Can't clean install

Do you have an external hard drive or another Mac you could use as one? It would isolate if it's just the hard drive ( and what's on it ) or some other hardware in your Mac that could be affecting it.
Also, where are those files located on your HD?
 
... After a supposed clean install, I have folders and files that I don't think come with OS X.
/usr/bin 122.4 MB
/usr/lib 72.3 MB
/usr/libexec 32 MB
/usr/sbin 67 MB
/usr/share 203.4 MB
/usr/standalone 468 KB
...

Those folders are all normal parts of an OS X install - just normally hidden.
 
Right, but it's the size and what's in the folders that concerns me. When I compare what's in them to what's on my install CD, I have many many more files.
For example, on the cd, /usr/bin is 8 MB, mine is 122.4 MB. A huge difference!
CD's /usr/bin has arch, atlookup, etc.
Mine has a2p, aclocal, etc.
And all of this wouldn't have ever become a concern if I could do the simplest thing like empty the trash, delete the cache, change firewall settings, or turn off bluetooth.
Firewall rules are--
65535 104150 44073325 allow ip from any to any

And no, I don't have an external drive or another mac.
 
You don't have a valid reason for assuming that /usr/bin would be the same on the installer CD, compared to your hard drive installed /usr/bin/
The installer disk does not need to have a full use of all the software. It's main purpose is to have a few utilities, and install your system. It has a very minimal GUI, and most OS X system services are not necessary.

My usr/bin is about 180MB, with over 700 files and folders. I don't find anything unusual about that.
 
Mazzy - have you ever: booted to your installer disk, open Disk Utility, click on your hard drive, click on the Partition tab, and change the Partition Scheme to something else (say, 5 volumes) just to choose something different, then click the Partition button? This is _not_ the same as the Erase tab. It's important in your case that you do _exactly_ these steps with the Partition tab, and changing the Volume Scheme. The only way to get there is choosing the device, and not just the volume.
I could be wrong, but I think you have only been erasing the volume, and not re-doing the partitions.
After partitioning, return to the Erase tab, and erase the drive, which will cause the partitions to be removed, and you will get a single partition after a simple erase. Then, continue with a reinstall of your system.
 
Yes, I've done exactly as you've said. I'm not electing just the volume. I've selected to erase the device and still the volume will popup after erasing the entire device. I know yall think I'm nuts, but I've done all of this. I cannot clean this.

And yes, I understand that after adding additional programs that the size of my /usr/lib and other folders will be different sizes. But, remember, I'm relating all of this to what is on my drive immediately after a clean install.

Should these folders be present in /usr/share/ after a clean install?
aclocal
aclocal- 1.6
automake- 1.6
calendar
cracklib
cups
curl
dict
doc
emacs
enscript
file
groff
httpd
icu
info
libiodbc
local
man
misc
openldap
ri
screen
skel
snmp
ssh.bin
swat
tabset
tcsh
terminfo
texi2html
texinfo
vim
wx
zoneinfo
zsh
 
Yes, I've done exactly as you've said. I'm not electing just the volume. I've selected to erase the device and still the volume will popup after erasing the entire device. I know yall think I'm nuts, but I've done all of this. I cannot clean this.

And yes, I understand that after adding additional programs that the size of my /usr/lib and other folders will be different sizes. But, remember, I'm relating all of this to what is on my drive immediately after a clean install.

Should these folders be present in /usr/share/ after a clean install?
...

I was waiting for you to use the word 'Partition' after I asked you if you tried the Partition tab/Volume Scheme. Erase is a different tab, and may leave you with the result that you have been describing. Please come back after you have tried the partition tab. Make sure that you change the _erase_ options first, so you don't start the 35-pass write-zeroes. One pass will tell you, and no need to waste time with more passes. If you have actually already done that (different Volume Scheme), then let us know.

I don't have a completely new, clean install to check, but I have all but about 5 of those on your list. They seem to relate to developer software, I never install the default xtools, for example. Xtools would add other libraries to your system. I don't see even one unusual item in that list that you posted.
I think you have a big distraction in those hidden folders, and you need to look in a different direction.
 
Yes, I've tried to repartion with exactly the same results. I don't install Xcode. I don't have an Epson printer and I don't install ANY printer drivers from the CD, yet I can't delete the Epson printer files.

And it may appear that I'm distracted with those hidden folders, but I'm just looking for answers to the other questions I've asked.....
Why can't I empty the trash, delete the cache, change firewall settings, or turn off bluetooth?
 
If this sounds redundant, I apologize. I would try a partition so you have 2 separate volumes, and install OS X on both. Start up each one and compare files, problems, etc. If both still don't work, there has to be a problem with the drive. It sounds like the drive reads and or writes at random. It won't delete files, remember or allow changes, etc. I know the hardware tests came out ok, but it could be wrong.
By the way, I don't you're crazy, just extremely frustrated... ;)
 
Thanks for the advice and the sympathetic ear! I really am frustrated, and about half crazy! I will give this a try over the weekend. I'll let you know the results.
 
I did the install on 2 partitions with the same results. I tried partitioning with 2, 3, 4, 5 partitions, and each time there are 2 folders automatically installed into each partition. I don't know what's on those 2 folders, but I think it's the 2 automount folders. One is servers, the other is static. The created dates are January 1, 1904 00:00:00. After my "clean" install, In /System/Library/Keychains/ I still have the same X509Certificates and X509Anchors. The created dates are, the same as the install dates. Opened in notepad, they expired in 1998 and 1999. I could write a book on all of the errors. I have a billion references in files to Windows, import old prefs, CVS version control, self-install, autoload, etc. I have no idea what is running my system, but I'm certain it's not purely os x. I ran rootkit hunter last night and got several warning errors. I apparently shut something down for the moment, because I normally can't get rkhunter, or virus scans to run. Today it won't even load. I get an error message saying "command not found". I'll post the log file and hopefully someone can tell me where to go from here.

