Thanks for the new version. After a few little tweaks (like tracking
down the move of the .conf file) and a propupd seems wonderful.

Except...

I had all tests enabled, and now it seemingly hangs. The display
gets to this point:

   Performing additional rootkit checks
     Suckit Rookit additional checks                          [ OK ]
     Checking for possible rootkit files and directories      [ None found ]
     Checking for possible rootkit strings                    [ None found ]
 

   Performing malware checks
     Checking running processes for deleted files             [ Warning ]
     Checking running processes for suspicious files          [ None found ]
     Checking for hidden processes                            [ Skipped ]

then does not progress any farther. The top tool reports 87% CPU
utilization, but adding up the process display below doesn't account
for more than about 10% or so. I left it running in that state
for over 10 minutes.

When I change the relevant lines in the .conf file from

ENABLE_TESTS="all"
#DISABLE_TESTS="suspscan hidden_procs deleted_files packet_cap_apps"
DISABLE_TESTS="none"

to

ENABLE_TESTS="all"
DISABLE_TESTS="suspscan hidden_procs deleted_files packet_cap_apps"
#DISABLE_TESTS="none"

it runs through all tests in less than three minutes.

Have I encountered a defect? Why is the "hidden process" test
skipped?

Mike
-- 
p="p=%c%s%c;main(){printf(p,34,p,34);}";main(){printf(p,34,p,34);}
Oppose globalization and One World Governments like the UN.
This message made from 100% recycled bits.
You have found the bank of Larn.
I speak only for myself, and I am unanimous in that!

------------------------------------------------------------------------------
This SF.net email is sponsored by:
SourcForge Community
SourceForge wants to tell your story.
http://p.sf.net/sfu/sf-spreadtheword
_______________________________________________
Rkhunter-users mailing list
Rkhunter-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/rkhunter-users

Reply via email to