Find the answer to your Linux question:
Results 1 to 8 of 8
Hello. Some 6 months ago when I was using Windows , I ended up having on my hdd the most nasty virus I have ever heard about. This virus is ...
Enjoy an ad free experience by logging in. Not a member yet? Register.
  1. #1
    Just Joined!
    Join Date
    Mar 2010
    Posts
    1

    "Virus" problem in Kubuntu


    Hello. Some 6 months ago when I was using Windows , I ended up having on my hdd the most nasty virus I have ever heard about. This virus is like an A.I. (artificial intelligence)! For real. He knows everything about windows and all the posibilities to repair it in order to get away. For 2 months I switched to Linux (Ubuntu first , now Kubuntu) and this "virus" as an A.I. that he is ... methamorphosed and learned how to bypass all formating , all instalations , all that can I know to do for eliminating him. I think some times ... that this "virus" is alive ffs! I know that I can change my HDD , and problably get rid of this nasty "virus" , but i really want to distroy him.

    So ... let me put u up to date with what I know about it.

    In windows he created a "boot partition" of 8mb that even after formating the entire HDD , still apears as a separate unllocated space (I delete first the partitions and then format them). I can't unite the unlocated spaces , and every time he keeps remaining in that separate partition.

    When I switched to Ubuntu , even If I tried to erase that partition and make it part of the entire HDD , I couldn't. In Ubuntu/Kubuntu ... it has a mutch less activity ... but it's still there and it's still making something.

    In Ubuntu , the partition where this "virus" is ... is not visible and accessible. One night ... a week ago I had a dream! Yes I had one ... ) ... and in that dream something keeped telling me to switch to Kubuntu.

    Now I use Kubuntu , and that partition is visible. But still I can't do anything to it.

    I tried to enter safe mode with root access this morning ... but it wouldn't let me ... and the log screen is returning to log and the only way is normal root access or user access .. but no safe mode.

    I installed Gparted and KDE partition manager. When I open up Gparted and unmount that 8mb partition to format it ... the partition isnt formating at all. I keep end up with used space where this little bugger is.

    Trough Kubuntu I managed to enter that partition and see what's there. In it there are a folder and one hidden text file. Every time I erase them permanently they keep recreating.

    When I check hidden files , the found and lost folder disapears and the text file apears (the name of the text file is ".directory" ).

    Now ... when I open up this text file (with kate) ... this is what's in it.

    ----
    [Dolphin]
    Timestamp=2010,3,31,12,19,58

    [Settings]
    ShowDotFiles=true
    ----

    Even if I change what's there (for example true with false) ... it keeps recreating itself.
    So , I can't erase it or change it.

    ----

    I installed rkhunter. This is the log file.