Thanks

[03:04:55] Checking configuration file and command-line options...
[03:04:55] Info: Detected operating system is 'Darwin'
[03:04:55] Info: Uname output is 'Darwin roxys-computer.local 8.11.1 Darwin Kernel Version 8.11.1: Wed Oct 10 18:23:28 PDT 2007; root:xnu-792.25.20~1/RELEASE_I386 i386 i386'
[03:04:55] Info: Command line is ./rkhunter --check
[03:04:55] Info: Environment shell is /bin/bash; rkhunter is using sh
[03:04:55] Info: Using configuration file '/etc/rkhunter.conf'
[03:04:55] Info: Installation directory is '/usr/local'
[03:04:55] Info: Using language 'en'
[03:04:55] Info: Using '/var/lib/rkhunter/db' as the database directory
[03:04:55] Info: Using '/usr/local/lib/rkhunter/scripts' as the support script directory
[03:04:55] Info: Using '/bin /sbin /usr/bin /usr/sbin /bin /usr/bin /sbin /usr/sbin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec' as the command directories
[03:04:55] Info: Using '/' as the root directory
[03:04:55] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[03:04:55] Info: No mail-on-warning address configured
[03:04:55] Info: X will automatically be detected
[03:04:55] Info: Found the 'diff' command: /usr/bin/diff
[03:04:55] Info: Found the 'file' command: /usr/bin/file
[03:04:56] Info: Found the 'find' command: /usr/bin/find
[03:04:56] Info: Found the 'ifconfig' command: /sbin/ifconfig
[03:04:56] Info: Unable to find the 'ip' command
[03:04:56] Info: Unable to find the 'ldd' command
[03:04:56] Info: Unable to find the 'lsattr' command
[03:04:56] Info: Unable to find the 'lsmod' command
[03:04:56] Info: Found the 'lsof' command: /usr/sbin/lsof
[03:04:56] Info: Found the 'mktemp' command: /usr/bin/mktemp
[03:04:56] Info: Found the 'netstat' command: /usr/sbin/netstat
[03:04:56] Info: Found the 'perl' command: /usr/bin/perl
[03:04:56] Info: Found the 'ps' command: /bin/ps
[03:04:56] Info: Found the 'pwd' command: /bin/pwd
[03:04:56] Info: Found the 'readlink' command: /usr/local/lib/rkhunter/scripts/readlink.sh
[03:04:56] Info: Found the 'sort' command: /usr/bin/sort
[03:04:56] Info: Found the 'stat' command: /usr/bin/stat
[03:04:56] Info: Found the 'strings' command: /usr/bin/strings
[03:04:56] Info: Found the 'uniq' command: /usr/bin/uniq
[03:04:57] Info: System is not using prelinking
[03:04:57] Info: Using the perl SHA1 module for the file hash checks
[03:04:57] Info: The hash function field index is set to 1
[03:04:57] Info: No package manager specified: using hash function '/usr/bin/perl /usr/local/lib/rkhunter/scripts/filehashsha1.pl'
[03:04:57] Info: Previous file attributes were stored
[03:04:57] Info: Enabled tests are: all
[03:04:57] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps
[03:04:57] Info: All ksyms and kallsyms checks will be skipped - neither file is present on the system.
[03:04:57]
[03:04:57] Starting system checks...
[03:04:57]
[03:04:57] Checking system commands...
[03:04:57] Info: Starting test name 'system_commands'
[03:04:57]
[03:04:57] Performing 'strings' command checks
[03:04:57] Info: Starting test name 'strings'
[03:04:57] Scanning for string /usr/sbin/ntpsx [ OK ]
[03:04:57] Scanning for string /usr/lib/.../ls [ OK ]
[03:04:58] Scanning for string /usr/lib/.../netstat [ OK ]
[03:04:58] Scanning for string /usr/lib/.../lsof [ OK ]
[03:04:58] Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[03:04:58] Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[03:04:58] Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[03:04:58] Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[03:04:58] Scanning for string /usr/lib/.../uconf.inv [ OK ]
[03:04:58] Scanning for string /usr/lib/.../psr [ OK ]
[03:04:58] Scanning for string /usr/lib/.../find [ OK ]
[03:04:58] Scanning for string /usr/lib/.../pstree [ OK ]
[03:04:59] Scanning for string /usr/lib/.../slocate [ OK ]
[03:04:59] Scanning for string /usr/lib/.../du [ OK ]
[03:04:59] Scanning for string /usr/lib/.../top [ OK ]
[03:04:59] Scanning for string /usr/lib/... [ OK ]
[03:04:59] Scanning for string /usr/lib/.../bkit-ssh [ OK ]
[03:04:59] Scanning for string /usr/lib/.bkit- [ OK ]
[03:04:59] Scanning for string /tmp/.bkp [ OK ]
[03:04:59] Scanning for string /tmp/.cinik [ OK ]
[03:04:59] Scanning for string /tmp/.font-unix/.cinik [ OK ]
[03:05:00] Scanning for string /lib/.sso [ OK ]
[03:05:00] Scanning for string /lib/.so [ OK ]
[03:05:00] Scanning for string /var/run/...dica/clean [ OK ]
[03:05:00] Scanning for string /var/run/...dica/xl [ OK ]
[03:05:00] Scanning for string /var/run/...dica/xdr [ OK ]
[03:05:00] Scanning for string /var/run/...dica/psg [ OK ]
[03:05:00] Scanning for string /var/run/...dica/secure [ OK ]
[03:05:00] Scanning for string /var/run/...dica/rdx [ OK ]
[03:05:00] Scanning for string /var/run/...dica/va [ OK ]
[03:05:01] Scanning for string /var/run/...dica/cl.sh [ OK ]
[03:05:01] Scanning for string /usr/bin/.etc [ OK ]
[03:05:01] Scanning for string /usr/lib/.fx/sched_host.2 [ OK ]
[03:05:01] Scanning for string /usr/lib/.fx/random_d.2 [ OK ]
[03:05:01] Scanning for string /usr/lib/.fx/set_pid.2 [ OK ]
[03:05:01] Scanning for string /usr/lib/.fx/cons.saver [ OK ]
[03:05:01] Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[03:05:01] Scanning for string /bin/sysback [ OK ]
[03:05:01] Scanning for string /usr/local/bin/sysback [ OK ]
[03:05:01] Scanning for string /usr/lib/.tbd [ OK ]
[03:05:02] Scanning for string /dev/.lib/lib/lib/t0rns [ OK ]
[03:05:02] Scanning for string /dev/.lib/lib/lib/du [ OK ]
[03:05:02] Scanning for string /dev/.lib/lib/lib/ls [ OK ]
[03:05:02] Scanning for string /dev/.lib/lib/lib/t0rnsb [ OK ]
[03:05:02] Scanning for string /dev/.lib/lib/lib/ps [ OK ]
[03:05:02] Scanning for string /dev/.lib/lib/lib/t0rnp [ OK ]
[03:05:02] Scanning for string /dev/.lib/lib/lib/find [ OK ]
[03:05:02] Scanning for string /dev/.lib/lib/lib/ifconfig [ OK ]
[03:05:02] Scanning for string /dev/.lib/lib/lib/pg [ OK ]
[03:05:03] Scanning for string /dev/.lib/lib/lib/ssh.tgz [ OK ]
[03:05:03] Scanning for string /dev/.lib/lib/lib/top [ OK ]
[03:05:03] Scanning for string /dev/.lib/lib/lib/sz [ OK ]
[03:05:03] Scanning for string /dev/.lib/lib/lib/login [ OK ]
[03:05:03] Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[03:05:03] Scanning for string /dev/.lib/lib/lib/1i0n.sh [ OK ]
[03:05:03] Scanning for string /dev/.lib/lib/lib/pstree [ OK ]
[03:05:03] Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[03:05:03] Scanning for string /dev/.lib/lib/lib/mjy [ OK ]
[03:05:03] Scanning for string /dev/.lib/lib/lib/sush [ OK ]
[03:05:04] Scanning for string /dev/.lib/lib/lib/tfn [ OK ]
[03:05:04] Scanning for string /dev/.lib/lib/lib/name [ OK ]
[03:05:04] Scanning for string /dev/.lib/lib/lib/getip.sh [ OK ]
[03:05:04] Scanning for string /usr/info/.torn/sh* [ OK ]
[03:05:04] Scanning for string /usr/src/.puta/.1addr [ OK ]
[03:05:04] Scanning for string /usr/src/.puta/.1file [ OK ]
[03:05:04] Scanning for string /usr/src/.puta/.1proc [ OK ]
[03:05:04] Scanning for string /usr/src/.puta/.1logz [ OK ]
[03:05:04] Scanning for string /usr/info/.t0rn [ OK ]
[03:05:05] Scanning for string /dev/.lib [ OK ]
[03:05:05] Scanning for string /dev/.lib/lib [ OK ]
[03:05:05] Scanning for string /dev/.lib/lib/lib [ OK ]
[03:05:05] Scanning for string /dev/.lib/lib/lib/dev [ OK ]
[03:05:05] Scanning for string /dev/.lib/lib/scan [ OK ]
[03:05:05] Scanning for string /usr/src/.puta [ OK ]
[03:05:05] Scanning for string /usr/man/man1/man1 [ OK ]
[03:05:05] Scanning for string /usr/man/man1/man1/lib [ OK ]
[03:05:05] Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[03:05:05] Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[03:05:06]
[03:05:06] Performing 'shared libraries' checks
[03:05:06] Info: Starting test name 'shared_libs'
[03:05:06] Checking for preloading variables [ None found ]
[03:05:06] Checking for preload file [ Not found ]
[03:05:06] Info: Starting test name 'shared_libs_path'
[03:05:06] Checking LD_LIBRARY_PATH variable [ Skipped ]
[03:05:06] Info: Unable to find the 'ldd' command
[03:05:06]
[03:05:06] Performing file properties checks
[03:05:06] Info: Starting test name 'properties'
[03:05:06] Info: Skipping all immutable-bit checks. This check is only available for Linux systems.
[03:05:06] Warning: Checking for prerequisites [ Warning ]
[03:05:07] The file of stored file properties (rkhunter.dat) does not exist, and so must be created. To do this type in 'rkhunter --propupd'.
[03:05:07]
[03:05:07] Warning: WARNING! It is the users responsibility to ensure that when the '--propupd' option
is used, all the files on their system are known to be genuine, and installed from a
reliable source. The rkhunter '--check' option will compare the current file properties
against previously stored values, and report if any values differ. However, rkhunter
cannot determine what has caused the change, that is for the user to do.
[03:05:07] /bin/bash [ OK ]
[03:05:07] /bin/cat [ OK ]
[03:05:07] /bin/chmod [ OK ]
[03:05:07] /bin/cp [ OK ]
[03:05:08] /bin/csh [ OK ]
[03:05:08] /bin/date [ OK ]
[03:05:08] /bin/df [ OK ]
[03:05:08] /bin/echo [ OK ]
[03:05:08] /bin/ed [ OK ]
[03:05:08] /bin/kill [ OK ]
[03:05:08] /bin/ls [ OK ]
[03:05:09] /bin/mv [ OK ]
[03:05:09] /bin/ps [ OK ]
[03:05:09] /bin/pwd [ OK ]
[03:05:09] /bin/sh [ OK ]
[03:05:09] /bin/test [ OK ]
[03:05:09] /usr/bin/awk [ OK ]
[03:05:10] /usr/bin/basename [ OK ]
[03:05:10] /usr/bin/curl [ OK ]
[03:05:10] /usr/bin/cut [ OK ]
[03:05:10] /usr/bin/diff [ OK ]
[03:05:10] /usr/bin/dirname [ OK ]
[03:05:10] /usr/bin/du [ OK ]
[03:05:10] /usr/bin/egrep [ OK ]
[03:05:11] /usr/bin/env [ OK ]
[03:05:11] /usr/bin/fgrep [ OK ]
