possible rootkit (false possitive???)











up vote
1
down vote

favorite
1












good day:



when I do a rkhunter --check shows me that I have possible rootkits:



/usr/bin/rkhunter: 14795: [: /usr/lib/firefox/firefox: unexpected operator
/usr/bin/rkhunter: 14795: [: /usr/lib/firefox/firefox: unexpected operator
/usr/bin/rkhunter: 14795: [: /usr/bin/konsole: unexpected operator
Checking for suspicious (large) shared memory segments [ Warning ]


In /var/log/rkhunter.log show me this:



Warning: The following suspicious (large) shared memory segments have been found:
[21:17:06] Process: /usr/lib/firefox/firefox (deleted) PID: 9750 Owner: louie Size: 4,0MB (configured size allowed: 1,0MB)
[21:17:07] Process: /usr/lib/firefox/firefox (deleted) PID: 9750 Owner: louie Size: 4,0MB (configured size allowed: 1,0MB)
[21:17:07] Process: /usr/bin/konsole (deleted) PID: 11415 Owner: louie Size: 1,7MB (configured size allowed: 1,0MB)


With Chkrootkit only show me an infection: "tcpd" I have read in several places that it is a false positive.



Rkhunter can also be false positives? Thanks.










share|improve this question
























  • rkhunter does indeed encounter false positives, notably tcpd
    – Nonny Moose
    Jun 6 at 1:59















up vote
1
down vote

favorite
1












good day:



when I do a rkhunter --check shows me that I have possible rootkits:



/usr/bin/rkhunter: 14795: [: /usr/lib/firefox/firefox: unexpected operator
/usr/bin/rkhunter: 14795: [: /usr/lib/firefox/firefox: unexpected operator
/usr/bin/rkhunter: 14795: [: /usr/bin/konsole: unexpected operator
Checking for suspicious (large) shared memory segments [ Warning ]


In /var/log/rkhunter.log show me this:



Warning: The following suspicious (large) shared memory segments have been found:
[21:17:06] Process: /usr/lib/firefox/firefox (deleted) PID: 9750 Owner: louie Size: 4,0MB (configured size allowed: 1,0MB)
[21:17:07] Process: /usr/lib/firefox/firefox (deleted) PID: 9750 Owner: louie Size: 4,0MB (configured size allowed: 1,0MB)
[21:17:07] Process: /usr/bin/konsole (deleted) PID: 11415 Owner: louie Size: 1,7MB (configured size allowed: 1,0MB)


With Chkrootkit only show me an infection: "tcpd" I have read in several places that it is a false positive.



Rkhunter can also be false positives? Thanks.










share|improve this question
























  • rkhunter does indeed encounter false positives, notably tcpd
    – Nonny Moose
    Jun 6 at 1:59













up vote
1
down vote

favorite
1









up vote
1
down vote

favorite
1






1





good day:



when I do a rkhunter --check shows me that I have possible rootkits:



/usr/bin/rkhunter: 14795: [: /usr/lib/firefox/firefox: unexpected operator
/usr/bin/rkhunter: 14795: [: /usr/lib/firefox/firefox: unexpected operator
/usr/bin/rkhunter: 14795: [: /usr/bin/konsole: unexpected operator
Checking for suspicious (large) shared memory segments [ Warning ]


In /var/log/rkhunter.log show me this:



Warning: The following suspicious (large) shared memory segments have been found:
[21:17:06] Process: /usr/lib/firefox/firefox (deleted) PID: 9750 Owner: louie Size: 4,0MB (configured size allowed: 1,0MB)
[21:17:07] Process: /usr/lib/firefox/firefox (deleted) PID: 9750 Owner: louie Size: 4,0MB (configured size allowed: 1,0MB)
[21:17:07] Process: /usr/bin/konsole (deleted) PID: 11415 Owner: louie Size: 1,7MB (configured size allowed: 1,0MB)


With Chkrootkit only show me an infection: "tcpd" I have read in several places that it is a false positive.



Rkhunter can also be false positives? Thanks.










share|improve this question















good day:



when I do a rkhunter --check shows me that I have possible rootkits:



/usr/bin/rkhunter: 14795: [: /usr/lib/firefox/firefox: unexpected operator
/usr/bin/rkhunter: 14795: [: /usr/lib/firefox/firefox: unexpected operator
/usr/bin/rkhunter: 14795: [: /usr/bin/konsole: unexpected operator
Checking for suspicious (large) shared memory segments [ Warning ]


In /var/log/rkhunter.log show me this:



Warning: The following suspicious (large) shared memory segments have been found:
[21:17:06] Process: /usr/lib/firefox/firefox (deleted) PID: 9750 Owner: louie Size: 4,0MB (configured size allowed: 1,0MB)
[21:17:07] Process: /usr/lib/firefox/firefox (deleted) PID: 9750 Owner: louie Size: 4,0MB (configured size allowed: 1,0MB)
[21:17:07] Process: /usr/bin/konsole (deleted) PID: 11415 Owner: louie Size: 1,7MB (configured size allowed: 1,0MB)


With Chkrootkit only show me an infection: "tcpd" I have read in several places that it is a false positive.



Rkhunter can also be false positives? Thanks.







kde5 rootkit rkhunter chkrootkit






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Nov 22 at 22:22









abu_bua

3,03881023




3,03881023










asked Jun 5 at 19:35









louiesanchezdj

9218




9218












  • rkhunter does indeed encounter false positives, notably tcpd
    – Nonny Moose
    Jun 6 at 1:59


















  • rkhunter does indeed encounter false positives, notably tcpd
    – Nonny Moose
    Jun 6 at 1:59
















rkhunter does indeed encounter false positives, notably tcpd
– Nonny Moose
Jun 6 at 1:59




rkhunter does indeed encounter false positives, notably tcpd
– Nonny Moose
Jun 6 at 1:59















active

oldest

votes











Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "89"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














 

draft saved


draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1043922%2fpossible-rootkit-false-possitive%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown






























active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes
















 

draft saved


draft discarded



















































 


draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1043922%2fpossible-rootkit-false-possitive%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

How did Captain America manage to do this?

迪纳利

南乌拉尔铁路局