    Code:
    [11:44:32] Running Rootkit Hunter version 1.3.4 on ordoabchao
    [11:44:32]
    [11:44:32] Info: Start date is Wed Mar 31 11:44:32 EEST 2010
    [11:44:32]
    [11:44:32] Checking configuration file and command-line options...
    [11:44:32] Info: Detected operating system is 'Linux'
    [11:44:32] Info: Found O/S name: Ubuntu 9.10
    [11:44:32] Info: Command line is /usr/bin/rkhunter --check
    [11:44:32] Info: Environment shell is /bin/bash; rkhunter is using dash
    [11:44:32] Info: Using configuration file '/etc/rkhunter.conf'
    [11:44:32] Info: Installation directory is '/usr'
    [11:44:32] Info: Using language 'en'
    [11:44:32] Info: Using '/var/lib/rkhunter/db' as the database directory
    [11:44:32] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
    [11:44:32] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin /usr/X11R6/bin /bin /usr/bin /sbin /usr/sbin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec' as the command directories
    [11:44:32] Info: Using '/' as the root directory by default
    [11:44:32] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
    [11:44:32] Info: No mail-on-warning address configured
    [11:44:32] Info: X will be automatically detected
    [11:44:32] Info: Using second color set
    [11:44:32] Info: Found the 'diff' command: /usr/bin/diff
    [11:44:32] Info: Found the 'file' command: /usr/bin/file
    [11:44:32] Info: Found the 'find' command: /usr/bin/find
    [11:44:32] Info: Found the 'ifconfig' command: /sbin/ifconfig
    [11:44:32] Info: Found the 'ip' command: /sbin/ip
    [11:44:32] Info: Found the 'ldd' command: /usr/bin/ldd
    [11:44:32] Info: Found the 'lsattr' command: /usr/bin/lsattr
    [11:44:32] Info: Found the 'lsmod' command: /sbin/lsmod
    [11:44:32] Info: Found the 'lsof' command: /usr/bin/lsof
    [11:44:32] Info: Found the 'mktemp' command: /bin/mktemp
    [11:44:32] Info: Found the 'netstat' command: /bin/netstat
    [11:44:32] Info: Found the 'perl' command: /usr/bin/perl
    [11:44:32] Info: Found the 'ps' command: /bin/ps
    [11:44:32] Info: Found the 'pwd' command: /bin/pwd
    [11:44:32] Info: Found the 'readlink' command: /bin/readlink
    [11:44:32] Info: Found the 'sort' command: /usr/bin/sort
    [11:44:32] Info: Found the 'stat' command: /usr/bin/stat
    [11:44:32] Info: Found the 'strings' command: /usr/bin/strings
    [11:44:32] Info: Found the 'uniq' command: /usr/bin/uniq
    [11:44:33] Info: System is not using prelinking
    [11:44:33] Info: Using the '/usr/bin/sha1sum' command for the file hash checks
    [11:44:33] Info: Stored hash values used hash function '/usr/bin/sha1sum'
    [11:44:33] Info: Stored hash values did not use a package manager
    [11:44:33] Info: The hash function field index is set to 1
    [11:44:33] Info: No package manager specified: using hash function '/usr/bin/sha1sum'
    [11:44:33] Info: Previous file attributes were stored
    [11:44:33] Info: Enabled tests are: all
    [11:44:33] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps
    [11:44:33] Info: Found ksym file '/proc/kallsyms'
    [11:44:33]
    [11:44:33] Checking if the O/S has changed since last time...
    [11:44:33] Info: Nothing seems to have changed
    [11:44:33]
    [11:44:33] Starting system checks...
    [11:44:33]
    [11:44:33] Checking system commands...
    [11:44:33] Info: Starting test name 'system_commands'
    [11:44:33]
    [11:44:33] Performing 'strings' command checks
    [11:44:33] Info: Starting test name 'strings'
    [11:44:33] Scanning for string /usr/sbin/ntpsx               [ OK ]
    [11:44:33] Scanning for string /usr/lib/.../ls               [ OK ]
    [11:44:33] Scanning for string /usr/lib/.../netstat          [ OK ]
    [11:44:33] Scanning for string /usr/lib/.../lsof             [ OK ]
    [11:44:33] Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
    [11:44:33] Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
    [11:44:33] Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
    [11:44:33] Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
    [11:44:33] Scanning for string /usr/lib/.../uconf.inv        [ OK ]
    [11:44:33] Scanning for string /usr/lib/.../psr              [ OK ]
    [11:44:33] Scanning for string /usr/lib/.../find             [ OK ]
    [11:44:34] Scanning for string /usr/lib/.../pstree           [ OK ]
    [11:44:34] Scanning for string /usr/lib/.../slocate          [ OK ]
    [11:44:34] Scanning for string /usr/lib/.../du               [ OK ]
    [11:44:34] Scanning for string /usr/lib/.../top              [ OK ]
    [11:44:34] Scanning for string /usr/lib/...                  [ OK ]
    [11:44:34] Scanning for string /usr/lib/.../bkit-ssh         [ OK ]
    [11:44:34] Scanning for string /usr/lib/.bkit-               [ OK ]
    [11:44:34] Scanning for string /tmp/.bkp                     [ OK ]
    [11:44:34] Scanning for string /tmp/.cinik                   [ OK ]
    [11:44:34] Scanning for string /tmp/.font-unix/.cinik        [ OK ]
    [11:44:34] Scanning for string /lib/.sso                     [ OK ]
    [11:44:34] Scanning for string /lib/.so                      [ OK ]
    [11:44:34] Scanning for string /var/run/...dica/clean        [ OK ]
    [11:44:34] Scanning for string /var/run/...dica/xl           [ OK ]
    [11:44:34] Scanning for string /var/run/...dica/xdr          [ OK ]
    [11:44:34] Scanning for string /var/run/...dica/psg          [ OK ]
    [11:44:34] Scanning for string /var/run/...dica/secure       [ OK ]
    [11:44:34] Scanning for string /var/run/...dica/rdx          [ OK ]
    [11:44:34] Scanning for string /var/run/...dica/va           [ OK ]
    [11:44:34] Scanning for string /var/run/...dica/cl.sh        [ OK ]
    [11:44:34] Scanning for string /usr/bin/.etc                 [ OK ]
    [11:44:34] Scanning for string /usr/lib/.fx/sched_host.2     [ OK ]
    [11:44:34] Scanning for string /usr/lib/.fx/random_d.2       [ OK ]
    [11:44:35] Scanning for string /usr/lib/.fx/set_pid.2        [ OK ]
    [11:44:35] Scanning for string /usr/lib/.fx/cons.saver       [ OK ]
    [11:44:35] Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
    [11:44:35] Scanning for string /bin/sysback                  [ OK ]
    [11:44:35] Scanning for string /usr/local/bin/sysback        [ OK ]
    [11:44:35] Scanning for string /usr/lib/.tbd                 [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/t0rns       [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/du          [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/ls          [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/t0rnsb      [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/ps          [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/t0rnp       [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/find        [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/ifconfig    [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/pg          [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/ssh.tgz     [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/top         [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/sz          [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/login       [ OK ]
    [11:44:35] Scanning for string /dev/.lib/lib/lib/in.fingerd  [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib/lib/1i0n.sh     [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib/lib/pstree      [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib/lib/in.telnetd  [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib/lib/mjy         [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib/lib/sush        [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib/lib/tfn         [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib/lib/name        [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib/lib/getip.sh    [ OK ]
    [11:44:36] Scanning for string /usr/info/.torn/sh*           [ OK ]
    [11:44:36] Scanning for string /usr/src/.puta/.1addr         [ OK ]
    [11:44:36] Scanning for string /usr/src/.puta/.1file         [ OK ]
    [11:44:36] Scanning for string /usr/src/.puta/.1proc         [ OK ]
    [11:44:36] Scanning for string /usr/src/.puta/.1logz         [ OK ]
    [11:44:36] Scanning for string /usr/info/.t0rn               [ OK ]
    [11:44:36] Scanning for string /dev/.lib                     [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib                 [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib/lib             [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib/lib/dev         [ OK ]
    [11:44:36] Scanning for string /dev/.lib/lib/scan            [ OK ]
    [11:44:36] Scanning for string /usr/src/.puta                [ OK ]
    [11:44:36] Scanning for string /usr/man/man1/man1            [ OK ]
    [11:44:36] Scanning for string /usr/man/man1/man1/lib        [ OK ]
    [11:44:37] Scanning for string /usr/man/man1/man1/lib/.lib   [ OK ]
    [11:44:37] Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
    [11:44:37]
    [11:44:37] Performing 'shared libraries' checks
    [11:44:37] Info: Starting test name 'shared_libs'
    [11:44:37] Checking for preloading variables                 [ None found ]
    [11:44:37] Checking for preload file                         [ Not found ]
    [11:44:37] Info: Starting test name 'shared_libs_path'
    [11:44:37] Checking LD_LIBRARY_PATH variable                 [ Not found ]
    [11:44:37]
    [11:44:37] Performing file properties checks
    [11:44:37] Info: Starting test name 'properties'
    [11:44:37] Checking for prerequisites                        [ OK ]
    [11:44:37] /bin/bash                                         [ OK ]
    [11:44:37] /bin/cat                                          [ OK ]
    [11:44:38] /bin/chmod                                        [ OK ]
    [11:44:38] /bin/chown                                        [ OK ]
    [11:44:38] /bin/cp                                           [ OK ]
    [11:44:38] /bin/date                                         [ OK ]
    [11:44:38] /bin/df                                           [ OK ]
    [11:44:38] /bin/dmesg                                        [ OK ]
    [11:44:39] /bin/echo                                         [ OK ]
    [11:44:39] /bin/ed                                           [ OK ]
    [11:44:39] /bin/egrep                                        [ OK ]
    [11:44:39] Info: Found file '/bin/egrep': it is whitelisted for the 'script replacement' check.
    [11:44:39] /bin/fgrep                                        [ OK ]
    [11:44:39] Info: Found file '/bin/fgrep': it is whitelisted for the 'script replacement' check.
    [11:44:39] /bin/fuser                                        [ OK ]
    [11:44:39] /bin/grep                                         [ OK ]
    [11:44:39] /bin/ip                                           [ OK ]
    [11:44:40] /bin/kill                                         [ OK ]
    [11:44:40] /bin/less                                         [ OK ]
    [11:44:40] /bin/login                                        [ OK ]
    [11:44:40] /bin/ls                                           [ OK ]
    [11:44:40] /bin/lsmod                                        [ OK ]
    [11:44:40] /bin/mktemp                                       [ OK ]
    [11:44:41] /bin/more                                         [ OK ]
    [11:44:41] /bin/mount                                        [ OK ]
    [11:44:41] /bin/mv                                           [ OK ]
    [11:44:41] /bin/netstat                                      [ OK ]
    [11:44:41] /bin/ps                                           [ OK ]
    [11:44:41] /bin/pwd                                          [ OK ]
    [11:44:41] /bin/readlink                                     [ OK ]
    [11:44:42] /bin/sed                                          [ OK ]
    [11:44:42] /bin/sh                                           [ OK ]
    [11:44:42] /bin/su                                           [ OK ]
    [11:44:42] /bin/touch                                        [ OK ]
    [11:44:42] /bin/uname                                        [ OK ]
    [11:44:43] /bin/which                                        [ OK ]
    [11:44:43] Info: Found file '/bin/which': it is whitelisted for the 'script replacement' check.
    [11:44:43] /bin/dash                                         [ OK ]
    [11:44:43] /usr/bin/awk                                      [ OK ]
    [11:44:43] /usr/bin/basename                                 [ OK ]
    [11:44:43] /usr/bin/chattr                                   [ OK ]
    [11:44:43] /usr/bin/cut                                      [ OK ]
    [11:44:44] /usr/bin/diff                                     [ OK ]
    [11:44:44] /usr/bin/dirname                                  [ OK ]
    [11:44:44] /usr/bin/dpkg                                     [ OK ]
    [11:44:44] /usr/bin/dpkg-query                               [ OK ]
    [11:44:44] /usr/bin/du                                       [ OK ]
    [11:44:44] /usr/bin/env                                      [ OK ]
