Hello, Every time I run rkhunter I get a message that says something like:
[1]+ Stopped /usr/local/bin/rkhunter and when I run rkhunter --check it get up to [Press <ENTER> to continue] and I press the Enter key and it doesn't complete the scanning and the process is still alive until I type skill rkhunter. I'm new to the mailing list and have never used one before. Here is some output I have gathered: www:/usr/src/rkhunter-1.3.4# /usr/local/bin/rkhunter --propupd [ Rootkit Hunter version 1.3.4 ] [1]+ Stopped /usr/local/bin/rkhunter --propupd www:/usr/src/rkhunter-1.3.4# File updated: searched for 153 files, found 122 /usr/local/bin/rkhunter --check [ Rootkit Hunter version 1.3.4 ] Checking system commands... Performing 'strings' command checks [1] Done /usr/local/bin/rkhunter --propupd [2]+ Stopped /usr/local/bin/rkhunter --check www:/usr/src/rkhunter-1.3.4# Checking 'strings' command [ OK ] Performing 'shared libraries' checks Checking for preloading variables [ None found ] Checking for preload file [ Not found ] Checking LD_LIBRARY_PATH variable [ Not found ] Performing file properties checks Checking for prerequisites [ OK ] /bin/bash [ OK ] /bin/cat [ OK ] /bin/chmod [ OK ] /bin/chown [ OK ] /bin/cp [ OK ] /bin/date [ OK ] /bin/df [ OK ] /bin/dmesg [ OK ] /bin/echo [ OK ] /bin/ed [ OK ] /bin/egrep [ OK ] /bin/fgrep [ OK ] /bin/fuser [ OK ] /bin/grep [ OK ] /bin/ip [ OK ] /bin/kill [ OK ] /bin/login [ OK ] /bin/ls [ OK ] /bin/lsmod [ OK ] /bin/mktemp [ OK ] /bin/more [ OK ] /bin/mount [ OK ] /bin/mv [ OK ] /bin/netstat [ OK ] /bin/ps [ OK ] /bin/pwd [ OK ] /bin/readlink [ OK ] /bin/sed [ OK ] /bin/sh [ OK ] /bin/su [ OK ] /bin/touch [ OK ] /bin/uname [ OK ] /bin/which [ Warning ] /usr/bin/awk [ OK ] /usr/bin/basename [ OK ] /usr/bin/chattr [ OK ] /usr/bin/cut [ OK ] /usr/bin/diff [ OK ] /usr/bin/dirname [ OK ] /usr/bin/dpkg [ OK ] /usr/bin/dpkg-query [ OK ] /usr/bin/du [ OK ] /usr/bin/env [ OK ] /usr/bin/file [ OK ] /usr/bin/find [ OK ] /usr/bin/GET [ OK ] /usr/bin/groups [ Warning ] /usr/bin/head [ OK ] /usr/bin/id [ OK ] /usr/bin/killall [ OK ] /usr/bin/last [ OK ] /usr/bin/lastlog [ OK ] /usr/bin/ldd [ Warning ] /usr/bin/logger [ OK ] /usr/bin/lsattr [ OK ] /usr/bin/lsof [ OK ] /usr/bin/mail [ OK ] /usr/bin/md5sum [ OK ] /usr/bin/newgrp [ OK ] /usr/bin/passwd [ OK ] /usr/bin/perl [ OK ] /usr/bin/pstree [ OK ] /usr/bin/runcon [ OK ] /usr/bin/sha1sum [ OK ] /usr/bin/size [ OK ] /usr/bin/sort [ OK ] /usr/bin/stat [ OK ] /usr/bin/strings [ OK ] /usr/bin/sudo [ OK ] /usr/bin/tail [ OK ] /usr/bin/test [ OK ] /usr/bin/top [ OK ] /usr/bin/touch [ OK ] /usr/bin/tr [ OK ] /usr/bin/uniq [ OK ] /usr/bin/users [ OK ] /usr/bin/vmstat [ OK ] /usr/bin/w [ OK ] /usr/bin/watch [ OK ] /usr/bin/wc [ OK ] /usr/bin/wget [ OK ] /usr/bin/whatis [ OK ] /usr/bin/whereis [ OK ] /usr/bin/which [ OK ] /usr/bin/who [ OK ] /usr/bin/whoami [ OK ] /usr/bin/gawk [ OK ] /usr/bin/lwp-request [ Warning ] /usr/bin/bsd-mailx [ OK ] /usr/bin/w.procps [ OK ] /sbin/depmod [ OK ] /sbin/ifconfig [ OK ] /sbin/ifdown [ OK ] /sbin/ifup [ OK ] /sbin/init [ OK ] /sbin/insmod [ OK ] /sbin/ip [ OK ] /sbin/lsmod [ OK ] /sbin/modinfo [ OK ] /sbin/modprobe [ OK ] /sbin/rmmod [ OK ] /sbin/runlevel [ OK ] /sbin/sulogin [ OK ] /sbin/sysctl [ OK ] /usr/sbin/adduser [ Warning ] /usr/sbin/chroot [ OK ] /usr/sbin/cron [ OK ] /usr/sbin/groupadd [ OK ] /usr/sbin/groupdel [ OK ] /usr/sbin/groupmod [ OK ] /usr/sbin/grpck [ OK ] /usr/sbin/nologin [ OK ] /usr/sbin/pwck [ OK ] /usr/sbin/rsyslogd [ OK ] /usr/sbin/tcpd [ OK ] /usr/sbin/unhide [ OK ] /usr/sbin/useradd [ OK ] /usr/sbin/userdel [ OK ] /usr/sbin/usermod [ OK ] /usr/sbin/vipw [ OK ] /usr/sbin/unhide-linux26 [ OK ] /usr/local/bin/rkhunter [ OK ] [Press <ENTER> to continue] [2]+ Stopped /usr/local/bin/rkhunter --check www:/usr/src/rkhunter-1.3.4#cat /var/log/rkhunter.log [00:28:21] Running Rootkit Hunter version 1.3.4 on www [00:28:21] [00:28:21] Info: Start date is Thu Aug 6 00:28:21 EST 2009 [00:28:21] [00:28:21] Checking configuration file and command-line options... [00:28:21] Info: Detected operating system is 'Linux' [00:28:21] Info: Found O/S name: Debian 5.0 [00:28:21] Info: Command line is /usr/local/bin/rkhunter --check [00:28:21] Info: Environment shell is /bin/bash; rkhunter is using bash [00:28:21] Info: Using configuration file '/etc/rkhunter.conf' [00:28:21] Info: Installation directory is '/usr/local' [00:28:21] Info: Using language 'en' [00:28:21] Info: Using '/var/lib/rkhunter/db' as the database directory [00:28:21] Info: Using '/usr/local/lib/rkhunter/scripts' as the support script directory [00:28:21] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin /bin /usr/bin /sbin /usr/sbin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec' as the command directories [00:28:21] Info: Using '/' as the root directory by default [00:28:22] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory [00:28:22] Info: No mail-on-warning address configured [00:28:22] Info: X will be automatically detected [00:28:22] Info: Found the 'diff' command: /usr/bin/diff [00:28:22] Info: Found the 'file' command: /usr/bin/file [00:28:22] Info: Found the 'find' command: /usr/bin/find [00:28:22] Info: Found the 'ifconfig' command: /sbin/ifconfig [00:28:22] Info: Found the 'ip' command: /sbin/ip [00:28:22] Info: Found the 'ldd' command: /usr/bin/ldd [00:28:22] Info: Found the 'lsattr' command: /usr/bin/lsattr [00:28:22] Info: Found the 'lsmod' command: /sbin/lsmod [00:28:22] Info: Found the 'lsof' command: /usr/bin/lsof [00:28:22] Info: Found the 'mktemp' command: /bin/mktemp [00:28:22] Info: Found the 'netstat' command: /bin/netstat [00:28:22] Info: Found the 'perl' command: /usr/bin/perl [00:28:22] Info: Found the 'ps' command: /bin/ps [00:28:22] Info: Found the 'pwd' command: /bin/pwd [00:28:22] Info: Found the 'readlink' command: /bin/readlink [00:28:22] Info: Found the 'sort' command: /usr/bin/sort [00:28:22] Info: Found the 'stat' command: /usr/bin/stat [00:28:22] Info: Found the 'strings' command: /usr/bin/strings [00:28:23] Info: Found the 'uniq' command: /usr/bin/uniq [00:28:23] Info: System is not using prelinking [00:28:23] Info: Using the '/usr/bin/sha1sum' command for the file hash checks [00:28:23] Info: Stored hash values used hash function '/usr/bin/sha1sum' [00:28:23] Info: Stored hash values did not use a package manager [00:28:23] Info: The hash function field index is set to 1 [00:28:23] Info: No package manager specified: using hash function '/usr/bin/sha1sum' [00:28:23] Info: Previous file attributes were stored [00:28:23] Info: Enabled tests are: all [00:28:23] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps [00:28:23] Info: Found ksym file '/proc/kallsyms' [00:28:23] [00:28:23] Checking if the O/S has changed since last time... [00:28:23] Info: Nothing seems to have changed [00:28:23] [00:28:23] Starting system checks... [00:28:23] [00:28:23] Checking system commands... [00:28:23] Info: Starting test name 'system_commands' [00:28:23] [00:28:23] Performing 'strings' command checks [00:28:24] Info: Starting test name 'strings' [00:28:24] Scanning for string /usr/sbin/ntpsx [ OK ] [00:28:24] Scanning for string /usr/lib/.../ls [ OK ] [00:28:24] Scanning for string /usr/lib/.../netstat [ OK ] [00:28:24] Scanning for string /usr/lib/.../lsof [ OK ] [00:28:24] Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ] [00:28:24] Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ] [00:28:24] Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ] [00:28:24] Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ] [00:28:24] Scanning for string /usr/lib/.../uconf.inv [ OK ] [00:28:24] Scanning for string /usr/lib/.../psr [ OK ] [00:28:25] Scanning for string /usr/lib/.../find [ OK ] [00:28:25] Scanning for string /usr/lib/.../pstree [ OK ] [00:28:25] Scanning for string /usr/lib/.../slocate [ OK ] [00:28:25] Scanning for string /usr/lib/.../du [ OK ] [00:28:25] Scanning for string /usr/lib/.../top [ OK ] [00:28:25] Scanning for string /usr/lib/... [ OK ] [00:28:25] Scanning for string /usr/lib/.../bkit-ssh [ OK ] [00:28:25] Scanning for string /usr/lib/.bkit- [ OK ] [00:28:25] Scanning for string /tmp/.bkp [ OK ] [00:28:25] Scanning for string /tmp/.cinik [ OK ] [00:28:25] Scanning for string /tmp/.font-unix/.cinik [ OK ] [00:28:26] Scanning for string /lib/.sso [ OK ] [00:28:26] Scanning for string /lib/.so [ OK ] [00:28:26] Scanning for string /var/run/...dica/clean [ OK ] [00:28:26] Scanning for string /var/run/...dica/xl [ OK ] [00:28:26] Scanning for string /var/run/...dica/xdr [ OK ] [00:28:26] Scanning for string /var/run/...dica/psg [ OK ] [00:28:26] Scanning for string /var/run/...dica/secure [ OK ] [00:28:26] Scanning for string /var/run/...dica/rdx [ OK ] [00:28:26] Scanning for string /var/run/...dica/va [ OK ] [00:28:26] Scanning for string /var/run/...dica/cl.sh [ OK ] [00:28:27] Scanning for string /usr/bin/.etc [ OK ] [00:28:27] Scanning for string /usr/lib/.fx/sched_host.2 [ OK ] [00:28:27] Scanning for string /usr/lib/.fx/random_d.2 [ OK ] [00:28:27] Scanning for string /usr/lib/.fx/set_pid.2 [ OK ] [00:28:27] Scanning for string /usr/lib/.fx/cons.saver [ OK ] [00:28:27] Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ] [00:28:27] Scanning for string /bin/sysback [ OK ] [00:28:27] Scanning for string /usr/local/bin/sysback [ OK ] [00:28:27] Scanning for string /usr/lib/.tbd [ OK ] [00:28:27] Scanning for string /dev/.lib/lib/lib/t0rns [ OK ] [00:28:27] Scanning for string /dev/.lib/lib/lib/du [ OK ] [00:28:28] Scanning for string /dev/.lib/lib/lib/ls [ OK ] [00:28:28] Scanning for string /dev/.lib/lib/lib/t0rnsb [ OK ] [00:28:28] Scanning for string /dev/.lib/lib/lib/ps [ OK ] [00:28:28] Scanning for string /dev/.lib/lib/lib/t0rnp [ OK ] [00:28:28] Scanning for string /dev/.lib/lib/lib/find [ OK ] [00:28:28] Scanning for string /dev/.lib/lib/lib/ifconfig [ OK ] [00:28:28] Scanning for string /dev/.lib/lib/lib/pg [ OK ] [00:28:28] Scanning for string /dev/.lib/lib/lib/ssh.tgz [ OK ] [00:28:28] Scanning for string /dev/.lib/lib/lib/top [ OK ] [00:28:28] Scanning for string /dev/.lib/lib/lib/sz [ OK ] [00:28:29] Scanning for string /dev/.lib/lib/lib/login [ OK ] [00:28:29] Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ] [00:28:29] Scanning for string /dev/.lib/lib/lib/1i0n.sh [ OK ] [00:28:29] Scanning for string /dev/.lib/lib/lib/pstree [ OK ] [00:28:29] Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ] [00:28:29] Scanning for string /dev/.lib/lib/lib/mjy [ OK ] [00:28:29] Scanning for string /dev/.lib/lib/lib/sush [ OK ] [00:28:29] Scanning for string /dev/.lib/lib/lib/tfn [ OK ] [00:28:29] Scanning for string /dev/.lib/lib/lib/name [ OK ] [00:28:29] Scanning for string /dev/.lib/lib/lib/getip.sh [ OK ] [00:28:30] Scanning for string /usr/info/.torn/sh* [ OK ] [00:28:30] Scanning for string /usr/src/.puta/.1addr [ OK ] [00:28:30] Scanning for string /usr/src/.puta/.1file [ OK ] [00:28:30] Scanning for string /usr/src/.puta/.1proc [ OK ] [00:28:30] Scanning for string /usr/src/.puta/.1logz [ OK ] [00:28:30] Scanning for string /usr/info/.t0rn [ OK ] [00:28:30] Scanning for string /dev/.lib [ OK ] [00:28:30] Scanning for string /dev/.lib/lib [ OK ] [00:28:30] Scanning for string /dev/.lib/lib/lib [ OK ] [00:28:30] Scanning for string /dev/.lib/lib/lib/dev [ OK ] [00:28:30] Scanning for string /dev/.lib/lib/scan [ OK ] [00:28:31] Scanning for string /usr/src/.puta [ OK ] [00:28:31] Scanning for string /usr/man/man1/man1 [ OK ] [00:28:31] Scanning for string /usr/man/man1/man1/lib [ OK ] [00:28:31] Scanning for string /usr/man/man1/man1/lib/.lib [ OK ] [00:28:31] Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ] [00:28:31] [00:28:31] Performing 'shared libraries' checks [00:28:31] Info: Starting test name 'shared_libs' [00:28:31] Checking for preloading variables [ None found ] [00:28:31] Checking for preload file [ Not found ] [00:28:31] Info: Starting test name 'shared_libs_path' [00:28:32] Checking LD_LIBRARY_PATH variable [ Not found ] [00:28:32] [00:28:32] Performing file properties checks [00:28:32] Info: Starting test name 'properties' [00:28:32] Checking for prerequisites [ OK ] [00:28:32] /bin/bash [ OK ] [00:28:32] /bin/cat [ OK ] [00:28:33] /bin/chmod [ OK ] [00:28:33] /bin/chown [ OK ] [00:28:33] /bin/cp [ OK ] [00:28:34] /bin/date [ OK ] [00:28:34] /bin/df [ OK ] [00:28:34] /bin/dmesg [ OK ] [00:28:35] /bin/echo [ OK ] [00:28:35] /bin/ed [ OK ] [00:28:35] /bin/egrep [ OK ] [00:28:36] /bin/fgrep [ OK ] [00:28:36] /bin/fuser [ OK ] [00:28:36] /bin/grep [ OK ] [00:28:37] /bin/ip [ OK ] [00:28:37] /bin/kill [ OK ] [00:28:37] /bin/login [ OK ] [00:28:38] /bin/ls [ OK ] [00:28:38] /bin/lsmod [ OK ] [00:28:38] /bin/ls [ OK ] [00:28:38] /bin/lsmod [ OK ] [00:28:38] /bin/mktemp [ OK ] [00:28:39] /bin/more [ OK ] [00:28:39] /bin/mount [ OK ] [00:28:39] /bin/mv [ OK ] [00:28:40] /bin/netstat [ OK ] [00:28:40] /bin/ps [ OK ] [00:28:40] /bin/pwd [ OK ] [00:28:41] /bin/readlink [ OK ] [00:28:41] /bin/sed [ OK ] [00:28:41] /bin/sh [ OK ] [00:28:42] /bin/su [ OK ] [00:28:42] /bin/touch [ OK ] [00:28:42] /bin/uname [ OK ] [00:28:43] /bin/which [ Warning ] [00:28:43] Warning: The command '/bin/which' has been replaced by a script: /bin/which: POSIX shell script text executable [00:28:43] /usr/bin/awk [ OK ] [00:28:44] /usr/bin/basename [ OK ] [00:28:44] /usr/bin/chattr [ OK ] [00:28:44] /usr/bin/cut [ OK ] [00:28:45] /usr/bin/diff [ OK ] [00:28:45] /usr/bin/dirname [ OK ] [00:28:45] /usr/bin/dpkg [ OK ] [00:28:46] /usr/bin/dpkg-query [ OK ] [00:28:46] /usr/bin/du [ OK ] [00:28:46] /usr/bin/env [ OK ] [00:28:46] /usr/bin/file [ OK ] [00:28:47] /usr/bin/find [ OK ] [00:28:47] /usr/bin/GET [ OK ] [00:28:47] /usr/bin/groups [ Warning ] [00:28:47] Warning: The command '/usr/bin/groups' has been replaced by a script: /usr/bin/groups: POSIX shell script text executable [00:28:48] /usr/bin/head [ OK ] [00:28:48] /usr/bin/id [ OK ] [00:28:48] /usr/bin/killall [ OK ] [00:28:49] /usr/bin/last [ OK ] [00:28:49] /usr/bin/lastlog [ OK ] [00:28:49] /usr/bin/ldd [ Warning ] [00:28:49] Warning: The command '/usr/bin/ldd' has been replaced by a script: /usr/bin/ldd: Bourne-Again shell script text executable [00:28:50] /usr/bin/logger [ OK ] [00:28:50] /usr/bin/lsattr [ OK ] [00:28:50] /usr/bin/lsof [ OK ] [00:28:50] /usr/bin/mail [ OK ] [00:28:51] /usr/bin/md5sum [ OK ] [00:28:51] /usr/bin/newgrp [ OK ] [00:28:51] /usr/bin/passwd [ OK ] [00:28:52] /usr/bin/perl [ OK ] [00:28:52] /usr/bin/pstree [ OK ] [00:28:52] /usr/bin/runcon [ OK ] [00:28:53] /usr/bin/sha1sum [ OK ] [00:28:53] /usr/bin/size [ OK ] [00:28:53] /usr/bin/sort [ OK ] [00:28:54] /usr/bin/stat [ OK ] [00:28:54] /usr/bin/strings [ OK ] [00:28:54] /usr/bin/sudo [ OK ] [00:28:54] /usr/bin/tail [ OK ] [00:28:55] /usr/bin/test [ OK ] [00:28:55] /usr/bin/top [ OK ] [00:28:55] /usr/bin/touch [ OK ] [00:28:56] /usr/bin/tr [ OK ] [00:28:56] /usr/bin/uniq [ OK ] [00:28:56] /usr/bin/users [ OK ] [00:28:56] /usr/bin/vmstat [ OK ] [00:28:57] /usr/bin/w [ OK ] [00:28:57] /usr/bin/watch [ OK ] [00:28:57] /usr/bin/wc [ OK ] [00:28:58] /usr/bin/wget [ OK ] [00:28:58] /usr/bin/whatis [ OK ] [00:28:58] /usr/bin/whereis [ OK ] [00:28:58] /usr/bin/which [ OK ] [00:28:59] /usr/bin/who [ OK ] [00:28:59] /usr/bin/whoami [ OK ] [00:28:59] /usr/bin/gawk [ OK ] [00:28:59] /usr/bin/lwp-request [ Warning ] [00:28:59] Warning: The command '/usr/bin/lwp-request' has been replaced by a script: /usr/bin/lwp-request: a /usr/bin/perl -w script text executable [00:29:00] /usr/bin/bsd-mailx [ OK ] [00:29:00] /usr/bin/w.procps [ OK ] [00:29:01] /sbin/depmod [ OK ] [00:29:01] /sbin/ifconfig [ OK ] [00:29:02] /sbin/ifdown [ OK ] [00:29:02] /sbin/ifup [ OK ] [00:29:02] /sbin/init [ OK ] [00:29:02] /sbin/insmod [ OK ] [00:29:03] /sbin/ip [ OK ] [00:29:03] /sbin/lsmod [ OK ] [00:29:03] /sbin/modinfo [ OK ] [00:29:04] /sbin/modprobe [ OK ] [00:29:04] /sbin/rmmod [ OK ] [00:29:05] /sbin/runlevel [ OK ] [00:29:05] /sbin/sulogin [ OK ] [00:29:06] /sbin/sysctl [ OK ] [00:29:06] /usr/sbin/adduser [ Warning ] [00:29:06] Warning: The command '/usr/sbin/adduser' has been replaced by a script: /usr/sbin/adduser: a /usr/bin/perl script text executable [00:29:07] /usr/sbin/chroot [ OK ] [00:29:07] /usr/sbin/cron [ OK ] [00:29:08] /usr/sbin/groupadd [ OK ] [00:29:08] /usr/sbin/groupdel [ OK ] [00:29:08] /usr/sbin/groupmod [ OK ] [00:29:09] /usr/sbin/grpck [ OK ] [00:29:09] /usr/sbin/nologin [ OK ] [00:29:10] /usr/sbin/pwck [ OK ] [00:29:10] /usr/sbin/rsyslogd [ OK ] [00:29:11] /usr/sbin/tcpd [ OK ] [00:29:11] /usr/sbin/unhide [ OK ] [00:29:12] /usr/sbin/useradd [ OK ] [00:29:12] /usr/sbin/userdel [ OK ] [00:29:12] /usr/sbin/usermod [ OK ] [00:29:12] /usr/sbin/vipw [ OK ] [00:29:13] /usr/sbin/unhide-linux26 [ OK ] [00:29:15] /usr/local/bin/rkhunter [ OK ] Thanks, Brenton Send instant messages to your online friends http://au.messenger.yahoo.com ------------------------------------------------------------------------------ Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day trial. Simplify your report design, integration and deployment - and focus on what you do best, core application coding. Discover what's new with Crystal Reports now. http://p.sf.net/sfu/bobj-july _______________________________________________ Rkhunter-users mailing list Rkhunter-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/rkhunter-users