انجمن‌های فارسی اوبونتو

لطفاً به انجمن‌ها وارد شده و یا جهت ورود ثبت‌نام نمائید

لطفاً جهت ورود نام کاربری و رمز عبورتان را وارد نمائید


ارائه ۲۴٫۱۰ اوبونتو منتشر شد 🎉

نویسنده موضوع: بدافزار adfoc.us  (دفعات بازدید: 900 بار)

0 کاربر و 1 مهمان درحال مشاهده موضوع.

آفلاین morilog

  • Newbie
  • *
  • ارسال: 14
  • جنسیت : پسر
    • وب‌نوشته‌ها
بدافزار adfoc.us
« : 15 آذر 1393، 02:28 ب‌ظ »
سلام
من اوبونتو 14.04 استفاده می‌کنم. جدیدن یه بدافزار جدید افتاده به جون سیستمم که با باز کردن هر صفحه جدید در مرورگر خود به خود صفحه به ادرس adfoc.us و یا آدرس‌های مشابه ریدایرکت می‌شه. درباره مشکل گوگل کردم و دیدم که این مشکلو کاربرای ویندوز دارن و هرجا هم دیدم راه حلش عوض کردن DNSها بود. ولی در مورد گنو-لینوکس ندیدم کسی صحبتی نکرده بود. پس به ناچار منم DNSها رو هم از طریق تنظیمات کارت شبکه و هم از توی مودم عوض کردم ولی بازم مشکل پابرجاست.
اگه راه حلی دارید که این دردسرو از بین ببرم. ممنون میشم باهام به اشتراک بذاریدش.


اینم خروجی نرم‌افزار rkhunter
[code]
[20:16:34] Running Rootkit Hunter version 1.4.0 on morilog
[20:16:34]
[20:16:34] Info: Start date is ‫شنبه ۰۶ دسامبر ۱۴، ساعت ۲۰:۱۶:۳۴ (IRST)‬
[20:16:34]
[20:16:34] Checking configuration file and command-line options...
[20:16:34] Info: Detected operating system is 'Linux'
[20:16:34] Info: Found O/S name: Ubuntu 14.04.1 LTS
[20:16:34] Info: Command line is /usr/bin/rkhunter -c
[20:16:34] Info: Environment shell is /bin/bash; rkhunter is using dash
[20:16:34] Info: Using configuration file '/etc/rkhunter.conf'
[20:16:34] Info: Installation directory is '/usr'
[20:16:34] Info: Using language 'en'
[20:16:34] Info: Using '/var/lib/rkhunter/db' as the database directory
[20:16:34] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[20:16:34] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin' as the command directories
[20:16:34] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[20:16:34] Info: No mail-on-warning address configured
[20:16:34] Info: X will be automatically detected
[20:16:34] Info: Using second color set
[20:16:34] Info: Found the 'basename' command: /usr/bin/basename
[20:16:35] Info: Found the 'diff' command: /usr/bin/diff
[20:16:35] Info: Found the 'dirname' command: /usr/bin/dirname
[20:16:35] Info: Found the 'file' command: /usr/bin/file
[20:16:35] Info: Found the 'find' command: /usr/bin/find
[20:16:35] Info: Found the 'ifconfig' command: /sbin/ifconfig
[20:16:35] Info: Found the 'ip' command: /sbin/ip
[20:16:35] Info: Found the 'ldd' command: /usr/bin/ldd
[20:16:35] Info: Found the 'lsattr' command: /usr/bin/lsattr
[20:16:35] Info: Found the 'lsmod' command: /sbin/lsmod
[20:16:35] Info: Found the 'lsof' command: /usr/bin/lsof
[20:16:35] Info: Found the 'mktemp' command: /bin/mktemp
[20:16:35] Info: Found the 'netstat' command: /bin/netstat
[20:16:35] Info: Found the 'perl' command: /usr/bin/perl
[20:16:35] Info: Found the 'pgrep' command: /usr/bin/pgrep
[20:16:35] Info: Found the 'ps' command: /bin/ps
[20:16:35] Info: Found the 'pwd' command: /bin/pwd
[20:16:35] Info: Found the 'readlink' command: /bin/readlink
[20:16:35] Info: Found the 'stat' command: /usr/bin/stat
[20:16:35] Info: Found the 'strings' command: /usr/bin/strings
[20:16:35] Info: System is not using prelinking
[20:16:35] Info: Using the '/usr/bin/sha1sum' command for the file hash checks
[20:16:35] Info: Stored hash values used hash function '/usr/bin/sha1sum'
[20:16:35] Info: Stored hash values did not use a package manager
[20:16:35] Info: The hash function field index is set to 1
[20:16:35] Info: No package manager specified: using hash function '/usr/bin/sha1sum'
[20:16:35] Info: Previous file attributes were stored
[20:16:35] Info: Enabled tests are: all
[20:16:35] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps apps
[20:16:35] Info: Found ksym file '/proc/kallsyms'
[20:16:35] Info: Using 'date' to process epoch second times
[20:16:35]
[20:16:35] Checking if the O/S has changed since last time...
[20:16:35] Info: Nothing seems to have changed.
[20:16:35] Info: Locking is not being used
[20:16:35]
[20:16:35] Starting system checks...
[20:16:35]
[20:16:35] Info: Starting test name 'system_commands'
[20:16:35] Checking system commands...
[20:16:35]
[20:16:35] Info: Starting test name 'strings'
[20:16:35] Performing 'strings' command checks
[20:16:35]   Scanning for string /usr/sbin/ntpsx             [ OK ]
[20:16:35]   Scanning for string /usr/sbin/.../bkit-ava      [ OK ]
[20:16:35]   Scanning for string /usr/sbin/.../bkit-d        [ OK ]
[20:16:35]   Scanning for string /usr/sbin/.../bkit-shd      [ OK ]
[20:16:36]   Scanning for string /usr/sbin/.../bkit-f        [ OK ]
[20:16:36]   Scanning for string /usr/include/.../proc.h     [ OK ]
[20:16:36]   Scanning for string /usr/include/.../.bash_history [ OK ]
[20:16:36]   Scanning for string /usr/include/.../bkit-get   [ OK ]
[20:16:36]   Scanning for string /usr/include/.../bkit-dl    [ OK ]
[20:16:36]   Scanning for string /usr/include/.../bkit-screen [ OK ]
[20:16:36]   Scanning for string /usr/include/.../bkit-sleep [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-adore.o   [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../ls             [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../netstat        [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../lsof           [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../bkit-ssh/bkit-mots [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../uconf.inv      [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../psr            [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../find           [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../pstree         [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../slocate        [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../du             [ OK ]
[20:16:36]   Scanning for string /usr/lib/.../top            [ OK ]
[20:16:36]   Scanning for string /usr/sbin/...               [ OK ]
[20:16:37]   Scanning for string /usr/include/...            [ OK ]
[20:16:37]   Scanning for string /usr/include/.../.tmp       [ OK ]
[20:16:37]   Scanning for string /usr/lib/...                [ OK ]
[20:16:37]   Scanning for string /usr/lib/.../.ssh           [ OK ]
[20:16:37]   Scanning for string /usr/lib/.../bkit-ssh       [ OK ]
[20:16:37]   Scanning for string /usr/lib/.bkit-             [ OK ]
[20:16:37]   Scanning for string /tmp/.bkp                   [ OK ]
[20:16:37]   Scanning for string /tmp/.cinik                 [ OK ]
[20:16:37]   Scanning for string /tmp/.font-unix/.cinik      [ OK ]
[20:16:37]   Scanning for string /lib/.sso                   [ OK ]
[20:16:37]   Scanning for string /lib/.so                    [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/clean      [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/dxr        [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/read       [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/write      [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/lf         [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/xl         [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/xdr        [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/psg        [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/secure     [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/rdx        [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/va         [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/cl.sh      [ OK ]
[20:16:37]   Scanning for string /var/run/...dica/last.log   [ OK ]
[20:16:38]   Scanning for string /usr/bin/.etc               [ OK ]
[20:16:38]   Scanning for string /etc/sshd_config            [ OK ]
[20:16:38]   Scanning for string /etc/ssh_host_key           [ OK ]
[20:16:38]   Scanning for string /etc/ssh_random_seed        [ OK ]
[20:16:38]   Scanning for string /dev/ptyp                   [ OK ]
[20:16:38]   Scanning for string /dev/ptyq                   [ OK ]
[20:16:38]   Scanning for string /dev/ptyr                   [ OK ]
[20:16:38]   Scanning for string /dev/ptys                   [ OK ]
[20:16:38]   Scanning for string /dev/ptyt                   [ OK ]
[20:16:38]   Scanning for string /dev/fd/.88/freshb-bsd      [ OK ]
[20:16:38]   Scanning for string /dev/fd/.88/fresht          [ OK ]
[20:16:38]   Scanning for string /dev/fd/.88/zxsniff         [ OK ]
[20:16:38]   Scanning for string /dev/fd/.88/zxsniff.log     [ OK ]
[20:16:38]   Scanning for string /dev/fd/.99/.ttyf00         [ OK ]
[20:16:38]   Scanning for string /dev/fd/.99/.ttyp00         [ OK ]
[20:16:38]   Scanning for string /dev/fd/.99/.ttyq00         [ OK ]
[20:16:38]   Scanning for string /dev/fd/.99/.ttys00         [ OK ]
[20:16:38]   Scanning for string /dev/fd/.99/.pwsx00         [ OK ]
[20:16:38]   Scanning for string /etc/.acid                  [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/sched_host.2   [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/random_d.2     [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/set_pid.2      [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/setrgrp.2      [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/TOHIDE         [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/cons.saver     [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/adore/ava/ava  [ OK ]
[20:16:38]   Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[20:16:38]   Scanning for string /bin/sysback                [ OK ]
[20:16:38]   Scanning for string /usr/local/bin/sysback      [ OK ]
[20:16:38]   Scanning for string /usr/lib/.tbd               [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/t0rns     [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/du        [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/ls        [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/t0rnsb    [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/ps        [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/t0rnp     [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/find      [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/ifconfig  [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/pg        [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/ssh.tgz   [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/top       [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/sz        [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/login     [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/1i0n.sh   [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/pstree    [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/mjy       [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/sush      [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/tfn       [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/name      [ OK ]
[20:16:39]   Scanning for string /dev/.lib/lib/lib/getip.sh  [ OK ]
[20:16:39]   Scanning for string /usr/info/.torn/sh*         [ OK ]
[20:16:39]   Scanning for string /usr/src/.puta/.1addr       [ OK ]
[20:16:39]   Scanning for string /usr/src/.puta/.1file       [ OK ]
[20:16:40]   Scanning for string /usr/src/.puta/.1proc       [ OK ]
[20:16:40]   Scanning for string /usr/src/.puta/.1logz       [ OK ]
[20:16:40]   Scanning for string /usr/info/.t0rn             [ OK ]
[20:16:40]   Scanning for string /dev/.lib                   [ OK ]
[20:16:40]   Scanning for string /dev/.lib/lib               [ OK ]
[20:16:40]   Scanning for string /dev/.lib/lib/lib           [ OK ]
[20:16:40]   Scanning for string /dev/.lib/lib/lib/dev       [ OK ]
[20:16:40]   Scanning for string /dev/.lib/lib/scan          [ OK ]
[20:16:40]   Scanning for string /usr/src/.puta              [ OK ]
[20:16:40]   Scanning for string /usr/man/man1/man1          [ OK ]
[20:16:40]   Scanning for string /usr/man/man1/man1/lib      [ OK ]
[20:16:40]   Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[20:16:40]   Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[20:16:40]
[20:16:40] Info: Starting test name 'shared_libs'
[20:16:40] Performing 'shared libraries' checks
[20:16:40]   Checking for preloading variables               [ None found ]
[20:16:40]   Checking for preloaded libraries                [ None found ]
[20:16:40]
[20:16:40] Info: Starting test name 'shared_libs_path'
[20:16:40]   Checking LD_LIBRARY_PATH variable               [ Not found ]
[20:16:40]
[20:16:40] Info: Starting test name 'properties'
[20:16:40] Performing file properties checks
[20:16:40]   Checking for prerequisites                      [ OK ]
[20:16:44]   /usr/sbin/adduser                               [ OK ]
[20:16:44] Info: Found file '/usr/sbin/adduser': it is whitelisted for the 'script replacement' check.
[20:16:44]   /usr/sbin/chroot                                [ OK ]
[20:16:44]   /usr/sbin/cron                                  [ OK ]
[20:16:44]   /usr/sbin/groupadd                              [ OK ]
[20:16:45]   /usr/sbin/groupdel                              [ OK ]
[20:16:45]   /usr/sbin/groupmod                              [ OK ]
[20:16:45]   /usr/sbin/grpck                                 [ OK ]
[20:16:45]   /usr/sbin/nologin                               [ OK ]
[20:16:46]   /usr/sbin/pwck                                  [ OK ]
[20:16:46]   /usr/sbin/rsyslogd                              [ OK ]
[20:16:46]   /usr/sbin/tcpd                                  [ OK ]
[20:16:46]   /usr/sbin/useradd                               [ OK ]
[20:16:46]   /usr/sbin/userdel                               [ OK ]
[20:16:47]   /usr/sbin/usermod                               [ OK ]
[20:16:47]   /usr/sbin/vipw                                  [ OK ]
[20:16:47]   /usr/sbin/xinetd                                [ OK ]
[20:16:47]   /usr/bin/awk                                    [ OK ]
[20:16:47]   /usr/bin/basename                               [ OK ]
[20:16:47]   /usr/bin/chattr                                 [ OK ]
[20:16:48]   /usr/bin/curl                                   [ OK ]
[20:16:48]   /usr/bin/cut                                    [ OK ]
[20:16:48]   /usr/bin/diff                                   [ OK ]
[20:16:48]   /usr/bin/dirname                                [ OK ]
[20:16:48]   /usr/bin/dpkg                                   [ OK ]
[20:16:48]   /usr/bin/dpkg-query                             [ OK ]
[20:16:48]   /usr/bin/du                                     [ OK ]
[20:16:48]   /usr/bin/env                                    [ OK ]
[20:16:48]   /usr/bin/file                                   [ OK ]
[20:16:48]   /usr/bin/find                                   [ OK ]
[20:16:49]   /usr/bin/groups                                 [ OK ]
[20:16:49] Info: Found file '/usr/bin/groups': it is whitelisted for the 'script replacement' check.
[20:16:49]   /usr/bin/head                                   [ OK ]
[20:16:49]   /usr/bin/id                                     [ OK ]
[20:16:49]   /usr/bin/killall                                [ OK ]
[20:16:49]   /usr/bin/last                                   [ OK ]
[20:16:49]   /usr/bin/lastlog                                [ OK ]
[20:16:49]   /usr/bin/ldd                                    [ OK ]
[20:16:49] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
[20:16:49]   /usr/bin/less                                   [ OK ]
[20:16:49]   /usr/bin/locate                                 [ OK ]
[20:16:50]   /usr/bin/logger                                 [ OK ]
[20:16:50]   /usr/bin/lsattr                                 [ OK ]
[20:16:50]   /usr/bin/lsof                                   [ OK ]
[20:16:50]   /usr/bin/mail                                   [ OK ]
[20:16:50]   /usr/bin/md5sum                                 [ OK ]
[20:16:50]   /usr/bin/mlocate                                [ OK ]
[20:16:50]   /usr/bin/newgrp                                 [ OK ]
[20:16:50]   /usr/bin/passwd                                 [ OK ]
[20:16:50]   /usr/bin/perl                                   [ OK ]
[20:16:50]   /usr/bin/pgrep                                  [ OK ]
[20:16:50]   /usr/bin/pkill                                  [ OK ]
[20:16:50]   /usr/bin/pstree                                 [ OK ]
[20:16:50]   /usr/bin/rkhunter                               [ OK ]
[20:16:50]   /usr/bin/runcon                                 [ OK ]
[20:16:51]   /usr/bin/sha1sum                                [ OK ]
[20:16:51]   /usr/bin/sha224sum                              [ OK ]
[20:16:51]   /usr/bin/sha256sum                              [ OK ]
[20:16:51]   /usr/bin/sha384sum                              [ OK ]
[20:16:51]   /usr/bin/sha512sum                              [ OK ]
[20:16:51]   /usr/bin/size                                   [ OK ]
[20:16:51]   /usr/bin/sort                                   [ OK ]
[20:16:51]   /usr/bin/stat                                   [ OK ]
[20:16:51]   /usr/bin/strace                                 [ OK ]
[20:16:51]   /usr/bin/strings                                [ OK ]
[20:16:51]   /usr/bin/sudo                                   [ OK ]
[20:16:51]   /usr/bin/tail                                   [ OK ]
[20:16:51]   /usr/bin/test                                   [ OK ]
[20:16:51]   /usr/bin/top                                    [ OK ]
[20:16:51]   /usr/bin/touch                                  [ OK ]
[20:16:52]   /usr/bin/tr                                     [ OK ]
[20:16:52]   /usr/bin/uniq                                   [ OK ]
[20:16:52]   /usr/bin/users                                  [ OK ]
[20:16:52]   /usr/bin/vmstat                                 [ OK ]
[20:16:52]   /usr/bin/w                                      [ OK ]
[20:16:52]   /usr/bin/watch                                  [ OK ]
[20:16:52]   /usr/bin/wc                                     [ OK ]
[20:16:52]   /usr/bin/wget                                   [ OK ]
[20:16:52]   /usr/bin/whatis                                 [ OK ]
[20:16:52]   /usr/bin/whereis                                [ OK ]
[20:16:52]   /usr/bin/which                                  [ OK ]
[20:16:52]   /usr/bin/who                                    [ OK ]
[20:16:52]   /usr/bin/whoami                                 [ OK ]
[20:16:52]   /usr/bin/unhide.rb                              [ Warning ]
[20:16:52] Warning: The command '/usr/bin/unhide.rb' has been replaced by a script: /usr/bin/unhide.rb: Ruby script, ASCII text
[20:16:53]   /usr/bin/gawk                                   [ OK ]
[20:16:53]   /usr/bin/heirloom-mailx                         [ OK ]
[20:16:53]   /usr/bin/w.procps                               [ OK ]
[20:16:53]   /sbin/depmod                                    [ OK ]
[20:16:53]   /sbin/fsck                                      [ OK ]
[20:16:53]   /sbin/ifconfig                                  [ OK ]
[20:16:53]   /sbin/ifdown                                    [ OK ]
[20:16:53]   /sbin/ifup                                      [ OK ]
[20:16:53]   /sbin/init                                      [ OK ]
[20:16:53]   /sbin/insmod                                    [ OK ]
[20:16:53]   /sbin/ip                                        [ OK ]
[20:16:54]   /sbin/lsmod                                     [ OK ]
[20:16:54]   /sbin/modinfo                                   [ OK ]
[20:16:54]   /sbin/modprobe                                  [ OK ]
[20:16:54]   /sbin/rmmod                                     [ OK ]
[20:16:54]   /sbin/route                                     [ OK ]
[20:16:55]   /sbin/runlevel                                  [ OK ]
[20:16:55]   /sbin/sulogin                                   [ OK ]
[20:16:55]   /sbin/sysctl                                    [ OK ]
[20:16:56]   /bin/bash                                       [ OK ]
[20:16:56]   /bin/cat                                        [ OK ]
[20:16:56]   /bin/chmod                                      [ OK ]
[20:16:56]   /bin/chown                                      [ OK ]
[20:16:56]   /bin/cp                                         [ OK ]
[20:16:56]   /bin/date                                       [ OK ]
[20:16:56]   /bin/df                                         [ OK ]
[20:16:56]   /bin/dmesg                                      [ OK ]
[20:16:57]   /bin/echo                                       [ OK ]
[20:16:57]   /bin/ed                                         [ OK ]
[20:16:57]   /bin/egrep                                      [ OK ]
[20:16:57] Info: Found file '/bin/egrep': it is whitelisted for the 'script replacement' check.
[20:16:57]   /bin/fgrep                                      [ OK ]
[20:16:57] Info: Found file '/bin/fgrep': it is whitelisted for the 'script replacement' check.
[20:16:57]   /bin/fuser                                      [ OK ]
[20:16:57]   /bin/grep                                       [ OK ]
[20:16:58]   /bin/ip                                         [ OK ]
[20:16:58]   /bin/kill                                       [ OK ]
[20:16:58]   /bin/less                                       [ OK ]
[20:16:58]   /bin/login                                      [ OK ]
[20:16:58]   /bin/ls                                         [ OK ]
[20:16:58]   /bin/lsmod                                      [ OK ]
[20:16:58]   /bin/mktemp                                     [ OK ]
[20:16:58]   /bin/more                                       [ OK ]
[20:16:58]   /bin/mount                                      [ OK ]
[20:16:59]   /bin/mv                                         [ OK ]
[20:16:59]   /bin/netstat                                    [ OK ]
[20:16:59]   /bin/ping                                       [ OK ]
[20:16:59]   /bin/ps                                         [ OK ]
[20:16:59]   /bin/pwd                                        [ OK ]
[20:16:59]   /bin/readlink                                   [ OK ]
[20:16:59]   /bin/sed                                        [ OK ]
[20:16:59]   /bin/sh                                         [ OK ]
[20:16:59]   /bin/su                                         [ OK ]
[20:17:00]   /bin/touch                                      [ OK ]
[20:17:00]   /bin/uname                                      [ OK ]
[20:17:00]   /bin/which                                      [ OK ]
[20:17:00] Info: Found file '/bin/which': it is whitelisted for the 'script replacement' check.
[20:17:00]   /bin/kmod                                       [ OK ]
[20:17:00]   /bin/dash                                       [ OK ]
[20:17:02]
[20:17:02] Info: Starting test name 'rootkits'
[20:17:02] Checking for rootkits...
[20:17:02]
[20:17:02] Info: Starting test name 'known_rkts'
[20:17:02] Performing check of known rootkit files and directories
[20:17:02]
[20:17:02] Checking for 55808 Trojan - Variant A...
[20:17:02]   Checking for file '/tmp/.../r'                  [ Not found ]
[20:17:02]   Checking for file '/tmp/.../a'                  [ Not found ]
[20:17:02] 55808 Trojan - Variant A                          [ Not found ]
[20:17:02]
[20:17:02] Checking for ADM Worm...
[20:17:02]   Checking for string 'w0rm'                      [ Not found ]
[20:17:02] ADM Worm                                          [ Not found ]
[20:17:02]
[20:17:02] Checking for AjaKit Rootkit...
[20:17:02]   Checking for file '/dev/tux/.addr'              [ Not found ]
[20:17:02]   Checking for file '/dev/tux/.proc'              [ Not found ]
[20:17:02]   Checking for file '/dev/tux/.file'              [ Not found ]
[20:17:02]   Checking for file '/lib/.libgh-gh/cleaner'      [ Not found ]
[20:17:02]   Checking for file '/lib/.libgh-gh/Patch/patch'  [ Not found ]
[20:17:02]   Checking for file '/lib/.libgh-gh/sb0k'         [ Not found ]
[20:17:02]   Checking for directory '/dev/tux'               [ Not found ]
[20:17:02]   Checking for directory '/lib/.libgh-gh'         [ Not found ]
[20:17:02] AjaKit Rootkit                                    [ Not found ]
[20:17:02]
[20:17:02] Checking for Adore Rootkit...
[20:17:02]   Checking for file '/usr/secure'                 [ Not found ]
[20:17:02]   Checking for file '/usr/doc/sys/qrt'            [ Not found ]
[20:17:02]   Checking for file '/usr/doc/sys/run'            [ Not found ]
[20:17:02]   Checking for file '/usr/doc/sys/crond'          [ Not found ]
[20:17:02]   Checking for file '/usr/sbin/kfd'               [ Not found ]
[20:17:02]   Checking for file '/usr/doc/kern/var'           [ Not found ]
[20:17:02]   Checking for file '/usr/doc/kern/string.o'      [ Not found ]
[20:17:03]   Checking for file '/usr/doc/kern/ava'           [ Not found ]
[20:17:03]   Checking for file '/usr/doc/kern/adore.o'       [ Not found ]
[20:17:03]   Checking for file '/var/log/ssh/old'            [ Not found ]
[20:17:03]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/kern'          [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/backup'        [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/backup/txt'    [ Not found ]
[20:17:03]   Checking for directory '/lib/backup'            [ Not found ]
[20:17:03]   Checking for directory '/lib/backup/txt'        [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/work'          [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/sys'           [ Not found ]
[20:17:03]   Checking for directory '/var/log/ssh'           [ Not found ]
[20:17:03]   Checking for directory '/usr/doc/.spool'        [ Not found ]
[20:17:03]   Checking for directory '/usr/lib/kterm'         [ Not found ]
[20:17:03] Adore Rootkit                                     [ Not found ]
[20:17:03]
[20:17:03] Checking for aPa Kit...
[20:17:03]   Checking for file '/usr/share/.aPa'             [ Not found ]
[20:17:03] aPa Kit                                           [ Not found ]
[20:17:03]
[20:17:03] Checking for Apache Worm...
[20:17:03]   Checking for file '/bin/.log'                   [ Not found ]
[20:17:03] Apache Worm                                       [ Not found ]
[20:17:03]
[20:17:03] Checking for Ambient (ark) Rootkit...
[20:17:03]   Checking for file '/usr/lib/.ark?'              [ Not found ]
[20:17:03]   Checking for file '/dev/ptyxx/.log'             [ Not found ]
[20:17:03]   Checking for file '/dev/ptyxx/.file'            [ Not found ]
[20:17:03]   Checking for file '/dev/ptyxx/.proc'            [ Not found ]
[20:17:03]   Checking for file '/dev/ptyxx/.addr'            [ Not found ]
[20:17:03]   Checking for directory '/dev/ptyxx'             [ Not found ]
[20:17:03] Ambient (ark) Rootkit                             [ Not found ]
[20:17:04]
[20:17:04] Checking for Balaur Rootkit...
[20:17:04]   Checking for file '/usr/lib/liblog.o'           [ Not found ]
[20:17:04]   Checking for directory '/usr/lib/.kinetic'      [ Not found ]
[20:17:04]   Checking for directory '/usr/lib/.egcs'         [ Not found ]
[20:17:04]   Checking for directory '/usr/lib/.wormie'       [ Not found ]
[20:17:04] Balaur Rootkit                                    [ Not found ]
[20:17:04]
[20:17:04] Checking for BeastKit Rootkit...
[20:17:04]   Checking for file '/usr/sbin/arobia'            [ Not found ]
[20:17:04]   Checking for file '/usr/sbin/idrun'             [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm'     [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/hk'  [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/sc'  [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
[20:17:04]   Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
[20:17:04]   Checking for directory '/lib/ldd.so/bktools'    [ Not found ]
[20:17:04] BeastKit Rootkit                                  [ Not found ]
[20:17:04]
[20:17:04] Checking for beX2 Rootkit...
[20:17:04]   Checking for file '/usr/info/termcap.info-5.gz' [ Not found ]
[20:17:04]   Checking for file '/usr/bin/sshd2'              [ Not found ]
[20:17:04]   Checking for directory '/usr/include/bex'       [ Not found ]
[20:17:04] beX2 Rootkit                                      [ Not found ]
[20:17:04]
[20:17:04] Checking for BOBKit Rootkit...
[20:17:04]   Checking for file '/usr/sbin/ntpsx'             [ Not found ]
[20:17:04]   Checking for file '/usr/sbin/.../bkit-ava'      [ Not found ]
[20:17:04]   Checking for file '/usr/sbin/.../bkit-d'        [ Not found ]
[20:17:04]   Checking for file '/usr/sbin/.../bkit-shd'      [ Not found ]
[20:17:05]   Checking for file '/usr/sbin/.../bkit-f'        [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../proc.h'     [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../.bash_history' [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../bkit-get'   [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../bkit-dl'    [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../bkit-screen' [ Not found ]
[20:17:05]   Checking for file '/usr/include/.../bkit-sleep' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-adore.o'   [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../ls'             [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../netstat'        [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../lsof'           [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-mots' [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../uconf.inv'      [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../psr'            [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../find'           [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../pstree'         [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../slocate'        [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../du'             [ Not found ]
[20:17:05]   Checking for file '/usr/lib/.../top'            [ Not found ]
[20:17:05]   Checking for directory '/usr/sbin/...'          [ Not found ]
[20:17:05]   Checking for directory '/usr/include/...'       [ Not found ]
[20:17:05]   Checking for directory '/usr/include/.../.tmp'  [ Not found ]
[20:17:05]   Checking for directory '/usr/lib/...'           [ Not found ]
[20:17:05]   Checking for directory '/usr/lib/.../.ssh'      [ Not found ]
[20:17:06]   Checking for directory '/usr/lib/.../bkit-ssh'  [ Not found ]
[20:17:06]   Checking for directory '/usr/lib/.bkit-'        [ Not found ]
[20:17:06]   Checking for directory '/tmp/.bkp'              [ Not found ]
[20:17:06] BOBKit Rootkit                                    [ Not found ]
[20:17:06]
[20:17:06] Checking for cb Rootkit...
[20:17:06]   Checking for file '/dev/srd0'                   [ Not found ]
[20:17:06]   Checking for file '/lib/libproc.so.2.0.6'       [ Not found ]
[20:17:06]   Checking for file '/dev/mounnt'                 [ Not found ]
[20:17:06]   Checking for file '/etc/rc.d/init.d/init'       [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /cl'       [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /.x.tgz'   [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /statdx'   [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /wted'     [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /write'    [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /scan'     [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /sc'       [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /sl2'      [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /wroot'    [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /wscan'    [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /wu'       [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /v'        [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /read'     [ Not found ]
[20:17:06]   Checking for file '/usr/lib/sshrc'              [ Not found ]
[20:17:06]   Checking for file '/usr/lib/ssh_host_key'       [ Not found ]
[20:17:06]   Checking for file '/usr/lib/ssh_host_key.pub'   [ Not found ]
[20:17:06]   Checking for file '/usr/lib/ssh_random_seed'    [ Not found ]
[20:17:06]   Checking for file '/usr/lib/sshd_config'        [ Not found ]
[20:17:06]   Checking for file '/usr/lib/shosts.equiv'       [ Not found ]
[20:17:06]   Checking for file '/usr/lib/ssh_known_hosts'    [ Not found ]
[20:17:06]   Checking for file '/u/zappa/.ssh/pid'           [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.system/.. /tcp.log' [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /curatare/attrib' [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /curatare/chattr' [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /curatare/ps' [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.zeen/.. /curatare/pstree' [ Not found ]
[20:17:06]   Checking for file '/usr/bin/.system/.. /.x/xC.o' [ Not found ]
[20:17:06]   Checking for directory '/usr/bin/.zeen'         [ Not found ]
[20:17:06]   Checking for directory '/usr/bin/.zeen/.. /curatare' [ Not found ]
[20:17:06]   Checking for directory '/usr/bin/.zeen/.. /scan' [ Not found ]
[20:17:06]   Checking for directory '/usr/bin/.system/.. '   [ Not found ]
[20:17:06] cb Rootkit                                        [ Not found ]
[20:17:07]
[20:17:07] Checking for CiNIK Worm (Slapper.B variant)...
[20:17:07]   Checking for file '/tmp/.cinik'                 [ Not found ]
[20:17:07]   Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
[20:17:07] CiNIK Worm (Slapper.B variant)                    [ Not found ]
[20:17:07]
[20:17:07] Checking for Danny-Boy's Abuse Kit...
[20:17:07]   Checking for file '/dev/mdev'                   [ Not found ]
[20:17:07]   Checking for file '/usr/lib/libX.a'             [ Not found ]
[20:17:07] Danny-Boy's Abuse Kit                             [ Not found ]
[20:17:07]
[20:17:07] Checking for Devil RootKit...
[20:17:07]   Checking for file '/var/lib/games/.src'         [ Not found ]
[20:17:07]   Checking for file '/dev/dsx'                    [ Not found ]
[20:17:07]   Checking for file '/dev/caca'                   [ Not found ]
[20:17:07]   Checking for file '/dev/pro'                    [ Not found ]
[20:17:07]   Checking for file '/bin/bye'                    [ Not found ]
[20:17:07]   Checking for file '/bin/homedir'                [ Not found ]
[20:17:07]   Checking for file '/usr/bin/xfss'               [ Not found ]
[20:17:07]   Checking for file '/usr/sbin/tzava'             [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/holber' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/sense' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/clear' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/tzava' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/citeste' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/killrk' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/searchlog' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/gaoaza' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/cleaner' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/shk' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/srs' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/utile.tgz' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/webpage' [ Not found ]
[20:17:07]   Checking for file '/usr/doc/tar/.../.dracusor/getpsy' [ Not found ]
[20:17:08]   Checking for file '/usr/doc/tar/.../.dracusor/getbnc' [ Not found ]
[20:17:08]   Checking for file '/usr/doc/tar/.../.dracusor/getemech' [ Not found ]
[20:17:08]   Checking for file '/usr/doc/tar/.../.dracusor/localroot.sh' [ Not found ]
[20:17:08]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/old/sense' [ Not found ]
[20:17:08]   Checking for directory '/usr/doc/tar/.../.dracusor' [ Not found ]
[20:17:08] Devil RootKit                                     [ Not found ]
[20:17:08]
[20:17:08] Checking for Dica-Kit Rootkit...
[20:17:08]   Checking for file '/lib/.sso'                   [ Not found ]
[20:17:08]   Checking for file '/lib/.so'                    [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/clean'      [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/dxr'        [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/read'       [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/write'      [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/lf'         [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/xl'         [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/xdr'        [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/psg'        [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/secure'     [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/rdx'        [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/va'         [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/cl.sh'      [ Not found ]
[20:17:08]   Checking for file '/var/run/...dica/last.log'   [ Not found ]
[20:17:08]   Checking for file '/usr/bin/.etc'               [ Not found ]
[20:17:08]   Checking for file '/etc/sshd_config'            [ Not found ]
[20:17:08]   Checking for file '/etc/ssh_host_key'           [ Not found ]
[20:17:08]   Checking for file '/etc/ssh_random_seed'        [ Not found ]
[20:17:08]   Checking for directory '/var/run/...dica'       [ Not found ]
[20:17:08]   Checking for directory '/var/run/...dica/mh'    [ Not found ]
[20:17:08]   Checking for directory '/var/run/...dica/scan'  [ Not found ]
[20:17:08] Dica-Kit Rootkit                                  [ Not found
« آخرین ویرایش: 15 آذر 1393، 08:20 ب‌ظ توسط morilog »