    [11:44:45] /usr/bin/file                                     [ OK ]
    [11:44:45] /usr/bin/find                                     [ OK ]
    [11:44:45] /usr/bin/GET                                      [ OK ]
    [11:44:45] /usr/bin/groups                                   [ OK ]
    [11:44:45] Info: Found file '/usr/bin/groups': it is whitelisted for the 'script replacement' check.
    [11:44:45] /usr/bin/head                                     [ OK ]
    [11:44:45] /usr/bin/id                                       [ OK ]
    [11:44:45] /usr/bin/killall                                  [ OK ]
    [11:44:46] /usr/bin/last                                     [ OK ]
    [11:44:46] /usr/bin/lastlog                                  [ OK ]
    [11:44:46] /usr/bin/ldd                                      [ OK ]
    [11:44:46] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
    [11:44:46] /usr/bin/less                                     [ OK ]
    [11:44:46] /usr/bin/locate                                   [ OK ]
    [11:44:46] /usr/bin/logger                                   [ OK ]
    [11:44:47] /usr/bin/lsattr                                   [ OK ]
    [11:44:47] /usr/bin/lsof                                     [ OK ]
    [11:44:47] /usr/bin/md5sum                                   [ OK ]
    [11:44:47] /usr/bin/mlocate                                  [ OK ]
    [11:44:47] /usr/bin/newgrp                                   [ OK ]
    [11:44:47] /usr/bin/passwd                                   [ OK ]
    [11:44:47] /usr/bin/perl                                     [ OK ]
    [11:44:48] /usr/bin/pstree                                   [ OK ]
    [11:44:48] /usr/bin/rkhunter                                 [ OK ]
    [11:44:48] /usr/bin/runcon                                   [ OK ]
    [11:44:48] /usr/bin/sha1sum                                  [ OK ]
    [11:44:48] /usr/bin/size                                     [ OK ]
    [11:44:49] /usr/bin/sort                                     [ OK ]
    [11:44:49] /usr/bin/stat                                     [ OK ]
    [11:44:49] /usr/bin/strace                                   [ OK ]
    [11:44:49] /usr/bin/strings                                  [ OK ]
    [11:44:49] /usr/bin/sudo                                     [ OK ]
    [11:44:49] /usr/bin/tail                                     [ OK ]
    [11:44:49] /usr/bin/test                                     [ OK ]
    [11:44:50] /usr/bin/top                                      [ OK ]
    [11:44:50] /usr/bin/touch                                    [ OK ]
    [11:44:50] /usr/bin/tr                                       [ OK ]
    [11:44:50] /usr/bin/uniq                                     [ OK ]
    [11:44:50] /usr/bin/users                                    [ OK ]
    [11:44:50] /usr/bin/vmstat                                   [ OK ]
    [11:44:50] /usr/bin/w                                        [ OK ]
    [11:44:51] /usr/bin/watch                                    [ OK ]
    [11:44:51] /usr/bin/wc                                       [ OK ]
    [11:44:51] /usr/bin/wget                                     [ OK ]
    [11:44:51] /usr/bin/whatis                                   [ OK ]
    [11:44:51] /usr/bin/whereis                                  [ OK ]
    [11:44:51] /usr/bin/which                                    [ OK ]
    [11:44:51] /usr/bin/who                                      [ OK ]
    [11:44:52] /usr/bin/whoami                                   [ OK ]
    [11:44:52] /usr/bin/mawk                                     [ OK ]
    [11:44:52] /usr/bin/lwp-request                              [ OK ]
    [11:44:52] Info: Found file '/usr/bin/lwp-request': it is whitelisted for the 'script replacement' check.
    [11:44:52] /usr/bin/w.procps                                 [ OK ]
    [11:44:52] /sbin/depmod                                      [ OK ]
    [11:44:53] /sbin/ifconfig                                    [ OK ]
    [11:44:53] /sbin/ifdown                                      [ OK ]
    [11:44:53] /sbin/ifup                                        [ OK ]
    [11:44:53] /sbin/init                                        [ OK ]
    [11:44:53] /sbin/insmod                                      [ OK ]
    [11:44:53] /sbin/ip                                          [ OK ]
    [11:44:54] /sbin/lsmod                                       [ OK ]
    [11:44:54] /sbin/modinfo                                     [ OK ]
    [11:44:54] /sbin/modprobe                                    [ OK ]
    [11:44:54] /sbin/rmmod                                       [ OK ]
    [11:44:54] /sbin/runlevel                                    [ OK ]
    [11:44:54] /sbin/sulogin                                     [ OK ]
    [11:44:55] /sbin/sysctl                                      [ OK ]
    [11:44:55] /usr/sbin/adduser                                 [ OK ]
    [11:44:55] Info: Found file '/usr/sbin/adduser': it is whitelisted for the 'script replacement' check.
    [11:44:55] /usr/sbin/chroot                                  [ OK ]
    [11:44:55] /usr/sbin/cron                                    [ OK ]
    [11:44:56] /usr/sbin/groupadd                                [ OK ]
    [11:44:56] /usr/sbin/groupdel                                [ OK ]
    [11:44:56] /usr/sbin/groupmod                                [ OK ]
    [11:44:56] /usr/sbin/grpck                                   [ OK ]
    [11:44:56] /usr/sbin/nologin                                 [ OK ]
    [11:44:57] /usr/sbin/pwck                                    [ OK ]
    [11:44:57] /usr/sbin/rsyslogd                                [ OK ]
    [11:44:57] /usr/sbin/tcpd                                    [ OK ]
    [11:44:57] /usr/sbin/useradd                                 [ OK ]
    [11:44:57] /usr/sbin/userdel                                 [ OK ]
    [11:44:58] /usr/sbin/usermod                                 [ OK ]
    [11:44:58] /usr/sbin/vipw                                    [ OK ]
    [11:45:02]
    [11:45:02] Checking for rootkits...
    [11:45:02] Info: Starting test name 'rootkits'
    [11:45:03]
    [11:45:03] Performing check of known rootkit files and directories
    [11:45:03] Info: Starting test name 'known_rkts'
    [11:45:03]
    [11:45:03] Checking for 55808 Trojan - Variant A...
    [11:45:03]   Checking for file '/tmp/.../r'                  [ Not found ]
    [11:45:03]   Checking for file '/tmp/.../a'                  [ Not found ]
    [11:45:03] 55808 Trojan - Variant A                          [ Not found ]
    [11:45:03]
    [11:45:03] Checking for ADM Worm...
    [11:45:03]   Checking for string 'w0rm'                      [ Not found ]
    [11:45:03] ADM Worm                                          [ Not found ]
    [11:45:03]
    [11:45:03] Checking for AjaKit Rootkit...
    [11:45:03]   Checking for file '/dev/tux/.addr'              [ Not found ]
    [11:45:03]   Checking for file '/dev/tux/.proc'              [ Not found ]
    [11:45:03]   Checking for file '/dev/tux/.file'              [ Not found ]
    [11:45:03]   Checking for file '/lib/.libgh-gh/cleaner'      [ Not found ]
    [11:45:03]   Checking for file '/lib/.libgh-gh/Patch/patch'  [ Not found ]
    [11:45:03]   Checking for file '/lib/.libgh-gh/sb0k'         [ Not found ]
    [11:45:03]   Checking for directory '/dev/tux'               [ Not found ]
    [11:45:03]   Checking for directory '/lib/.libgh-gh'         [ Not found ]
    [11:45:03] AjaKit Rootkit                                    [ Not found ]
    [11:45:03]
    [11:45:03] Checking for aPa Kit...
    [11:45:03]   Checking for file '/usr/share/.aPa'             [ Not found ]
    [11:45:04] aPa Kit                                           [ Not found ]
    [11:45:04]
    [11:45:04] Checking for Apache Worm...
    [11:45:04]   Checking for file '/bin/.log'                   [ Not found ]
    [11:45:04] Apache Worm                                       [ Not found ]
    [11:45:04]
    [11:45:04] Checking for Ambient (ark) Rootkit...
    [11:45:04]   Checking for file '/usr/lib/.ark?'              [ Not found ]
    [11:45:04]   Checking for file '/dev/ptyxx/.log'             [ Not found ]
    [11:45:04]   Checking for file '/dev/ptyxx/.file'            [ Not found ]
    [11:45:04]   Checking for directory '/dev/ptyxx'             [ Not found ]
    [11:45:04] Ambient (ark) Rootkit                             [ Not found ]
    [11:45:04]
    [11:45:04] Checking for Balaur Rootkit...
    [11:45:04]   Checking for file '/usr/lib/liblog.o'           [ Not found ]
    [11:45:04]   Checking for directory '/usr/lib/.kinetic'      [ Not found ]
    [11:45:04]   Checking for directory '/usr/lib/.egcs'         [ Not found ]
    [11:45:04]   Checking for directory '/usr/lib/.wormie'       [ Not found ]
    [11:45:04] Balaur Rootkit                                    [ Not found ]
    [11:45:04]
    [11:45:04] Checking for BeastKit Rootkit...
    [11:45:04]   Checking for file '/usr/sbin/arobia'            [ Not found ]
    [11:45:04]   Checking for file '/usr/sbin/idrun'             [ Not found ]
    [11:45:04]   Checking for file '/usr/lib/elm/arobia/elm'     [ Not found ]
    [11:45:04]   Checking for file '/usr/lib/elm/arobia/elm/hk'  [ Not found ]
    [11:45:04]   Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/elm/arobia/elm/sc'  [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
    [11:45:05]   Checking for directory '/lib/ldd.so/bktools'    [ Not found ]
    [11:45:05] BeastKit Rootkit                                  [ Not found ]
    [11:45:05]
    [11:45:05] Checking for beX2 Rootkit...
    [11:45:05]   Checking for directory '/usr/include/bex'       [ Not found ]
    [11:45:05] beX2 Rootkit                                      [ Not found ]
    [11:45:05]
    [11:45:05] Checking for BOBKit Rootkit...
    [11:45:05]   Checking for file '/usr/sbin/ntpsx'             [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/.../ls'             [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/.../netstat'        [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/.../lsof'           [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/.../uconf.inv'      [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/.../psr'            [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/.../find'           [ Not found ]
    [11:45:05]   Checking for file '/usr/lib/.../pstree'         [ Not found ]
    [11:45:06]   Checking for file '/usr/lib/.../slocate'        [ Not found ]
    [11:45:06]   Checking for file '/usr/lib/.../du'             [ Not found ]
    [11:45:06]   Checking for file '/usr/lib/.../top'            [ Not found ]
    [11:45:06]   Checking for directory '/usr/lib/...'           [ Not found ]
    [11:45:06]   Checking for directory '/usr/lib/.../bkit-ssh'  [ Not found ]
    [11:45:06]   Checking for directory '/usr/lib/.bkit-'        [ Not found ]
    [11:45:06]   Checking for directory '/tmp/.bkp'              [ Not found ]
    [11:45:06] BOBKit Rootkit                                    [ Not found ]
    [11:45:06]
    [11:45:06] Checking for CiNIK Worm (Slapper.B variant)...
    [11:45:06]   Checking for file '/tmp/.cinik'                 [ Not found ]
    [11:45:06]   Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
    [11:45:06] CiNIK Worm (Slapper.B variant)                    [ Not found ]
    [11:45:06]
    [11:45:06] Checking for Danny-Boy's Abuse Kit...
    [11:45:06]   Checking for file '/dev/mdev'                   [ Not found ]
    [11:45:06]   Checking for file '/usr/lib/libX.a'             [ Not found ]
    [11:45:06] Danny-Boy's Abuse Kit                             [ Not found ]
    [11:45:06]
    [11:45:06] Checking for Devil RootKit...
    [11:45:06]   Checking for file '/var/lib/games/.src'         [ Not found ]
    [11:45:06]   Checking for file '/dev/dsx'                    [ Not found ]
    [11:45:06]   Checking for file '/dev/caca'                   [ Not found ]
    [11:45:06] Devil RootKit                                     [ Not found ]
    [11:45:06]
    [11:45:06] Checking for Dica-Kit Rootkit...
    [11:45:06]   Checking for file '/lib/.sso'                   [ Not found ]
    [11:45:06]   Checking for file '/lib/.so'                    [ Not found ]
    [11:45:06]   Checking for file '/var/run/...dica/clean'      [ Not found ]
    [11:45:07]   Checking for file '/var/run/...dica/xl'         [ Not found ]
    [11:45:07]   Checking for file '/var/run/...dica/xdr'        [ Not found ]
    [11:45:07]   Checking for file '/var/run/...dica/psg'        [ Not found ]
    [11:45:07]   Checking for file '/var/run/...dica/secure'     [ Not found ]
    [11:45:07]   Checking for file '/var/run/...dica/rdx'        [ Not found ]
    [11:45:07]   Checking for file '/var/run/...dica/va'         [ Not found ]
    [11:45:07]   Checking for file '/var/run/...dica/cl.sh'      [ Not found ]
    [11:45:07]   Checking for file '/usr/bin/.etc'               [ Not found ]
    [11:45:07]   Checking for directory '/var/run/...dica'       [ Not found ]
