Code: Alles auswählen
Searching for suspicious files and dirs, it may take a while... The following suspicious files and directories were found:
/usr/lib/jvm/.java-1.8.0-openjdk-amd64.jinfo /usr/lib/debug/.build-id
/usr/lib/debug/.build-id
Code: Alles auswählen
Checking `lkm'... You have 1 process hidden for readdir command
You have 1 process hidden for ps command
chkproc: Warning: Possible LKM Trojan installed
chkdirs: nothing detected
Checking `rexedcs'... not found
Checking `sniffer'... lo: not promisc and no packet sniffer sockets
enp2s0: PACKET SNIFFER(/sbin/dhclient[666])
Checking `w55808'... not infected
Checking `wted'... chkwtmp: nothing deleted
Checking `scalper'... not infected
Checking `slapper'... not infected
Checking `z2'... chklastlog: nothing deleted
Checking `chkutmp'... The tty of the following user process(es) were not found
in /var/run/utmp !
! RUID PID TTY CMD
! root 21101 pts/0 bash
! root 21105 pts/0 /bin/sh /usr/sbin/chkrootkit
! root 21771 pts/0 ./chkutmp
! root 21773 pts/0 ps axk tty,ruser,args -o tty,pid,ruser,args
! root 21772 pts/0 sh -c ps axk "tty,ruser,args" -o "tty,pid,ruser,args"
chkutmp: nothing deleted
Checking `OSX_RSPLUG'... not infected

Also habe ich noch rkhunter laufen lassen, in der Hoffnung, dass es wenigstens da nichts zu beanstanden gibt, erhielt aber bei /usr/bin/lwp-request eine Warnmeldung. Ebenso als es hieß Checking for hidden files and directories. Ausgabe von rkhunter am Ende:
Code: Alles auswählen
System checks summary
=====================
File properties checks...
Files checked: 141
Suspect files: 1
Rootkit checks...
Rootkits checked : 361
Possible rootkits: 0
Applications checks...
All checks skipped
The system checks took: 3 minutes and 23 seconds
All results have been written to the log file: /var/log/rkhunter.log
One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter.log)
root@nerv-kommandozentrale:~#
/Edit
Hab die Logdatei nochmal geprüft (natürlich als root), diesmal in einem Editor anstatt mit cat. Hab folgende Warmeldung gefunden:
Code: Alles auswählen
[12:23:38] /usr/bin/lwp-request [ Warning ]
Code: Alles auswählen
rkhunter -c