[03:05:11] /usr/bin/file [ OK ]
[03:05:11] /usr/bin/find [ OK ]
[03:05:11] /usr/bin/grep [ OK ]
[03:05:11] /usr/bin/groups [ OK ]
[03:05:12] /usr/bin/head [ OK ]
[03:05:12] /usr/bin/id [ OK ]
[03:05:12] /usr/bin/killall [ OK ]
[03:05:12] /usr/bin/last [ OK ]
[03:05:12] /usr/bin/less [ OK ]
[03:05:12] /usr/bin/locate [ OK ]
[03:05:12] /usr/bin/logger [ OK ]
[03:05:13] /usr/bin/login [ OK ]
[03:05:13] /usr/bin/mail [ OK ]
[03:05:13] /usr/bin/mktemp [ OK ]
[03:05:13] /usr/bin/more [ OK ]
[03:05:13] /usr/bin/passwd [ OK ]
[03:05:13] /usr/bin/perl [ OK ]
[03:05:14] /usr/bin/readlink [ OK ]
[03:05:14] /usr/bin/sed [ OK ]
[03:05:14] /usr/bin/sort [ OK ]
[03:05:14] /usr/bin/stat [ OK ]
[03:05:14] /usr/bin/strings [ OK ]
[03:05:14] /usr/bin/su [ OK ]
[03:05:14] /usr/bin/sudo [ OK ]
[03:05:15] /usr/bin/tail [ OK ]
[03:05:15] /usr/bin/top [ OK ]
[03:05:15] /usr/bin/touch [ OK ]
[03:05:15] /usr/bin/tr [ OK ]
[03:05:15] /usr/bin/uname [ OK ]
[03:05:15] /usr/bin/uniq [ OK ]
[03:05:15] /usr/bin/users [ OK ]
[03:05:16] /usr/bin/w [ OK ]
[03:05:16] /usr/bin/wc [ OK ]
[03:05:16] /usr/bin/whatis [ Warning ]
[03:05:16] Warning: The command '/usr/bin/whatis' has been replaced by a script: /usr/bin/whatis: Bourne shell script text executable
[03:05:16] /usr/bin/whereis [ OK ]
[03:05:16] /usr/bin/which [ Warning ]
[03:05:16] Warning: The command '/usr/bin/which' has been replaced by a script: /usr/bin/which: C shell script text executable
[03:05:16] /usr/bin/who [ OK ]
[03:05:17] /usr/bin/whoami [ OK ]
[03:05:17] /sbin/dmesg [ OK ]
[03:05:17] /sbin/ifconfig [ OK ]
[03:05:17] /sbin/md5 [ OK ]
[03:05:17] /sbin/mount [ OK ]
[03:05:17] /sbin/nologin [ Warning ]
[03:05:18] Warning: The command '/sbin/nologin' has been replaced by a script: /sbin/nologin: Bourne shell script text executable
[03:05:18] /usr/sbin/chown [ OK ]
[03:05:18] /usr/sbin/chroot [ OK ]
[03:05:18] /usr/sbin/cron [ OK ]
[03:05:18] /usr/sbin/lsof [ OK ]
[03:05:18] /usr/sbin/netstat [ OK ]
[03:05:18] /usr/sbin/sysctl [ OK ]
[03:05:19] /usr/sbin/syslogd [ OK ]
[03:05:19] /usr/sbin/vipw [ OK ]
[03:05:19] /usr/sbin/xinetd [ OK ]
[03:05:19] /usr/local/bin/rkhunter [ OK ]
[03:05:19] /usr/libexec/tcpd [ OK ]
[03:05:23]
[03:05:23] Checking for rootkits...
[03:05:23] Info: Starting test name 'rootkits'
[03:05:23]
[03:05:23] Performing check of known rootkit files and directories
[03:05:23] Info: Starting test name 'known_rkts'
[03:05:23]
[03:05:23] Checking for 55808 Trojan - Variant A...
[03:05:23] Checking for file '/tmp/.../r' [ Not found ]
[03:05:23] Checking for file '/tmp/.../a' [ Not found ]
[03:05:23] 55808 Trojan - Variant A [ Not found ]
[03:05:23]
[03:05:23] Checking for ADM Worm...
[03:05:23] Checking for string 'w0rm' [ Not found ]
[03:05:24] ADM Worm [ Not found ]
[03:05:24]
[03:05:24] Checking for AjaKit Rootkit...
[03:05:24] Checking for file '/dev/tux/.addr' [ Not found ]
[03:05:24] Checking for file '/dev/tux/.proc' [ Not found ]
[03:05:24] Checking for file '/dev/tux/.file' [ Not found ]
[03:05:24] Checking for file '/lib/.libgh-gh/cleaner' [ Not found ]
[03:05:24] Checking for file '/lib/.libgh-gh/Patch/patch' [ Not found ]
[03:05:24] Checking for file '/lib/.libgh-gh/sb0k' [ Not found ]
[03:05:24] Checking for directory '/dev/tux' [ Not found ]
[03:05:24] Checking for directory '/lib/.libgh-gh' [ Not found ]
[03:05:24] AjaKit Rootkit [ Not found ]
[03:05:25]
[03:05:25] Checking for aPa Kit...
[03:05:25] Checking for file '/usr/share/.aPa' [ Not found ]
[03:05:25] aPa Kit [ Not found ]
[03:05:25]
[03:05:25] Checking for Apache Worm...
[03:05:25] Checking for file '/bin/.log' [ Not found ]
[03:05:25] Apache Worm [ Not found ]
[03:05:25]
[03:05:25] Checking for Ambient (ark) Rootkit...
[03:05:25] Checking for file '/usr/lib/.ark?' [ Not found ]
[03:05:25] Checking for file '/dev/ptyxx/.log' [ Not found ]
[03:05:25] Checking for file '/dev/ptyxx/.file' [ Not found ]
[03:05:26] Checking for directory '/dev/ptyxx' [ Not found ]
[03:05:26] Ambient (ark) Rootkit [ Not found ]
[03:05:26]
[03:05:26] Checking for Balaur Rootkit...
[03:05:26] Checking for file '/usr/lib/liblog.o' [ Not found ]
[03:05:26] Checking for directory '/usr/lib/.kinetic' [ Not found ]
[03:05:26] Checking for directory '/usr/lib/.egcs' [ Not found ]
[03:05:26] Checking for directory '/usr/lib/.wormie' [ Not found ]
[03:05:26] Balaur Rootkit [ Not found ]
[03:05:26]
[03:05:26] Checking for BeastKit Rootkit...
[03:05:26] Checking for file '/usr/sbin/arobia' [ Not found ]
[03:05:27] Checking for file '/usr/sbin/idrun' [ Not found ]
[03:05:27] Checking for file '/usr/lib/elm/arobia/elm' [ Not found ]
[03:05:27] Checking for file '/usr/lib/elm/arobia/elm/hk' [ Not found ]
[03:05:27] Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
[03:05:27] Checking for file '/usr/lib/elm/arobia/elm/sc' [ Not found ]
[03:05:27] Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
[03:05:27] Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
[03:05:27] Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
[03:05:27] Checking for directory '/lib/ldd.so/bktools' [ Not found ]
[03:05:27] BeastKit Rootkit [ Not found ]
[03:05:28]
[03:05:28] Checking for beX2 Rootkit...
[03:05:28] Checking for directory '/usr/include/bex' [ Not found ]
[03:05:28] beX2 Rootkit [ Not found ]
[03:05:28]
[03:05:28] Checking for BOBKit Rootkit...
[03:05:28] Checking for file '/usr/sbin/ntpsx' [ Not found ]
[03:05:28] Checking for file '/usr/lib/.../ls' [ Not found ]
[03:05:28] Checking for file '/usr/lib/.../netstat' [ Not found ]
[03:05:28] Checking for file '/usr/lib/.../lsof' [ Not found ]
[03:05:28] Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
[03:05:28] Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
[03:05:28] Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
[03:05:29] Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
[03:05:29] Checking for file '/usr/lib/.../uconf.inv' [ Not found ]
[03:05:29] Checking for file '/usr/lib/.../psr' [ Not found ]
[03:05:29] Checking for file '/usr/lib/.../find' [ Not found ]
[03:05:29] Checking for file '/usr/lib/.../pstree' [ Not found ]
[03:05:29] Checking for file '/usr/lib/.../slocate' [ Not found ]
[03:05:29] Checking for file '/usr/lib/.../du' [ Not found ]
[03:05:29] Checking for file '/usr/lib/.../top' [ Not found ]
[03:05:29] Checking for directory '/usr/lib/...' [ Not found ]
[03:05:29] Checking for directory '/usr/lib/.../bkit-ssh' [ Not found ]
[03:05:30] Checking for directory '/usr/lib/.bkit-' [ Not found ]
[03:05:30] Checking for directory '/tmp/.bkp' [ Not found ]
[03:05:30] BOBKit Rootkit [ Not found ]
[03:05:30]
[03:05:30] Checking for CiNIK Worm (Slapper.B variant)...
[03:05:30] Checking for file '/tmp/.cinik' [ Not found ]
[03:05:31] Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
[03:05:31] CiNIK Worm (Slapper.B variant) [ Not found ]
[03:05:31]
[03:05:31] Checking for Danny-Boy's Abuse Kit...
[03:05:31] Checking for file '/dev/mdev' [ Not found ]
[03:05:31] Checking for file '/usr/lib/libX.a' [ Not found ]
[03:05:31] Danny-Boy's Abuse Kit [ Not found ]
[03:05:31]
[03:05:31] Checking for Devil RootKit...
[03:05:31] Checking for file '/var/lib/games/.src' [ Not found ]
[03:05:32] Checking for file '/dev/dsx' [ Not found ]
[03:05:32] Checking for file '/dev/caca' [ Not found ]
[03:05:32] Devil RootKit [ Not found ]
[03:05:32]
[03:05:32] Checking for Dica-Kit Rootkit...
[03:05:32] Checking for file '/lib/.sso' [ Not found ]
[03:05:32] Checking for file '/lib/.so' [ Not found ]
[03:05:32] Checking for file '/var/run/...dica/clean' [ Not found ]
[03:05:32] Checking for file '/var/run/...dica/xl' [ Not found ]
[03:05:32] Checking for file '/var/run/...dica/xdr' [ Not found ]
[03:05:32] Checking for file '/var/run/...dica/psg' [ Not found ]
[03:05:33] Checking for file '/var/run/...dica/secure' [ Not found ]
[03:05:33] Checking for file '/var/run/...dica/rdx' [ Not found ]
[03:05:33] Checking for file '/var/run/...dica/va' [ Not found ]
[03:05:33] Checking for file '/var/run/...dica/cl.sh' [ Not found ]
[03:05:33] Checking for file '/usr/bin/.etc' [ Not found ]
[03:05:33] Checking for directory '/var/run/...dica' [ Not found ]
[03:05:33] Checking for directory '/var/run/...dica/mh' [ Not found ]
[03:05:33] Checking for directory '/var/run/...dica/scan' [ Not found ]
[03:05:33] Dica-Kit Rootkit [ Not found ]
[03:05:33]
[03:05:33] Checking for Dreams Rootkit...
[03:05:33] Checking for file '/dev/ttyoa' [ Not found ]
[03:05:34] Checking for file '/dev/ttyof' [ Not found ]
[03:05:34] Checking for file '/dev/ttyop' [ Not found ]
[03:05:34] Checking for file '/usr/bin/sense' [ Not found ]
[03:05:34] Checking for file '/usr/bin/sl2' [ Not found ]
[03:05:34] Checking for file '/usr/bin/logclear' [ Not found ]
[03:05:34] Checking for file '/usr/bin/(swapd)' [ Not found ]
[03:05:34] Checking for file '/usr/bin/snfs' [ Not found ]
[03:05:34] Checking for file '/usr/lib/libsss' [ Not found ]
[03:05:34] Checking for directory '/dev/ida/.hpd' [ Not found ]
[03:05:34] Dreams Rootkit [ Not found ]
[03:05:35]
[03:05:35] Checking for Duarawkz Rootkit...
[03:05:35] Checking for file '/usr/bin/duarawkz/loginpass' [ Not found ]
[03:05:35] Checking for directory '/usr/bin/duarawkz' [ Not found ]
[03:05:35] Duarawkz Rootkit [ Not found ]
[03:05:35]
[03:05:35] Checking for Enye LKM...
[03:05:35] Checking for file '/etc/.enyelkmHIDE^IT.ko' [ Not found ]
[03:05:35] Enye LKM [ Not found ]
[03:05:35]
[03:05:35] Checking for Flea Linux Rootkit...
[03:05:35] Checking for file '/etc/ld.so.hash' [ Not found ]
