Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [ Rootkit Hunter version 1.3.8 ]
- [1;33mChecking system commands...[0;39m
- Performing 'strings' command checks
- Checking 'strings' command[31C[ [1;32mOK[0;39m ]
- Performing 'shared libraries' checks
- Checking for preloading variables[24C[ [1;32mNone found[0;39m ]
- Checking for preloaded libraries[25C[ [1;32mNone found[0;39m ]
- Checking LD_LIBRARY_PATH variable[24C[ [1;32mNot found[0;39m ]
- Performing file properties checks
- Checking for prerequisites[31C[ [1;31mWarning[0;39m ]
- /usr/local/bin/rkhunter[34C[ [1;32mOK[0;39m ]
- /usr/sbin/adduser[40C[ [1;31mWarning[0;39m ]
- /usr/sbin/chroot[41C[ [1;32mOK[0;39m ]
- /usr/sbin/cron[43C[ [1;32mOK[0;39m ]
- /usr/sbin/groupadd[39C[ [1;32mOK[0;39m ]
- /usr/sbin/groupdel[39C[ [1;32mOK[0;39m ]
- /usr/sbin/groupmod[39C[ [1;32mOK[0;39m ]
- /usr/sbin/grpck[42C[ [1;32mOK[0;39m ]
- /usr/sbin/nologin[40C[ [1;32mOK[0;39m ]
- /usr/sbin/pwck[43C[ [1;32mOK[0;39m ]
- /usr/sbin/tcpd[43C[ [1;32mOK[0;39m ]
- /usr/sbin/useradd[40C[ [1;32mOK[0;39m ]
- /usr/sbin/userdel[40C[ [1;32mOK[0;39m ]
- /usr/sbin/usermod[40C[ [1;32mOK[0;39m ]
- /usr/sbin/vipw[43C[ [1;32mOK[0;39m ]
- /usr/sbin/xinetd[41C[ [1;32mOK[0;39m ]
- /usr/bin/awk[45C[ [1;32mOK[0;39m ]
- /usr/bin/basename[40C[ [1;32mOK[0;39m ]
- /usr/bin/chattr[42C[ [1;32mOK[0;39m ]
- /usr/bin/curl[44C[ [1;32mOK[0;39m ]
- /usr/bin/cut[45C[ [1;32mOK[0;39m ]
- /usr/bin/diff[44C[ [1;32mOK[0;39m ]
- /usr/bin/dirname[41C[ [1;32mOK[0;39m ]
- /usr/bin/dpkg[44C[ [1;32mOK[0;39m ]
- /usr/bin/dpkg-query[38C[ [1;32mOK[0;39m ]
- /usr/bin/du[46C[ [1;32mOK[0;39m ]
- /usr/bin/env[45C[ [1;32mOK[0;39m ]
- /usr/bin/file[44C[ [1;32mOK[0;39m ]
- /usr/bin/find[44C[ [1;31mWarning[0;39m ]
- /usr/bin/GET[45C[ [1;32mOK[0;39m ]
- /usr/bin/groups[42C[ [1;31mWarning[0;39m ]
- /usr/bin/head[44C[ [1;32mOK[0;39m ]
- /usr/bin/id[46C[ [1;32mOK[0;39m ]
- /usr/bin/killall[41C[ [1;32mOK[0;39m ]
- /usr/bin/last[44C[ [1;32mOK[0;39m ]
- /usr/bin/lastlog[41C[ [1;32mOK[0;39m ]
- /usr/bin/ldd[45C[ [1;31mWarning[0;39m ]
- /usr/bin/less[44C[ [1;32mOK[0;39m ]
- /usr/bin/locate[42C[ [1;32mOK[0;39m ]
- /usr/bin/logger[42C[ [1;32mOK[0;39m ]
- /usr/bin/lsattr[42C[ [1;32mOK[0;39m ]
- /usr/bin/lsof[44C[ [1;32mOK[0;39m ]
- /usr/bin/lynx[44C[ [1;32mOK[0;39m ]
- /usr/bin/mail[44C[ [1;32mOK[0;39m ]
- /usr/bin/md5sum[42C[ [1;31mWarning[0;39m ]
- /usr/bin/newgrp[42C[ [1;32mOK[0;39m ]
- /usr/bin/passwd[42C[ [1;32mOK[0;39m ]
- /usr/bin/perl[44C[ [1;32mOK[0;39m ]
- /usr/bin/pgrep[43C[ [1;32mOK[0;39m ]
- /usr/bin/pstree[42C[ [1;31mWarning[0;39m ]
- /usr/bin/runcon[42C[ [1;32mOK[0;39m ]
- /usr/bin/sha1sum[41C[ [1;32mOK[0;39m ]
- /usr/bin/sha224sum[39C[ [1;32mOK[0;39m ]
- /usr/bin/sha256sum[39C[ [1;32mOK[0;39m ]
- /usr/bin/sha384sum[39C[ [1;32mOK[0;39m ]
- /usr/bin/sha512sum[39C[ [1;32mOK[0;39m ]
- /usr/bin/size[44C[ [1;32mOK[0;39m ]
- /usr/bin/slocate[41C[ [1;31mWarning[0;39m ]
- /usr/bin/sort[44C[ [1;32mOK[0;39m ]
- /usr/bin/stat[44C[ [1;32mOK[0;39m ]
- /usr/bin/strings[41C[ [1;32mOK[0;39m ]
- /usr/bin/sudo[44C[ [1;32mOK[0;39m ]
- /usr/bin/tail[44C[ [1;32mOK[0;39m ]
- /usr/bin/test[44C[ [1;32mOK[0;39m ]
- /usr/bin/top[45C[ [1;31mWarning[0;39m ]
- /usr/bin/touch[43C[ [1;32mOK[0;39m ]
- /usr/bin/tr[46C[ [1;32mOK[0;39m ]
- /usr/bin/uniq[44C[ [1;32mOK[0;39m ]
- /usr/bin/users[43C[ [1;32mOK[0;39m ]
- /usr/bin/vmstat[42C[ [1;32mOK[0;39m ]
- /usr/bin/w[47C[ [1;32mOK[0;39m ]
- /usr/bin/watch[43C[ [1;32mOK[0;39m ]
- /usr/bin/wc[46C[ [1;32mOK[0;39m ]
- /usr/bin/wget[44C[ [1;32mOK[0;39m ]
- /usr/bin/whatis[42C[ [1;32mOK[0;39m ]
- /usr/bin/whereis[41C[ [1;32mOK[0;39m ]
- /usr/bin/which[43C[ [1;32mOK[0;39m ]
- /usr/bin/who[45C[ [1;32mOK[0;39m ]
- /usr/bin/whoami[42C[ [1;32mOK[0;39m ]
- /usr/bin/gawk[44C[ [1;32mOK[0;39m ]
- /usr/bin/lwp-request[37C[ [1;31mWarning[0;39m ]
- /usr/bin/lynx.stable[37C[ [1;32mOK[0;39m ]
- /usr/bin/bsd-mailx[39C[ [1;32mOK[0;39m ]
- /usr/bin/w.procps[40C[ [1;32mOK[0;39m ]
- /usr/bin/tcsh[44C[ [1;32mOK[0;39m ]
- /sbin/depmod[45C[ [1;32mOK[0;39m ]
- /sbin/fsck[47C[ [1;32mOK[0;39m ]
- /sbin/ifconfig[43C[ [1;31mWarning[0;39m ]
- /sbin/ifdown[45C[ [1;32mOK[0;39m ]
- /sbin/ifup[47C[ [1;32mOK[0;39m ]
- /sbin/init[47C[ [1;32mOK[0;39m ]
- /sbin/insmod[45C[ [1;32mOK[0;39m ]
- /sbin/ip[49C[ [1;32mOK[0;39m ]
- /sbin/lsmod[46C[ [1;32mOK[0;39m ]
- /sbin/modinfo[44C[ [1;32mOK[0;39m ]
- /sbin/modprobe[43C[ [1;32mOK[0;39m ]
- /sbin/rmmod[46C[ [1;32mOK[0;39m ]
- /sbin/route[46C[ [1;32mOK[0;39m ]
- /sbin/runlevel[43C[ [1;32mOK[0;39m ]
- /sbin/sulogin[44C[ [1;32mOK[0;39m ]
- /sbin/sysctl[45C[ [1;32mOK[0;39m ]
- /sbin/syslogd[44C[ [1;32mOK[0;39m ]
- /bin/bash[48C[ [1;32mOK[0;39m ]
- /bin/cat[49C[ [1;32mOK[0;39m ]
- /bin/chmod[47C[ [1;32mOK[0;39m ]
- /bin/chown[47C[ [1;32mOK[0;39m ]
- /bin/cp[50C[ [1;32mOK[0;39m ]
- /bin/csh[49C[ [1;32mOK[0;39m ]
- /bin/date[48C[ [1;32mOK[0;39m ]
- /bin/df[50C[ [1;32mOK[0;39m ]
- /bin/dmesg[47C[ [1;32mOK[0;39m ]
- /bin/echo[48C[ [1;32mOK[0;39m ]
- /bin/ed[50C[ [1;32mOK[0;39m ]
- /bin/egrep[47C[ [1;32mOK[0;39m ]
- /bin/fgrep[47C[ [1;32mOK[0;39m ]
- /bin/fuser[47C[ [1;32mOK[0;39m ]
- /bin/grep[48C[ [1;32mOK[0;39m ]
- /bin/ip[50C[ [1;32mOK[0;39m ]
- /bin/kill[48C[ [1;32mOK[0;39m ]
- /bin/login[47C[ [1;32mOK[0;39m ]
- /bin/ls[50C[ [1;31mWarning[0;39m ]
- /bin/lsmod[47C[ [1;32mOK[0;39m ]
- /bin/mktemp[46C[ [1;32mOK[0;39m ]
- /bin/more[48C[ [1;32mOK[0;39m ]
- /bin/mount[47C[ [1;32mOK[0;39m ]
- /bin/mv[50C[ [1;32mOK[0;39m ]
- /bin/netstat[45C[ [1;31mWarning[0;39m ]
- /bin/ps[50C[ [1;31mWarning[0;39m ]
- /bin/pwd[49C[ [1;32mOK[0;39m ]
- /bin/readlink[44C[ [1;32mOK[0;39m ]
- /bin/sed[49C[ [1;32mOK[0;39m ]
- /bin/sh[50C[ [1;32mOK[0;39m ]
- /bin/su[50C[ [1;32mOK[0;39m ]
- /bin/touch[47C[ [1;32mOK[0;39m ]
- /bin/uname[47C[ [1;32mOK[0;39m ]
- /bin/which[47C[ [1;31mWarning[0;39m ]
- /bin/tcsh[48C[ [1;32mOK[0;39m ]
- /bin/dash[48C[ [1;32mOK[0;39m ]
- /etc/rkhunter.conf[39C[ [1;32mOK[0;39m ]
- [Press <ENTER> to continue]
- Checking for rootkits...
- Performing check of known rootkit files and directories
- 55808 Trojan - Variant A [ Not found ]
- ADM Worm [ Not found ]
- AjaKit Rootkit [ Not found ]
- Adore Rootkit [ Not found ]
- aPa Kit [ Not found ]
- Apache Worm [ Not found ]
- Ambient (ark) Rootkit [ Not found ]
- Balaur Rootkit [ Not found ]
- BeastKit Rootkit [ Not found ]
- beX2 Rootkit [ Not found ]
- BOBKit Rootkit [ Not found ]
- cb Rootkit [ Warning ]
- CiNIK Worm (Slapper.B variant) [ Not found ]
- Danny-Boy's Abuse Kit [ Not found ]
- Devil RootKit [ Not found ]
- Dica-Kit Rootkit [ Not found ]
- Dreams Rootkit [ Not found ]
- Duarawkz Rootkit [ Not found ]
- Enye LKM [ Not found ]
- Flea Linux Rootkit [ Not found ]
- FreeBSD Rootkit [ Not found ]
- Fu Rootkit [ Not found ]
- Fuck`it Rootkit [ Not found ]
- GasKit Rootkit [ Not found ]
- Heroin LKM [ Not found ]
- HjC Kit [ Not found ]
- ignoKit Rootkit [ Not found ]
- iLLogiC Rootkit [ Not found ]
- IntoXonia-NG Rootkit [ Not found ]
- Irix Rootkit [ Not found ]
- Kitko Rootkit [ Not found ]
- Knark Rootkit [ Not found ]
- ld-linuxv.so Rootkit [ Not found ]
- Li0n Worm [ Not found ]
- Lockit / LJK2 Rootkit [ Not found ]
- Mood-NT Rootkit [ Not found ]
- MRK Rootkit [ Not found ]
- Ni0 Rootkit [ Not found ]
- Ohhara Rootkit [ Not found ]
- Optic Kit (Tux) Worm [ Not found ]
- Oz Rootkit [ Not found ]
- Phalanx Rootkit [ Not found ]
- Phalanx2 Rootkit [ Not found ]
- Phalanx2 Rootkit (extended tests) [ Not found ]
- Portacelo Rootkit [ Not found ]
- R3dstorm Toolkit [ Not found ]
- RH-Sharpe's Rootkit [ Not found ]
- RSHA's Rootkit [ Not found ]
- Scalper Worm [ Not found ]
- Sebek LKM [ Not found ]
- Shutdown Rootkit [ Not found ]
- SHV4 Rootkit [ Warning ]
- SHV5 Rootkit [ Warning ]
- Sin Rootkit [ Not found ]
- Slapper Worm [ Not found ]
- Sneakin Rootkit [ Not found ]
- 'Spanish' Rootkit [ Not found ]
- Suckit Rootkit [ Not found ]
- SunOS Rootkit [ Not found ]
- SunOS / NSDAP Rootkit [ Not found ]
- Superkit Rootkit [ Not found ]
- TBD (Telnet BackDoor) [ Not found ]
- TeLeKiT Rootkit [ Not found ]
- T0rn Rootkit [ Not found ]
- trNkit Rootkit [ Not found ]
- Trojanit Kit [ Not found ]
- Tuxtendo Rootkit [ Not found ]
- URK Rootkit [ Not found ]
- Vampire Rootkit [ Not found ]
- VcKit Rootkit [ Not found ]
- Volc Rootkit [ Not found ]
- Xzibit Rootkit [ Not found ]
- X-Org SunOS Rootkit [ Not found ]
- zaRwT.KiT Rootkit [ Not found ]
- ZK Rootkit [ Not found ]
- Performing additional rootkit checks
- Suckit Rookit additional checks [ OK ]
- Checking for possible rootkit files and directories [ None found ]
- Checking for possible rootkit strings [ Warning ]
- Performing malware checks
- Checking running processes for suspicious files [ None found ]
- Checking for login backdoors [ None found ]
- Checking for suspicious directories [ None found ]
- Checking for sniffer log files [ None found ]
- Performing trojan specific checks
- Checking for enabled inetd services [ OK ]
- Checking for enabled xinetd services [ None found ]
- Checking for Apache backdoor [ Not found ]
- Performing Linux specific checks
- Checking loaded kernel modules [ Warning ]
- Checking kernel module names [ OK ]
- [Press <ENTER> to continue]
- Checking the network...
- Performing checks on the network ports
- Checking for backdoor ports [ Warning ]
- Performing checks on the network interfaces
- Checking for promiscuous interfaces [ None found ]
- Checking the local host...
- Performing system boot checks
- Checking for local host name [ Found ]
- Checking for system startup files [ Found ]
- Checking system startup files for malware [ None found ]
- Performing group and account checks
- Checking for passwd file [ Found ]
- Checking for root equivalent (UID 0) accounts [ Warning ]
- Checking for passwordless accounts [ None found ]
- Checking for passwd file changes [ None found ]
- Checking for group file changes [ None found ]
- Checking root account shell history files [ OK ]
- Performing system configuration file checks
- Checking for SSH configuration file [ Found ]
- Checking if SSH root access is allowed [ Warning ]
- Checking if SSH protocol v1 is allowed [ Not allowed ]
- Unknown HZ value! (380) Assume 100.
- Internal error!
- Internal error!
- Checking for running syslog daemon [ Found ]
- Checking for syslog configuration file [ Found ]
- Checking if syslog remote logging is allowed [ Not allowed ]
- Performing filesystem checks
- Checking /dev for suspicious file types [ None found ]
- Checking for hidden files and directories [ Warning ]
- [Press <ENTER> to continue]
- Checking application versions...
- Checking version of Exim MTA [ Warning ]
- Checking version of GnuPG [ Warning ]
- Checking version of Bind DNS [ OK ]
- Checking version of OpenSSL [ Warning ]
- Checking version of PHP [ Warning ]
- Checking version of Procmail MTA [ OK ]
- Checking version of OpenSSH [ Warning ]
- System checks summary
- =====================
- File properties checks...
- Required commands check failed
- Files checked: 139
- Suspect files: 14
- Rootkit checks...
- Rootkits checked : 254
- Possible rootkits: 3
- Rootkit names : cb Rootkit, SHV4 Rootkit, SHV5 Rootkit
- Applications checks...
- Applications checked: 7
- Suspect applications: 5
- The system checks took: 2 minutes and 7 seconds
- All results have been written to the log file (/var/log/rkhunter.log)
- One or more warnings have been found while checking the system.
- Please check the log file (/var/log/rkhunter.log)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement