* [gentoo-amd64] rkhunter results
@ 2010-09-28 9:34 Paul Stear
2010-10-09 9:28 ` Thanasis
2010-10-10 13:43 ` [gentoo-amd64] " Lie Ryan
0 siblings, 2 replies; 4+ messages in thread
From: Paul Stear @ 2010-09-28 9:34 UTC (permalink / raw
To: gentoo-amd64
Hi all,
rkhunter runs every day and reports the following:-
System checks summary
=====================
File properties checks...
Files checked: 142
Suspect files: 141
Rootkit checks...
Rootkits checked : 246
Possible rootkits: 2
Rootkit names : Xzibit Rootkit, Dica-Kit Rootkit
Any idea how I find and remove these Rootkits?
thanks for any help
Paul
--
This message has been sent using kmail on gentoo.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [gentoo-amd64] rkhunter results
2010-09-28 9:34 [gentoo-amd64] rkhunter results Paul Stear
@ 2010-10-09 9:28 ` Thanasis
2010-10-10 11:10 ` [gentoo-amd64] " Duncan
2010-10-10 13:43 ` [gentoo-amd64] " Lie Ryan
1 sibling, 1 reply; 4+ messages in thread
From: Thanasis @ 2010-10-09 9:28 UTC (permalink / raw
To: gentoo-amd64; +Cc: Paul Stear
on 09/28/2010 12:34 PM Paul Stear wrote the following:
> Hi all,
> rkhunter runs every day and reports the following:-
>
> System checks summary
> =====================
>
> File properties checks...
> Files checked: 142
> Suspect files: 141
>
> Rootkit checks...
> Rootkits checked : 246
> Possible rootkits: 2
> Rootkit names : Xzibit Rootkit, Dica-Kit Rootkit
>
> Any idea how I find and remove these Rootkits?
>
> thanks for any help
> Paul
Did you check the log file (/var/log/rkhunter.log)?
^ permalink raw reply [flat|nested] 4+ messages in thread
* [gentoo-amd64] Re: rkhunter results
2010-10-09 9:28 ` Thanasis
@ 2010-10-10 11:10 ` Duncan
0 siblings, 0 replies; 4+ messages in thread
From: Duncan @ 2010-10-10 11:10 UTC (permalink / raw
To: gentoo-amd64
Thanasis posted on Sat, 09 Oct 2010 12:28:26 +0300 as excerpted:
> on 09/28/2010 12:34 PM Paul Stear wrote the following:
>> Hi all,
>> rkhunter runs every day and reports the following:-
>>
>> System checks summary
>> =====================
>>
>> File properties checks...
>> Files checked: 142
>> Suspect files: 141
>>
>> Rootkit checks...
>> Rootkits checked : 246
>> Possible rootkits: 2
>> Rootkit names : Xzibit Rootkit, Dica-Kit Rootkit
>>
>> Any idea how I find and remove these Rootkits?
>>
>> thanks for any help
>> Paul
> Did you check the log file (/var/log/rkhunter.log)?
If rkhunter is based on recorded file checksums, it's obviously going to
have false-positives every time you update the files it checks, which
tends to be reasonably frequently for many gentoo users (especially ~arch
users), since given gentoo's rolling update nature.
That's very possibly why it's saying 141 out of 142 files are suspect. A
possible workaround would be running it before every update, to be sure,
then running it after the update to update its checksums.
But that doesn't explain the possible rootkits detected. Of course,
depending on how it detects specific rootkits, that too may have false
positives. If it happens to the big AV folks like Norton and McAfee, and
it does, it's going to happen to everyone, occasionally.
--
Duncan - List replies preferred. No HTML msgs.
"Every nonfree program has a lord, a master --
and if you use the program, he is your master." Richard Stallman
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [gentoo-amd64] rkhunter results
2010-09-28 9:34 [gentoo-amd64] rkhunter results Paul Stear
2010-10-09 9:28 ` Thanasis
@ 2010-10-10 13:43 ` Lie Ryan
1 sibling, 0 replies; 4+ messages in thread
From: Lie Ryan @ 2010-10-10 13:43 UTC (permalink / raw
To: gentoo-amd64
On Tue, Sep 28, 2010 at 7:34 PM, Paul Stear <gentoo@appjaws.plus.com> wrote:
> Hi all,
> rkhunter runs every day and reports the following:-
>
> System checks summary
> =====================
>
> File properties checks...
> Files checked: 142
> Suspect files: 141
>
> Rootkit checks...
> Rootkits checked : 246
> Possible rootkits: 2
> Rootkit names : Xzibit Rootkit, Dica-Kit Rootkit
>
> Any idea how I find and remove these Rootkits?
FYI, some info about Dica-Kit from Sophos:
http://www.sophos.com/security/analyses/viruses-and-spyware/trojdicakit.html
and a quick google search about Xzibit seems to say that rkhunter
often give false positive for Xzibit. You might want to research about
Xzibit, and assess whether or not your case is false positive.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2010-10-10 14:04 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-09-28 9:34 [gentoo-amd64] rkhunter results Paul Stear
2010-10-09 9:28 ` Thanasis
2010-10-10 11:10 ` [gentoo-amd64] " Duncan
2010-10-10 13:43 ` [gentoo-amd64] " Lie Ryan
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox