انجمن‌های فارسی اوبونتو

کمک و پشتیبانی => انجمن عمومی => نویسنده: morilog در 15 آذر 1393، 02:28 ب‌ظ

عنوان: بدافزار adfoc.us
ارسال شده توسط: morilog در 15 آذر 1393، 02:28 ب‌ظ
سلام
من اوبونتو 14.04 استفاده می‌کنم. جدیدن یه بدافزار جدید افتاده به جون سیستمم که با باز کردن هر صفحه جدید در مرورگر خود به خود صفحه به ادرس adfoc.us و یا آدرس‌های مشابه ریدایرکت می‌شه. درباره مشکل گوگل کردم و دیدم که این مشکلو کاربرای ویندوز دارن و هرجا هم دیدم راه حلش عوض کردن DNSها بود. ولی در مورد گنو-لینوکس ندیدم کسی صحبتی نکرده بود. پس به ناچار منم DNSها رو هم از طریق تنظیمات کارت شبکه و هم از توی مودم عوض کردم ولی بازم مشکل پابرجاست.
اگه راه حلی دارید که این دردسرو از بین ببرم. ممنون میشم باهام به اشتراک بذاریدش.


اینم خروجی نرم‌افزار rkhunter
[code]
[20:16:34] Running Rootkit Hunter version 1.4.0 on morilog
[20:16:34]
[20:16:34] Info: Start date is ‫شنبه ۰۶ دسامبر ۱۴، ساعت ۲۰:۱۶:۳۴ (IRST)‬
[20:16:34]
[20:16:34] Checking configuration file and command-line options...
[20:16:34] Info: Detected operating system is 'Linux'
[20:16:34] Info: Found O/S name: Ubuntu 14.04.1 LTS
[20:16:34] Info: Command line is /usr/bin/rkhunter -c
[20:16:34] Info: Environment shell is /bin/bash; rkhunter is using dash
[20:16:34] Info: Using configuration file '/etc/rkhunter.conf'
[20:16:34] Info: Installation directory is '/usr'
[20:16:34] Info: Using language 'en'
[20:16:34] Info: Using '/var/lib/rkhunter/db' as the database directory
[20:16:34] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[20:16:34] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin' as the command directories
[20:16:34] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[20:16:34] Info: No mail-on-warning address configured
[20:16:34] Info: X will be automatically detected
[20:16:34] Info: Using second color set
[20:16:34] Info: Found the 'basename' command: /usr/bin/basename
[20:16:35] Info: Found the 'diff' command: /usr/bin/diff
[20:16:35] Info: Found the 'dirname' command: /usr/bin/dirname
[20:16:35] Info: Found the 'file' command: /usr/bin/file
[20:16:35] Info: Found the 'find' command: /usr/bin/find
[20:16:35] Info: Found the 'ifconfig' command: /sbin/ifconfig
[20:16:35] Info: Found the 'ip' command: /sbin/ip
[20:16:35] Info: Found the 'ldd' command: /usr/bin/ldd
[20:16:35] Info: Found the 'lsattr' command: /usr/bin/lsattr
[20:16:35] Info: Found the 'lsmod' command: /sbin/lsmod
[20:16:35] Info: Found the 'lsof' command: /usr/bin/lsof
[20:16:35] Info: Found the 'mktemp' command: /bin/mktemp
[20:16:35] Info: Found the 'netstat' command: /bin/netstat
[20:16:35] Info: Found the 'perl' command: /usr/bin/perl
[20:16:35] Info: Found the 'pgrep' command: /usr/bin/pgrep
[20:16:35] Info: Found the 'ps' command: /bin/ps
[20:16:35] Info: Found the 'pwd' command: /bin/pwd
[20:16:35] Info: Found the 'readlink' command: /bin/readlink
[20:16:35] Info: Found the 'stat' command: /usr/bin/stat
[20:16:35] Info: Found the 'strings' command: /usr/bin/strings
[20:16:35] Info: System is not using prelinking
[20:16:35] Info: Using the '/usr/bin/sha1sum' command for the file hash checks
[20:16:35] Info: Stored hash values used hash function '/usr/bin/sha1sum'
[20:16:35] Info: Stored hash values did not use a package manager
[20:16:35] Info: The hash function field index is set to 1
[20:16:35] Info: No package manager specified: using hash function '/usr/bin/sha1sum'
[20:16:35] Info: Previous file attributes were stored
[20:16:35] Info: Enabled tests are: all
[20:16:35] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps apps
[20:16:35] Info: Found ksym file '/proc/kallsyms'
[20:16:35] Info: Using 'date' to process epoch second times
[20:16:35]
[20:16:35] Checking if the O/S has changed since last time...
