by dirk on Wed May 06, 2009 3:52 am
part two besause of to much characters
08:55:56]
[08:55:56] Checking for Sebek LKM...
[08:55:56] Checking for kernel symbol 'adore or sebek' [ Not found ]
[08:55:56] Sebek LKM [ Not found ]
[08:55:56]
[08:55:56] Checking for Shutdown Rootkit...
[08:55:56] Checking for file '/usr/man/man5/.. /.dir/scannah/asus' [ Not found ]
[08:55:56] Checking for file '/usr/man/man5/.. /.dir/see' [ Not found ]
[08:55:56] Checking for file '/usr/man/man5/.. /.dir/nscd' [ Not found ]
[08:55:56] Checking for file '/usr/man/man5/.. /.dir/alpd' [ Not found ]
[08:55:56] Checking for file '/etc/rc.d/rc.local ' [ Not found ]
[08:55:57] Checking for directory '/usr/man/man5/.. /.dir' [ Not found ]
[08:55:57] Checking for directory '/usr/man/man5/.. /.dir/scannah' [ Not found ]
[08:55:57] Checking for directory '/etc/rc.d/rc0.d/.. /.dir' [ Not found ]
[08:55:57] Shutdown Rootkit [ Not found ]
[08:55:57]
[08:55:57] Checking for SHV4 Rootkit...
[08:55:57] Checking for file '/etc/ld.so.hash' [ Not found ]
[08:55:57] Checking for file '/lib/libext-2.so.7' [ Not found ]
[08:55:57] Checking for file '/lib/lidps1.so' [ Not found ]
[08:55:57] Checking for file '/usr/sbin/xntps' [ Not found ]
[08:55:57] Checking for directory '/lib/security/.config' [ Not found ]
[08:55:57] Checking for directory '/lib/security/.config/ssh' [ Not found ]
[08:55:57] SHV4 Rootkit [ Not found ]
[08:55:57]
[08:55:57] Checking for SHV5 Rootkit...
[08:55:57] Checking for file '/etc/sh.conf' [ Not found ]
[08:55:57] Checking for file '/dev/srd0' [ Not found ]
[08:55:57] Checking for directory '/usr/lib/libsh' [ Not found ]
[08:55:57] SHV5 Rootkit [ Not found ]
[08:55:57]
[08:55:57] Checking for Sin Rootkit...
[08:55:57] Checking for file '/dev/.haos/haos1/.f/Denyed' [ Not found ]
[08:55:57] Checking for file '/dev/ttyoa' [ Not found ]
[08:55:57] Checking for file '/dev/ttyof' [ Not found ]
[08:55:57] Checking for file '/dev/ttyop' [ Not found ]
[08:55:57] Checking for file '/dev/ttyos' [ Not found ]
[08:55:57] Checking for file '/usr/lib/.lib' [ Not found ]
[08:55:57] Checking for file '/usr/lib/sn/.X' [ Not found ]
[08:55:57] Checking for file '/usr/lib/sn/.sys' [ Not found ]
[08:55:57] Checking for file '/usr/lib/ld/.X' [ Not found ]
[08:55:57] Checking for file '/usr/man/man1/...' [ Not found ]
[08:55:57] Checking for file '/usr/man/man1/.../.m' [ Not found ]
[08:55:57] Checking for file '/usr/man/man1/.../.w' [ Not found ]
[08:55:57] Checking for directory '/usr/lib/sn' [ Not found ]
[08:55:57] Checking for directory '/usr/lib/man1/...' [ Not found ]
[08:55:57] Checking for directory '/dev/.haos' [ Not found ]
[08:55:57] Sin Rootkit [ Not found ]
[08:55:57]
[08:55:57] Checking for Slapper Worm...
[08:55:57] Checking for file '/tmp/.bugtraq' [ Not found ]
[08:55:57] Checking for file '/tmp/.uubugtraq' [ Not found ]
[08:55:57] Checking for file '/tmp/.bugtraq.c' [ Not found ]
[08:55:57] Checking for file '/tmp/httpd' [ Not found ]
[08:55:58] Checking for file '/tmp/.unlock' [ Not found ]
[08:55:58] Checking for file '/tmp/update' [ Not found ]
[08:55:58] Checking for file '/tmp/.cinik' [ Not found ]
[08:55:58] Checking for file '/tmp/.b' [ Not found ]
[08:55:58] Slapper Worm [ Not found ]
[08:55:58]
[08:55:58] Checking for Sneakin Rootkit...
[08:55:58] Checking for directory '/tmp/.X11-unix/.../rk' [ Not found ]
[08:55:58] Sneakin Rootkit [ Not found ]
[08:55:58]
[08:55:58] Checking for Suckit Rootkit...
[08:55:58] Checking for file '/sbin/initsk12' [ Not found ]
[08:55:58] Checking for file '/sbin/initxrk' [ Not found ]
[08:55:58] Checking for file '/usr/bin/null' [ Not found ]
[08:55:58] Checking for file '/usr/share/locale/sk/.sk12/sk' [ Not found ]
[08:55:58] Checking for file '/etc/rc.d/rc0.d/S23kmdac' [ Not found ]
[08:55:58] Checking for file '/etc/rc.d/rc1.d/S23kmdac' [ Not found ]
[08:55:58] Checking for file '/etc/rc.d/rc2.d/S23kmdac' [ Not found ]
[08:55:58] Checking for file '/etc/rc.d/rc3.d/S23kmdac' [ Not found ]
[08:55:58] Checking for file '/etc/rc.d/rc4.d/S23kmdac' [ Not found ]
[08:55:58] Checking for file '/etc/rc.d/rc5.d/S23kmdac' [ Not found ]
[08:55:58] Checking for file '/etc/rc.d/rc6.d/S23kmdac' [ Not found ]
[08:55:58] Checking for directory '/dev/sdhu0/tehdrakg' [ Not found ]
[08:55:58] Checking for directory '/etc/.MG' [ Not found ]
[08:55:58] Checking for directory '/usr/share/locale/sk/.sk12' [ Not found ]
[08:55:58] Checking for directory '/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist' [ Not found ]
[08:55:58] Suckit Rootkit [ Not found ]
[08:55:58]
[08:55:58] Checking for SunOS Rootkit...
[08:55:58] Checking for file '/etc/ld.so.hash' [ Not found ]
[08:55:58] Checking for file '/lib/libext-2.so.7' [ Not found ]
[08:55:58] Checking for file '/usr/bin/ssh2d' [ Not found ]
[08:55:58] Checking for file '/bin/xlogin' [ Not found ]
[08:55:58] Checking for file '/usr/lib/crth.o' [ Not found ]
[08:55:58] Checking for file '/usr/lib/crtz.o' [ Not found ]
[08:55:58] Checking for file '/sbin/login' [ Not found ]
[08:55:58] Checking for file '/lib/security/.config/sn' [ Not found ]
[08:55:58] Checking for file '/lib/security/.config/lpsched' [ Not found ]
[08:55:58] Checking for file '/dev/kmod' [ Not found ]
[08:55:58] Checking for file '/dev/dos' [ Not found ]
[08:55:58] SunOS Rootkit [ Not found ]
[08:55:58]
[08:55:58] Checking for SunOS / NSDAP Rootkit...
[08:55:59] Checking for file '/usr/lib/vold/nsdap/.kit' [ Not found ]
[08:55:59] Checking for file '/usr/lib/vold/nsdap/defines' [ Not found ]
[08:55:59] Checking for file '/usr/lib/vold/nsdap/patcher' [ Not found ]
[08:55:59] Checking for file '/usr/lib/vold/nsdap/pg' [ Not found ]
[08:55:59] Checking for file '/usr/lib/vold/nsdap/cleaner' [ Not found ]
[08:55:59] Checking for file '/usr/lib/vold/nsdap/utime' [ Not found ]
[08:55:59] Checking for file '/usr/lib/vold/nsdap/crypt' [ Not found ]
[08:55:59] Checking for file '/usr/lib/vold/nsdap/findkit' [ Not found ]
[08:55:59] Checking for file '/usr/lib/vold/nsdap/sn2' [ Not found ]
[08:55:59] Checking for file '/usr/lib/vold/nsdap/sniffload' [ Not found ]
[08:55:59] Checking for file '/usr/lib/vold/nsdap/runsniff' [ Not found ]
[08:55:59] Checking for file '/usr/lib/lpset' [ Not found ]
[08:55:59] Checking for directory '/usr/lib/vold/nsdap' [ Not found ]
[08:55:59] SunOS / NSDAP Rootkit [ Not found ]
[08:55:59]
[08:55:59] Checking for Superkit Rootkit...
[08:55:59] Checking for file '/usr/man/.sman/sk' [ Not found ]
[08:55:59] Superkit Rootkit [ Not found ]
[08:55:59]
[08:55:59] Checking for TBD (Telnet BackDoor)...
[08:55:59] Checking for file '/usr/lib/.tbd' [ Not found ]
[08:55:59] TBD (Telnet BackDoor) [ Not found ]
[08:55:59]
[08:55:59] Checking for TeLeKiT Rootkit...
[08:55:59] Checking for file '/usr/man/man3/.../TeLeKiT/bin/sniff' [ Not found ]
[08:55:59] Checking for file '/usr/man/man3/.../TeLeKiT/bin/telnetd' [ Not found ]
[08:55:59] Checking for file '/usr/man/man3/.../TeLeKiT/bin/teleulo' [ Not found ]
[08:55:59] Checking for file '/usr/man/man3/.../cl' [ Not found ]
[08:55:59] Checking for file '/dev/ptyr' [ Not found ]
[08:55:59] Checking for file '/dev/ptyp' [ Not found ]
[08:55:59] Checking for file '/dev/ptyq' [ Not found ]
[08:55:59] Checking for file '/dev/hda06' [ Not found ]
[08:55:59] Checking for file '/usr/info/libc1.so' [ Not found ]
[08:55:59] Checking for directory '/usr/man/man3/...' [ Not found ]
[08:55:59] Checking for directory '/usr/man/man3/.../lsniff' [ Not found ]
[08:55:59] Checking for directory '/usr/man/man3/.../TeLeKiT' [ Not found ]
[08:55:59] TeLeKiT Rootkit [ Not found ]
[08:55:59]
[08:55:59] Checking for T0rn Rootkit...
[08:55:59] Checking for file '/dev/.lib/lib/lib/t0rns' [ Not found ]
[08:55:59] Checking for file '/dev/.lib/lib/lib/du' [ Not found ]
[08:55:59] Checking for file '/dev/.lib/lib/lib/ls' [ Not found ]
[08:55:59] Checking for file '/dev/.lib/lib/lib/t0rnsb' [ Not found ]
[08:55:59] Checking for file '/dev/.lib/lib/lib/ps' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/t0rnp' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/find' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/ifconfig' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/pg' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/ssh.tgz' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/top' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/sz' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/login' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/in.fingerd' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/1i0n.sh' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/pstree' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/in.telnetd' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/mjy' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/sush' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/tfn' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/name' [ Not found ]
[08:56:00] Checking for file '/dev/.lib/lib/lib/getip.sh' [ Not found ]
[08:56:00] Checking for file '/usr/info/.torn/sh*' [ Not found ]
[08:56:00] Checking for file '/usr/src/.puta/.1addr' [ Not found ]
[08:56:00] Checking for file '/usr/src/.puta/.1file' [ Not found ]
[08:56:00] Checking for file '/usr/src/.puta/.1proc' [ Not found ]
[08:56:00] Checking for file '/usr/src/.puta/.1logz' [ Not found ]
[08:56:00] Checking for file '/usr/info/.t0rn' [ Not found ]
[08:56:00] Checking for directory '/dev/.lib' [ Not found ]
[08:56:00] Checking for directory '/dev/.lib/lib' [ Not found ]
[08:56:00] Checking for directory '/dev/.lib/lib/lib' [ Not found ]
[08:56:00] Checking for directory '/dev/.lib/lib/lib/dev' [ Not found ]
[08:56:00] Checking for directory '/dev/.lib/lib/scan' [ Not found ]
[08:56:00] Checking for directory '/usr/src/.puta' [ Not found ]
[08:56:00] Checking for directory '/usr/man/man1/man1' [ Not found ]
[08:56:00] Checking for directory '/usr/man/man1/man1/lib' [ Not found ]
[08:56:00] Checking for directory '/usr/man/man1/man1/lib/.lib' [ Not found ]
[08:56:00] Checking for directory '/usr/man/man1/man1/lib/.lib/.backup' [ Not found ]
[08:56:00] T0rn Rootkit [ Not found ]
[08:56:00]
[08:56:00] Checking for Trojanit Kit...
[08:56:00] Checking for file '/bin/.ls' [ Not found ]
[08:56:00] Checking for file '/bin/.ps' [ Not found ]
[08:56:00] Checking for file '/bin/.netstat' [ Not found ]
[08:56:00] Checking for file '/usr/bin/.nop' [ Not found ]
[08:56:00] Checking for file '/usr/bin/.who' [ Not found ]
[08:56:01] Trojanit Kit [ Not found ]
[08:56:01]
[08:56:01] Checking for Tuxtendo Rootkit...
[08:56:01] Checking for file '/dev/tux/.addr' [ Not found ]
[08:56:01] Checking for file '/dev/tux/.cron' [ Not found ]
[08:56:01] Checking for file '/dev/tux/.file' [ Not found ]
[08:56:01] Checking for file '/dev/tux/.log' [ Not found ]
[08:56:01] Checking for file '/dev/tux/.proc' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/crontab' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/df' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/dir' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/find' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/ifconfig' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/locate' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/netstat' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/ps' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/pstree' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/syslogd' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/tcpd' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/top' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/updatedb' [ Not found ]
[08:56:01] Checking for file '/dev/tux/backup/vdir' [ Not found ]
[08:56:01] Checking for directory '/dev/tux' [ Not found ]
[08:56:01] Checking for directory '/dev/tux/ssh2' [ Not found ]
[08:56:01] Checking for directory '/dev/tux/backup' [ Not found ]
[08:56:01] Tuxtendo Rootkit [ Not found ]
[08:56:01]
[08:56:01] Checking for URK Rootkit...
[08:56:01] Checking for file '/usr/man/man1/xxxxxxbin/find' [ Not found ]
[08:56:01] Checking for file '/usr/man/man1/xxxxxxbin/du' [ Not found ]
[08:56:01] Checking for file '/usr/man/man1/xxxxxxbin/ps' [ Not found ]
[08:56:01] Checking for file '/tmp/conf.inf' [ Not found ]
[08:56:01] Checking for directory '/usr/man/man1/xxxxxxbin' [ Not found ]
[08:56:01] URK Rootkit [ Not found ]
[08:56:01]
[08:56:01] Checking for VcKit Rootkit...
[08:56:01] Checking for directory '/usr/include/linux/modules/lib.so' [ Not found ]
[08:56:01] Checking for directory '/usr/include/linux/modules/lib.so/bin' [ Not found ]
[08:56:01] VcKit Rootkit [ Not found ]
[08:56:01]
[08:56:01] Checking for Volc Rootkit...
[08:56:02] Checking for directory '/var/spool/.recent' [ Not found ]
[08:56:02] Checking for directory '/var/spool/.recent/.files' [ Not found ]
[08:56:02] Checking for directory '/usr/lib/volc' [ Not found ]
[08:56:02] Checking for directory '/usr/lib/volc/backup' [ Not found ]
[08:56:02] Volc Rootkit [ Not found ]
[08:56:02]
[08:56:02] Checking for X-Org SunOS Rootkit...
[08:56:02] Checking for file '/usr/lib/libX.a/bin/tmpfl' [ Not found ]
[08:56:02] Checking for file '/usr/lib/libX.a/bin/rps' [ Not found ]
[08:56:02] Checking for file '/usr/bin/srload' [ Not found ]
[08:56:02] Checking for file '/usr/lib/libX.a/bin/sparcv7/rps' [ Not found ]
[08:56:02] Checking for file '/usr/sbin/modcheck' [ Not found ]
[08:56:02] Checking for directory '/usr/lib/libX.a' [ Not found ]
[08:56:02] Checking for directory '/usr/lib/libX.a/bin' [ Not found ]
[08:56:02] Checking for directory '/usr/lib/libX.a/bin/sparcv7' [ Not found ]
[08:56:02] Checking for directory '/usr/share/man...' [ Not found ]
[08:56:02] X-Org SunOS Rootkit [ Not found ]
[08:56:02]
[08:56:02] Checking for zaRwT.KiT Rootkit...
[08:56:02] Checking for file '/dev/rd/s/sendmeil' [ Not found ]
[08:56:02] Checking for file '/dev/ttyf' [ Not found ]
[08:56:02] Checking for file '/dev/ttyp' [ Not found ]
[08:56:02] Checking for file '/dev/ttyn' [ Not found ]
[08:56:02] Checking for file '/rk/tulz' [ Not found ]
[08:56:02] Checking for directory '/rk' [ Not found ]
[08:56:02] Checking for directory '/dev/rd/s' [ Not found ]
[08:56:02] zaRwT.KiT Rootkit [ Not found ]
[08:56:02]
[08:56:02] Performing additional rootkit checks
[08:56:02] Info: Starting test name 'additional_rkts'
[08:56:02]
[08:56:02] Performing Suckit Rookit additional checks
[08:56:02] Checking /sbin/init link count [ OK ]
[08:56:02] Checking for hidden file extensions [ None found ]
[08:56:02] Running skdet command [ Skipped ]
[08:56:02] Info: Unable to find the 'skdet' command
[08:56:02] Suckit Rookit additional checks [ OK ]
[08:56:02]
[08:56:02] Performing check of possible rootkit files and directories
[08:56:02] Info: Starting test name 'possible_rkt_files'
[08:56:02] Checking for file '/dev/sdr0' [ Not found ]
[08:56:02] Checking for file '/tmp/.syshackfile' [ Not found ]
[08:56:03] Checking for file '/tmp/.bash_history' [ Not found ]
[08:56:03] Checking for file '/usr/info/.clib' [ Not found ]
[08:56:03] Checking for file '/usr/sbin/tcp.log' [ Not found ]
[08:56:03] Checking for file '/usr/bin/take/pid' [ Not found ]
[08:56:03] Checking for file '/sbin/create' [ Not found ]
[08:56:03] Checking for file '/dev/ttypz' [ Not found ]
[08:56:03] Checking for directory '/usr/bin/take' [ Not found ]
[08:56:03] Checking for directory '/usr/src/.lib' [ Not found ]
[08:56:03] Checking for directory '/usr/share/man/man1/.1c' [ Not found ]
[08:56:03] Checking for directory '/lib/lblip.tk' [ Not found ]
[08:56:03] Checking for directory '/usr/sbin/...' [ Not found ]
[08:56:03] Checking for directory '/usr/share/.gun' [ Not found ]
[08:56:03] Checking for possible rootkit files and directories [ None found ]
[08:56:03]
[08:56:03] Performing check for possible rootkit strings
[08:56:03] Info: Starting test name 'possible_rkt_strings'
[08:56:03] Info: Found local startup file: /etc/rc.local
[08:56:03] Checking for string '/dev/proc/rainbows' [ Not found ]
[08:56:03] Checking for string 'rainbows' [ Not found ]
[08:56:03] Checking for string 'backdoor' [ Not found ]
[08:56:03] Checking for string 'vt200' [ Not found ]
[08:56:03] Checking for string '/usr/bin/xstat' [ Not found ]
[08:56:03] Checking for string '/bin/envpc' [ Not found ]
[08:56:03] Checking for string 'L4m3r0x' [ Not found ]
[08:56:03] Checking for string '/usr/lib/.tbd' [ Not found ]
[08:56:03] Checking for string '/dev/ptyxx/.file' [ Not found ]
[08:56:03] Checking for string '/dev/sgk' [ Not found ]
[08:56:03] Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[08:56:04] Checking for string '/usr/lib/.tbd' [ Not found ]
[08:56:04] Checking for string '/dev/proc/rainbows' [ Not found ]
[08:56:04] Checking for string '/lib/.sso' [ Not found ]
[08:56:04] Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[08:56:04] Checking for string '/dev/caca' [ Not found ]
[08:56:04] Checking for string '/dev/ttyoa' [ Not found ]
[08:56:04] Checking for string 'syg' [ Not found ]
[08:56:04] Checking for string '/dev/pts/01' [ Not found ]
[08:56:04] Checking for string 'tw33dl3' [ Not found ]
[08:56:04] Checking for string 'psniff' [ Not found ]
[08:56:04] Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[08:56:04] Checking for string '/dev/ptyxx' [ Not found ]
[08:56:04] Checking for string 'promiscuous' [ Not found ]
[08:56:04] Checking for string '/usr/lib/.tbd' [ Not found ]
[08:56:04] Checking for string '/dev/xdta' [ Not found ]
[08:56:04] Checking for string '/usr/lib/.tbd' [ Not found ]
[08:56:04] Checking for string 'in.inetd' [ Not found ]
[08:56:04] Checking for string '#<HIDE_.*>' [ Not found ]
[08:56:04] Checking for string 'bin/xchk' [ Not found ]
[08:56:04] Checking for string 'bin/xsf' [ Not found ]
[08:56:04] Checking for possible rootkit strings [ None found ]
[08:56:04]
[08:56:04] Performing malware checks
[08:56:04] Info: Starting test name 'malware'
[08:56:04]
[08:56:04] Info: Test 'deleted_files' disabled at users request.