[03:05:35] Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[03:05:36] Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[03:05:36] Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[03:05:36] Checking for file '/usr/bin/ssh2d' [ Not found ]
[03:05:36] Checking for file '/usr/lib/ldlibns.so' [ Not found ]
[03:05:36] Checking for file '/usr/lib/ldlibpst.so' [ Not found ]
[03:05:36] Checking for file '/usr/lib/ldlibdu.so' [ Not found ]
[03:05:36] Checking for file '/usr/lib/ldlibct.so' [ Not found ]
[03:05:36] Checking for directory '/lib/security/.config/ssh' [ Not found ]
[03:05:36] Checking for directory '/dev/..0' [ Not found ]
[03:05:36] Checking for directory '/dev/..0/backup' [ Not found ]
[03:05:37] Flea Linux Rootkit [ Not found ]
[03:05:37]
[03:05:37] Checking for FreeBSD Rootkit...
[03:05:37] Checking for file '/usr/lib/.fx/sched_host.2' [ Not found ]
[03:05:37] Checking for file '/usr/lib/.fx/random_d.2' [ Not found ]
[03:05:37] Checking for file '/usr/lib/.fx/set_pid.2' [ Not found ]
[03:05:37] Checking for file '/usr/lib/.fx/cons.saver' [ Not found ]
[03:05:37] Checking for file '/usr/lib/.fx/adore/adore/adore.ko' [ Not found ]
[03:05:37] Checking for file '/bin/sysback' [ Not found ]
[03:05:37] Checking for file '/usr/local/bin/sysback' [ Not found ]
[03:05:37] Checking for directory '/usr/lib/.fx' [ Not found ]
[03:05:38] Checking for directory '/usr/lib/.fx/adore' [ Not found ]
[03:05:38] FreeBSD Rootkit [ Not found ]
[03:05:38]
[03:05:38] Checking for Fuck`it Rootkit...
[03:05:38] Checking for file '/dev/proc/fuckit/hax0r' [ Not found ]
[03:05:38] Checking for file '/dev/proc/fuckit/hax0rshell' [ Not found ]
[03:05:38] Checking for file '/dev/proc/fuckit/config/lports' [ Not found ]
[03:05:38] Checking for file '/dev/proc/fuckit/config/rports' [ Not found ]
[03:05:38] Checking for file '/dev/proc/fuckit/config/rkconf' [ Not found ]
[03:05:38] Checking for file '/dev/proc/fuckit/config/password' [ Not found ]
[03:05:38] Checking for file '/dev/proc/fuckit/config/progs' [ Not found ]
[03:05:39] Checking for file '/dev/proc/system-bins/init' [ Not found ]
[03:05:39] Fuck`it Rootkit [ Not found ]
[03:05:39]
[03:05:39] Checking for GasKit Rootkit...
[03:05:39] Checking for file '/dev/dev/gaskit/sshd/sshdd' [ Not found ]
[03:05:39] Checking for directory '/dev/dev' [ Not found ]
[03:05:39] Checking for directory '/dev/dev/gaskit' [ Not found ]
[03:05:39] Checking for directory '/dev/dev/gaskit/sshd' [ Not found ]
[03:05:39] GasKit Rootkit [ Not found ]
[03:05:39]
[03:05:39] Checking for Heroin LKM...
[03:05:39] Checking for kernel symbol 'heroin' [ Skipped ]
[03:05:39] Heroin LKM [ Not found ]
[03:05:40]
[03:05:40] Checking for HjC Kit...
[03:05:40] Checking for directory '/dev/.hijackerz' [ Not found ]
[03:05:40] HjC Kit [ Not found ]
[03:05:40]
[03:05:40] Checking for ignoKit Rootkit...
[03:05:40] Checking for file '/lib/defs/p' [ Not found ]
[03:05:40] Checking for file '/lib/defs/q' [ Not found ]
[03:05:40] Checking for file '/lib/defs/r' [ Not found ]
[03:05:40] Checking for file '/lib/defs/s' [ Not found ]
[03:05:40] Checking for file '/lib/defs/t' [ Not found ]
[03:05:40] Checking for file '/usr/lib/defs/p' [ Not found ]
[03:05:40] Checking for file '/usr/lib/defs/q' [ Not found ]
[03:05:41] Checking for file '/usr/lib/defs/r' [ Not found ]
[03:05:41] Checking for file '/usr/lib/defs/s' [ Not found ]
[03:05:41] Checking for file '/usr/lib/defs/t' [ Not found ]
[03:05:41] Checking for file '/usr/lib/.libigno/pkunsec' [ Not found ]
[03:05:41] Checking for file '/usr/lib/.libigno/.igno/psybnc/psybnc' [ Not found ]
[03:05:41] Checking for directory '/usr/lib/.libigno' [ Not found ]
[03:05:41] Checking for directory '/usr/lib/.libigno/.igno' [ Not found ]
[03:05:41] ignoKit Rootkit [ Not found ]
[03:05:41]
[03:05:41] Checking for ImperalsS-FBRK Rootkit...
[03:05:41] Checking for directory '/dev/fd/.88' [ Not found ]
[03:05:42] Checking for directory '/dev/fd/.99' [ Not found ]
[03:05:42] ImperalsS-FBRK Rootkit [ Not found ]
[03:05:42]
[03:05:42] Checking for Irix Rootkit...
[03:05:42] Checking for directory '/dev/pts/01' [ Not found ]
[03:05:42] Checking for directory '/dev/pts/01/backup' [ Not found ]
[03:05:42] Checking for directory '/dev/pts/01/etc' [ Not found ]
[03:05:42] Checking for directory '/dev/pts/01/tmp' [ Not found ]
[03:05:42] Irix Rootkit [ Not found ]
[03:05:42]
[03:05:42] Checking for Kitko Rootkit...
[03:05:42] Checking for directory '/usr/src/redhat/SRPMS/...' [ Not found ]
[03:05:43] Kitko Rootkit [ Not found ]
[03:05:43]
[03:05:43] Checking for Knark Rootkit...
[03:05:43] Checking for file '/proc/knark/pids' [ Not found ]
[03:05:43] Checking for directory '/proc/knark' [ Not found ]
[03:05:43] Knark Rootkit [ Not found ]
[03:05:43]
[03:05:43] Checking for Li0n Worm...
[03:05:43] Checking for file '/bin/in.telnetd' [ Not found ]
[03:05:43] Checking for file '/bin/mjy' [ Not found ]
[03:05:43] Checking for file '/usr/man/man1/man1/lib/.lib/mjy' [ Not found ]
[03:05:43] Checking for file '/usr/man/man1/man1/lib/.lib/in.telnetd' [ Not found ]
[03:05:43] Checking for file '/usr/man/man1/man1/lib/.lib/.x' [ Not found ]
[03:05:44] Checking for file '/dev/.lib/lib/scan/1i0n.sh' [ Not found ]
[03:05:44] Checking for file '/dev/.lib/lib/scan/hack.sh' [ Not found ]
[03:05:44] Checking for file '/dev/.lib/lib/scan/bind' [ Not found ]
[03:05:44] Checking for file '/dev/.lib/lib/scan/randb' [ Not found ]
[03:05:44] Checking for file '/dev/.lib/lib/scan/scan.sh' [ Not found ]
[03:05:44] Checking for file '/dev/.lib/lib/scan/pscan' [ Not found ]
[03:05:44] Checking for file '/dev/.lib/lib/scan/star.sh' [ Not found ]
[03:05:44] Checking for file '/dev/.lib/lib/scan/bindx.sh' [ Not found ]
[03:05:44] Checking for file '/dev/.lib/lib/scan/bindname.log' [ Not found ]
[03:05:44] Checking for file '/dev/.lib/lib/1i0n.sh' [ Not found ]
[03:05:45] Checking for file '/dev/.lib/lib/lib/netstat' [ Not found ]
[03:05:45] Checking for file '/dev/.lib/lib/lib/dev/.1addr' [ Not found ]
[03:05:45] Checking for file '/dev/.lib/lib/lib/dev/.1logz' [ Not found ]
[03:05:45] Checking for file '/dev/.lib/lib/lib/dev/.1proc' [ Not found ]
[03:05:45] Checking for file '/dev/.lib/lib/lib/dev/.1file' [ Not found ]
[03:05:45] Li0n Worm [ Not found ]
[03:05:45]
[03:05:45] Checking for Lockit / LJK2 Rootkit...
[03:05:45] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_config' [ Not found ]
[03:05:45] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key' [ Not found ]
[03:05:45] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub' [ Not found ]
[03:05:46] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_random_seed*' [ Not found ]
[03:05:46] Checking for file '/usr/lib/libmen.oo/.LJK2/sshd_config' [ Not found ]
[03:05:46] Checking for file '/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd' [ Not found ]
[03:05:46] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/du' [ Not found ]
[03:05:46] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ifconfig' [ Not found ]
[03:05:46] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/inetd.conf' [ Not found ]
[03:05:46] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/locate' [ Not found ]
[03:05:46] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/login' [ Not found ]
[03:05:46] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ls' [ Not found ]
[03:05:46] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/netstat' [ Not found ]
[03:05:47] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ps' [ Not found ]
[03:05:47] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/pstree' [ Not found ]
[03:05:47] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit' [ Not found ]
[03:05:47] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/syslogd' [ Not found ]
[03:05:47] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/tcpd' [ Not found ]
[03:05:47] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/top' [ Not found ]
[03:05:47] Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1sauber' [ Not found ]
[03:05:47] Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1wted' [ Not found ]
[03:05:47] Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1parser' [ Not found ]
[03:05:47] Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1sniff' [ Not found ]
[03:05:48] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1addr' [ Not found ]
[03:05:48] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1dir' [ Not found ]
[03:05:48] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1log' [ Not found ]
[03:05:48] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1proc' [ Not found ]
[03:05:48] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c' [ Not found ]
[03:05:48] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/README.modules' [ Not found ]
[03:05:48] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c' [ Not found ]
[03:05:48] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1phide' [ Not found ]
[03:05:48] Checking for file '/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh' [ Not found ]
[03:05:49] Checking for directory '/usr/lib/libmen.oo/.LJK2' [ Not found ]
[03:05:49] Lockit / LJK2 Rootkit [ Not found ]
[03:05:49]
[03:05:49] Checking for Mood-NT Rootkit...
[03:05:49] Checking for file '/sbin/init__mood-nt-_-_cthulhu' [ Not found ]
[03:05:49] Checking for file '/_cthulhu/mood-nt.init' [ Not found ]
[03:05:49] Checking for file '/_cthulhu/mood-nt.conf' [ Not found ]
[03:05:49] Checking for file '/_cthulhu/mood-nt.sniff' [ Not found ]
[03:05:49] Checking for directory '/_cthulhu' [ Not found ]
[03:05:49] Mood-NT Rootkit [ Not found ]
[03:05:49]
[03:05:49] Checking for MRK Rootkit...
