Guest
Public paste!

Untitled

By: a guest | Mar 21st, 2010 | Syntax: None | Size: 5.35 KB | Hits: 57 | Expires: Never
Copy text to clipboard
  1. [root@pipy screamboy]# chrootkit
  2. -bash: chrootkit: command not found
  3. [root@pipy screamboy]# chkrootkit
  4. ROOTDIR is `/'
  5. Checking `amd'... not found
  6. Checking `basename'... not infected
  7. Checking `biff'... not found
  8. Checking `chfn'... not infected
  9. Checking `chsh'... not infected
  10. Checking `cron'... not infected
  11. Checking `crontab'... not infected
  12. Checking `date'... not infected
  13. Checking `du'... not infected
  14. Checking `dirname'... not infected
  15. Checking `echo'... not infected
  16. Checking `egrep'... not infected
  17. Checking `env'... not infected
  18. Checking `find'... not infected
  19. Checking `fingerd'... not found
  20. Checking `gpm'... not infected
  21. Checking `grep'... not infected
  22. Checking `hdparm'... not infected
  23. Checking `su'... not infected
  24. Checking `ifconfig'... not infected
  25. Checking `inetd'... not found
  26. Checking `inetdconf'... not found
  27. Checking `identd'... not found
  28. Checking `init'... not infected
  29. Checking `killall'... not infected
  30. Checking `ldsopreload'... not infected
  31. Checking `login'... not infected
  32. Checking `ls'... not infected
  33. Checking `lsof'... not infected
  34. Checking `mail'... not infected
  35. Checking `mingetty'... not infected
  36. Checking `netstat'... not infected
  37. Checking `named'... not infected
  38. Checking `passwd'... not infected
  39. Checking `pidof'... not infected
  40. Checking `pop2'... not found
  41. Checking `pop3'... not found
  42. Checking `ps'... not infected
  43. Checking `pstree'... not infected
  44. Checking `rpcinfo'... not infected
  45. Checking `rlogind'... not found
  46. Checking `rshd'... not found
  47. Checking `slogin'... not infected
  48. Checking `sendmail'... not infected
  49. Checking `sshd'... not infected
  50. Checking `syslogd'... not infected
  51. Checking `tar'... not infected
  52. Checking `tcpd'... not infected
  53. Checking `tcpdump'... not infected
  54. Checking `top'... not infected
  55. Checking `telnetd'... not infected
  56. Checking `timed'... not found
  57. Checking `traceroute'... not infected
  58. Checking `vdir'... not infected
  59. Checking `w'... not infected
  60. Checking `write'... not infected
  61. Checking `aliens'... no suspect files
  62. Searching for sniffer's logs, it may take a while... nothing found
  63. Searching for HiDrootkit's default dir... nothing found
  64. Searching for t0rn's default files and dirs... nothing found
  65. Searching for t0rn's v8 defaults... nothing found
  66. Searching for Lion Worm default files and dirs... nothing found
  67. Searching for RSHA's default files and dir... nothing found
  68. Searching for RH-Sharpe's default files... nothing found
  69. Searching for Ambient's rootkit (ark) default files and dirs... nothing found
  70. Searching for suspicious files and dirs, it may take a while...
  71. /usr/lib/.libfipscheck.so.1.1.0.hmac /usr/lib/.libgcrypt.so.11.hmac /usr/lib/.libfipscheck.so.1.hmac /usr/lib/perl5/5.8.8/i386-linux-thread-multi/.packlist /lib/.libcrypto.so.0.9.8e.hmac /lib/.libcrypto.so.6.hmac /lib/.libssl.so.6.hmac /lib/.libssl.so.0.9.8e.hmac
  72.  
  73. Searching for LPD Worm files and dirs... nothing found
  74. Searching for Ramen Worm files and dirs... nothing found
  75. Searching for Maniac files and dirs... nothing found
  76. Searching for RK17 files and dirs... nothing found
  77. Searching for Ducoci rootkit... nothing found
  78. Searching for Adore Worm... nothing found
  79. Searching for ShitC Worm... nothing found
  80. Searching for Omega Worm... nothing found
  81. Searching for Sadmind/IIS Worm... nothing found
  82. Searching for MonKit... nothing found
  83. Searching for Showtee... nothing found
  84. Searching for OpticKit... nothing found
  85. Searching for T.R.K... nothing found
  86. Searching for Mithra... nothing found
  87. Searching for LOC rootkit... nothing found
  88. Searching for Romanian rootkit... nothing found
  89. Searching for HKRK rootkit... nothing found
  90. Searching for Suckit rootkit... nothing found
  91. Searching for Volc rootkit... nothing found
  92. Searching for Gold2 rootkit... nothing found
  93. Searching for TC2 Worm default files and dirs... nothing found
  94. Searching for Anonoying rootkit default files and dirs... nothing found
  95. Searching for ZK rootkit default files and dirs... nothing found
  96. Searching for ShKit rootkit default files and dirs... nothing found
  97. Searching for AjaKit rootkit default files and dirs... nothing found
  98. Searching for zaRwT rootkit default files and dirs... nothing found
  99. Searching for Madalin rootkit default files... nothing found
  100. Searching for Fu rootkit default files... nothing found
  101. Searching for ESRK rootkit default files... nothing found
  102. Searching for rootedoor... nothing found
  103. Searching for ENYELKM rootkit default files... nothing found
  104. Searching for common ssh-scanners default files... nothing found
  105. Searching for anomalies in shell history files... nothing found
  106. Checking `asp'... not infected
  107. Checking `bindshell'... not infected
  108. Checking `lkm'... chkproc: nothing detected
  109. chkdirs: nothing detected
  110. Checking `rexedcs'... not found
  111. Checking `sniffer'... eth0: not promisc and no PF_PACKET sockets
  112. Checking `w55808'... not infected
  113. Checking `wted'... chkwtmp: nothing deleted
  114. Checking `scalper'... not infected
  115. Checking `slapper'... not infected
  116. Checking `z2'... chklastlog: nothing deleted
  117. Checking `chkutmp'...  The tty of the following user process(es) were not found
  118.  in /var/run/utmp !
  119. ! RUID          PID TTY    CMD
  120. ! root         2635 tty1   /sbin/mingetty tty1
  121. ! root         2636 tty2   /sbin/mingetty tty2
  122. ! root         2648 tty4   /sbin/mingetty tty4
  123. ! root         2649 tty5   /sbin/mingetty tty5
  124. ! root         2650 tty6   /sbin/mingetty tty6
  125. chkutmp: nothing deleted
  126. [root@pipy screamboy]#