00:22] Info: Found the 'dpkg-query' command: /usr/bin/dpkg-query
    [01:00:22] Info: Using package manager 'DPKG' for file property checks
    [01:00:22] Info: Found the 'dpkg-query' command: /usr/bin/dpkg-query
    [01:00:22] Info: Using MD5 hash function command '/usr/bin/md5sum' to assist package manager verification
    [01:00:22] Info: Previous file attributes were stored
    [01:00:22] Info: Current file attributes will be stored
    [01:00:22] Info: Enabled tests are: all
    [01:00:22] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps
    [01:00:22] Info: All ksyms and kallsyms checks will be skipped - neither file is present on the system.
    [01:00:22]
    [01:00:22] Checking if the O/S has changed since last time...
    [01:00:22] Info: Nothing seems to have changed
    [01:00:22]
    [01:00:22] Info: Starting file properties data update...
    [01:00:22] Info: Created temporary file '/opt/psa/var/modules/watchdog/lib/rkhunter/lib/rkhunter/tmp/rkhunter.dat.RimOBW2IxF'
    [01:00:22] Collecting O/S info...
    [01:00:22] Info: Found system architecture: x86_64
    [01:00:22] Info: Found release file: /etc/debian_version
    [01:00:22] Info: Found O/S name: Debian 6.0.8
    [01:00:22] Getting file properties...
    [01:00:37] Info: Found 34 files in /bin
    [01:00:45] Info: Found 59 files in /usr/bin
    [01:00:48] Info: Found 16 files in /sbin
    [01:00:50] Info: Found 14 files in /usr/sbin
    [01:00:50] Info: Found 0 files in /usr/local/bin
    [01:00:50] Info: Found 0 files in /usr/local/sbin
    [01:00:50] Info: File updated: searched for 152 files, found 123
    [01:00:50] Info: New rkhunter.dat file installed in '/opt/psa/var/modules/watchdog/lib/rkhunter/lib/rkhunter/db'
    [01:00:50]
    [01:00:50] Starting system checks...
    [01:00:50]
    [01:00:50] Checking system commands...
    [01:00:50] Info: Starting test name 'system_commands'
    [01:00:50]
    [01:00:50] Performing 'strings' command checks
    [01:00:50] Info: Starting test name 'strings'
    [01:00:51] Scanning for string /usr/sbin/ntpsx               [ OK ]
    [01:00:51] Scanning for string /usr/lib/.../ls               [ OK ]
    [01:00:51] Scanning for string /usr/lib/.../netstat          [ OK ]
    [01:00:51] Scanning for string /usr/lib/.../lsof             [ OK ]
    [01:00:51] Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
    [01:00:51] Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
    [01:00:52] Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
    [01:00:52] Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
    [01:00:52] Scanning for string /usr/lib/.../uconf.inv        [ OK ]
    [01:00:52] Scanning for string /usr/lib/.../psr              [ OK ]
    [01:00:53] Scanning for string /usr/lib/.../find             [ OK ]
    [01:00:53] Scanning for string /usr/lib/.../pstree           [ OK ]
    [01:00:53] Scanning for string /usr/lib/.../slocate          [ OK ]
    [01:00:53] Scanning for string /usr/lib/.../du               [ OK ]
    [01:00:53] Scanning for string /usr/lib/.../top              [ OK ]
    [01:00:53] Scanning for string /usr/lib/...                  [ OK ]
    [01:00:53] Scanning for string /usr/lib/.../bkit-ssh         [ OK ]
    [01:00:54] Scanning for string /usr/lib/.bkit-               [ OK ]
    [01:00:54] Scanning for string /tmp/.bkp                     [ OK ]
    [01:00:54] Scanning for string /tmp/.cinik                   [ OK ]
    [01:00:54] Scanning for string /tmp/.font-unix/.cinik        [ OK ]
    [01:00:54] Scanning for string /lib/.sso                     [ OK ]
    [01:00:54] Scanning for string /lib/.so                      [ OK ]
    [01:00:54] Scanning for string /var/run/...dica/clean        [ OK ]
    [01:00:54] Scanning for string /var/run/...dica/xl           [ OK ]
    [01:00:54] Scanning for string /var/run/...dica/xdr          [ OK ]
    [01:00:54] Scanning for string /var/run/...dica/psg          [ OK ]
    [01:00:54] Scanning for string /var/run/...dica/secure       [ OK ]
    [01:00:54] Scanning for string /var/run/...dica/rdx          [ OK ]
    [01:00:54] Scanning for string /var/run/...dica/va           [ OK ]
    [01:00:54] Scanning for string /var/run/...dica/cl.sh        [ OK ]