[03:05:49] Checking for file '/dev/ida/.inet/pid' [ Not found ]
[03:05:50] Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[03:05:50] Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[03:05:50] Checking for file '/dev/ida/.inet/tcp.log' [ Not found ]
[03:05:50] Checking for directory '/dev/ida/.inet' [ Not found ]
[03:05:50] Checking for directory '/var/spool/cron/.sh' [ Not found ]
[03:05:50] MRK Rootkit [ Not found ]
[03:05:50]
[03:05:50] Checking for Ni0 Rootkit...
[03:05:50] Checking for file '/var/lock/subsys/...datafile.../...net...' [ Not found ]
[03:05:50] Checking for file '/var/lock/subsys/...datafile.../...port...' [ Not found ]
[03:05:50] Checking for file '/var/lock/subsys/...datafile.../...ps...' [ Not found ]
[03:05:51] Checking for file '/var/lock/subsys/...datafile.../...file...' [ Not found ]
[03:05:51] Checking for directory '/tmp/waza' [ Not found ]
[03:05:51] Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[03:05:51] Checking for directory '/usr/sbin/es' [ Not found ]
[03:05:51] Ni0 Rootkit [ Not found ]
[03:05:51]
[03:05:51] Checking for Ohhara Rootkit...
[03:05:51] Checking for file '/var/lock/subsys/...datafile.../...datafile.../in.smbd.log' [ Not found ]
[03:05:51] Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[03:05:51] Checking for directory '/var/lock/subsys/...datafile.../...datafile...' [ Not found ]
[03:05:51] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../bin' [ Not found ]
[03:05:52] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/bin' [ Not found ]
[03:05:52] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/sbin' [ Not found ]
[03:05:52] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../lib/security' [ Not found ]
[03:05:52] Ohhara Rootkit [ Not found ]
[03:05:52]
[03:05:52] Checking for Optic Kit (Tux) Worm...
[03:05:52] Checking for directory '/dev/tux' [ Not found ]
[03:05:52] Checking for directory '/usr/bin/xchk' [ Not found ]
[03:05:52] Checking for directory '/usr/bin/xsf' [ Not found ]
[03:05:52] Checking for directory '/usr/bin/ssh2d' [ Not found ]
[03:05:52] Optic Kit (Tux) Worm [ Not found ]
[03:05:52]
[03:05:52] Checking for Oz Rootkit...
[03:05:53] Checking for file '/dev/.oz/.nap/rkit/terror' [ Not found ]
[03:05:53] Checking for directory '/dev/.oz' [ Not found ]
[03:05:53] Oz Rootkit [ Not found ]
[03:05:53]
[03:05:53] Checking for Phalanx Rootkit...
[03:05:53] Checking for file '/usr/share/.home.ph1/cb' [ Not found ]
[03:05:53] Checking for file '/etc/host.ph1' [ Not found ]
[03:05:53] Checking for file '/bin/host.ph1' [ Not found ]
[03:05:53] Checking for file '/usr/share/.home.ph1/phalanx' [ Not found ]
[03:05:53] Checking for directory '/usr/share/.home.ph1' [ Not found ]
[03:05:53] Phalanx Rootkit [ Not found ]
[03:05:54]
[03:05:54] Checking for Portacelo Rootkit...
[03:05:54] Checking for file '/var/lib/.../.ak' [ Not found ]
[03:05:54] Checking for file '/var/lib/.../.hk' [ Not found ]
[03:05:54] Checking for file '/var/lib/.../.rs' [ Not found ]
[03:05:54] Checking for file '/var/lib/.../.p' [ Not found ]
[03:05:54] Checking for file '/var/lib/.../getty' [ Not found ]
[03:05:54] Checking for file '/var/lib/.../lkt.o' [ Not found ]
[03:05:54] Checking for file '/var/lib/.../show' [ Not found ]
[03:05:54] Checking for file '/var/lib/.../nlkt.o' [ Not found ]
[03:05:54] Checking for file '/var/lib/.../ssshrc' [ Not found ]
[03:05:55] Checking for file '/var/lib/.../sssh_equiv' [ Not found ]
[03:05:55] Checking for file '/var/lib/.../sssh_known_hosts' [ Not found ]
[03:05:55] Checking for file '/var/lib/.../sssh_pid' [ Not found ]
[03:05:55] Checking for file '~/.sssh/known_hosts' [ Not found ]
[03:05:55] Portacelo Rootkit [ Not found ]
[03:05:55]
[03:05:55] Checking for R3dstorm Toolkit...
[03:05:55] Checking for file '/var/log/tk02/see_all' [ Not found ]
[03:05:55] Checking for file '/bin/.../sshd/sbin/sshd1' [ Not found ]
[03:05:55] Checking for file '/bin/.../hate/sk' [ Not found ]
[03:05:55] Checking for file '/bin/.../see_all' [ Not found ]
[03:05:55] Checking for directory '/var/log/tk02' [ Not found ]
[03:05:56] Checking for directory '/var/log/tk02/old' [ Not found ]
[03:05:56] Checking for directory '/bin/...' [ Not found ]
[03:05:56] R3dstorm Toolkit [ Not found ]
[03:05:56]
[03:05:56] Checking for RH-Sharpe's Rootkit...
[03:05:56] Checking for file '/bin/lps' [ Not found ]
[03:05:56] Checking for file '/usr/bin/lpstree' [ Not found ]
[03:05:56] Checking for file '/usr/bin/ltop' [ Not found ]
[03:05:56] Checking for file '/usr/bin/lkillall' [ Not found ]
[03:05:56] Checking for file '/usr/bin/ldu' [ Not found ]
[03:05:56] Checking for file '/usr/bin/lnetstat' [ Not found ]
[03:05:57] Checking for file '/usr/bin/wp' [ Not found ]
[03:05:57] Checking for file '/usr/bin/shad' [ Not found ]
[03:05:57] Checking for file '/usr/bin/vadim' [ Not found ]
[03:05:57] Checking for file '/usr/bin/slice' [ Not found ]
[03:05:57] Checking for file '/usr/bin/cleaner' [ Not found ]
[03:05:57] Checking for file '/usr/include/rpcsvc/du' [ Not found ]
[03:05:57] RH-Sharpe's Rootkit [ Not found ]
[03:05:57]
[03:05:57] Checking for RSHA's Rootkit...
[03:05:57] Checking for file '/bin/kr4p' [ Not found ]
[03:05:57] Checking for file '/usr/bin/n3tstat' [ Not found ]
[03:05:58] Checking for file '/usr/bin/chsh2' [ Not found ]
[03:05:58] Checking for file '/usr/bin/slice2' [ Not found ]
[03:05:58] Checking for file '/usr/src/linux/arch/alpha/lib/.lib/.1proc' [ Not found ]
[03:05:58] Checking for file '/etc/rc.d/arch/alpha/lib/.lib/.1addr' [ Not found ]
[03:05:58] Checking for directory '/etc/rc.d/rsha' [ Not found ]
[03:05:58] Checking for directory '/etc/rc.d/arch/alpha/lib/.lib' [ Not found ]
[03:05:58] RSHA's Rootkit [ Not found ]
[03:05:58]
[03:05:58] Checking for Scalper Worm...
[03:05:58] Checking for file '/tmp/.a' [ Not found ]
[03:05:58] Checking for file '/tmp/.uua' [ Not found ]
[03:05:59] Scalper Worm [ Not found ]
[03:05:59]
[03:05:59] Checking for Sebek LKM...
[03:05:59] Checking for kernel symbol 'adore or sebek' [ Skipped ]
[03:05:59] Sebek LKM [ Not found ]
[03:05:59]
[03:05:59] Checking for Shutdown Rootkit...
[03:05:59] Checking for file '/usr/man/man5/.. /.dir/scannah/asus' [ Not found ]
[03:05:59] Checking for file '/usr/man/man5/.. /.dir/see' [ Not found ]
[03:05:59] Checking for file '/usr/man/man5/.. /.dir/nscd' [ Not found ]
[03:05:59] Checking for file '/usr/man/man5/.. /.dir/alpd' [ Not found ]
[03:05:59] Checking for file '/etc/rc.d/rc.local ' [ Not found ]
[03:05:59] Checking for directory '/usr/man/man5/.. /.dir' [ Not found ]
[03:06:00] Checking for directory '/usr/man/man5/.. /.dir/scannah' [ Not found ]
[03:06:00] Checking for directory '/etc/rc.d/rc0.d/.. /.dir' [ Not found ]
[03:06:00] Shutdown Rootkit [ Not found ]
[03:06:00]
[03:06:00] Checking for SHV4 Rootkit...
[03:06:00] Checking for file '/etc/ld.so.hash' [ Not found ]
[03:06:00] Checking for file '/lib/libext-2.so.7' [ Not found ]
[03:06:00] Checking for file '/lib/lidps1.so' [ Not found ]
[03:06:00] Checking for file '/usr/sbin/xntps' [ Not found ]
[03:06:00] Checking for directory '/lib/security/.config' [ Not found ]
[03:06:00] Checking for directory '/lib/security/.config/ssh' [ Not found ]
[03:06:01] SHV4 Rootkit [ Not found ]
[03:06:01]
[03:06:01] Checking for SHV5 Rootkit...
[03:06:01] Checking for file '/etc/sh.conf' [ Not found ]
[03:06:01] Checking for file '/dev/srd0' [ Not found ]
[03:06:01] Checking for directory '/usr/lib/libsh' [ Not found ]
[03:06:01] SHV5 Rootkit [ Not found ]
[03:06:01]
[03:06:01] Checking for Sin Rootkit...
[03:06:01] Checking for file '/dev/.haos/haos1/.f/Denyed' [ Not found ]
[03:06:01] Checking for file '/dev/ttyoa' [ Not found ]
[03:06:01] Checking for file '/dev/ttyof' [ Not found ]
[03:06:01] Checking for file '/dev/ttyop' [ Not found ]
[03:06:02] Checking for file '/dev/ttyos' [ Not found ]
[03:06:02] Checking for file '/usr/lib/.lib' [ Not found ]
[03:06:02] Checking for file '/usr/lib/sn/.X' [ Not found ]
[03:06:02] Checking for file '/usr/lib/sn/.sys' [ Not found ]
[03:06:02] Checking for file '/usr/lib/ld/.X' [ Not found ]
[03:06:02] Checking for file '/usr/man/man1/...' [ Not found ]
[03:06:02] Checking for file '/usr/man/man1/.../.m' [ Not found ]
[03:06:02] Checking for file '/usr/man/man1/.../.w' [ Not found ]
[03:06:02] Checking for directory '/usr/lib/sn' [ Not found ]
[03:06:02] Checking for directory '/usr/lib/man1/...' [ Not found ]
[03:06:03] Checking for directory '/dev/.haos' [ Not found ]
[03:06:03] Sin Rootkit [ Not found ]
[03:06:03]
[03:06:03] Checking for Slapper Worm...
[03:06:03] Checking for file '/tmp/.bugtraq' [ Not found ]
[03:06:03] Checking for file '/tmp/.uubugtraq' [ Not found ]
[03:06:03] Checking for file '/tmp/.bugtraq.c' [ Not found ]
[03:06:03] Checking for file '/tmp/httpd' [ Not found ]
[03:06:03] Checking for file '/tmp/.unlock' [ Not found ]
[03:06:03] Checking for file '/tmp/update' [ Not found ]
[03:06:03] Checking for file '/tmp/.cinik' [ Not found ]
[03:06:04] Checking for file '/tmp/.b' [ Not found ]
[03:06:04] Slapper Worm [ Not found ]
[03:06:04]
[03:06:04] Checking for Sneakin Rootkit...
[03:06:04] Checking for directory '/tmp/.X11-unix/.../rk' [ Not found ]
[03:06:04] Sneakin Rootkit [ Not found ]
[03:06:04]
[03:06:04] Checking for Suckit Rootkit...
[03:06:04] Checking for file '/sbin/initsk12' [ Not found ]
[03:06:04] Checking for file '/sbin/initxrk' [ Not found ]
[03:06:04] Checking for file '/usr/bin/null' [ Not found ]
[03:06:04] Checking for file '/usr/share/locale/sk/.sk12/sk' [ Not found ]
[03:06:05] Checking for file '/etc/rc.d/rc0.d/S23kmdac' [ Not found ]
[03:06:05] Checking for file '/etc/rc.d/rc1.d/S23kmdac' [ Not found ]
[03:06:05] Checking for file '/etc/rc.d/rc2.d/S23kmdac' [ Not found ]
[03:06:05] Checking for file '/etc/rc.d/rc3.d/S23kmdac' [ Not found ]
[03:06:05] Checking for file '/etc/rc.d/rc4.d/S23kmdac' [ Not found ]
[03:06:05] Checking for file '/etc/rc.d/rc5.d/S23kmdac' [ Not found ]
[03:06:05] Checking for file '/etc/rc.d/rc6.d/S23kmdac' [ Not found ]
[03:06:05] Checking for directory '/dev/sdhu0/tehdrakg' [ Not found ]
[03:06:05] Checking for directory '/etc/.MG' [ Not found ]
[03:06:05] Checking for directory '/usr/share/locale/sk/.sk12' [ Not found ]
[03:06:06] Checking for directory '/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist' [ Not found ]
[03:06:06] Suckit Rootkit [ Not found ]
[03:06:06]
[03:06:06] Checking for SunOS Rootkit...
[03:06:06] Checking for file '/etc/ld.so.hash' [ Not found ]
[03:06:06] Checking for file '/lib/libext-2.so.7' [ Not found ]
[03:06:06] Checking for file '/usr/bin/ssh2d' [ Not found ]
[03:06:06] Checking for file '/bin/xlogin' [ Not found ]
[03:06:06] Checking for file '/usr/lib/crth.o' [ Not found ]
[03:06:06] Checking for file '/usr/lib/crtz.o' [ Not found ]
[03:06:06] Checking for file '/sbin/login' [ Not found ]
[03:06:07] Checking for file '/lib/security/.config/sn' [ Not found ]
[03:06:07] Checking for file '/lib/security/.config/lpsched' [ Not found ]
[03:06:07] Checking for file '/dev/kmod' [ Not found ]
[03:06:07] Checking for file '/dev/dos' [ Not found ]
[03:06:07] SunOS Rootkit [ Not found ]
[03:06:07]
[03:06:07] Checking for SunOS / NSDAP Rootkit...
[03:06:07] Checking for file '/usr/lib/vold/nsdap/.kit' [ Not found ]
[03:06:07] Checking for file '/usr/lib/vold/nsdap/defines' [ Not found ]
[03:06:07] Checking for file '/usr/lib/vold/nsdap/patcher' [ Not found ]
[03:06:07] Checking for file '/usr/lib/vold/nsdap/pg' [ Not found ]
[03:06:08] Checking for file '/usr/lib/vold/nsdap/cleaner' [ Not found ]
[03:06:08] Checking for file '/usr/lib/vold/nsdap/utime' [ Not found ]
[03:06:08] Checking for file '/usr/lib/vold/nsdap/crypt' [ Not found ]
[03:06:08] Checking for file '/usr/lib/vold/nsdap/findkit' [ Not found ]
[03:06:08] Checking for file '/usr/lib/vold/nsdap/sn2' [ Not found ]
[03:06:08] Checking for file '/usr/lib/vold/nsdap/sniffload' [ Not found ]
[03:06:08] Checking for file '/usr/lib/vold/nsdap/runsniff' [ Not found ]
[03:06:08] Checking for file '/usr/lib/lpset' [ Not found ]
[03:06:08] Checking for directory '/usr/lib/vold/nsdap' [ Not found ]
[03:06:08] SunOS / NSDAP Rootkit [ Not found ]
[03:06:09]
[03:06:09] Checking for Superkit Rootkit...
[03:06:09] Checking for file '/usr/man/.sman/sk' [ Not found ]
[03:06:09] Superkit Rootkit [ Not found ]
[03:06:09]
[03:06:09] Checking for TBD (Telnet BackDoor)...
[03:06:09] Checking for file '/usr/lib/.tbd' [ Not found ]
[03:06:09] TBD (Telnet BackDoor) [ Not found ]
[03:06:09]
[03:06:09] Checking for TeLeKiT Rootkit...
[03:06:09] Checking for file '/usr/man/man3/.../TeLeKiT/bin/sniff' [ Not found ]
[03:06:09] Checking for file '/usr/man/man3/.../TeLeKiT/bin/telnetd' [ Not found ]
[03:06:09] Checking for file '/usr/man/man3/.../TeLeKiT/bin/teleulo' [ Not found ]
[03:06:09] Checking for file '/usr/man/man3/.../cl' [ Not found ]
[03:06:10] Checking for file '/dev/ptyr' [ Not found ]
[03:06:10] Checking for file '/dev/ptyp' [ Not found ]
[03:06:10] Checking for file '/dev/ptyq' [ Not found ]
[03:06:10] Checking for file '/dev/hda06' [ Not found ]
[03:06:10] Checking for file '/usr/info/libc1.so' [ Not found ]
[03:06:10] Checking for directory '/usr/man/man3/...' [ Not found ]
[03:06:10] Checking for directory '/usr/man/man3/.../lsniff' [ Not found ]
[03:06:10] Checking for directory '/usr/man/man3/.../TeLeKiT' [ Not found ]
[03:06:10] TeLeKiT Rootkit [ Not found ]
[03:06:10]
[03:06:10] Checking for T0rn Rootkit...
[03:06:11] Checking for file '/dev/.lib/lib/lib/t0rns' [ Not found ]
[03:06:11] Checking for file '/dev/.lib/lib/lib/du' [ Not found ]
[03:06:11] Checking for file '/dev/.lib/lib/lib/ls' [ Not found ]
[03:06:11] Checking for file '/dev/.lib/lib/lib/t0rnsb' [ Not found ]
[03:06:11] Checking for file '/dev/.lib/lib/lib/ps' [ Not found ]
[03:06:11] Checking for file '/dev/.lib/lib/lib/t0rnp' [ Not found ]
[03:06:11] Checking for file '/dev/.lib/lib/lib/find' [ Not found ]
[03:06:11] Checking for file '/dev/.lib/lib/lib/ifconfig' [ Not found ]
[03:06:11] Checking for file '/dev/.lib/lib/lib/pg' [ Not found ]
[03:06:11] Checking for file '/dev/.lib/lib/lib/ssh.tgz' [ Not found ]
[03:06:12] Checking for file '/dev/.lib/lib/lib/top' [ Not found ]
[03:06:12] Checking for file '/dev/.lib/lib/lib/sz' [ Not found ]
[03:06:12] Checking for file '/dev/.lib/lib/lib/login' [ Not found ]
[03:06:12] Checking for file '/dev/.lib/lib/lib/in.fingerd' [ Not found ]
[03:06:12] Checking for file '/dev/.lib/lib/lib/1i0n.sh' [ Not found ]
[03:06:12] Checking for file '/dev/.lib/lib/lib/pstree' [ Not found ]
[03:06:12] Checking for file '/dev/.lib/lib/lib/in.telnetd' [ Not found ]
[03:06:12] Checking for file '/dev/.lib/lib/lib/mjy' [ Not found ]
[03:06:12] Checking for file '/dev/.lib/lib/lib/sush' [ Not found ]
[03:06:12] Checking for file '/dev/.lib/lib/lib/tfn' [ Not found ]
[03:06:13] Checking for file '/dev/.lib/lib/lib/name' [ Not found ]
[03:06:13] Checking for file '/dev/.lib/lib/lib/getip.sh' [ Not found ]
[03:06:13] Checking for file '/usr/info/.torn/sh*' [ Not found ]
[03:06:13] Checking for file '/usr/src/.puta/.1addr' [ Not found ]
[03:06:13] Checking for file '/usr/src/.puta/.1file' [ Not found ]
[03:06:13] Checking for file '/usr/src/.puta/.1proc' [ Not found ]
[03:06:13] Checking for file '/usr/src/.puta/.1logz' [ Not found ]
[03:06:13] Checking for file '/usr/info/.t0rn' [ Not found ]
[03:06:13] Checking for directory '/dev/.lib' [ Not found ]
[03:06:13] Checking for directory '/dev/.lib/lib' [ Not found ]
[03:06:14] Checking for directory '/dev/.lib/lib/lib' [ Not found ]
[03:06:14] Checking for directory '/dev/.lib/lib/lib/dev' [ Not found ]
[03:06:14] Checking for directory '/dev/.lib/lib/scan' [ Not found ]
[03:06:14] Checking for directory '/usr/src/.puta' [ Not found ]
[03:06:14] Checking for directory '/usr/man/man1/man1' [ Not found ]
[03:06:14] Checking for directory '/usr/man/man1/man1/lib' [ Not found ]
[03:06:14] Checking for directory '/usr/man/man1/man1/lib/.lib' [ Not found ]
[03:06:14] Checking for directory '/usr/man/man1/man1/lib/.lib/.backup' [ Not found ]
[03:06:14] T0rn Rootkit [ Not found ]
[03:06:15]
[03:06:15] Checking for Trojanit Kit...
[03:06:15] Checking for file '/bin/.ls' [ Not found ]
[03:06:15] Checking for file '/bin/.ps' [ Not found ]
[03:06:15] Checking for file '/bin/.netstat' [ Not found ]
[03:06:15] Checking for file '/usr/bin/.nop' [ Not found ]
[03:06:15] Checking for file '/usr/bin/.who' [ Not found ]
[03:06:15] Trojanit Kit [ Not found ]
[03:06:15]
[03:06:15] Checking for Tuxtendo Rootkit...
[03:06:15] Checking for file '/dev/tux/.addr' [ Not found ]
[03:06:15] Checking for file '/dev/tux/.cron' [ Not found ]
[03:06:15] Checking for file '/dev/tux/.file' [ Not found ]
[03:06:16] Checking for file '/dev/tux/.log' [ Not found ]
[03:06:16] Checking for file '/dev/tux/.proc' [ Not found ]
[03:06:16] Checking for file '/dev/tux/backup/crontab' [ Not found ]
[03:06:16] Checking for file '/dev/tux/backup/df' [ Not found ]
[03:06:16] Checking for file '/dev/tux/backup/dir' [ Not found ]
[03:06:16] Checking for file '/dev/tux/backup/find' [ Not found ]
[03:06:16] Checking for file '/dev/tux/backup/ifconfig' [ Not found ]
[03:06:16] Checking for file '/dev/tux/backup/locate' [ Not found ]
[03:06:16] Checking for file '/dev/tux/backup/netstat' [ Not found ]
[03:06:16] Checking for file '/dev/tux/backup/ps' [ Not found ]
[03:06:17] Checking for file '/dev/tux/backup/pstree' [ Not found ]
[03:06:17] Checking for file '/dev/tux/backup/syslogd' [ Not found ]
[03:06:17] Checking for file '/dev/tux/backup/tcpd' [ Not found ]
[03:06:17] Checking for file '/dev/tux/backup/top' [ Not found ]
[03:06:17] Checking for file '/dev/tux/backup/updatedb' [ Not found ]
[03:06:17] Checking for file '/dev/tux/backup/vdir' [ Not found ]
[03:06:17] Checking for directory '/dev/tux' [ Not found ]
[03:06:17] Checking for directory '/dev/tux/ssh2' [ Not found ]
[03:06:17] Checking for directory '/dev/tux/backup' [ Not found ]
[03:06:17] Tuxtendo Rootkit [ Not found ]
[03:06:18]
[03:06:18] Checking for URK Rootkit...
[03:06:18] Checking for file '/usr/man/man1/xxxxxxbin/find' [ Not found ]
[03:06:18] Checking for file '/usr/man/man1/xxxxxxbin/du' [ Not found ]
[03:06:18] Checking for file '/usr/man/man1/xxxxxxbin/ps' [ Not found ]
[03:06:18] Checking for file '/tmp/conf.inf' [ Not found ]
[03:06:18] Checking for directory '/usr/man/man1/xxxxxxbin' [ Not found ]
[03:06:18] URK Rootkit [ Not found ]
[03:06:18]
[03:06:18] Checking for VcKit Rootkit...
[03:06:18] Checking for directory '/usr/include/linux/modules/lib.so' [ Not found ]
[03:06:18] Checking for directory '/usr/include/linux/modules/lib.so/bin' [ Not found ]
[03:06:19] VcKit Rootkit [ Not found ]
[03:06:19]
[03:06:19] Checking for Volc Rootkit...
[03:06:19] Checking for directory '/var/spool/.recent' [ Not found ]
[03:06:19] Checking for directory '/var/spool/.recent/.files' [ Not found ]
[03:06:19] Checking for directory '/usr/lib/volc' [ Not found ]
[03:06:19] Checking for directory '/usr/lib/volc/backup' [ Not found ]
[03:06:19] Volc Rootkit [ Not found ]
[03:06:19]
[03:06:19] Checking for X-Org SunOS Rootkit...
[03:06:19] Checking for file '/usr/lib/libX.a/bin/tmpfl' [ Not found ]
[03:06:19] Checking for file '/usr/lib/libX.a/bin/rps' [ Not found ]
[03:06:19] Checking for file '/usr/bin/srload' [ Not found ]
[03:06:20] Checking for file '/usr/lib/libX.a/bin/sparcv7/rps' [ Not found ]
[03:06:20] Checking for file '/usr/sbin/modcheck' [ Not found ]
[03:06:20] Checking for directory '/usr/lib/libX.a' [ Not found ]
[03:06:20] Checking for directory '/usr/lib/libX.a/bin' [ Not found ]
[03:06:20] Checking for directory '/usr/lib/libX.a/bin/sparcv7' [ Not found ]
[03:06:20] Checking for directory '/usr/share/man...' [ Not found ]
[03:06:20] X-Org SunOS Rootkit [ Not found ]
[03:06:20]
[03:06:20] Checking for zaRwT.KiT Rootkit...
[03:06:20] Checking for file '/dev/rd/s/sendmeil' [ Not found ]
[03:06:20] Checking for file '/dev/ttyf' [ Not found ]
[03:06:21] Checking for file '/dev/ttyp' [ Not found ]
[03:06:21] Checking for file '/dev/ttyn' [ Not found ]
[03:06:21] Checking for file '/rk/tulz' [ Not found ]
[03:06:21] Checking for directory '/rk' [ Not found ]
[03:06:21] Checking for directory '/dev/rd/s' [ Not found ]
[03:06:21] zaRwT.KiT Rootkit [ Not found ]
[03:06:21]
[03:06:21] Performing additional rootkit checks
[03:06:21] Info: Starting test name 'additional_rkts'
[03:06:21]
[03:06:21] Performing check of possible rootkit files and directories
[03:06:21] Info: Starting test name 'possible_rkt_files'
[03:06:21] Checking for file '/dev/sdr0' [ Not found ]
[03:06:22] Checking for file '/tmp/.syshackfile' [ Not found ]
[03:06:22] Checking for file '/tmp/.bash_history' [ Not found ]
[03:06:22] Checking for file '/usr/info/.clib' [ Not found ]
[03:06:22] Checking for file '/usr/sbin/tcp.log' [ Not found ]
[03:06:22] Checking for file '/usr/bin/take/pid' [ Not found ]
[03:06:22] Checking for file '/sbin/create' [ Not found ]
[03:06:22] Checking for file '/dev/ttypz' [ Not found ]
[03:06:23] Checking for directory '/usr/bin/take' [ Not found ]
[03:06:23] Checking for directory '/usr/src/.lib' [ Not found ]
[03:06:23] Checking for directory '/usr/share/man/man1/.1c' [ Not found ]
[03:06:23] Checking for directory '/lib/lblip.tk' [ Not found ]
[03:06:23] Checking for directory '/usr/sbin/...' [ Not found ]
[03:06:23] Checking for directory '/usr/share/.gun' [ Not found ]
[03:06:23] Checking for possible rootkit files and directories [ None found ]
[03:06:23]
[03:06:23] Performing check for possible rootkit strings
[03:06:24] Info: Starting test name 'possible_rkt_strings'
[03:06:24] Warning: Checking for possible rootkit strings [ Warning ]
[03:06:24] No system startup files found.
[03:06:24]
[03:06:24] Performing malware checks
[03:06:24] Info: Starting test name 'malware'
[03:06:24]
[03:06:24] Info: Test 'deleted_files' disabled at users request.
[03:06:24] Info: Starting test name 'running_procs'
[03:06:26] Checking running processes for suspicious files [ None found ]
[03:06:26]
[03:06:26] Info: Test 'hidden_procs' disabled at users request.
[03:06:27]
[03:06:27] Info: Test 'suspscan' disabled at users request.
[03:06:27]
[03:06:27] Performing check for login backdoors
[03:06:27] Info: Starting test name 'other_malware'
[03:06:27] Checking for '/bin/.login' [ Not found ]
[03:06:27] Checking for '/sbin/.login' [ Not found ]
[03:06:27] Checking for login backdoors [ None found ]
[03:06:27]
[03:06:27] Performing check for suspicious directories
[03:06:27] Checking for directory '/usr/X11R6/bin/.,/copy' [ Not found ]
[03:06:27] Checking for directory '/dev/rd/cdb' [ Not found ]
[03:06:27] Checking for suspicious directories [ None found ]
[03:06:27]
[03:06:27] Checking for software intrusions [ Skipped ]
[03:06:27] Info: Check skipped - tripwire not installed
[03:06:28]
[03:06:28] Performing check for sniffer log files
[03:06:28] Checking for file '/usr/lib/libice.log' [ Not found ]
[03:06:28] Checking for sniffer log files [ None found ]
[03:06:28]
[03:06:28] Performing trojan specific checks
[03:06:28] Info: Starting test name 'trojans'
[03:06:28] Info: Using inetd configuration file '/etc/inetd.conf'
[03:06:28] Checking for enabled inetd services [ OK ]
[03:06:28]
[03:06:28] Performing check for enabled xinetd services
[03:06:28] Info: Using xinetd configuration file '/etc/xinetd.conf'
[03:06:28] Checking '/etc/xinetd.conf' for enabled services [ None found ]
[03:06:28] Found 'includedir /etc/xinetd.d' directive
[03:06:29] Checking for enabled xinetd services [ None found ]
[03:06:29] Info: Apache backdoor check skipped: Apache modules and configuration directories not found.
[03:06:29]
[03:06:29] Performing Darwin specific checks
[03:06:29] Info: Starting test name 'os_specific'
[03:06:29] Info: No specific tests available
[03:06:37]
[03:06:37] Checking the network...
[03:06:37] Info: Starting test name 'network'
[03:06:37] Info: Starting test name 'ports'
[03:06:37]
[03:06:37] Performing check for backdoor ports
[03:06:38] Checking for UDP port 2001 [ Not found ]
[03:06:38] Checking for TCP port 2006 [ Not found ]
[03:06:39] Checking for TCP port 2128 [ Not found ]
[03:06:40] Checking for TCP port 14856 [ Not found ]
[03:06:40] Checking for TCP port 47107 [ Not found ]
[03:06:41] Checking for TCP port 60922 [ Not found ]
[03:06:41]
[03:06:41] Performing checks on the network interfaces
[03:06:41] Info: Starting test name 'promisc'
[03:06:41] Checking for promiscuous interfaces [ None found ]
[03:06:41] Info: Test 'packet_cap_apps' skipped due to O/S: /proc/net/packet required
[03:06:45]
[03:06:45] Checking the local host...
[03:06:45] Info: Starting test name 'local_host'
[03:06:45]
[03:06:45] Performing system boot checks
[03:06:45] Info: Starting test name 'startup_files'
[03:06:45] Checking for local host name [ Found ]
[03:06:45] Info: Starting test name 'startup_malware'
[03:06:45] Checking for local startup files [ Warning ]
[03:06:45] Warning: No local startup files found.
[03:06:46] Checking local startup files for malware [ Skipped ]
[03:06:46] Warning: No local startup files found.
[03:06:46] Checking system startup files for malware [ Warning ]
[03:06:46] Warning: No system startup files found.
[03:06:46]
[03:06:46] Performing group and account checks
[03:06:46] Info: Starting test name 'group_accounts'
[03:06:46] Checking for passwd file [ Found ]
[03:06:46] Info: Found password file: /etc/passwd
[03:06:46] Checking for root equivalent (UID 0) accounts [ None found ]
[03:06:46] Checking for passwordless accounts [ Warning ]
[03:06:46] Warning: No shadow/password file found.
[03:06:47] Info: Starting test name 'passwd_changes'
[03:06:47] Checking for passwd file changes [ None found ]
[03:06:47] Info: Starting test name 'group_changes'
[03:06:47] Checking for group file changes [ None found ]
[03:06:47] Checking root account shell history files [ None found ]
[03:06:47]
[03:06:47] Performing system configuration file checks
[03:06:47] Info: Starting test name 'system_configs'
[03:06:47] Checking for SSH configuration file [ Found ]
[03:06:47] Info: Found SSH configuration file: /etc/sshd_config
[03:06:47] Info: Rkhunter option ALLOW_SSH_ROOT_USER set to 'no'.
[03:06:48] Checking if SSH root access is allowed [ Warning ]
[03:06:48] Warning: The SSH configuration option 'PermitRootLogin' has not been set.
The default value may be 'yes', to allow root access.
[03:06:48] Checking if SSH protocol v1 is allowed [ Warning ]
[03:06:48] Warning: The SSH configuration option 'Protocol' has not been set.
The default value may be '2,1', to allow the use of protocol v1.
[03:06:48] Checking for running syslog daemon [ Found ]
[03:06:48] Checking for syslog configuration file [ Found ]
[03:06:48] Info: Found syslog configuration file: /etc/syslog.conf
[03:06:48] Checking if syslog remote logging is allowed [ Warning ]
[03:06:49] Warning: Syslog configuration file allows remote logging: install.* @127.0.0.1:32376
[03:06:49]
[03:06:49] Performing filesystem checks
[03:06:49] Info: Starting test name 'filesystem'
[03:06:49] Info: SCAN_MODE_DEV set to 'THOROUGH'
[03:07:00] Checking /dev for suspicious file types [ None found ]
[03:07:00] Checking for hidden files and directories [ None found ]
[03:07:07]
[03:07:07] Checking application versions...
[03:07:07] Info: Starting test name 'apps'
[03:07:09] Info: Application 'exim' not found.
[03:07:09] Info: Application 'gpg' not found.
[03:07:09] Checking version of Apache [ Warning ]
[03:07:09] Warning: Application 'httpd', version '1.3.33', is out of date, and possibly a security risk.
[03:07:10] Checking version of Bind DNS [ OK ]
[03:07:10] Info: Application 'named' version '9.3.4' found.
[03:07:10] Checking version of OpenSSL [ OK ]
[03:07:10] Info: Application 'openssl' version '0.9.7l' found.
[03:07:10] Checking version of PHP [ OK ]
[03:07:10] Info: Application 'php' version '4.4.7' found.
[03:07:10] Checking version of Procmail MTA [ OK ]
[03:07:10] Info: Application 'procmail' version '3.22' found.
[03:07:10] Info: Application 'proftpd' not found.
[03:07:11] Checking version of OpenSSH [ OK ]
[03:07:11] Info: Application 'sshd' version '4.5p1' found.
[03:07:11] Info: Applications checked: 6 out of 9
[03:07:11]
[03:07:11] System checks summary
[03:07:11] =====================
[03:07:11]
[03:07:11] File properties checks...
[03:07:11] Required commands check failed
[03:07:11] Files checked: 80
[03:07:11] Suspect files: 3
[03:07:11]
[03:07:11] Rootkit checks...
[03:07:11] Rootkits checked : 77
[03:07:11] Possible rootkits: 0
[03:07:11]
[03:07:11] Applications checks...
[03:07:11] Applications checked: 6
[03:07:11] Suspect applications: 1
[03:07:12]
[03:07:12] The system checks took: 2 minutes and 14 seconds
[03:07:12]
[03:07:12] Info: End date is Tue Jan 8 03:07:12 CST 2008
 
And I forgot to mention that in the log where it says-
Info: Test 'deleted_files' disabled at users request.
Info: Test 'hidden_procs' disabled at users request.
Info: Test 'suspscan' disabled at users request.

Not true!! I would love to run these test!!
 
If the time reverts to 1904 then you probably need to replace the internal battery.
It can cause a lot of problems. Lets hope that might be it. If not, the logic board could be going bad...
 
No, it was new in the box, never opened.

I don't think my problem is hardware. I think it's malware. Please, please, look at the warnings from the RKHunter log and tell me what I can do. If it was a memory problem, don't you think some of the old sht I'm trying to remove would begin to degrade?? Why after a 35X wipe do I have certificates that expired in 1998 and 1999 when this computer and software weren't even made until probably 2005 or 2006?

I feel like I've gone to the Dr. with a broken leg, only to receive an enema!?

And maybe I'm not giving the right information, but I just don't know where to begin. I wish I could just say "broken leg"! But I've told you spoofed website, outdated certificates, uncleanable caches, unstoppable services, unmountable automounts. And then the rkhunter log with all of the warnings, and tests that were skipped and NOT because I wanted them skipped as the log states. It's not a freakin hardware problem!
 
I just reread my post, and sorry! It sounds like I'm going off on you who are giving your free time to help me (an idiot at times) for free. I apologize!! I'm just a little frustrated!

I'm very very sorry!
 
Hey, no problem. I know you're having a hard time.
Actually, I was asking when you bought it, to see if it's still under warranty.
And the report did have 3 suspect files and 1 application. So you either need a very good virus software to remove whatever is hiding in there, or try to get it fixed or exchange it for another. (hence, the warranty)
It is hard for some of us to "believe" in viruses for a Mac. I've had 4 Macs. I "retired" one for just being old, gave away 1 to a friend, and still use 2 today. The only problem I have ever had is a crashed hard drive. I use an external one now. I've never had any kind of malware in the last 11 yrs. Ever. (that's why it's hard for people) :)
Do you have an Apple store nearby you could bring it to?
I'm still doing some research myself, I just like to keep all options open...
Don't worry, I haven't given up yet... ;)
 
Thanks for being so nice. The reason I bought a Mac was because I'd been hacked using Windows. And it took me a while to start feeling safe with the Mac. But I finally did. And then all of this odd stuff started happening again......things similar to before. An automounting system that just won't die. Can't shut off bluetooth or airport......Spoofed antivirus sites, spoofed updates.

Yes, there's an Apple store nearby, but I was hoping to figure this out myself (or with help from y'all) The people at the Mac store don't believe in viruses on Mac either.

I don't think I mentioned that most of my files are world writeable and owned by root. So I guess anyone can write to them, except me! Changing ownership doesn't help. I change them, delete them only to have them return at the next install.
 
Back
Top