    [11:45:07]   Checking for directory '/var/run/...dica/mh'    [ Not found ]
    [11:45:07]   Checking for directory '/var/run/...dica/scan'  [ Not found ]
    [11:45:07] Dica-Kit Rootkit                                  [ Not found ]
    [11:45:07]
    [11:45:07] Checking for Dreams Rootkit...
    [11:45:07]   Checking for file '/dev/ttyoa'                  [ Not found ]
    [11:45:07]   Checking for file '/dev/ttyof'                  [ Not found ]
    [11:45:07]   Checking for file '/dev/ttyop'                  [ Not found ]
    [11:45:07]   Checking for file '/usr/bin/sense'              [ Not found ]
    [11:45:07]   Checking for file '/usr/bin/sl2'                [ Not found ]
    [11:45:07]   Checking for file '/usr/bin/logclear'           [ Not found ]
    [11:45:07]   Checking for file '/usr/bin/(swapd)'            [ Not found ]
    [11:45:07]   Checking for file '/usr/bin/snfs'               [ Not found ]
    [11:45:07]   Checking for file '/usr/lib/libsss'             [ Not found ]
    [11:45:07]   Checking for directory '/dev/ida/.hpd'          [ Not found ]
    [11:45:08] Dreams Rootkit                                    [ Not found ]
    [11:45:08]
    [11:45:08] Checking for Duarawkz Rootkit...
    [11:45:08]   Checking for file '/usr/bin/duarawkz/loginpass' [ Not found ]
    [11:45:08]   Checking for directory '/usr/bin/duarawkz'      [ Not found ]
    [11:45:08] Duarawkz Rootkit                                  [ Not found ]
    [11:45:08]
    [11:45:08] Checking for Enye LKM...
    [11:45:08]   Checking for file '/etc/.enyelkmHIDE^IT.ko'     [ Not found ]
    [11:45:08] Enye LKM                                          [ Not found ]
    [11:45:08]
    [11:45:08] Checking for Flea Linux Rootkit...
    [11:45:08]   Checking for file '/etc/ld.so.hash'             [ Not found ]
    [11:45:08]   Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
    [11:45:08]   Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
    [11:45:08]   Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
    [11:45:08]   Checking for file '/usr/bin/ssh2d'              [ Not found ]
    [11:45:08]   Checking for file '/usr/lib/ldlibns.so'         [ Not found ]
    [11:45:08]   Checking for file '/usr/lib/ldlibpst.so'        [ Not found ]
    [11:45:08]   Checking for file '/usr/lib/ldlibdu.so'         [ Not found ]
    [11:45:08]   Checking for file '/usr/lib/ldlibct.so'         [ Not found ]
    [11:45:08]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
    [11:45:08]   Checking for directory '/dev/..0'               [ Not found ]
    [11:45:08]   Checking for directory '/dev/..0/backup'        [ Not found ]
    [11:45:08] Flea Linux Rootkit                                [ Not found ]
    [11:45:08]
    [11:45:08] Checking for FreeBSD Rootkit...
    [11:45:08]   Checking for file '/usr/lib/.fx/sched_host.2'   [ Not found ]
    [11:45:09]   Checking for file '/usr/lib/.fx/random_d.2'     [ Not found ]
    [11:45:09]   Checking for file '/usr/lib/.fx/set_pid.2'      [ Not found ]
    [11:45:09]   Checking for file '/usr/lib/.fx/cons.saver'     [ Not found ]
    [11:45:09]   Checking for file '/usr/lib/.fx/adore/adore/adore.ko' [ Not found ]
    [11:45:09]   Checking for file '/bin/sysback'                [ Not found ]
    [11:45:09]   Checking for file '/usr/local/bin/sysback'      [ Not found ]
    [11:45:09]   Checking for directory '/usr/lib/.fx'           [ Not found ]
    [11:45:09]   Checking for directory '/usr/lib/.fx/adore'     [ Not found ]
    [11:45:09] FreeBSD Rootkit                                   [ Not found ]
    [11:45:09]
    [11:45:09] Checking for ****`it Rootkit...
    [11:45:09]   Checking for file '/dev/proc/****it/hax0r'      [ Not found ]
    [11:45:09]   Checking for file '/dev/proc/****it/hax0rshell' [ Not found ]
    [11:45:09]   Checking for file '/dev/proc/****it/config/lports' [ Not found ]
    [11:45:09]   Checking for file '/dev/proc/****it/config/rports' [ Not found ]
    [11:45:09]   Checking for file '/dev/proc/****it/config/rkconf' [ Not found ]
    [11:45:09]   Checking for file '/dev/proc/****it/config/password' [ Not found ]
    [11:45:09]   Checking for file '/dev/proc/****it/config/progs' [ Not found ]
    [11:45:09]   Checking for file '/dev/proc/system-bins/init'  [ Not found ]
    [11:45:09] ****`it Rootkit                                   [ Not found ]
    [11:45:09]
    [11:45:09] Checking for GasKit Rootkit...
    [11:45:09]   Checking for file '/dev/dev/gaskit/sshd/sshdd'  [ Not found ]
    [11:45:09]   Checking for directory '/dev/dev'               [ Not found ]
    [11:45:09]   Checking for directory '/dev/dev/gaskit'        [ Not found ]
    [11:45:10]   Checking for directory '/dev/dev/gaskit/sshd'   [ Not found ]
    [11:45:10] GasKit Rootkit                                    [ Not found ]
    [11:45:10]
    [11:45:10] Checking for Heroin LKM...
    [11:45:10]   Checking for kernel symbol 'heroin'             [ Not found ]
    [11:45:10] Heroin LKM                                        [ Not found ]
    [11:45:10]
    [11:45:10] Checking for HjC Kit...
    [11:45:10]   Checking for directory '/dev/.hijackerz'        [ Not found ]
    [11:45:10] HjC Kit                                           [ Not found ]
    [11:45:10]
    [11:45:10] Checking for ignoKit Rootkit...
    [11:45:10]   Checking for file '/lib/defs/p'                 [ Not found ]
    [11:45:10]   Checking for file '/lib/defs/q'                 [ Not found ]
    [11:45:10]   Checking for file '/lib/defs/r'                 [ Not found ]
    [11:45:10]   Checking for file '/lib/defs/s'                 [ Not found ]
    [11:45:10]   Checking for file '/lib/defs/t'                 [ Not found ]
    [11:45:10]   Checking for file '/usr/lib/defs/p'             [ Not found ]
    [11:45:10]   Checking for file '/usr/lib/defs/q'             [ Not found ]
    [11:45:10]   Checking for file '/usr/lib/defs/r'             [ Not found ]
    [11:45:10]   Checking for file '/usr/lib/defs/s'             [ Not found ]
    [11:45:10]   Checking for file '/usr/lib/defs/t'             [ Not found ]
    [11:45:10]   Checking for file '/usr/lib/.libigno/pkunsec'   [ Not found ]
    [11:45:10]   Checking for file '/usr/lib/.libigno/.igno/psybnc/psybnc' [ Not found ]
    [11:45:10]   Checking for directory '/usr/lib/.libigno'      [ Not found ]
    [11:45:11]   Checking for directory '/usr/lib/.libigno/.igno' [ Not found ]
    [11:45:11] ignoKit Rootkit                                   [ Not found ]
    [11:45:11]
    [11:45:11] Checking for ImperalsS-FBRK Rootkit...
    [11:45:11]   Checking for directory '/dev/fd/.88'            [ Not found ]
    [11:45:11]   Checking for directory '/dev/fd/.99'            [ Not found ]
    [11:45:11] ImperalsS-FBRK Rootkit                            [ Not found ]
    [11:45:11]
    [11:45:11] Checking for IntoXonia-NG Rootkit...
    [11:45:11]   Checking for kernel symbol 'funces'             [ Not found ]
    [11:45:11]   Checking for kernel symbol 'ixinit'             [ Not found ]
    [11:45:11]   Checking for kernel symbol 'tricks'             [ Not found ]
    [11:45:11]   Checking for kernel symbol 'kernel_unlink'      [ Not found ]
    [11:45:11]   Checking for kernel symbol 'rootme'             [ Not found ]
    [11:45:11]   Checking for kernel symbol 'hide_module'        [ Not found ]
    [11:45:12]   Checking for kernel symbol 'find_sys_call_tbl'  [ Not found ]
    [11:45:12] IntoXonia-NG Rootkit                              [ Not found ]
    [11:45:12]
    [11:45:12] Checking for Irix Rootkit...
    [11:45:12]   Checking for directory '/dev/pts/01'            [ Not found ]
    [11:45:12]   Checking for directory '/dev/pts/01/backup'     [ Not found ]
    [11:45:12]   Checking for directory '/dev/pts/01/etc'        [ Not found ]
    [11:45:12]   Checking for directory '/dev/pts/01/tmp'        [ Not found ]
    [11:45:12] Irix Rootkit                                      [ Not found ]
    [11:45:12]
    [11:45:12] Checking for Kitko Rootkit...
    [11:45:12]   Checking for directory '/usr/src/redhat/SRPMS/...' [ Not found ]
    [11:45:12] Kitko Rootkit                                     [ Not found ]
    [11:45:12]
    [11:45:12] Checking for Knark Rootkit...
    [11:45:12]   Checking for file '/proc/knark/pids'            [ Not found ]
    [11:45:12]   Checking for directory '/proc/knark'            [ Not found ]
    [11:45:12] Knark Rootkit                                     [ Not found ]
    [11:45:12]
    [11:45:12] Checking for Li0n Worm...
    [11:45:12]   Checking for file '/bin/in.telnetd'             [ Not found ]
    [11:45:12]   Checking for file '/bin/mjy'                    [ Not found ]
    [11:45:12]   Checking for file '/usr/man/man1/man1/lib/.lib/mjy' [ Not found ]
    [11:45:12]   Checking for file '/usr/man/man1/man1/lib/.lib/in.telnetd' [ Not found ]
    [11:45:12]   Checking for file '/usr/man/man1/man1/lib/.lib/.x' [ Not found ]
    [11:45:12]   Checking for file '/dev/.lib/lib/scan/1i0n.sh'  [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/scan/hack.sh'  [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/scan/bind'     [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/scan/randb'    [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/scan/scan.sh'  [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/scan/pscan'    [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/scan/star.sh'  [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/scan/bindx.sh' [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/scan/bindname.log' [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/1i0n.sh'       [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/lib/netstat'   [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/lib/dev/.1addr' [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/lib/dev/.1logz' [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/lib/dev/.1proc' [ Not found ]
    [11:45:13]   Checking for file '/dev/.lib/lib/lib/dev/.1file' [ Not found ]
    [11:45:13] Li0n Worm                                         [ Not found ]
    [11:45:13]
    [11:45:13] Checking for Lockit / LJK2 Rootkit...
    [11:45:13]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_config' [ Not found ]
    [11:45:13]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key' [ Not found ]
    [11:45:13]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub' [ Not found ]
    [11:45:13]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_random_seed*' [ Not found ]
    [11:45:13]   Checking for file '/usr/lib/libmen.oo/.LJK2/sshd_config' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/du' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ifconfig' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/inetd.conf' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/locate' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/login' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ls' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/netstat' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ps' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/pstree' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/syslogd' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/tcpd' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/top' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1sauber' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1wted' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1parser' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1sniff' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1addr' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1dir' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1log' [ Not found ]
    [11:45:14]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1proc' [ Not found ]
    [11:45:15]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c' [ Not found ]
    [11:45:15]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/README.modules' [ Not found ]
    [11:45:15]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c' [ Not found ]
    [11:45:15]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1phide' [ Not found ]
    [11:45:15]   Checking for file '/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh' [ Not found ]
    [11:45:15]   Checking for directory '/usr/lib/libmen.oo/.LJK2' [ Not found ]
    [11:45:15] Lockit / LJK2 Rootkit                             [ Not found ]
    [11:45:15]
    [11:45:15] Checking for Mood-NT Rootkit...
    [11:45:15]   Checking for file '/sbin/init__mood-nt-_-_cthulhu' [ Not found ]
    [11:45:15]   Checking for file '/_cthulhu/mood-nt.init'      [ Not found ]
    [11:45:15]   Checking for file '/_cthulhu/mood-nt.conf'      [ Not found ]
    [11:45:15]   Checking for file '/_cthulhu/mood-nt.sniff'     [ Not found ]
    [11:45:15]   Checking for directory '/_cthulhu'              [ Not found ]
    [11:45:15] Mood-NT Rootkit                                   [ Not found ]
    [11:45:15]
    [11:45:15] Checking for MRK Rootkit...
    [11:45:15]   Checking for file '/dev/ida/.inet/pid'          [ Not found ]
    [11:45:15]   Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
    [11:45:15]   Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
    [11:45:15]   Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
    [11:45:15]   Checking for directory '/dev/ida/.inet'         [ Not found ]
    [11:45:16]   Checking for directory '/var/spool/cron/.sh'    [ Not found ]
    [11:45:16] MRK Rootkit                                       [ Not found ]
    [11:45:16]
    [11:45:16] Checking for Ni0 Rootkit...
    [11:45:16]   Checking for file '/var/lock/subsys/...datafile.../...net...' [ Not found ]
    [11:45:16]   Checking for file '/var/lock/subsys/...datafile.../...port...' [ Not found ]
    [11:45:16]   Checking for file '/var/lock/subsys/...datafile.../...ps...' [ Not found ]
    [11:45:16]   Checking for file '/var/lock/subsys/...datafile.../...file...' [ Not found ]
    [11:45:16]   Checking for directory '/tmp/waza'              [ Not found ]
    [11:45:16]   Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
    [11:45:16]   Checking for directory '/usr/sbin/es'           [ Not found ]
    [11:45:16] Ni0 Rootkit                                       [ Not found ]
    [11:45:16]
    [11:45:16] Checking for Ohhara Rootkit...
    [11:45:16]   Checking for file '/var/lock/subsys/...datafile.../...datafile.../in.smbd.log' [ Not found ]
    [11:45:16]   Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
    [11:45:16]   Checking for directory '/var/lock/subsys/...datafile.../...datafile...' [ Not found ]
    [11:45:16]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../bin' [ Not found ]
    [11:45:16]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/bin' [ Not found ]
    [11:45:16]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/sbin' [ Not found ]
    [11:45:16]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../lib/security' [ Not found ]
    [11:45:16] Ohhara Rootkit                                    [ Not found ]
    [11:45:16]
    [11:45:16] Checking for Optic Kit (Tux) Worm...
    [11:45:16]   Checking for directory '/dev/tux'               [ Not found ]
    [11:45:17]   Checking for directory '/usr/bin/xchk'          [ Not found ]
    [11:45:17]   Checking for directory '/usr/bin/xsf'           [ Not found ]
    [11:45:17]   Checking for directory '/usr/bin/ssh2d'         [ Not found ]
    [11:45:17] Optic Kit (Tux) Worm                              [ Not found ]
    [11:45:17]
    [11:45:17] Checking for Oz Rootkit...
    [11:45:17]   Checking for file '/dev/.oz/.nap/rkit/terror'   [ Not found ]
    [11:45:17]   Checking for directory '/dev/.oz'               [ Not found ]
    [11:45:17] Oz Rootkit                                        [ Not found ]
    [11:45:17]
    [11:45:17] Checking for Phalanx Rootkit...
    [11:45:17]   Checking for file '/usr/share/.home.ph1/cb'     [ Not found ]
    [11:45:17]   Checking for file '/etc/host.ph1'               [ Not found ]
    [11:45:17]   Checking for file '/bin/host.ph1'               [ Not found ]
    [11:45:17]   Checking for file '/usr/share/.home.ph1/phalanx' [ Not found ]
    [11:45:17]   Checking for directory '/usr/share/.home.ph1'   [ Not found ]
    [11:45:17] Phalanx Rootkit                                   [ Not found ]
    [11:45:17]
    [11:45:17] Checking for Phalanx Rootkit (strings)...
    [11:45:17]   Checking for string 'phalanx'                   [ Not found ]
    [11:45:17] Phalanx Rootkit (strings)                         [ Not found ]
    [11:45:17]
    [11:45:17] Checking for Phalanx2 Rootkit...
    [11:45:17]   Checking for file '/etc/khubd.p2/.p2rc'         [ Not found ]
    [11:45:17]   Checking for file '/etc/khubd.p2/.phalanx2'     [ Not found ]
    [11:45:17]   Checking for file '/etc/khubd.p2/.sniff'        [ Not found ]
    [11:45:17]   Checking for file '/etc/khubd.p2/sshgrab.py'    [ Not found ]
    [11:45:18]   Checking for file '/etc/lolzz.p2/.p2rc'         [ Not found ]
    [11:45:18]   Checking for file '/etc/lolzz.p2/.phalanx2'     [ Not found ]
    [11:45:18]   Checking for file '/etc/lolzz.p2/.sniff'        [ Not found ]
    [11:45:18]   Checking for file '/etc/lolzz.p2/sshgrab.py'    [ Not found ]
    [11:45:18]   Checking for directory '/etc/khubd.p2'          [ Not found ]
    [11:45:18]   Checking for directory '/etc/lolzz.p2'          [ Not found ]
    [11:45:18] Phalanx2 Rootkit                                  [ Not found ]
    [11:45:18]
    [11:45:18] Checking for Phalanx2 Rootkit (extended tests)...
    [11:45:18]   Checking for directory '/etc/khubd.p2'          [ Not found ]
    [11:45:18]   Checking for directory '/etc/lolzz.p2'          [ Not found ]
    [11:45:18] Phalanx2 Rootkit (extended tests)                 [ Not found ]
    [11:45:18]
    [11:45:18] Checking for Portacelo Rootkit...
    [11:45:18]   Checking for file '/var/lib/.../.ak'            [ Not found ]
    [11:45:18]   Checking for file '/var/lib/.../.hk'            [ Not found ]
    [11:45:18]   Checking for file '/var/lib/.../.rs'            [ Not found ]
    [11:45:18]   Checking for file '/var/lib/.../.p'             [ Not found ]
    [11:45:18]   Checking for file '/var/lib/.../getty'          [ Not found ]
    [11:45:18]   Checking for file '/var/lib/.../lkt.o'          [ Not found ]
    [11:45:18]   Checking for file '/var/lib/.../show'           [ Not found ]
    [11:45:18]   Checking for file '/var/lib/.../nlkt.o'         [ Not found ]
    [11:45:18]   Checking for file '/var/lib/.../ssshrc'         [ Not found ]
    [11:45:18]   Checking for file '/var/lib/.../sssh_equiv'     [ Not found ]
    [11:45:19]   Checking for file '/var/lib/.../sssh_known_hosts' [ Not found ]
    [11:45:19]   Checking for file '/var/lib/.../sssh_pid'       [ Not found ]
    [11:45:19]   Checking for file '~/.sssh/known_hosts'         [ Not found ]
    [11:45:19] Portacelo Rootkit                                 [ Not found ]
    [11:45:19]
    [11:45:19] Checking for R3dstorm Toolkit...
    [11:45:19]   Checking for file '/var/log/tk02/see_all'       [ Not found ]
    [11:45:19]   Checking for file '/bin/.../sshd/sbin/sshd1'    [ Not found ]
    [11:45:19]   Checking for file '/bin/.../hate/sk'            [ Not found ]
    [11:45:19]   Checking for file '/bin/.../see_all'            [ Not found ]
    [11:45:19]   Checking for directory '/var/log/tk02'          [ Not found ]
    [11:45:19]   Checking for directory '/var/log/tk02/old'      [ Not found ]
    [11:45:19]   Checking for directory '/bin/...'               [ Not found ]
    [11:45:19] R3dstorm Toolkit                                  [ Not found ]
    [11:45:19]
    [11:45:19] Checking for RH-Sharpe's Rootkit...
    [11:45:19]   Checking for file '/bin/lps'                    [ Not found ]
    [11:45:19]   Checking for file '/usr/bin/lpstree'            [ Not found ]
    [11:45:19]   Checking for file '/usr/bin/ltop'               [ Not found ]
    [11:45:19]   Checking for file '/usr/bin/lkillall'           [ Not found ]
    [11:45:19]   Checking for file '/usr/bin/ldu'                [ Not found ]
    [11:45:19]   Checking for file '/usr/bin/lnetstat'           [ Not found ]
    [11:45:19]   Checking for file '/usr/bin/wp'                 [ Not found ]
    [11:45:20]   Checking for file '/usr/bin/shad'               [ Not found ]
    [11:45:20]   Checking for file '/usr/bin/vadim'              [ Not found ]
    [11:45:20]   Checking for file '/usr/bin/slice'              [ Not found ]
    [11:45:20]   Checking for file '/usr/bin/cleaner'            [ Not found ]
    [11:45:20]   Checking for file '/usr/include/rpcsvc/du'      [ Not found ]
    [11:45:20] RH-Sharpe's Rootkit                               [ Not found ]
    [11:45:20]
    [11:45:20] Checking for RSHA's Rootkit...
    [11:45:20]   Checking for file '/bin/kr4p'                   [ Not found ]
    [11:45:20]   Checking for file '/usr/bin/n3tstat'            [ Not found ]
    [11:45:20]   Checking for file '/usr/bin/chsh2'              [ Not found ]
    [11:45:20]   Checking for file '/usr/bin/slice2'             [ Not found ]
    [11:45:20]   Checking for file '/usr/src/linux/arch/alpha/lib/.lib/.1proc' [ Not found ]
    [11:45:20]   Checking for file '/etc/rc.d/arch/alpha/lib/.lib/.1addr' [ Not found ]
    [11:45:20]   Checking for directory '/etc/rc.d/rsha'         [ Not found ]
    [11:45:20]   Checking for directory '/etc/rc.d/arch/alpha/lib/.lib' [ Not found ]
    [11:45:20] RSHA's Rootkit                                    [ Not found ]
    [11:45:20]
    [11:45:20] Checking for Scalper Worm...
    [11:45:20]   Checking for file '/tmp/.a'                     [ Not found ]
    [11:45:20]   Checking for file '/tmp/.uua'                   [ Not found ]
    [11:45:20] Scalper Worm                                      [ Not found ]
    [11:45:20]
    [11:45:20] Checking for Sebek LKM...
    [11:45:21]   Checking for kernel symbol 'adore or sebek'     [ Not found ]
    [11:45:21] Sebek LKM                                         [ Not found ]
    [11:45:21]
    [11:45:21] Checking for Shutdown Rootkit...
    [11:45:21]   Checking for file '/usr/man/man5/.. /.dir/scannah/asus' [ Not found ]
    [11:45:21]   Checking for file '/usr/man/man5/.. /.dir/see'  [ Not found ]
    [11:45:21]   Checking for file '/usr/man/man5/.. /.dir/nscd' [ Not found ]
    [11:45:21]   Checking for file '/usr/man/man5/.. /.dir/alpd' [ Not found ]
    [11:45:21]   Checking for file '/etc/rc.d/rc.local '         [ Not found ]
    [11:45:21]   Checking for directory '/usr/man/man5/.. /.dir' [ Not found ]
    [11:45:21]   Checking for directory '/usr/man/man5/.. /.dir/scannah' [ Not found ]
    [11:45:21]   Checking for directory '/etc/rc.d/rc0.d/.. /.dir' [ Not found ]
    [11:45:21] Shutdown Rootkit                                  [ Not found ]
    [11:45:21]
    [11:45:21] Checking for SHV4 Rootkit...
    [11:45:21]   Checking for file '/etc/ld.so.hash'             [ Not found ]
    [11:45:21]   Checking for file '/lib/libext-2.so.7'          [ Not found ]
    [11:45:21]   Checking for file '/lib/lidps1.so'              [ Not found ]
    [11:45:21]   Checking for file '/usr/sbin/xntps'             [ Not found ]
    [11:45:21]   Checking for directory '/lib/security/.config'  [ Not found ]
    [11:45:21]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
    [11:45:22] SHV4 Rootkit                                      [ Not found ]
    [11:45:22]
    [11:45:22] Checking for SHV5 Rootkit...
    [11:45:22]   Checking for file '/etc/sh.conf'                [ Not found ]
    [11:45:22]   Checking for file '/dev/srd0'                   [ Not found ]
    [11:45:22]   Checking for directory '/usr/lib/libsh'         [ Not found ]
    [11:45:22] SHV5 Rootkit                                      [ Not found ]
    [11:45:22]
    [11:45:22] Checking for Sin Rootkit...
    [11:45:22]   Checking for file '/dev/.haos/haos1/.f/Denyed'  [ Not found ]
    [11:45:22]   Checking for file '/dev/ttyoa'                  [ Not found ]
    [11:45:22]   Checking for file '/dev/ttyof'                  [ Not found ]
    [11:45:22]   Checking for file '/dev/ttyop'                  [ Not found ]
    [11:45:22]   Checking for file '/dev/ttyos'                  [ Not found ]
    [11:45:22]   Checking for file '/usr/lib/.lib'               [ Not found ]
    [11:45:22]   Checking for file '/usr/lib/sn/.X'              [ Not found ]
    [11:45:22]   Checking for file '/usr/lib/sn/.sys'            [ Not found ]
    [11:45:22]   Checking for file '/usr/lib/ld/.X'              [ Not found ]
    [11:45:22]   Checking for file '/usr/man/man1/...'           [ Not found ]
    [11:45:22]   Checking for file '/usr/man/man1/.../.m'        [ Not found ]
    [11:45:22]   Checking for file '/usr/man/man1/.../.w'        [ Not found ]
    [11:45:22]   Checking for directory '/usr/lib/sn'            [ Not found ]
    [11:45:22]   Checking for directory '/usr/lib/man1/...'      [ Not found ]
    [11:45:22]   Checking for directory '/dev/.haos'             [ Not found ]
    [11:45:22] Sin Rootkit                                       [ Not found ]
    [11:45:22]
    [11:45:22] Checking for Slapper Worm...
    [11:45:23]   Checking for file '/tmp/.bugtraq'               [ Not found ]
    [11:45:23]   Checking for file '/tmp/.uubugtraq'             [ Not found ]
    [11:45:23]   Checking for file '/tmp/.bugtraq.c'             [ Not found ]
    [11:45:23]   Checking for file '/tmp/httpd'                  [ Not found ]
    [11:45:23]   Checking for file '/tmp/.unlock'                [ Not found ]
    [11:45:23]   Checking for file '/tmp/update'                 [ Not found ]
    [11:45:23]   Checking for file '/tmp/.cinik'                 [ Not found ]
    [11:45:23]   Checking for file '/tmp/.b'                     [ Not found ]
    [11:45:23] Slapper Worm                                      [ Not found ]
    [11:45:23]
    [11:45:23] Checking for Sneakin Rootkit...
    [11:45:23]   Checking for directory '/tmp/.X11-unix/.../rk'  [ Not found ]
    [11:45:23] Sneakin Rootkit                                   [ Not found ]
    [11:45:23]
    [11:45:23] Checking for Suckit Rootkit...
    [11:45:23]   Checking for file '/sbin/initsk12'              [ Not found ]
    [11:45:23]   Checking for file '/sbin/initxrk'               [ Not found ]
    [11:45:23]   Checking for file '/usr/bin/null'               [ Not found ]
    [11:45:23]   Checking for file '/usr/share/locale/sk/.sk12/sk' [ Not found ]
    [11:45:23]   Checking for file '/etc/rc.d/rc0.d/S23kmdac'    [ Not found ]
    [11:45:23]   Checking for file '/etc/rc.d/rc1.d/S23kmdac'    [ Not found ]
    [11:45:23]   Checking for file '/etc/rc.d/rc2.d/S23kmdac'    [ Not found ]
    [11:45:23]   Checking for file '/etc/rc.d/rc3.d/S23kmdac'    [ Not found ]
    [11:45:23]   Checking for file '/etc/rc.d/rc4.d/S23kmdac'    [ Not found ]
    [11:45:23]   Checking for file '/etc/rc.d/rc5.d/S23kmdac'    [ Not found ]
    [11:45:23]   Checking for file '/etc/rc.d/rc6.d/S23kmdac'    [ Not found ]
    [11:45:24]   Checking for directory '/dev/sdhu0/tehdrakg'    [ Not found ]
    [11:45:24]   Checking for directory '/etc/.MG'               [ Not found ]
    [11:45:24]   Checking for directory '/usr/share/locale/sk/.sk12' [ Not found ]
    [11:45:24]   Checking for directory '/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist' [ Not found ]
    [11:45:24] Suckit Rootkit                                    [ Not found ]
    [11:45:24]
    [11:45:24] Checking for SunOS Rootkit...
    [11:45:24]   Checking for file '/etc/ld.so.hash'             [ Not found ]
    [11:45:24]   Checking for file '/lib/libext-2.so.7'          [ Not found ]
    [11:45:24]   Checking for file '/usr/bin/ssh2d'              [ Not found ]
    [11:45:24]   Checking for file '/bin/xlogin'                 [ Not found ]
    [11:45:24]   Checking for file '/usr/lib/crth.o'             [ Not found ]
    [11:45:24]   Checking for file '/usr/lib/crtz.o'             [ Not found ]
    [11:45:24]   Checking for file '/sbin/login'                 [ Not found ]
    [11:45:24]   Checking for file '/lib/security/.config/sn'    [ Not found ]
    [11:45:24]   Checking for file '/lib/security/.config/lpsched' [ Not found ]
    [11:45:24]   Checking for file '/dev/kmod'                   [ Not found ]
    [11:45:24]   Checking for file '/dev/dos'                    [ Not found ]
    [11:45:24] SunOS Rootkit                                     [ Not found ]
    [11:45:24]
    [11:45:24] Checking for SunOS / NSDAP Rootkit...
    [11:45:24]   Checking for file '/usr/lib/vold/nsdap/.kit'    [ Not found ]
    [11:45:24]   Checking for file '/usr/lib/vold/nsdap/defines' [ Not found ]
    [11:45:24]   Checking for file '/usr/lib/vold/nsdap/patcher' [ Not found ]
    [11:45:24]   Checking for file '/usr/lib/vold/nsdap/pg'      [ Not found ]
    [11:45:24]   Checking for file '/usr/lib/vold/nsdap/cleaner' [ Not found ]
    [11:45:24]   Checking for file '/usr/lib/vold/nsdap/utime'   [ Not found ]
    [11:45:25]   Checking for file '/usr/lib/vold/nsdap/crypt'   [ Not found ]
    [11:45:25]   Checking for file '/usr/lib/vold/nsdap/findkit' [ Not found ]
    [11:45:25]   Checking for file '/usr/lib/vold/nsdap/sn2'     [ Not found ]
    [11:45:25]   Checking for file '/usr/lib/vold/nsdap/sniffload' [ Not found ]
    [11:45:25]   Checking for file '/usr/lib/vold/nsdap/runsniff' [ Not found ]
    [11:45:25]   Checking for file '/usr/lib/lpset'              [ Not found ]
    [11:45:25]   Checking for directory '/usr/lib/vold/nsdap'    [ Not found ]
    [11:45:25] SunOS / NSDAP Rootkit                             [ Not found ]
    [11:45:25]
    [11:45:25] Checking for Superkit Rootkit...
    [11:45:25]   Checking for file '/usr/man/.sman/sk'           [ Not found ]
    [11:45:25] Superkit Rootkit                                  [ Not found ]
    [11:45:25]
    [11:45:25] Checking for TBD (Telnet BackDoor)...
    [11:45:25]   Checking for file '/usr/lib/.tbd'               [ Not found ]
    [11:45:25] TBD (Telnet BackDoor)                             [ Not found ]
    [11:45:25]
    [11:45:25] Checking for TeLeKiT Rootkit...
    [11:45:25]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/sniff' [ Not found ]
    [11:45:25]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/telnetd' [ Not found ]
    [11:45:25]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/teleulo' [ Not found ]
    [11:45:25]   Checking for file '/usr/man/man3/.../cl'        [ Not found ]
    [11:45:25]   Checking for file '/dev/ptyr'                   [ Not found ]
    [11:45:25]   Checking for file '/dev/ptyp'                   [ Not found ]
    [11:45:25]   Checking for file '/dev/ptyq'                   [ Not found ]
    [11:45:25]   Checking for file '/dev/hda06'                  [ Not found ]
    [11:45:25]   Checking for file '/usr/info/libc1.so'          [ Not found ]
    [11:45:26]   Checking for directory '/usr/man/man3/...'      [ Not found ]
    [11:45:26]   Checking for directory '/usr/man/man3/.../lsniff' [ Not found ]
    [11:45:26]   Checking for directory '/usr/man/man3/.../TeLeKiT' [ Not found ]
    [11:45:26] TeLeKiT Rootkit                                   [ Not found ]
    [11:45:26]
    [11:45:26] Checking for T0rn Rootkit...
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/t0rns'     [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/du'        [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/ls'        [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/t0rnsb'    [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/ps'        [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/t0rnp'     [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/find'      [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/ifconfig'  [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/pg'        [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/ssh.tgz'   [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/top'       [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/sz'        [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/login'     [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/in.fingerd' [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/1i0n.sh'   [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/pstree'    [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/in.telnetd' [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/mjy'       [ Not found ]
    [11:45:26]   Checking for file '/dev/.lib/lib/lib/sush'      [ Not found ]
    [11:45:27]   Checking for file '/dev/.lib/lib/lib/tfn'       [ Not found ]
    [11:45:27]   Checking for file '/dev/.lib/lib/lib/name'      [ Not found ]
    [11:45:27]   Checking for file '/dev/.lib/lib/lib/getip.sh'  [ Not found ]
    [11:45:27]   Checking for file '/usr/info/.torn/sh*'         [ Not found ]
    [11:45:27]   Checking for file '/usr/src/.puta/.1addr'       [ Not found ]
    [11:45:27]   Checking for file '/usr/src/.puta/.1file'       [ Not found ]
    [11:45:27]   Checking for file '/usr/src/.puta/.1proc'       [ Not found ]
    [11:45:27]   Checking for file '/usr/src/.puta/.1logz'       [ Not found ]
    [11:45:27]   Checking for file '/usr/info/.t0rn'             [ Not found ]
    [11:45:27]   Checking for directory '/dev/.lib'              [ Not found ]
    [11:45:27]   Checking for directory '/dev/.lib/lib'          [ Not found ]
    [11:45:27]   Checking for directory '/dev/.lib/lib/lib'      [ Not found ]
    [11:45:27]   Checking for directory '/dev/.lib/lib/lib/dev'  [ Not found ]
    [11:45:27]   Checking for directory '/dev/.lib/lib/scan'     [ Not found ]
    [11:45:27]   Checking for directory '/usr/src/.puta'         [ Not found ]
    [11:45:27]   Checking for directory '/usr/man/man1/man1'     [ Not found ]
    [11:45:27]   Checking for directory '/usr/man/man1/man1/lib' [ Not found ]
    [11:45:27]   Checking for directory '/usr/man/man1/man1/lib/.lib' [ Not found ]
    [11:45:27]   Checking for directory '/usr/man/man1/man1/lib/.lib/.backup' [ Not found ]
    [11:45:27] T0rn Rootkit                                      [ Not found ]
    [11:45:27]
    [11:45:27] Checking for Trojanit Kit...
    [11:45:27]   Checking for file '/bin/.ls'                    [ Not found ]
    [11:45:27]   Checking for file '/bin/.ps'                    [ Not found ]
    [11:45:28]   Checking for file '/bin/.netstat'               [ Not found ]
    [11:45:28]   Checking for file '/usr/bin/.nop'               [ Not found ]
    [11:45:28]   Checking for file '/usr/bin/.who'               [ Not found ]
    [11:45:28] Trojanit Kit                                      [ Not found ]
    [11:45:28]
    [11:45:28] Checking for Tuxtendo Rootkit...
    [11:45:28]   Checking for file '/dev/tux/.addr'              [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/.cron'              [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/.file'              [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/.log'               [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/.proc'              [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/crontab'     [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/df'          [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/dir'         [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/find'        [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/ifconfig'    [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/locate'      [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/netstat'     [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/ps'          [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/pstree'      [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/syslogd'     [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/tcpd'        [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/top'         [ Not found ]
    [11:45:28]   Checking for file '/dev/tux/backup/updatedb'    [ Not found ]
    [11:45:29]   Checking for file '/dev/tux/backup/vdir'        [ Not found ]
    [11:45:29]   Checking for directory '/dev/tux'               [ Not found ]
    [11:45:29]   Checking for directory '/dev/tux/ssh2'          [ Not found ]
    [11:45:29]   Checking for directory '/dev/tux/backup'        [ Not found ]
    [11:45:29] Tuxtendo Rootkit                                  [ Not found ]
    [11:45:29]
    [11:45:29] Checking for URK Rootkit...
    [11:45:29]   Checking for file '/usr/man/man1/xxxxxxbin/find' [ Not found ]
    [11:45:29]   Checking for file '/usr/man/man1/xxxxxxbin/du'  [ Not found ]
    [11:45:29]   Checking for file '/usr/man/man1/xxxxxxbin/ps'  [ Not found ]
    [11:45:29]   Checking for file '/tmp/conf.inf'               [ Not found ]
    [11:45:29]   Checking for directory '/usr/man/man1/xxxxxxbin' [ Not found ]
    [11:45:29] URK Rootkit                                       [ Not found ]
    [11:45:29]
    [11:45:29] Checking for Vampire Rootkit...
    [11:45:29]   Checking for kernel symbol 'new_getdents'       [ Not found ]
    [11:45:29]   Checking for kernel symbol 'old_getdents'       [ Not found ]
    [11:45:29]   Checking for kernel symbol 'should_hide_file_name' [ Not found ]
    [11:45:29]   Checking for kernel symbol 'should_hide_task_name' [ Not found ]
    [11:45:29] Vampire Rootkit                                   [ Not found ]
    [11:45:29]
    [11:45:29] Checking for VcKit Rootkit...
    [11:45:29]   Checking for directory '/usr/include/linux/modules/lib.so' [ Not found ]
    [11:45:30]   Checking for directory '/usr/include/linux/modules/lib.so/bin' [ Not found ]
    [11:45:30] VcKit Rootkit                                     [ Not found ]
    [11:45:30]
    [11:45:30] Checking for Volc Rootkit...
    [11:45:30]   Checking for directory '/var/spool/.recent'     [ Not found ]
    [11:45:30]   Checking for directory '/var/spool/.recent/.files' [ Not found ]
    [11:45:30]   Checking for directory '/usr/lib/volc'          [ Not found ]
    [11:45:30]   Checking for directory '/usr/lib/volc/backup'   [ Not found ]
    [11:45:30] Volc Rootkit                                      [ Not found ]
    [11:45:30]
    [11:45:30] Checking for X-Org SunOS Rootkit...
    [11:45:30]   Checking for file '/usr/lib/libX.a/bin/tmpfl'   [ Not found ]
    [11:45:30]   Checking for file '/usr/lib/libX.a/bin/rps'     [ Not found ]
    [11:45:30]   Checking for file '/usr/bin/srload'             [ Not found ]
    [11:45:30]   Checking for file '/usr/lib/libX.a/bin/sparcv7/rps' [ Not found ]
    [11:45:30]   Checking for file '/usr/sbin/modcheck'          [ Not found ]
    [11:45:30]   Checking for directory '/usr/lib/libX.a'        [ Not found ]
    [11:45:30]   Checking for directory '/usr/lib/libX.a/bin'    [ Not found ]
    [11:45:30]   Checking for directory '/usr/lib/libX.a/bin/sparcv7' [ Not found ]
    [11:45:30]   Checking for directory '/usr/share/man...'      [ Not found ]
    [11:45:30] X-Org SunOS Rootkit                               [ Not found ]
    [11:45:30]
    [11:45:30] Checking for zaRwT.KiT Rootkit...
    [11:45:30]   Checking for file '/dev/rd/s/sendmeil'          [ Not found ]
    [11:45:30]   Checking for file '/dev/ttyf'                   [ Not found ]
    [11:45:30]   Checking for file '/dev/ttyp'                   [ Not found ]
    [11:45:30]   Checking for file '/dev/ttyn'                   [ Not found ]