[20:16:35] Info: Nothing seems to have changed.
[20:16:35] Info: Locking is not being used
[20:16:35]
[20:16:35] Starting system checks...
[20:16:35]
[20:16:35] Info: Starting test name 'system_commands'
[20:16:35] Checking system commands...
[20:16:35]
[20:16:35] Info: Starting test name 'strings'
[20:16:35] Performing 'strings' command checks
[20:16:35]   Scanning for string /usr/sbin/ntpsx             [ OK ]
[20:16:35]   Scanning for string /usr/sbin/.../bkit-ava      [ OK ]
[20:16:35]   Scanning for string /usr/sbin/.../bkit-d        [ OK ]
[20:16:35]   Scanning for string /usr/sbin/.../bkit-shd      [ OK ]
[20:16:36]   Scanning for string /usr/sbin/.../bkit-f        [ OK ]
[20:16:36]   Scanning for string /usr/include/.../proc.h     [ OK ]
[20:16:36]   Scanning for string /usr/include/.../.bash_history [ OK ]
[20:16:36]   Scanning for string /usr/include/.../bkit-get   [ OK ]
[20:16:36]   Scanning for string /usr/include/.../bkit-dl    [ OK ]
[20:16:36]   Scanning for string /usr/include/.../bkit-screen [ OK ]
[20:16:36]   Scanning for string /usr/include/.../bkit-sleep [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-adore.o   [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../ls             [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../netstat        [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../lsof           [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-ssh/bkit-mots [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../uconf.inv      [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../psr            [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../find           [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../pstree         [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../slocate        [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../du             [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../top            [ OK ]
[20:16:36]   Scanning for string /usr/sbin/...               [ OK ]
[20:16:37]   Scanning for string /usr/include/...            [ OK ]
[20:16:37]   Scanning for string /usr/include/.../.tmp       [ OK ]
[20:16:37]   Scanning for string /usr/lib/...                [ OK ]
[20:16:37]   Scanning for string /usr/lib/.../.ssh           [ OK ]
[20:16:37]   Scanning for string /usr/lib/.../bkit-ssh       [ OK ]
[20:16:37]   Scanning for string /usr/lib/.bkit-             [ OK ]
[20:16:37]   Scanning for string /tmp/.bkp                   [ OK ]
[20:16:37]   Scanning for string /tmp/.cinik                 [ OK ]
[20:16:37]   Scanning for string /tmp/.font-unix/.cinik      [ OK ]
[20:16:37]   Scanning for string /lib/.sso                   [ OK ]
[20:16:37]   Scanning for string /lib/.so                    [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/clean      [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/dxr        [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/read       [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/write      [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/lf         [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/xl         [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/xdr        [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/psg        [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/secure     [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/rdx        [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/va         [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/cl.sh      [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/last.log   [ OK ]
[20:16:38]   Scanning for string /usr/bin/.etc               [ OK ]
[20:16:38]   Scanning for string /etc/sshd_config            [ OK ]
[20:16:38]   Scanning for string /etc/ssh_host_key           [ OK ]
[20:16:38]   Scanning for string /etc/ssh_random_seed        [ OK ]
[20:16:38]   Scanning for string /dev/ptyp                   [ OK ]
[20:16:38]   Scanning for string /dev/ptyq                   [ OK ]
[20:16:38]   Scanning for string /dev/ptyr                   [ OK ]
[20:16:38]   Scanning for string /dev/ptys                   [ OK ]
[20:16:38]   Scanning for string /dev/ptyt                   [ OK ]
[20:16:38]   Scanning for string /dev/fd/.88/freshb-bsd      [ OK ]
[20:16:38]   Scanning for string /dev/fd/.88/fresht          [ OK ]
[20:16:38]   Scanning for string /dev/fd/.88/zxsniff         [ OK ]
[20:16:38]   Scanning for string /dev/fd/.88/zxsniff.log     [ OK ]
[20:16:38]   Scanning for string /dev/fd/.99/.ttyf00         [ OK ]
[20:16:38]   Scanning for string /dev/fd/.99/.ttyp00         [ OK ]
[20:16:38]   Scanning for string /dev/fd/.99/.ttyq00         [ OK ]
[20:16:38]   Scanning for string /dev/fd/.99/.ttys00         [ OK ]
[20:16:38]   Scanning for string /dev/fd/.99/.pwsx00         [ OK ]
[20:16:38]   Scanning for string /etc/.acid                  [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/sched_host.2   [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/random_d.2     [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/set_pid.2      [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/setrgrp.2      [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/TOHIDE         [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/cons.saver     [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/adore/ava/ava  [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[20:16:38]   Scanning for string /bin/sysback                [ OK ]
[20:16:38]   Scanning for string /usr/local/bin/sysback      [ OK ]
[20:16:38]   Scanning for string /usr/lib/.tbd               [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/t0rns     [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/du        [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/ls        [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/t0rnsb    [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/ps        [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/t0rnp     [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/find      [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/ifconfig  [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/pg        [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/ssh.tgz   [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/top       [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/sz        [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/login     [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/1i0n.sh   [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/pstree    [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/mjy       [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/sush      [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/tfn       [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/name      [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/getip.sh  [ OK ]
[20:16:39]   Scanning for string /usr/info/.torn/sh*         [ OK ]
[20:16:39]   Scanning for string /usr/src/.puta/.1addr       [ OK ]
[20:16:39]   Scanning for string /usr/src/.puta/.1file       [ OK ]
[20:16:40]   Scanning for string /usr/src/.puta/.1proc       [ OK ]
[20:16:40]   Scanning for string /usr/src/.puta/.1logz       [ OK ]
[20:16:40]   Scanning for string /usr/info/.t0rn             [ OK ]
[20:16:40]   Scanning for string /dev/.lib                   [ OK ]
[20:16:40]   Scanning for string /dev/.lib/lib               [ OK ]
[20:16:40]   Scanning for string /dev/.lib/lib/lib           [ OK ]
[20:16:40]   Scanning for string /dev/.lib/lib/lib/dev       [ OK ]
[20:16:40]   Scanning for string /dev/.lib/lib/scan          [ OK ]
[20:16:40]   Scanning for string /usr/src/.puta              [ OK ]
[20:16:40]   Scanning for string /usr/man/man1/man1          [ OK ]
[20:16:40]   Scanning for string /usr/man/man1/man1/lib      [ OK ]
[20:16:40]   Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[20:16:40]   Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[20:16:40]
[20:16:40] Info: Starting test name 'shared_libs'
[20:16:40] Performing 'shared libraries' checks
[20:16:40]   Checking for preloading variables               [ None found ]
[20:16:40]   Checking for preloaded libraries                [ None found ]
[20:16:40]
[20:16:40] Info: Starting test name 'shared_libs_path'
[20:16:40]   Checking LD_LIBRARY_PATH variable               [ Not found ]
[20:16:40]
[20:16:40] Info: Starting test name 'properties'
[20:16:40] Performing file properties checks
[20:16:40]   Checking for prerequisites                      [ OK ]
[20:16:44]   /usr/sbin/adduser                               [ OK ]
[20:16:44] Info: Found file '/usr/sbin/adduser': it is whitelisted for the 'script replacement' check.
[20:16:44]   /usr/sbin/chroot                                [ OK ]
[20:16:44]   /usr/sbin/cron                                  [ OK ]
[20:16:44]   /usr/sbin/groupadd                              [ OK ]
[20:16:45]   /usr/sbin/groupdel                              [ OK ]
[20:16:45]   /usr/sbin/groupmod                              [ OK ]
[20:16:45]   /usr/sbin/grpck                                 [ OK ]
[20:16:45]   /usr/sbin/nologin                               [ OK ]
[20:16:46]   /usr/sbin/pwck                                  [ OK ]
[20:16:46]   /usr/sbin/rsyslogd                              [ OK ]
[20:16:46]   /usr/sbin/tcpd                                  [ OK ]
[20:16:46]   /usr/sbin/useradd                               [ OK ]
[20:16:46]   /usr/sbin/userdel                               [ OK ]
[20:16:47]   /usr/sbin/usermod                               [ OK ]
[20:16:47]   /usr/sbin/vipw                                  [ OK ]
[20:16:47]   /usr/sbin/xinetd                                [ OK ]
[20:16:47]   /usr/bin/awk                                    [ OK ]
[20:16:47]   /usr/bin/basename                               [ OK ]
[20:16:47]   /usr/bin/chattr                                 [ OK ]
[20:16:48]   /usr/bin/curl                                   [ OK ]
[20:16:48]   /usr/bin/cut                                    [ OK ]
[20:16:48]   /usr/bin/diff                                   [ OK ]
[20:16:48]   /usr/bin/dirname                                [ OK ]
[20:16:48]   /usr/bin/dpkg                                   [ OK ]
[20:16:48]   /usr/bin/dpkg-query                             [ OK ]
[20:16:48]   /usr/bin/du                                     [ OK ]
[20:16:48]   /usr/bin/env                                    [ OK ]
[20:16:48]   /usr/bin/file                                   [ OK ]
[20:16:48]   /usr/bin/find                                   [ OK ]
[20:16:49]   /usr/bin/groups                                 [ OK ]
[20:16:49] Info: Found file '/usr/bin/groups': it is whitelisted for the 'script replacement' check.
[20:16:49]   /usr/bin/head                                   [ OK ]
[20:16:49]   /usr/bin/id                                     [ OK ]
[20:16:49]   /usr/bin/killall                                [ OK ]
[20:16:49]   /usr/bin/last                                   [ OK ]
[20:16:49]   /usr/bin/lastlog                                [ OK ]
[20:16:49]   /usr/bin/ldd                                    [ OK ]
[20:16:49] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
[20:16:49]   /usr/bin/less                                   [ OK ]
[20:16:49]   /usr/bin/locate                                 [ OK ]
[20:16:50]   /usr/bin/logger                                 [ OK ]
[20:16:50]   /usr/bin/lsattr                                 [ OK ]
[20:16:50]   /usr/bin/lsof                                   [ OK ]
[20:16:50]   /usr/bin/mail                                   [ OK ]
[20:16:50]   /usr/bin/md5sum                                 [ OK ]
[20:16:50]   /usr/bin/mlocate                                [ OK ]
[20:16:50]   /usr/bin/newgrp                                 [ OK ]
[20:16:50]   /usr/bin/passwd                                 [ OK ]
[20:16:50]   /usr/bin/perl                                   [ OK ]
[20:16:50]   /usr/bin/pgrep                                  [ OK ]
[20:16:50]   /usr/bin/pkill                                  [ OK ]
[20:16:50]   /usr/bin/pstree                                 [ OK ]
[20:16:50]   /usr/bin/rkhunter                               [ OK ]
[20:16:50]   /usr/bin/runcon                                 [ OK ]
[20:16:51]   /usr/bin/sha1sum                                [ OK ]
[20:16:51]   /usr/bin/sha224sum                              [ OK ]
[20:16:51]   /usr/bin/sha256sum                              [ OK ]
[20:16:51]   /usr/bin/sha384sum                              [ OK ]
[20:16:51]   /usr/bin/sha512sum                              [ OK ]
[20:16:51]   /usr/bin/size                                   [ OK ]
[20:16:51]   /usr/bin/sort                                   [ OK ]
[20:16:51]   /usr/bin/stat                                   [ OK ]
[20:16:51]   /usr/bin/strace                                 [ OK ]
[20:16:51]   /usr/bin/strings                                [ OK ]
[20:16:51]   /usr/bin/sudo                                   [ OK ]
[20:16:51]   /usr/bin/tail                                   [ OK ]
[20:16:51]   /usr/bin/test                                   [ OK ]
[20:16:51]   /usr/bin/top                                    [ OK ]
[20:16:51]   /usr/bin/touch                                  [ OK ]
[20:16:52]   /usr/bin/tr                                     [ OK ]
[20:16:52]   /usr/bin/uniq                                   [ OK ]
[20:16:52]   /usr/bin/users                                  [ OK ]
[20:16:52]   /usr/bin/vmstat                                 [ OK ]
[20:16:52]   /usr/bin/w                                      [ OK ]
[20:16:52]   /usr/bin/watch                                  [ OK ]
[20:16:52]   /usr/bin/wc                                     [ OK ]
[20:16:52]   /usr/bin/wget                                   [ OK ]
[20:16:52]   /usr/bin/whatis                                 [ OK ]
[20:16:52]   /usr/bin/whereis                                [ OK ]
[20:16:52]   /usr/bin/which                                  [ OK ]
[20:16:52]   /usr/bin/who                                    [ OK ]
[20:16:52]   /usr/bin/whoami                                 [ OK ]
[20:16:52]   /usr/bin/unhide.rb                              [ Warning ]
[20:16:52] Warning: The command '/usr/bin/unhide.rb' has been replaced by a script: /usr/bin/unhide.rb: Ruby script, ASCII text
[20:16:53]   /usr/bin/gawk                                   [ OK ]
[20:16:53]   /usr/bin/heirloom-mailx                         [ OK ]
[20:16:53]   /usr/bin/w.procps                               [ OK ]
[20:16:53]   /sbin/depmod                                    [ OK ]
[20:16:53]   /sbin/fsck                                      [ OK ]
[20:16:53]   /sbin/ifconfig                                  [ OK ]
[20:16:53]   /sbin/ifdown                                    [ OK ]
[20:16:53]   /sbin/ifup                                      [ OK ]
[20:16:53]   /sbin/init                                      [ OK ]
[20:16:53]   /sbin/insmod                                    [ OK ]
[20:16:53]   /sbin/ip                                        [ OK ]
[20:16:54]   /sbin/lsmod                                     [ OK ]
[20:16:54]   /sbin/modinfo                                   [ OK ]
[20:16:54]   /sbin/modprobe                                  [ OK ]
[20:16:54]   /sbin/rmmod                                     [ OK ]
[20:16:54]   /sbin/route                                     [ OK ]
[20:16:55]   /sbin/runlevel                                  [ OK ]
[20:16:55]   /sbin/sulogin                                   [ OK ]
[20:16:55]   /sbin/sysctl                                    [ OK ]
[20:16:56]   /bin/bash                                       [ OK ]
[20:16:56]   /bin/cat                                        [ OK ]
[20:16:56]   /bin/chmod                                      [ OK ]
[20:16:56]   /bin/chown                                      [ OK ]
[20:16:56]   /bin/cp                                         [ OK ]
[20:16:56]   /bin/date                                       [ OK ]
[20:16:56]   /bin/df                                         [ OK ]
[20:16:56]   /bin/dmesg                                      [ OK ]
[20:16:57]   /bin/echo                                       [ OK ]
[20:16:57]   /bin/ed                                         [ OK ]
[20:16:57]   /bin/egrep                                      [ OK ]
[20:16:57] Info: Found file '/bin/egrep': it is whitelisted for the 'script replacement' check.
[20:16:57]   /bin/fgrep                                      [ OK ]
[20:16:57] Info: Found file '/bin/fgrep': it is whitelisted for the 'script replacement' check.
[20:16:57]   /bin/fuser                                      [ OK ]
[20:16:57]   /bin/grep                                       [ OK ]
[20:16:58]   /bin/ip                                         [ OK ]
[20:16:58]   /bin/kill                                       [ OK ]
[20:16:58]   /bin/less                                       [ OK ]
[20:16:58]   /bin/login                                      [ OK ]
[20:16:58]   /bin/ls                                         [ OK ]
[20:16:58]   /bin/lsmod                                      [ OK ]
[20:16:58]   /bin/mktemp                                     [ OK ]
[20:16:58]   /bin/more                                       [ OK ]
[20:16:58]   /bin/mount                                      [ OK ]
[20:16:59]   /bin/mv                                         [ OK ]
[20:16:59]   /bin/netstat                                    [ OK ]
[20:16:59]   /bin/ping                                       [ OK ]
[20:16:59]   /bin/ps                                         [ OK ]
[20:16:59]   /bin/pwd                                        [ OK ]
[20:16:59]   /bin/readlink                                   [ OK ]
[20:16:59]   /bin/sed                                        [ OK ]
[20:16:59]   /bin/sh                                         [ OK ]
[20:16:59]   /bin/su                                         [ OK ]
[20:17:00]   /bin/touch                                      [ OK ]
[20:17:00]   /bin/uname                                      [ OK ]
[20:17:00]   /bin/which                                      [ OK ]
[20:17:00] Info: Found file '/bin/which': it is whitelisted for the 'script replacement' check.
[20:17:00]   /bin/kmod                                       [ OK ]
[20:17:00]   /bin/dash                                       [ OK ]
[20:17:02]
[20:17:02] Info: Starting test name 'rootkits'
[20:17:02] Checking for rootkits...
[20:17:02]
[20:17:02] Info: Starting test name 'known_rkts'
[20:17:02] Performing check of known rootkit files and directories
[20:17:02]
[20:17:02] Checking for 55808 Trojan - Variant A...
[20:17:02]   Checking for file '/tmp/.../r'                  [ Not found ]
[20:17:02]   Checking for file '/tmp/.../a'                  [ Not found ]
[20:17:02] 55808 Trojan - Variant A                          [ Not found ]
[20:17:02]
[20:17:02] Checking for ADM Worm...
[20:17:02]   Checking for string 'w0rm'                      [ Not found ]
[20:17:02] ADM Worm                                          [ Not found ]
[20:17:02]
[20:17:02] Checking for AjaKit Rootkit...
[20:17:02]   Checking for file '/dev/tux/.addr'              [ Not found ]
[20:17:02]   Checking for file '/dev/tux/.proc'              [ Not found ]
[20:17:02]   Checking for file '/dev/tux/.file'              [ Not found ]
[20:17:02]   Checking for file '/lib/.libgh-gh/cleaner'      [ Not found ]
[20:17:02]   Checking for file '/lib/.libgh-gh/Patch/patch'  [ Not found ]
[20:17:02]   Checking for file '/lib/.libgh-gh/sb0k'         [ Not found ]
[20:17:02]   Checking for directory '/dev/tux'               [ Not found ]
[20:17:02]   Checking for directory '/lib/.libgh-gh'         [ Not found ]
[20:17:02] AjaKit Rootkit                                    [ Not found ]
[20:17:02]
[20:17:02] Checking for Adore Rootkit...
[20:17:02]   Checking for file '/usr/secure'                 [ Not found ]
[20:17:02]   Checking for file '/usr/doc/sys/qrt'            [ Not found ]
[20:17:02]   Checking for file '/usr/doc/sys/run'            [ Not found ]
[20:17:02]   Checking for file '/usr/doc/sys/crond'          [ Not found ]
[20:17:02]   Checking for file '/usr/sbin/kfd'               [ Not found ]
[20:17:02]   Checking for file '/usr/doc/kern/var'           [ Not found ]
[20:17:02]   Checking for file '/usr/doc/kern/string.o'      [ Not found ]
[20:17:03]   Checking for file '/usr/doc/kern/ava'           [ Not found ]
[20:17:03]   Checking for file '/usr/doc/kern/adore.o'       [ Not found ]
[20:17:03]   Checking for file '/var/log/ssh/old'            [ Not found ]
[20:17:03]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/kern'          [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/backup'        [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/backup/txt'    [ Not found ]
[20:17:03]   Checking for directory '/lib/backup'            [ Not found ]
[20:17:03]   Checking for directory '/lib/backup/txt'        [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/work'          [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/sys'           [ Not found ]
[20:17:03]   Checking for directory '/var/log/ssh'           [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/.spool'        [ Not found ]
[20:17:03]   Checking for directory '/usr/lib/kterm'         [ Not found ]
[20:17:03] Adore Rootkit                                     [ Not found ]
[20:17:03]
[20:17:03] Checking for aPa Kit...
[20:17:03]   Checking for file '/usr/share/.aPa'             [ Not found ]
[20:17:03] aPa Kit                                           [ Not found ]
[20:17:03]
[20:17:03] Checking for Apache Worm...
[20:17:03]   Checking for file '/bin/.log'                   [ Not found ]
[20:17:03] Apache Worm                                       [ Not found ]
[20:17:03]
[20:17:03] Checking for Ambient (ark) Rootkit...
[20:17:03]   Checking for file '/usr/lib/.ark?'              [ Not found ]
[20:17:03]   Checking for file '/dev/ptyxx/.log'             [ Not found ]
[20:17:03]   Checking for file '/dev/ptyxx/.file'            [ Not found ]
[20:17:03]   Checking for file '/dev/ptyxx/.proc'            [ Not found ]
[20:17:03]   Checking for file '/dev/ptyxx/.addr'            [ Not found ]
[20:17:03]   Checking for directory '/dev/ptyxx'             [ Not found ]
[20:17:03] Ambient (ark) Rootkit                             [ Not found ]
[20:17:04]
[20:17:04] Checking for Balaur Rootkit...
[20:17:04]   Checking for file '/usr/lib/liblog.o'           [ Not found ]
[20:17:04]   Checking for directory '/usr/lib/.kinetic'      [ Not found ]
[20:17:04]   Checking for directory '/usr/lib/.egcs'         [ Not found ]
[20:17:04]   Checking for directory '/usr/lib/.wormie'       [ Not found ]
[20:17:04] Balaur Rootkit                                    [ Not found ]
[20:17:04]
[20:17:04] Checking for BeastKit Rootkit...
[20:17:04]   Checking for file '/usr/sbin/arobia'            [ Not found ]
[20:17:04]   Checking for file '/usr/sbin/idrun'             [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm'     [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/hk'  [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/sc'  [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
[20:17:04]   Checking for directory '/lib/ldd.so/bktools'    [ Not found ]
[20:17:04] BeastKit Rootkit                                  [ Not found ]
[20:17:04]
[20:17:04] Checking for beX2 Rootkit...
[20:17:04]   Checking for file '/usr/info/termcap.info-5.gz' [ Not found ]
[20:17:04]   Checking for file '/usr/bin/sshd2'              [ Not found ]
[20:17:04]   Checking for directory '/usr/include/bex'       [ Not found ]
[20:17:04] beX2 Rootkit                                      [ Not found ]
[20:17:04]
[20:17:04] Checking for BOBKit Rootkit...
[20:17:04]   Checking for file '/usr/sbin/ntpsx'             [ Not found ]
[20:17:04]   Checking for file '/usr/sbin/.../bkit-ava'      [ Not found ]
[20:17:04]   Checking for file '/usr/sbin/.../bkit-d'        [ Not found ]
[20:17:04]   Checking for file '/usr/sbin/.../bkit-shd'      [ Not found ]
[20:17:05]   Checking for file '/usr/sbin/.../bkit-f'        [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../proc.h'     [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../.bash_history' [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../bkit-get'   [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../bkit-dl'    [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../bkit-screen' [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../bkit-sleep' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-adore.o'   [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../ls'             [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../netstat'        [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../lsof'           [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-mots' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../uconf.inv'      [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../psr'            [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../find'           [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../pstree'         [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../slocate'        [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../du'             [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../top'            [ Not found ]
[20:17:05]   Checking for directory '/usr/sbin/...'          [ Not found ]
[20:17:05]   Checking for directory '/usr/include/...'       [ Not found ]
[20:17:05]   Checking for directory '/usr/include/.../.tmp'  [ Not found ]
[20:17:05]   Checking for directory '/usr/lib/...'           [ Not found ]
[20:17:05]   Checking for directory '/usr/lib/.../.ssh'      [ Not found ]
[20:17:06]   Checking for directory '/usr/lib/.../bkit-ssh'  [ Not found ]
[20:17:06]   Checking for directory '/usr/lib/.bkit-'        [ Not found ]
[20:17:06]   Checking for directory '/tmp/.bkp'              [ Not found ]
[20:17:06] BOBKit Rootkit                                    [ Not found ]
[20:17:06]
[20:17:06] Checking for cb Rootkit...
[20:17:06]   Checking for file '/dev/srd0'                   [ Not found ]
[20:17:06]   Checking for file '/lib/libproc.so.2.0.6'       [ Not found ]
[20:17:06]   Checking for file '/dev/mounnt'                 [ Not found ]
[20:17:06]   Checking for file '/etc/rc.d/init.d/init'       [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /cl'       [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /.x.tgz'   [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /statdx'   [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /wted'     [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /write'    [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /scan'     [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /sc'       [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /sl2'      [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /wroot'    [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /wscan'    [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /wu'       [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /v'        [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /read'     [ Not found ]
[20:17:06]   Checking for file '/usr/lib/sshrc'              [ Not found ]
[20:17:06]   Checking for file '/usr/lib/ssh_host_key'       [ Not found ]
[20:17:06]   Checking for file '/usr/lib/ssh_host_key.pub'   [ Not found ]
[20:17:06]   Checking for file '/usr/lib/ssh_random_seed'    [ Not found ]
[20:17:06]   Checking for file '/usr/lib/sshd_config'        [ Not found ]
[20:17:06]   Checking for file '/usr/lib/shosts.equiv'       [ Not found ]
[20:17:06]   Checking for file '/usr/lib/ssh_known_hosts'    [ Not found ]
[20:17:06]   Checking for file '/u/zappa/.ssh/pid'           [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.system/.. /tcp.log' [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /curatare/attrib' [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /curatare/chattr' [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /curatare/ps' [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /curatare/pstree' [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.system/.. /.x/xC.o' [ Not found ]
[20:17:06]   Checking for directory '/usr/bin/.zeen'         [ Not found ]
[20:17:06]   Checking for directory '/usr/bin/.zeen/.. /curatare' [ Not found ]
[20:17:06]   Checking for directory '/usr/bin/.zeen/.. /scan' [ Not found ]
[20:17:06]   Checking for directory '/usr/bin/.system/.. '   [ Not found ]
[20:17:06] cb Rootkit                                        [ Not found ]
[20:17:07]
[20:17:07] Checking for CiNIK Worm (Slapper.B variant)...
[20:17:07]   Checking for file '/tmp/.cinik'                 [ Not found ]
[20:17:07]   Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
[20:17:07] CiNIK Worm (Slapper.B variant)                    [ Not found ]
[20:17:07]
[20:17:07] Checking for Danny-Boy's Abuse Kit...
[20:17:07]   Checking for file '/dev/mdev'                   [ Not found ]
[20:17:07]   Checking for file '/usr/lib/libX.a'             [ Not found ]
[20:17:07] Danny-Boy's Abuse Kit                             [ Not found ]
[20:17:07]
[20:17:07] Checking for Devil RootKit...
[20:17:07]   Checking for file '/var/lib/games/.src'         [ Not found ]
[20:17:07]   Checking for file '/dev/dsx'                    [ Not found ]
[20:17:07]   Checking for file '/dev/caca'                   [ Not found ]
[20:17:07]   Checking for file '/dev/pro'                    [ Not found ]
[20:17:07]   Checking for file '/bin/bye'                    [ Not found ]
[20:17:07]   Checking for file '/bin/homedir'                [ Not found ]
[20:17:07]   Checking for file '/usr/bin/xfss'               [ Not found ]
[20:17:07]   Checking for file '/usr/sbin/tzava'             [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/holber' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/sense' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/clear' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/tzava' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/citeste' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/killrk' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/searchlog' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/gaoaza' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/cleaner' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/shk' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/srs' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/utile.tgz' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/webpage' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/getpsy' [ Not found ]
[20:17:08]   Checking for file '/usr/doc/tar/.../.dracusor/getbnc' [ Not found ]
[20:17:08]   Checking for file '/usr/doc/tar/.../.dracusor/getemech' [ Not found ]
[20:17:08]   Checking for file '/usr/doc/tar/.../.dracusor/localroot.sh' [ Not found ]
[20:17:08]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/old/sense' [ Not found ]
[20:17:08]   Checking for directory '/usr/doc/tar/.../.dracusor' [ Not found ]
[20:17:08] Devil RootKit                                     [ Not found ]
[20:17:08]
[20:17:08] Checking for Dica-Kit Rootkit...
[20:17:08]   Checking for file '/lib/.sso'                   [ Not found ]
[20:17:08]   Checking for file '/lib/.so'                    [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/clean'      [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/dxr'        [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/read'       [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/write'      [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/lf'         [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/xl'         [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/xdr'        [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/psg'        [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/secure'     [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/rdx'        [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/va'         [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/cl.sh'      [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/last.log'   [ Not found ]
[20:17:08]   Checking for file '/usr/bin/.etc'               [ Not found ]
[20:17:08]   Checking for file '/etc/sshd_config'            [ Not found ]
[20:17:08]   Checking for file '/etc/ssh_host_key'           [ Not found ]
[20:17:08]   Checking for file '/etc/ssh_random_seed'        [ Not found ]
[20:17:08]   Checking for directory '/var/run/...dica'       [ Not found ]
[20:17:08]   Checking for directory '/var/run/...dica/mh'    [ Not found ]
[20:17:08]   Checking for directory '/var/run/...dica/scan'  [ Not found ]
[20:17:08] Dica-Kit Rootkit                                  [ Not found