[08:56:04] Info: Starting test name 'running_procs'
[08:56:05] Checking running processes for suspicious files [ None found ]
[08:56:05]
[08:56:05] Info: Test 'hidden_procs' disabled at users request.
[08:56:05]
[08:56:05] Info: Test 'suspscan' disabled at users request.
[08:56:05]
[08:56:05] Performing check for login backdoors
[08:56:05] Info: Starting test name 'other_malware'
[08:56:05] Checking for '/bin/.login' [ Not found ]
[08:56:05] Checking for '/sbin/.login' [ Not found ]
[08:56:05] Checking for login backdoors [ None found ]
[08:56:05]
[08:56:05] Performing check for suspicious directories
[08:56:05] Checking for directory '/usr/X11R6/bin/.,/copy' [ Not found ]
[08:56:05] Checking for directory '/dev/rd/cdb' [ Not found ]
[08:56:05] Checking for suspicious directories [ None found ]
[08:56:05]
[08:56:05] Checking for software intrusions [ Skipped ]
[08:56:05] Info: Check skipped - tripwire not installed
[08:56:05]
[08:56:05] Performing check for sniffer log files
[08:56:05] Checking for file '/usr/lib/libice.log' [ Not found ]
[08:56:05] Checking for sniffer log files [ None found ]
[08:56:05]
[08:56:05] Performing trojan specific checks
[08:56:05] Info: Starting test name 'trojans'
[08:56:05] Info: Using inetd configuration file '/etc/inetd.conf'
[08:56:05] Checking for enabled inetd services [ OK ]
[08:56:05]
[08:56:05] Performing check for enabled xinetd services
[08:56:05] Checking for enabled xinetd services [ Skipped ]
[08:56:05] Info: Check skipped - file '/etc/xinetd.conf' does not exist.
[08:56:05] Checking for Apache backdoor [ Not found ]
[08:56:05]
[08:56:05] Performing Linux specific checks
[08:56:05] Info: Starting test name 'os_specific'
[08:56:05] Checking kernel module commands [ OK ]
[08:56:05] Info: Using modules pathname of '/lib/modules/2.6.24-16-generic'
[08:56:05] Checking kernel module names [ OK ]
[08:56:08]
[08:56:08] Checking the network...
[08:56:08] Info: Starting test name 'network'
[08:56:08] Info: Starting test name 'ports'
[08:56:08]
[08:56:08] Performing check for backdoor ports
[08:56:08] Checking for UDP port 2001 [ Not found ]
[08:56:08] Checking for TCP port 2006 [ Not found ]
[08:56:08] Checking for TCP port 2128 [ Not found ]
[08:56:08] Checking for TCP port 14856 [ Not found ]
[08:56:09] Checking for TCP port 47107 [ Not found ]
[08:56:09] Checking for TCP port 60922 [ Not found ]
[08:56:09]
[08:56:09] Performing checks on the network interfaces
[08:56:09] Info: Starting test name 'promisc'
[08:56:09] Checking for promiscuous interfaces [ None found ]
[08:56:09]
[08:56:09] Info: Test 'packet_cap_apps' disabled at users request.
[08:56:12]
[08:56:12] Checking the local host...
[08:56:12] Info: Starting test name 'local_host'
[08:56:12]
[08:56:12] Performing system boot checks
[08:56:12] Info: Starting test name 'startup_files'
[08:56:12] Checking for local host name [ Found ]
[08:56:13] Info: Starting test name 'startup_malware'
[08:56:13] Info: Found local startup file: /etc/rc.local
[08:56:13] Checking for local startup files [ Found ]
[08:56:13] Checking local startup files for malware [ None found ]
[08:56:13] Info: Found system startup directory: /etc/init.d
[08:56:14] Checking system startup files for malware [ None found ]
[08:56:14]
[08:56:14] Performing group and account checks
[08:56:14] Info: Starting test name 'group_accounts'
[08:56:14] Checking for passwd file [ Found ]
[08:56:14] Info: Found password file: /etc/passwd
[08:56:14] Checking for root equivalent (UID 0) accounts [ None found ]
[08:56:14] Info: Found shadow file: /etc/shadow
[08:56:14] Checking for passwordless accounts [ None found ]
[08:56:14] Info: Starting test name 'passwd_changes'
[08:56:14] Checking for passwd file changes [ Warning ]
[08:56:14] Warning: Users have been added to the passwd file:
[08:56:14] dirk:x:1000:1000:dirk,,,,:/home/dirk:/bin/bash
[08:56:14] Warning: Users have been removed from the passwd file:
[08:56:14] dirk:x:1000:0:dirk,,,,:/home/dirk:/bin/bash
[08:56:14] admin:x:1001:100::/home/admin:/bin/bash
[08:56:15] Info: Starting test name 'group_changes'
[08:56:15] Checking for group file changes [ Warning ]
[08:56:15] Warning: Groups have been added to the group file:
[08:56:15] root:x:0:dirk,root
[08:56:15] Warning: Groups have been removed from the group file:
[08:56:15] root:x:0:dirk,root,admin
[08:56:15] Checking root account shell history files [ OK ]
[08:56:15]
[08:56:15] Performing system configuration file checks
[08:56:15] Info: Starting test name 'system_configs'
[08:56:15] Checking for SSH configuration file [ Found ]
[08:56:15] Info: Found SSH configuration file: /etc/ssh/sshd_config
[08:56:15] Info: Rkhunter option ALLOW_SSH_ROOT_USER set to 'no'.
[08:56:15] Checking if SSH root access is allowed [ Not allowed ]
[08:56:15] Checking if SSH protocol v1 is allowed [ Not allowed ]
[08:56:15] Checking for running syslog daemon [ Found ]
[08:56:15] Checking for syslog configuration file [ Found ]
[08:56:15] Info: Found syslog configuration file: /etc/syslog.conf
[08:56:15] Checking if syslog remote logging is allowed [ Not allowed ]
[08:56:15]
[08:56:15] Performing filesystem checks
[08:56:15] Info: Starting test name 'filesystem'
[08:56:15] Info: SCAN_MODE_DEV set to 'THOROUGH'
[08:56:26] Checking /dev for suspicious file types [ None found ]
[08:56:26] Checking for hidden files and directories [ Warning ]
[08:56:26] Warning: Hidden directory found: /etc/.java
[08:56:26] Warning: Hidden directory found: /dev/.static
[08:56:26] Warning: Hidden directory found: /dev/.udev
[08:56:26] Warning: Hidden directory found: /dev/.initramfs
[08:56:36]
[08:56:36] Checking application versions...
[08:56:36] Info: Starting test name 'apps'
[08:56:37] Checking version of Exim MTA [ OK ]
[08:56:37] Info: Application 'exim' version '4.69' found.
[08:56:37] Checking version of GnuPG [ OK ]
[08:56:37] Info: Application 'gpg' version '1.4.6' found.
[08:56:37] Info: Application 'httpd' not found.
[08:56:37] Info: Application 'named' not found.
[08:56:37] Checking version of OpenSSL [ OK ]
[08:56:37] Info: Application 'openssl' version '0.9.8g' found.
[08:56:37] Info: Application 'php' not found.
[08:56:37] Info: Application 'procmail' not found.
[08:56:37] Info: Application 'proftpd' not found.
[08:56:37] Checking version of OpenSSH [ OK ]
[08:56:37] Info: Application 'sshd' version '4.7p1' found.
[08:56:37] Info: Applications checked: 4 out of 9
[08:56:37]
[08:56:37] System checks summary
[08:56:37] =====================
[08:56:37]
[08:56:37] File properties checks...
[08:56:37] Files checked: 125
[08:56:37] Suspect files: 0
[08:56:37]
[08:56:37] Rootkit checks...
[08:56:37] Rootkits checked : 110
[08:56:37] Possible rootkits: 0
[08:56:37]
[08:56:37] Applications checks...
[08:56:37] Applications checked: 4
[08:56:37] Suspect applications: 0
[08:56:37]
[08:56:37] The system checks took: 1 minute and 11 second