    [11:45:31]   Checking for file '/rk/tulz'                    [ Not found ]
    [11:45:31]   Checking for directory '/rk'                    [ Not found ]
    [11:45:31]   Checking for directory '/dev/rd/s'              [ Not found ]
    [11:45:31] zaRwT.KiT Rootkit                                 [ Not found ]
    [11:45:31]
    [11:45:31] Performing additional rootkit checks
    [11:45:31] Info: Starting test name 'additional_rkts'
    [11:45:31]
    [11:45:31]   Performing Suckit Rookit additional checks
    [11:45:31]     Checking hard link count on '/sbin/init'      [ OK ]
    [11:45:31]     Checking for hidden file extensions           [ None found ]
    [11:45:31]     Running skdet command                         [ Skipped ]
    [11:45:31] Info: Unable to find the 'skdet' command
    [11:45:31]   Suckit Rookit additional checks                 [ OK ]
    [11:45:31]
    [11:45:31]   Performing check of possible rootkit files and directories
    [11:45:31] Info: Starting test name 'possible_rkt_files'
    [11:45:31]     Checking for file '/dev/sdr0'                 [ Not found ]
    [11:45:31]     Checking for file '/tmp/.syshackfile'         [ Not found ]
    [11:45:31]     Checking for file '/tmp/.bash_history'        [ Not found ]
    [11:45:31]     Checking for file '/usr/info/.clib'           [ Not found ]
    [11:45:31]     Checking for file '/usr/sbin/tcp.log'         [ Not found ]
    [11:45:31]     Checking for file '/usr/bin/take/pid'         [ Not found ]
    [11:45:31]     Checking for file '/sbin/create'              [ Not found ]
    [11:45:32]     Checking for file '/dev/ttypz'                [ Not found ]
    [11:45:32]     Checking for directory '/usr/bin/take'        [ Not found ]
    [11:45:32]     Checking for directory '/usr/src/.lib'        [ Not found ]
    [11:45:32]     Checking for directory '/usr/share/man/man1/.1c' [ Not found ]
    [11:45:32]     Checking for directory '/lib/lblip.tk'        [ Not found ]
    [11:45:32]     Checking for directory '/usr/sbin/...'        [ Not found ]
    [11:45:32]     Checking for directory '/usr/share/.gun'      [ Not found ]
    [11:45:32]   Checking for possible rootkit files and directories [ None found ]
    [11:45:32]
    [11:45:32]   Performing check for possible rootkit strings
    [11:45:32] Info: Starting test name 'possible_rkt_strings'
    [11:45:32] Info: Using system startup paths: /etc/rc.local /etc/init.d
    [11:45:32]     Checking for string '/dev/proc/****it'        [ Not found ]
    [11:45:32]     Checking for string '****'                    [ Not found ]
    [11:45:32]     Checking for string 'backdoor'                [ Not found ]
    [11:45:32]     Checking for string 'vt200'                   [ Not found ]
    [11:45:32]     Checking for string '/usr/bin/xstat'          [ Not found ]
    [11:45:32]     Checking for string '/bin/envpc'              [ Not found ]
    [11:45:33]     Checking for string 'L4m3r0x'                 [ Not found ]
    [11:45:33]     Checking for string '/usr/lib/.tbd'           [ Not found ]
    [11:45:33]     Checking for string '/dev/ptyxx/.file'        [ Not found ]
    [11:45:33]     Checking for string '/dev/sgk'                [ Not found ]
    [11:45:33]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
    [11:45:33]     Checking for string '/usr/lib/.tbd'           [ Not found ]
    [11:45:33]     Checking for string '/dev/proc/****it'        [ Not found ]
    [11:45:33]     Checking for string '/lib/.sso'               [ Not found ]
    [11:45:33]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
    [11:45:33]     Checking for string '/dev/caca'               [ Not found ]
    [11:45:33]     Checking for string '/dev/ttyoa'              [ Not found ]
    [11:45:33]     Checking for string 'syg'                     [ Not found ]
    [11:45:33]     Checking for string '/dev/pts/01'             [ Not found ]
    [11:45:33]     Checking for string 'tw33dl3'                 [ Not found ]
    [11:45:33]     Checking for string 'psniff'                  [ Not found ]
    [11:45:34]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
    [11:45:34]     Checking for string '/dev/xdta'               [ Not found ]
    [11:45:34]     Checking for string '/usr/lib/.tbd'           [ Not found ]
    [11:45:34]     Checking for string 'in.inetd'                [ Not found ]
    [11:45:34]     Checking for string '#<HIDE_.*>'              [ Not found ]
    [11:45:35]     Checking for string 'bin/xchk'                [ Not found ]
    [11:45:35]     Checking for string 'bin/xsf'                 [ Not found ]
    [11:45:35]   Checking for possible rootkit strings           [ None found ]
    [11:45:35]
    [11:45:35] Performing malware checks
    [11:45:35] Info: Starting test name 'malware'
    [11:45:35]
    [11:45:35] Info: Test 'deleted_files' disabled at users request.
    [11:45:35] Info: Starting test name 'running_procs'
    [11:45:36]   Checking running processes for suspicious files [ None found ]
    [11:45:36]
    [11:45:36] Info: Test 'hidden_procs' disabled at users request.
    [11:45:36]
    [11:45:36] Info: Test 'suspscan' disabled at users request.
    [11:45:36]
    [11:45:36]   Performing check for login backdoors
    [11:45:36] Info: Starting test name 'other_malware'
    [11:45:36]     Checking for '/bin/.login'                    [ Not found ]
    [11:45:36]     Checking for '/sbin/.login'                   [ Not found ]
    [11:45:36]   Checking for login backdoors                    [ None found ]
    [11:45:36]
    [11:45:36]   Performing check for suspicious directories
    [11:45:36]     Checking for directory '/usr/X11R6/bin/.,/copy' [ Not found ]
    [11:45:36]     Checking for directory '/dev/rd/cdb'          [ Not found ]
    [11:45:36]   Checking for suspicious directories             [ None found ]
    [11:45:36]
    [11:45:36]   Checking for software intrusions                [ Skipped ]
    [11:45:36] Info: Check skipped - tripwire not installed
    [11:45:36]
    [11:45:36]   Performing check for sniffer log files
    [11:45:36]     Checking for file '/usr/lib/libice.log'       [ Not found ]
    [11:45:36]   Checking for sniffer log files                  [ None found ]
    [11:45:36]
    [11:45:36] Performing trojan specific checks
    [11:45:36] Info: Starting test name 'trojans'
    [11:45:36] Info: Using inetd configuration file '/etc/inetd.conf'
    [11:45:36]   Checking for enabled inetd services             [ OK ]
    [11:45:36]
    [11:45:36]   Performing check for enabled xinetd services
    [11:45:36]   Checking for enabled xinetd services            [ Skipped ]
    [11:45:36] Info: Check skipped - file '/etc/xinetd.conf' does not exist.
    [11:45:36] Info: Apache backdoor check skipped: Apache modules and configuration directories not found.
    [11:45:37]
    [11:45:37] Performing Linux specific checks
    [11:45:37] Info: Starting test name 'os_specific'
    [11:45:37]   Checking loaded kernel modules                  [ OK ]
    [11:45:37] Info: Using modules pathname of '/lib/modules/2.6.31-20-generic'
    [11:45:37]   Checking kernel module names                    [ OK ]
    [11:45:40]
    [11:45:40] Checking the network...
    [11:45:40] Info: Starting test name 'network'
    [11:45:40] Info: Starting test name 'ports'
    [11:45:40]
    [11:45:40] Performing check for backdoor ports
    [11:45:40]   Checking for TCP port 1524                      [ Not found ]
    [11:45:40]   Checking for TCP port 1984                      [ Not found ]
    [11:45:40]   Checking for UDP port 2001                      [ Not found ]
    [11:45:40]   Checking for TCP port 2006                      [ Not found ]
    [11:45:40]   Checking for TCP port 2128                      [ Not found ]
    [11:45:40]   Checking for TCP port 6666                      [ Not found ]
    [11:45:40]   Checking for TCP port 6667                      [ Not found ]
    [11:45:41]   Checking for TCP port 6668                      [ Not found ]
    [11:45:41]   Checking for TCP port 6669                      [ Not found ]
    [11:45:41]   Checking for TCP port 7000                      [ Not found ]
    [11:45:41]   Checking for TCP port 13000                     [ Not found ]
    [11:45:41]   Checking for TCP port 14856                     [ Not found ]
    [11:45:41]   Checking for TCP port 25000                     [ Not found ]
    [11:45:41]   Checking for TCP port 29812                     [ Not found ]
    [11:45:41]   Checking for TCP port 31337                     [ Not found ]
    [11:45:41]   Checking for TCP port 33369                     [ Not found ]
    [11:45:42]   Checking for TCP port 47107                     [ Not found ]
    [11:45:42]   Checking for TCP port 47018                     [ Not found ]
    [11:45:42]   Checking for TCP port 60922                     [ Not found ]
    [11:45:42]   Checking for TCP port 62883                     [ Not found ]
    [11:45:42]   Checking for TCP port 65535                     [ Not found ]
    [11:45:42]
    [11:45:42] Performing checks on the network interfaces
    [11:45:42] Info: Starting test name 'promisc'
    [11:45:42]   Checking for promiscuous interfaces             [ None found ]
    [11:45:42]
    [11:45:42] Info: Test 'packet_cap_apps' disabled at users request.
    [11:45:45]
    [11:45:45] Checking the local host...
    [11:45:45] Info: Starting test name 'local_host'
    [11:45:45]
    [11:45:45] Performing system boot checks
    [11:45:45] Info: Starting test name 'startup_files'
    [11:45:45]   Checking for local host name                    [ Found ]
    [11:45:45] Info: Starting test name 'startup_malware'
    [11:45:45]   Checking for system startup files               [ Found ]
    [11:45:46]   Checking system startup files for malware       [ None found ]
    [11:45:46]
    [11:45:46] Performing group and account checks
    [11:45:46] Info: Starting test name 'group_accounts'
    [11:45:46]   Checking for passwd file                        [ Found ]
    [11:45:46] Info: Found password file: /etc/passwd
    [11:45:46]   Checking for root equivalent (UID 0) accounts   [ None found ]
    [11:45:46] Info: Found shadow file: /etc/shadow
    [11:45:46]   Checking for passwordless accounts              [ None found ]
    [11:45:47] Info: Starting test name 'passwd_changes'
    [11:45:47]   Checking for passwd file changes                [ None found ]
    [11:45:47] Info: Starting test name 'group_changes'
    [11:45:47]   Checking for group file changes                 [ None found ]
    [11:45:47]   Checking root account shell history files       [ OK ]
    [11:45:47]
    [11:45:47] Performing system configuration file checks
    [11:45:47] Info: Starting test name 'system_configs'
    [11:45:47]   Checking for SSH configuration file             [ Not found ]
    [11:45:47]   Checking for running syslog daemon              [ Found ]
    [11:45:47]   Checking for syslog configuration file          [ Found ]
    [11:45:47] Info: Found syslog configuration file: /etc/rsyslog.conf
    [11:45:47]   Checking if syslog remote logging is allowed    [ Not allowed ]
    [11:45:47]
    [11:45:47] Performing filesystem checks
    [11:45:47] Info: Starting test name 'filesystem'
    [11:45:47] Info: SCAN_MODE_DEV set to 'THOROUGH'
    [11:45:47]   Checking /dev for suspicious file types         [ None found ]
    [11:45:47]   Checking for hidden files and directories       [ None found ]
    [11:45:50]
    [11:45:50] Checking application versions...
    [11:45:50] Info: Starting test name 'apps'
    [11:45:50]   Checking version of Exim MTA                    [ Warning ]
    [11:45:50] Warning: Application 'exim', version '4.69', is out of date, and possibly a security risk.
    [11:45:50]   Checking version of GnuPG                       [ Warning ]
    [11:45:50] Warning: Application 'gpg', version '1.4.9', is out of date, and possibly a security risk.
    [11:45:50] Info: Application 'httpd' not found.
    [11:45:50] Info: Application 'named' not found.
    [11:45:50]   Checking version of OpenSSL                     [ Warning ]
    [11:45:50] Warning: Application 'openssl', version '0.9.8g', is out of date, and possibly a security risk.
    [11:45:50] Info: Application 'php' not found.
    [11:45:50] Info: Application 'procmail' not found.
    [11:45:50] Info: Application 'proftpd' not found.
    [11:45:50] Info: Application 'sshd' not found.
    [11:45:51] Info: Applications checked: 3 out of 9
    [11:45:51]
    [11:45:51] System checks summary
    [11:45:51] =====================
    [11:45:51]
    [11:45:51] File properties checks...
    [11:45:51] Files checked: 124
    [11:45:51] Suspect files: 0
    [11:45:51]
    [11:45:51] Rootkit checks...
    [11:45:51] Rootkits checked : 111
    [11:45:51] Possible rootkits: 0
    [11:45:51]
    [11:45:51] Applications checks...
    [11:45:51] Applications checked: 3
    [11:45:51] Suspect applications: 3
    [11:45:51]
    [11:45:51] The system checks took: 1 minute and 18 seconds
    [11:45:51]
    [11:45:51] Info: End date is Wed Mar 31 11:45:51 EEST 2010
    ---