    [01:00:54] Scanning for string /usr/bin/.etc                 [ OK ]
    [01:00:54] Scanning for string /usr/lib/.fx/sched_host.2     [ OK ]
    [01:00:54] Scanning for string /usr/lib/.fx/random_d.2       [ OK ]
    [01:00:54] Scanning for string /usr/lib/.fx/set_pid.2        [ OK ]
    [01:00:54] Scanning for string /usr/lib/.fx/cons.saver       [ OK ]
    [01:00:54] Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
    [01:00:54] Scanning for string /bin/sysback                  [ OK ]
    [01:00:54] Scanning for string /usr/local/bin/sysback        [ OK ]
    [01:00:54] Scanning for string /usr/lib/.tbd                 [ OK ]
    [01:00:54] Scanning for string /dev/.lib/lib/lib/t0rns       [ OK ]
    [01:00:54] Scanning for string /dev/.lib/lib/lib/du          [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/ls          [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/t0rnsb      [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/ps          [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/t0rnp       [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/find        [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/ifconfig    [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/pg          [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/ssh.tgz     [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/top         [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/sz          [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/login       [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/in.fingerd  [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/1i0n.sh     [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/pstree      [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/in.telnetd  [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/mjy         [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/sush        [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/tfn         [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/name        [ OK ]
    [01:00:55] Scanning for string /dev/.lib/lib/lib/getip.sh    [ OK ]
    [01:00:55] Scanning for string /usr/info/.torn/sh*           [ OK ]
    [01:00:55] Scanning for string /usr/src/.puta/.1addr         [ OK ]
    [01:00:55] Scanning for string /usr/src/.puta/.1file         [ OK ]
    [01:00:55] Scanning for string /usr/src/.puta/.1proc         [ OK ]
    [01:00:55] Scanning for string /usr/src/.puta/.1logz         [ OK ]
    [01:00:55] Scanning for string /usr/info/.t0rn               [ OK ]
    [01:00:55] Scanning for string /dev/.lib                     [ OK ]
    [01:00:56] Scanning for string /dev/.lib/lib                 [ OK ]
    [01:00:56] Scanning for string /dev/.lib/lib/lib             [ OK ]
    [01:00:56] Scanning for string /dev/.lib/lib/lib/dev         [ OK ]
    [01:00:56] Scanning for string /dev/.lib/lib/scan            [ OK ]
    [01:00:56] Scanning for string /usr/src/.puta                [ OK ]
    [01:00:56] Scanning for string /usr/man/man1/man1            [ OK ]
    [01:00:56] Scanning for string /usr/man/man1/man1/lib        [ OK ]
    [01:00:56] Scanning for string /usr/man/man1/man1/lib/.lib   [ OK ]
    [01:00:56] Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
    [01:00:56]
    [01:00:56] Performing 'shared libraries' checks
    [01:00:56] Info: Starting test name 'shared_libs'
    [01:00:56] Checking for preloading variables                 [ None found ]
    [01:00:56] Checking for preload file                         [ Not found ]
    [01:00:56] Info: Starting test name 'shared_libs_path'
    [01:00:56] Checking LD_LIBRARY_PATH variable                 [ Not found ]
    [01:00:56]
    [01:00:56] Performing file properties checks
    [01:00:56] Info: Starting test name 'properties'
    [01:00:56] Checking for prerequisites                        [ OK ]
    [01:00:57] /bin/bash                                         [ OK ]
    [01:00:57] /bin/cat                                          [ OK ]
    [01:00:57] /bin/chmod                                        [ OK ]
    [01:00:58] /bin/chown                                        [ OK ]
    [01:00:58] /bin/cp                                           [ OK ]
    [01:00:58] /bin/date                                         [ OK ]
    [01:00:58] /bin/df                                           [ OK ]
    [01:00:59] /bin/dmesg                                        [ OK ]
    [01:00:59] /bin/echo                                         [ OK ]
    [01:00:59] /bin/ed                                           [ OK ]
    [01:01:00] /bin/egrep                                        [ OK ]
    [01:01:00] /bin/fgrep                                        [ OK ]
    [01:01:00] /bin/fuser                                        [ OK ]
    [01:01:00] /bin/grep                                         [ OK ]
    [01:01:01] /bin/ip                                           [ OK ]
    [01:01:01] /bin/kill                                         [ OK ]
    [01:01:01] /bin/less                                         [ OK ]
    [01:01:02] /bin/login                                        [ OK ]
    [01:01:02] /bin/ls                                           [ OK ]
    [01:01:02] /bin/lsmod                                        [ OK ]
    [01:01:02] /bin/mktemp                                       [ OK ]
    [01:01:02] /bin/more                                         [ OK ]
    [01:01:03] /bin/mount                                        [ OK ]
    [01:01:03] /bin/mv                                           [ OK ]
    [01:01:03] /bin/netstat                                      [ OK ]
    [01:01:04] /bin/ps                                           [ OK ]
    [01:01:04] /bin/pwd                                          [ OK ]
    [01:01:04] /bin/readlink                                     [ OK ]
    [01:01:04] /bin/sed                                          [ OK ]
    [01:01:05] /bin/sh                                           [ OK ]
    [01:01:05] /bin/su                                           [ OK ]
    [01:01:05] /bin/touch                                        [ OK ]
    [01:01:05] /bin/uname                                        [ OK ]
    [01:01:06] /bin/which                                        [ OK ]
    [01:01:06] /usr/bin/awk                                      [ OK ]
    [01:01:06] /usr/bin/basename                                 [ OK ]
    [01:01:07] /usr/bin/chattr                                   [ OK ]
    [01:01:07] /usr/bin/curl                                     [ OK ]
    [01:01:07] /usr/bin/cut                                      [ OK ]
    [01:01:07] /usr/bin/diff                                     [ OK ]
    [01:01:08] /usr/bin/dirname                                  [ OK ]
    [01:01:08] /usr/bin/dpkg                                     [ OK ]
    [01:01:08] /usr/bin/dpkg-query                               [ OK ]
    [01:01:08] /usr/bin/du                                       [ OK ]
    [01:01:08] /usr/bin/env                                      [ OK ]
    [01:01:09] /usr/bin/file                                     [ OK ]
    [01:01:09] /usr/bin/find                                     [ OK ]
    [01:01:09] /usr/bin/GET                                      [ OK ]
    [01:01:09] /usr/bin/groups                                   [ OK ]
    [01:01:09] /usr/bin/head                                     [ OK ]
    [01:01:10] /usr/bin/id                                       [ OK ]
    [01:01:10] /usr/bin/killall                                  [ OK ]
    [01:01:10] /usr/bin/last                                     [ OK ]
    [01:01:10] /usr/bin/lastlog                                  [ OK ]
    [01:01:11] /usr/bin/ldd                                      [ OK ]
    [01:01:11] /usr/bin/less                                     [ OK ]
    [01:01:11] /usr/bin/logger                                   [ OK ]
    [01:01:11] /usr/bin/lsattr                                   [ OK ]
    [01:01:11] /usr/bin/lsof                                     [ OK ]
    [01:01:12] /usr/bin/mail                                     [ OK ]
    [01:01:12] /usr/bin/md5sum                                   [ OK ]
    [01:01:12] /usr/bin/newgrp                                   [ OK ]
    [01:01:12] /usr/bin/passwd                                   [ OK ]
    [01:01:12] Info: Found file '/usr/bin/passwd': it is whitelisted for the 'file immutable-bit' check.
    [01:01:13] /usr/bin/perl                                     [ OK ]
    [01:01:13] /usr/bin/pstree                                   [ OK ]
    [01:01:13] /usr/bin/runcon                                   [ OK ]
    [01:01:13] /usr/bin/sha1sum                                  [ OK ]
    [01:01:14] /usr/bin/size                                     [ OK ]
    [01:01:14] /usr/bin/sort                                     [ OK ]
    [01:01:14] /usr/bin/stat                                     [ OK ]
    [01:01:14] /usr/bin/strings                                  [ OK ]
    [01:01:14] /usr/bin/sudo                                     [ OK ]
    [01:01:15] /usr/bin/tail                                     [ OK ]
    [01:01:15] /usr/bin/test                                     [ OK ]
    [01:01:15] /usr/bin/top                                      [ OK ]
    [01:01:15] /usr/bin/touch                                    [ OK ]
    [01:01:15] /usr/bin/tr                                       [ OK ]
    [01:01:16] /usr/bin/uniq                                     [ OK ]
    [01:01:16] /usr/bin/users                                    [ OK ]
    [01:01:16] /usr/bin/vmstat                                   [ OK ]
    [01:01:16] /usr/bin/w                                        [ OK ]
    [01:01:16] /usr/bin/watch                                    [ OK ]
    [01:01:17] /usr/bin/wc                                       [ OK ]
    [01:01:17] /usr/bin/wget                                     [ OK ]
    [01:01:17] /usr/bin/whatis                                   [ OK ]
    [01:01:17] /usr/bin/whereis                                  [ OK ]
    [01:01:17] /usr/bin/which                                    [ OK ]
    [01:01:18] /usr/bin/who                                      [ OK ]
    [01:01:18] /usr/bin/whoami                                   [ OK ]
    [01:01:18] /usr/bin/gawk                                     [ OK ]
    [01:01:18] /usr/bin/lwp-request                              [ OK ]
    [01:01:18] /usr/bin/heirloom-mailx                           [ OK ]
    [01:01:19] /usr/bin/w.procps                                 [ OK ]
    [01:01:19] /sbin/chkconfig                                   [ OK ]
    [01:01:19] /sbin/depmod                                      [ OK ]
    [01:01:19] /sbin/ifconfig                                    [ OK ]
    [01:01:20] /sbin/ifdown                                      [ OK ]
    [01:01:20] /sbin/ifup                                        [ OK ]
    [01:01:20] /sbin/init                                        [ OK ]
    [01:01:20] Info: Found file '/sbin/init': it is whitelisted for the 'file immutable-bit' check.
    [01:01:20] /sbin/insmod                                      [ OK ]
    [01:01:20] /sbin/ip                                          [ OK ]
    [01:01:21] /sbin/lsmod                                       [ OK ]
    [01:01:21] /sbin/modinfo                                     [ OK ]
    [01:01:21] /sbin/modprobe                                    [ OK ]
    [01:01:21] /sbin/rmmod                                       [ OK ]
    [01:01:22] /sbin/runlevel                                    [ OK ]
    [01:01:22] /sbin/sulogin                                     [ OK ]
    [01:01:22] /sbin/sysctl                                      [ OK ]
    [01:01:22] /sbin/syslogd                                     [ OK ]
    [01:01:23] /usr/sbin/adduser                                 [ OK ]
    [01:01:23] /usr/sbin/chroot                                  [ OK ]
    [01:01:23] /usr/sbin/cron                                    [ OK ]
    [01:01:23] /usr/sbin/groupadd                                [ OK ]
    [01:01:24] /usr/sbin/groupdel                                [ OK ]
    [01:01:24] /usr/sbin/groupmod                                [ OK ]
    [01:01:24] /usr/sbin/grpck                                   [ OK ]
    [01:01:25] /usr/sbin/nologin                                 [ OK ]
    [01:01:25] /usr/sbin/pwck                                    [ OK ]
    [01:01:25] /usr/sbin/useradd                                 [ OK ]
    [01:01:25] /usr/sbin/userdel                                 [ OK ]
    [01:01:26] /usr/sbin/usermod                                 [ OK ]
    [01:01:26] /usr/sbin/vipw                                    [ OK ]
    [01:01:26] /usr/sbin/xinetd                                  [ OK ]
    [01:01:28]
    [01:01:28] Checking for rootkits...
    [01:01:28] Info: Starting test name 'rootkits'
    [01:01:28]
    [01:01:28] Performing check of known rootkit files and directories
    [01:01:28] Info: Starting test name 'known_rkts'
    [01:01:28]
    [01:01:28] Checking for 55808 Trojan - Variant A...
    [01:01:28]   Checking for file '/tmp/.../r'                  [ Not found ]
    [01:01:28]   Checking for file '/tmp/.../a'                  [ Not found ]
    [01:01:28] 55808 Trojan - Variant A                          [ Not found ]
    [01:01:28]
    [01:01:28] Checking for ADM Worm...
    [01:01:28]   Checking for string 'w0rm'                      [ Not found ]
    [01:01:28] ADM Worm                                          [ Not found ]
    [01:01:28]
    [01:01:28] Checking for AjaKit Rootkit...
    [01:01:28]   Checking for file '/dev/tux/.addr'              [ Not found ]
    [01:01:28]   Checking for file '/dev/tux/.proc'              [ Not found ]
    [01:01:28]   Checking for file '/dev/tux/.file'              [ Not found ]
    [01:01:28]   Checking for file '/lib/.libgh-gh/cleaner'      [ Not found ]
    [01:01:28]   Checking for file '/lib/.libgh-gh/Patch/patch'  [ Not found ]
    [01:01:28]   Checking for file '/lib/.libgh-gh/sb0k'         [ Not found ]
    [01:01:28]   Checking for directory '/dev/tux'               [ Not found ]
    [01:01:28]   Checking for directory '/lib/.libgh-gh'         [ Not found ]
    [01:01:28] AjaKit Rootkit                                    [ Not found ]
    [01:01:28]
    [01:01:28] Checking for aPa Kit...
    [01:01:28]   Checking for file '/usr/share/.aPa'             [ Not found ]
    [01:01:28] aPa Kit                                           [ Not found ]
    [01:01:28]
    [01:01:28] Checking for Apache Worm...
    [01:01:28]   Checking for file '/bin/.log'                   [ Not found ]
    [01:01:29] Apache Worm                                       [ Not found ]
    [01:01:29]
    [01:01:29] Checking for Ambient (ark) Rootkit...
    [01:01:29]   Checking for file '/usr/lib/.ark?'              [ Not found ]
    [01:01:29]   Checking for file '/dev/ptyxx/.log'             [ Not found ]
    [01:01:29]   Checking for file '/dev/ptyxx/.file'            [ Not found ]
    [01:01:29]   Checking for directory '/dev/ptyxx'             [ Not found ]
    [01:01:29] Ambient (ark) Rootkit                             [ Not found ]
    [01:01:29]
    [01:01:29] Checking for Balaur Rootkit...
    [01:01:29]   Checking for file '/usr/lib/liblog.o'           [ Not found ]
    [01:01:29]   Checking for directory '/usr/lib/.kinetic'      [ Not found ]
    [01:01:29]   Checking for directory '/usr/lib/.egcs'         [ Not found ]
    [01:01:29]   Checking for directory '/usr/lib/.wormie'       [ Not found ]
    [01:01:29] Balaur Rootkit                                    [ Not found ]
    [01:01:29]
    [01:01:29] Checking for BeastKit Rootkit...
    [01:01:29]   Checking for file '/usr/sbin/arobia'            [ Not found ]
    [01:01:29]   Checking for file '/usr/sbin/idrun'             [ Not found ]
    [01:01:29]   Checking for file '/usr/lib/elm/arobia/elm'     [ Not found ]
    [01:01:29]   Checking for file '/usr/lib/elm/arobia/elm/hk'  [ Not found ]
    [01:01:29]   Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
    [01:01:29]   Checking for file '/usr/lib/elm/arobia/elm/sc'  [ Not found ]
    [01:01:29]   Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
    [01:01:29]   Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
    [01:01:29]   Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
    [01:01:29]   Checking for directory '/lib/ldd.so/bktools'    [ Not found ]
    [01:01:29] BeastKit Rootkit                                  [ Not found ]
    [01:01:29]
    [01:01:29] Checking for beX2 Rootkit...
    [01:01:29]   Checking for directory '/usr/include/bex'       [ Not found ]
    [01:01:29] beX2 Rootkit                                      [ Not found ]
    [01:01:29]
    [01:01:29] Checking for BOBKit Rootkit...
    [01:01:29]   Checking for file '/usr/sbin/ntpsx'             [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../ls'             [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../netstat'        [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../lsof'           [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../uconf.inv'      [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../psr'            [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../find'           [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../pstree'         [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../slocate'        [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../du'             [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/.../top'            [ Not found ]
    [01:01:30]   Checking for directory '/usr/lib/...'           [ Not found ]
    [01:01:30]   Checking for directory '/usr/lib/.../bkit-ssh'  [ Not found ]
    [01:01:30]   Checking for directory '/usr/lib/.bkit-'        [ Not found ]
    [01:01:30]   Checking for directory '/tmp/.bkp'              [ Not found ]
    [01:01:30] BOBKit Rootkit                                    [ Not found ]
    [01:01:30]
    [01:01:30] Checking for CiNIK Worm (Slapper.B variant)...
    [01:01:30]   Checking for file '/tmp/.cinik'                 [ Not found ]
    [01:01:30]   Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
    [01:01:30] CiNIK Worm (Slapper.B variant)                    [ Not found ]
    [01:01:30]
    [01:01:30] Checking for Danny-Boy's Abuse Kit...
    [01:01:30]   Checking for file '/dev/mdev'                   [ Not found ]
    [01:01:30]   Checking for file '/usr/lib/libX.a'             [ Not found ]
    [01:01:30] Danny-Boy's Abuse Kit                             [ Not found ]
    [01:01:30]
    [01:01:30] Checking for Devil RootKit...
    [01:01:31]   Checking for file '/var/lib/games/.src'         [ Not found ]
    [01:01:31]   Checking for file '/dev/dsx'                    [ Not found ]
    [01:01:31]   Checking for file '/dev/caca'                   [ Not found ]
    [01:01:31] Devil RootKit                                     [ Not found ]
    [01:01:31]
    [01:01:31] Checking for Dica-Kit Rootkit...
    [01:01:31]   Checking for file '/lib/.sso'                   [ Not found ]
    [01:01:31]   Checking for file '/lib/.so'                    [ Not found ]
    [01:01:31]   Checking for file '/var/run/...dica/clean'      [ Not found ]
    [01:01:31]   Checking for file '/var/run/...dica/xl'         [ Not found ]
    [01:01:31]   Checking for file '/var/run/...dica/xdr'        [ Not found ]
    [01:01:31]   Checking for file '/var/run/...dica/psg'        [ Not found ]
    [01:01:31]   Checking for file '/var/run/...dica/secure'     [ Not found ]
    [01:01:32]   Checking for file '/var/run/...dica/rdx'        [ Not found ]
    [01:01:32]   Checking for file '/var/run/...dica/va'         [ Not found ]
    [01:01:32]   Checking for file '/var/run/...dica/cl.sh'      [ Not found ]
    [01:01:32]   Checking for file '/usr/bin/.etc'               [ Not found ]
    [01:01:32]   Checking for directory '/var/run/...dica'       [ Not found ]
    [01:01:32]   Checking for directory '/var/run/...dica/mh'    [ Not found ]
    [01:01:32]   Checking for directory '/var/run/...dica/scan'  [ Not found ]
    [01:01:32] Dica-Kit Rootkit                                  [ Not found ]
    [01:01:32]
    [01:01:32] Checking for Dreams Rootkit...
    [01:01:32]   Checking for file '/dev/ttyoa'                  [ Not found ]
    [01:01:32]   Checking for file '/dev/ttyof'                  [ Not found ]
    [01:01:32]   Checking for file '/dev/ttyop'                  [ Not found ]
    [01:01:32]   Checking for file & 
Viewing 1 post (of 1 total)
  • You must be logged in to reply to this topic.
×