    Another important thing is the hidden files from root/media. There I find again that .directory file plus .hal-mtab file.

    How can I permanent erase the files from that partition or that partition?

    Pls help!
    Last edited by oz; 03-31-2010 at 01:33 PM. Reason: inserted code tags

  2. #2
    Just Joined! ultimatelinux's Avatar
    Join Date
    Mar 2010
    Posts
    36
    you may not get answer if you create a thread of this length.

  3. #3
    Linux Guru techieMoe's Avatar
    Join Date
    Aug 2004
    Location
    Texas
    Posts
    9,496
    Quote Originally Posted by Oraculum View Post
    How can I permanent erase the files from that partition or that partition?

    Pls help!
    I don't know much about your particular problem, but if you want to cleanly and completely erase a harddrive you can use the harddrive utilities on something like the Ultimate Boot CD to completely scrape a drive to its original factory state. Fair warning, it's going to take several hours, perhaps the better part of a day depending on how many passes you make.
    Registered Linux user #270181
    TechieMoe's Tech Rants

  4. #4
    Linux Engineer nujinini's Avatar
    Join Date
    Apr 2009
    Posts
    1,272
    nujinini
    Linux User #489667

  5. #5
    Linux Guru reed9's Avatar
    Join Date
    Feb 2009
    Location
    Boston, MA
    Posts
    4,651
    When I check hidden files , the found and lost folder disapears and the text file apears (the name of the text file is ".directory" ).

    Now ... when I open up this text file (with kate) ... this is what's in it.

    ----
    [Dolphin]
    Timestamp=2010,3,31,12,19,58

    [Settings]
    ShowDotFiles=true
    I'm pretty sure Dolphin is creating that hidden file.

    Print Page - Changing the Defaults: Dolphin

  6. #6
    Linux Guru Rubberman's Avatar
    Join Date
    Apr 2009
    Location
    I can be found either 40 miles west of Chicago, or in a galaxy far, far away.
    Posts
    11,158
    Step 1, boot with a Linux Live CD/DVD or Rescue CD/DVD.
    Step 2, erase the entire drive with the command dd if=/dev/zero of=/dev/sda, assuming that /dev/sda is your hard drive (normally it would be).
    Step 3, install OS (or OS's) of choice.

    The ONLY way to 100% remove a virus that has infected the boot sector is to erase the entire disc, as this will do. You can also just erase the boot sector, and restore your partition table, but in your case, I think the entire disc should be wiped.
    Sometimes, real fast is almost as good as real time.
    Just remember, Semper Gumbi - always be flexible!

  7. #7
    Linux Guru reed9's Avatar
    Join Date
    Feb 2009
    Location
    Boston, MA
    Posts
    4,651
    Quote Originally Posted by ryan14 View Post
    wow i never knew linux had viruses.
    It doesn't really. To my knowledge there is no known linux virus in the wild. It is possible, though up to know I think there have only been proof of concept things out there. Even without a real virus, there's plenty of unfortunate things someone might be able to do to your computer if you are taking precautions. Practice safe computing!

    I suppose it might also be possible while running Windows to get a virus that infects the BIOS, which would then survive harddrive wipes.
    New BIOS Virus Withstands HDD Wipes

    But it's not clear to me at least that this was a virus. At least, the files mentioned are legit - as I said the .directory file is created by dolphin and the .hal-mtab file is legit also.

  8. #8
    Linux Guru Rubberman's Avatar
    Join Date
    Apr 2009
    Location
    I can be found either 40 miles west of Chicago, or in a galaxy far, far away.
    Posts
    11,158
    Quote Originally Posted by reed9 View Post
    It doesn't really. To my knowledge there is no known linux virus in the wild. It is possible, though up to know I think there have only been proof of concept things out there. Even without a real virus, there's plenty of unfortunate things someone might be able to do to your computer if you are taking precautions. Practice safe computing!

    I suppose it might also be possible while running Windows to get a virus that infects the BIOS, which would then survive harddrive wipes.
    New BIOS Virus Withstands HDD Wipes

    But it's not clear to me at least that this was a virus. At least, the files mentioned are legit - as I said the .directory file is created by dolphin and the .hal-mtab file is legit also.
    True that there are no known Windows-style viruses such as keystroke loggers, trojans, etc. on Linux: however, there are software tools that can give a black-hat root access to an improperly configured system, especially one that has direct internet exposure (not behind a good firewall). That root access means they can install whatever software on your system they want, and access whatever files and applications they want. Usually these attacks target the systems of major corporations or others with high value IP (intellectual property) to steal. However, if your system is exposed directly to the internet, just look at the logs for attempts to access your system in a myriad of ways - you would be appalled and amazed how many hit you with an hour of that exposure.
    Sometimes, real fast is almost as good as real time.
    Just remember, Semper Gumbi - always be flexible!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •